1. The Short Version
- Your passport is never stored on our servers. Your passport details and health declarations are encrypted on your device (WebCrypto AES-GCM) and stay there, apart from the brief OCR transit and the extension filling described below.
- We could not read your passport data from our servers if we wanted to. For data kept on your device, the encryption key is generated and kept only on your device. We hold no key that can decrypt it, and none of it is transmitted to us. This includes the passport profile you can save for reuse. It lives encrypted on your device, and our servers cannot decrypt or read it. What this protects against is anyone reading your passport from our side, including us; it is not a defense against software running on your own computer, such as a malicious browser extension. You retain all rights to your information.
- Your answers stay on your device too. The answers you give while preparing a form are saved only in your browser. That covers dates, flights, accommodation, purpose of visit, and contact details. They are not stored on our servers, so we have no way to read them.
- OCR photos pass through; they do not stay. When you scan a passport photo, the image travels through our API in memory to a cloud OCR provider and is discarded immediately. We never write it to disk.
- Beyond that, our database knows only who you are, where you first arrived from, what Premium you hold, what you paid, a record of each card you send to the visayes helper, and a minimal record per draft. The draft record holds the country, arrival date, and number of travelers. It holds no passport details and no health declarations.
- Analytics without cookies. Self-hosted Umami. It sets no cookies and stores no name, email, or IP address. Your address is used only in passing, to count you once for the day. Logging in uses strictly necessary session cookies, described under Cookies below.
2. Information We Handle
Stored by us (server-side):
- Account identity: email address and login provider. If you use “Sign in with Google”, Google also gives us your name and profile picture, and an identifier for your Google account. We use them only to create and recognize your account. We ask Google for nothing else, so not your Gmail, contacts, calendar, or files. We do not sell or share what Google gives us. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
- Premium: for each purchase, what it covers, when it starts and ends, when it was first used, and whether it was refunded or ended. Cards sent to the visayes helper: for each one, its country, number of travelers, whether it used your free allowance or your Premium, and how far it got on the official site. That last part is one of three marks: every field filled in, the submit button clicked, or your submission confirmed.
- Where you first arrived from: the first page you opened on visayes and the address of the site that sent you there, saved with your account when you sign up, so we can see which pages bring people who go on to use visayes. Until you sign up, it is kept only in your browser, and if you never sign up, it is never sent to us. With Do Not Track on, we do not record it.
- Payment records, processed by Stripe, including the IP address your browser used when you opened the checkout page. We keep that address to detect payment fraud and to defend chargebacks, and delete it from our records 24 months after the payment.
- Draft record: for each entry-form draft, the country, arrival date, number of travelers, its status, and when we last sent you a reminder email.
- OCR usage audit: for each scan, the time, which of the two providers handled it, and whether it succeeded or failed. Because the provider is chosen by whether the passport is a mainland-China one, this row tells us that much and nothing more. It holds no passport number, no name, and no image.
- Feedback you send: your message, an optional rating, and contact details if you choose to leave them. It reaches us as email in our support inbox, not as a row in our database.
- Security audit log: we record who did it, what it was, when, and whether it succeeded. It covers actions on your Premium, your free allowance or your payments, actions that delete a draft, and security events on your account such as logins. It carries no form content and no passport data.
- Error reports: when something breaks, our own server records the route, the error message, and a short stack trace. If your browser is the thing that broke, it sends us the page address and technical details of the error. Neither carries your form answers.
- Analytics events: which pages you open, where you arrived from, and a few product signals, such as how far you get in an official government entry form and whether the visayes helper is installed. They carry no name, no email address, and no IP address.
Kept on your device (never stored by us): passport details, your saved passport profile, health declarations including vaccine documents, and every answer you give while preparing a form. These are encrypted locally and leave your device only in the OCR transit and extension filling described in section 3. Passport details are not even written to your own disk unless you tick “Keep passport details on this device for next time” while filling in a form, or save a passport on your account page; without that they live only in the page you are filling in, and are gone when you close it.
visayes is the data controller for the server-side data described in this section. We process account, Premium, and payment data, the record of each card you send to the visayes helper, and your draft records, reminder emails about your own drafts included, to perform our contract with you; OCR images to provide the scan you request; feedback because you choose to send it; security and anti-abuse logs in our legitimate interest of keeping the Service safe; where you first arrived from, in our legitimate interest of understanding which of our pages work (GDPR Art. 6(1)(f)); and the payment IP address in our legitimate interest of preventing payment fraud (GDPR Art. 6(1)(f); see Recital 47) and of defending payment disputes. Data that stays on your device, in your browser or in the extension, is never transmitted to us, so we are not in a position to access, correct, or delete it; you control it directly, and clearing it is described in section 8.
3. How Information Moves
- OCR: your passport photo transits our API in memory to the OCR provider (section 5), and is immediately discarded. Recognized text returns to your browser and merges into your local, encrypted draft. We keep no copy of either.
- Draft record: as you prepare a form, we record that you have a card in progress for a country, with its arrival date and number of travelers, so your account page can show it and we can remind you when a submission window opens. Your answers themselves are not sent; they stay in your browser.
- Filling official forms: when you use the extension, your prepared data moves from your device directly into the official website’s form fields, inside your browser. It does not pass through our servers.
4. What We Never Do
We do not sell or share your data. We do not run third-party advertising or trackers. We do not build profiles of you. We do not store your passport details, your health declarations, or your form answers on our servers, and we have no way to read them.
We make no automated decisions about you that have legal effects. Automatic limits do exist to stop abuse, and one can block a request or an account; if that happens to you, email us and a person will look at it.
5. Third-Party Services
For what we cannot self-host, we use the providers below, under their standard data-processing terms and only for the purposes described here. Review their policies if you want the details.
- OCR for mainland-China passports: Tencent Cloud OCR (operated in mainland China) · policy. All other passports: Microsoft Azure Document Intelligence · policy. You can always type your passport details in by hand instead of scanning; then no image leaves your device.
- Payments: Stripe · policy. Stripe handles your card; we never see the full number.
- Authentication: Supabase Auth; optional Google OAuth for “Sign in with Google”.
- Email: Resend, for transactional email such as feedback receipts and the reminder email we send when a draft’s official submission window opens. Every reminder email includes a one-click unsubscribe. Feedback you send is not stored in our database. It is delivered to our support inbox and lives there as email.
- Error tracking: self-hosted GlitchTip, so error logs stay on our own server.
- Analytics: self-hosted Umami, cookie-free.
- Cloudflare: our site sits behind Cloudflare, so it sees the network requests you make to us. Cloudflare Turnstile runs the human check on the log-in and sign-up dialog. Cloudflare R2 holds our encrypted off-site database backups, and Cloudflare Email Routing forwards mail sent to our support address · policy
This policy covers visayes only. Official government websites and the providers named above have their own policies. While you are on their site theirs applies and ours does not.
6. Cookies
Logging in sets a strictly necessary session cookie. By default it ends when you close your browser. If you tick “Remember me” when you log in or sign up, it lasts until you log out or for up to 400 days. The checkout page, and no other page on this site, loads Stripe’s payment script, which sets its own cookies here and reads device and activity signals so Stripe can detect card fraud. Stripe states it never uses that data for advertising and never sells or rents it.
We set no analytics cookies and no advertising cookies. Nothing we set here can be read by another website.
Our analytics honors your browser’s Do Not Track setting: with it on, your visit is not counted at all.
7. Where Data Lives and Travels
- Account, Premium, and payment data, the records of cards sent to the visayes helper, and draft records: our PostgreSQL database, hosted with Supabase in Singapore. Our own server, which holds the encrypted backups, is in the United States, and off-site copies go to Cloudflare R2.
- Passport details, health declarations, and your form answers: your device only (encrypted), except the OCR image transit described in section 3.
- OCR images: for mainland-China passports, Tencent Cloud in Guangzhou, mainland China. That region is fixed in our code. For all other passports, Microsoft Azure Document Intelligence, in the single Azure region our account is provisioned in. Which one handles your scan depends only on the passport you select.
- Analytics events: our own server in the United States.
- If you are in the EEA or the UK, your account data is therefore processed outside your country; where that happens we rely on our providers’ standard contractual clauses (SCCs).
- If you use visayes from mainland China: your account data (email, Premium, payments) and your draft records are stored and processed outside mainland China.
8. Retention
Account data is kept while your account exists, and deleted when your account is deleted. Where you first arrived from is account data, and is deleted with it. Two things outlive the account by design. The first is payment records, holding what each payment bought and whether it was refunded, which we and Stripe are required to retain for as long as the tax and accounting law we are subject to requires. The second is our security audit log, which records that an action happened (who, what, when, and whether it succeeded) with no form content in it. When your account is deleted we also strip your account identifier out of that log; an entry about a payment still refers to that payment’s record. The IP address on a payment record is the exception to that tax retention: we delete it from our records 24 months after the payment. We delete feedback email once it is no longer useful. Analytics events carry no personal data and have no fixed retention period. Locally stored data stays on your device until you delete it or clear your browser storage.
Backups: our database backups hold the account data and draft records described above, never your passport details, health declarations, or form answers, because those are never on our servers to begin with. Backup copies are destroyed as backups rotate on a short, fixed cycle.
Draft records: for cards you complete, we keep the draft record (country, arrival date, number of travelers) as your trip history. If you delete a draft yourself, that record is deleted from our database. What remains is the record of each time you sent it to the visayes helper (section 2), which is how we know whether you have used your free allowance for that country. It carries the deleted draft’s identifier and the number of travelers, never your answers.
9. Your Rights
You retain all rights to your information. Data-protection laws (GDPR, CCPA, China PIPL, and others) give you the rights to:
- Access a copy of the data we hold about you.
- Delete your account and all associated data (except records we are legally required to keep, such as payment records). If you ask within 7 days of the day you paid for Premium, and that Premium has not been used, we refund it first. See Payment Terms, section 10.
- Export your data in a machine-readable format (JSON).
- Correct inaccurate data.
- Object to specific processing, or restrict it.
- Withdraw consent where processing is based on consent.
Email support@visayesapp.com. We will ask you to send the request from the email address on the account before we act on it. If you ask us to delete your account within 7 days of the day you paid for Premium, and that Premium has not been used, we refund it first and then delete (Payment Terms, section 10); we complete closures within 14 days. We answer within 30 days; if a request is complex we may need up to two further months, and we will tell you if that happens. You may also complain to the data-protection authority where you live.
10. Filling In for Others
If you prepare forms for fellow travelers, their information is handled exactly like yours: their passport details, health declarations, and answers stay on your device. You must have their permission, or their guardian’s (see Terms of Service).
If you believe someone entered another person’s data without permission, contact us and we will help. Their details stay on the device that entered them, in your browser and in the extension if you send the card to it, and are deleted when that draft is deleted.
11. Children
visayes accounts are for adults (18+). We do not knowingly collect children’s data server-side. A traveler profile for a minor, such as your child’s entry form, is entered under a guardian’s authority and stays encrypted on your device, subject only to the OCR transit described in section 3.
12. Data Breach Notification
If a breach affects your personal data, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where required (GDPR Art. 33), and, where the law requires it, affected users without undue delay (GDPR Art. 34).
13. Security
Local data is encrypted with WebCrypto AES-GCM. Transport uses TLS. Server-side, we keep only the minimum described in section 2, protected by row-level security and access controls.
Your passport details, health declarations, and form answers are encrypted on your device and are not sent to our servers, apart from the OCR transit in section 3, which we never store. So there is no key for us to hold and nothing for us to be compelled to hand over.
No security is perfect. That is exactly why our architecture keeps your passport off our servers in the first place.
14. The Browser Extension
The visayes helper is a browser extension you install yourself. It fills the official government entry form in on the official government site, in front of you. This policy covers it, and this section describes everything it does with your data.
What it holds. Only the entry-form details you choose to send it from visayes: the travelers’ passport fields, the trip answers, and an arrival date. Nothing is read off the page you are on, and nothing is collected from your browsing.
Where it holds them. In the extension’s own storage on your computer, encrypted with AES-GCM. The key is generated on your device, cannot be exported by any code including ours, and is never sent anywhere.
How long. Once a card is submitted, that traveler’s answers and passport number are erased on the spot. The traveler’s name stays, so the extension can show you who is done. A card is erased in full a few days after you send it to the extension, whether or not you used it. A few small bookkeeping records outlive the card, so that the same trip is never counted twice, so the extension can show you how far along a group is, and so a late confirmation from the official site is still recognized. They carry no passport details and no form answers beyond the arrival date of the trip you were preparing, each is dropped once it is stale or replaced, and they stay in the extension’s storage on your computer.
What leaves your device. Two kinds of request, both to visayes and neither carrying your form data. Small progress reports as a card is filled in, submitted, confirmed, or canceled. Each carries a one-time trip identifier and the step name and never your form data. They are how we know whether your free allowance or your Premium has been used. And one download of a small configuration file that tells the extension what the official site’s fields are currently called; it is sent without cookies and without any data of yours.
What never leaves. There is no analytics and no usage tracking in the extension. Its diagnostic log is written to your own browser storage and is never sent to us. We do not sell or share anything the extension holds, because we never receive it. Our use of information received from the visayes helper adheres to the policies of each store that distributes it, including the Chrome Web Store User Data Policy and its Limited Use requirements.
Removing it. Uninstalling the extension deletes everything it holds, including the encryption key. You can also delete a single card from the extension’s panel or from your account page.
15. Changes; Contact
We may update this policy. Material changes will be announced by email or in-product notification; continued use after notice constitutes acceptance.
If the Service changes hands, the account and payment data described in section 2 would pass to the new operator. We will tell you by email before that happens, so you can delete your account first.
visayes is operated by an individual developer. You can reach us at support@visayesapp.com.