USCIS Developer Integration
USCIS Case-Status API — Privacy & Data Practices
This page covers one specific thing: how Brown Law, PLLC handles data in its integration with the USCIS Case Status API. Odin’s Rune is the application that queries the API — it looks up a case’s status by its receipt number and writes the result into Ether, the firm’s own case-management system. It is one integration using a single API key, for firm-internal use only, and which staff account ran a given lookup is recorded programmatically. This page is separate from our main platform terms. We do not sell this data and we do not share it with anyone outside the firm.
1. What this integration does (scope)
- Odin’s Rune sends a USCIS receipt number to the USCIS Case Status API, receives that case’s current status, and writes it into Ether (the firm’s case-management system).
- We cache (save) the result in the firm’s own data store so our staff can see case progress without re-querying.
- Use is firm-internal only, through a single API key. Brown Law, PLLC is the only user of this integration and the data it returns.
2. The specific data we collect
- The USCIS receipt numbers we look up.
- The case-status results USCIS returns — such as the status text, the status date, the form type, and related notice information.
- The link between a receipt number and the firm’s own client or matter record.
- Basic technical logs — the date and time of a lookup and which staff account ran it — for security and audit.
We do not collect biometric data, government-account passwords, or anything USCIS does not return in a status response.
3. How we use the data
We use it only to track and manage our own clients’ immigration cases inside the firm: to see what is pending, what has changed, and what needs action. We do not use it for advertising, profiling, or any purpose outside the client’s case.
De-identified or anonymized data: we do not create, use, or share de-identified or anonymized versions of this data with anyone.
4. Who we share it with
No one outside Brown Law, PLLC controls or uses this data. We do not share it with any partner, affiliate, advertiser, or data broker, and we do not sell it. Two infrastructure facts, disclosed for completeness: the data is queried against the USCIS API itself (under USCIS’s own terms), and the firm’s copy is hosted on Microsoft Azure, our infrastructure provider, which stores it under contract on our behalf and may not access it for its own purposes (see Section 8).
5. We do not sell your data
We do not sell, rent, or trade this data. There is no exception.
6. Your choices, the risks, and the limits of sharing
- Because we do not share this data, there is no third-party sharing for you to opt out of.
- The only data flow is between the firm and USCIS, at the firm’s direction, to manage your own case.
- Limit we cannot control: once a query reaches USCIS, USCIS’s own privacy practices govern what USCIS does on its side. This page covers what the firm does, not what the government does.
7. Effect on other people
A case record can mention family members or derivatives on the same petition. We treat that information as confidential client data and use it only for that case — never for anything else.
8. Third parties and active consent
The firm’s copy of this data is hosted on Microsoft Azure (Azure Database for PostgreSQL and Azure Container Apps, in a United States region), which provides the secure infrastructure that runs the integration. Microsoft acts as our service provider under contract: it is bound to data-protection terms at least as protective as these (Microsoft’s enterprise Data Protection Addendum), may use the data only to provide that infrastructure to us, and may never use it for its own purposes. Apart from this infrastructure provider, any third-party use or disclosure of the data is prohibited without the affected person’s active, opt-in consent, and we will hold any future provider to the same equal-or-stronger standard.
9. If there is a data breach
If a breach affects this data, we will notify the affected individuals and the proper authorities without undue delay, and within the time the law requires. Our notice will explain, as best we can, what happened, what data was involved, and the steps you can take — such as monitoring your USCIS case account and contacting us at the address below.
10. How long we keep it (retention), including dormant matters
We keep cached case-status data only as long as we need it for your active matter, plus any period required by the file-retention rules that apply to law firms in our jurisdiction or by a legal hold. For dormant or closed matters, we keep only what those rules require and securely delete or de-identify the rest.
11. How to permanently delete your data
Email [email protected], or write to the address below, and ask us to delete the case-status data we hold about you. This is free, and we will not treat you differently for asking.
How soon: we confirm your request within 10 business days and complete the deletion within 45 days. If we need more time we will tell you why and take no more than 45 additional days.
Permanent, with one lawful limit. We purge the data from active systems right away and from routine backups within 90 days, as those backups cycle out — the deletion is permanent. As a law firm, we must keep the narrow set of records we are legally or ethically required to retain (bar-rule file retention, a legal hold, or an active matter). We delete everything we are not required to keep, and we will tell you what we kept and why.
12. California privacy rights (if applicable)
If you are a California resident, and to the extent the California Consumer Privacy Act (as amended by the CPRA) applies, you have the right to know, access, delete, and correct your personal information, and the right not to be treated differently for exercising those rights. We do not sell or share your personal information, so there is nothing to opt out of. Contact us using the details below; we will verify your identity before we act on a request.
13. If the firm changes ownership or winds down
If Brown Law, PLLC merges, is acquired, or transfers or winds down this integration, your data will either (a) transfer to a successor that is bound by terms at least as protective as these, or (b) be securely disposed of. Before disposal, on your request we will transmit a copy to you or let you download it. We will notify you before your data becomes subject to a different owner or a different policy.
14. Closing access
An authorized user may close their access at any time by contacting us. When access is closed, we deactivate the account and delete the data tied to it, except the records we must keep under Section 10 and Section 11.
15. Changes to this policy
If we make a material change to how we handle this data, we will post the updated policy here with a new effective date, include a short plain-language summary of what changed, and ask for your active, opt-in consent before the change applies to you. We will not treat your silence or your continued use as consent to a material change.
16. Contact
Brown Law, PLLC — Attn: Privacy
109 North Henry Street, Alexandria, Virginia 22314
[email protected]