Back to Home

Privacy Policy

Last updated: September 25, 2026 · Version 2026-09-25

TrackMyOPT is operated by Zyene, Inc.. This page is not legal advice.

1. Who we are

TrackMyOPT is a software product of Zyene, Inc. (Delaware), with offices in San Francisco, California. This Privacy Policy explains how we handle personal information when you use our website, web app, Chrome extension, and related services (the "Service").

Contact: support@trackmyopt.com (general) · privacy@trackmyopt.com (privacy requests)

2. Information we collect

2.1 Account information

  • Email address, name (if provided), and authentication credentials (passwords are hashed; we do not store plain-text passwords)
  • Sign-in method (email/password or Google OAuth)
  • Account settings and preferences

2.2 Immigration and workflow information you provide

You may voluntarily enter information to use OPT/STEM OPT tools, for example:

  • Program end dates, OPT/STEM OPT start and end dates, DSO recommendation dates
  • Employment history, unemployment tracking inputs, and related notes
  • USCIS receipt numbers for case status tracking
  • Case status text, descriptions, and status history returned via USCIS Case Status API access

This information can be sensitive. We use it only to provide the features you request (timelines, reminders, dashboards, notifications).

2.3 Documents and files

Premium users may upload files to the document vault (e.g. immigration-related PDFs or images). Files are stored using our cloud infrastructure (AWS S3). The vault screen uses a passcode (stored as a hash). The passcode controls access in the product; it is not end-to-end encryption. If you reset a forgotten passcode, existing vault files may be removed per our recovery policy.

2.4 Payment and billing

Paid subscriptions are processed by Stripe. We receive subscription status, customer IDs, and transaction metadata from Stripe. We do not store full payment card numbers on our servers.

2.5 Communications

  • Transactional emails (welcome, billing, case status, reminders, support replies)
  • Email addresses and message metadata in our email queue logs
  • Information you send via contact or support forms

2.6 Device, log, and usage data

  • IP address, browser type, device information, and timestamps (security and abuse prevention)
  • Authentication session cookies (see Cookie Policy)
  • PostHog browser analytics — when you choose Accept All, browser analytics may collect product events such as feature interactions and page visits. PostHog is not used by TrackMyOPT for advertising targeting.
  • Server-side service events — limited events generated by account and API activity may be processed for security, billing, reliability, error diagnosis, and operation of core features. These events do not depend on optional browser cookies and are not controlled by the cookie choice.
  • Google Analytics (GA4) — when you accept cookies in our banner, we load GA4 to collect aggregated website traffic and usage data (e.g. pages visited, session duration). See Google's Privacy Policy.
  • Google AdSense — when you accept cookies in our banner, we may display ads via AdSense on free content pages. AdSense may use cookies for ad delivery and measurement. See Google's Privacy Policy.
  • Aggregated performance metrics (Vercel Analytics / Speed Insights) on our website
  • Chrome extension: version and content-free usage diagnostics. Non-sensitive display preferences may use browser sync storage; authentication tokens, generated resume artifacts, PDFs, structured resume fields, screening questions, and answers are not stored in sync storage.

2.7 AI-assisted features

If you use resume or document AI features, content you submit may be sent to our AI provider (e.g. Google Gemini) to generate output. Do not submit information you are not comfortable sharing with that provider. AI output is not legal advice.

2.8 Chrome extension application prefill

When you click Prefill this application, the Chrome extension reads the open application form and may place eligible information from your dedicated job-portal prefill profile and the active job-scoped generated resume into empty supported fields. The dedicated profile may include contact information, address, LinkedIn, GitHub, and website details and is separate from your normal TrackMyOPT account profile. A generated resume artifact is kept in extension session storage for up to 30 minutes and is invalidated when the normalized job URL, company, or role changes.

You may optionally save work-authorization, visa, sponsorship, citizenship, annual or hourly compensation, in-person/relocation/start/transportation/accommodation preferences, date-of-birth, sex/gender, race/ethnicity, veteran, disability, and EEO answers in a separate server-side record protected with authenticated encryption. Clicking Prefill this application loads your saved private answers and fills matching empty supported fields. No separate approval step is required for these answers. Existing answers stay unchanged. Review all filled answers before submitting. A saved date of birth can fill an ordinary supported date-of-birth question; it is not used as a password or verification code. Private answers are fetched on your Prefill click, not merely by opening the sidebar. If enabled, Continuous filling may reuse those loaded answers on supported steps of the same application. Changing to a different job or reloading the page requires another Prefill click. Eligible private answers may also be passed to supported application frames for the requested fill; portal credentials are excluded from that payload.

On an explicit Prefill click, eligible non-sensitive screening questions may be answered using a previously saved matching answer or a new AI draft grounded in the active job-scoped generated resume. New drafts send the screening question, current job description, and generated-resume snapshot to our AI provider. Drafts can be inserted into eligible empty fields and are marked for your review; check and edit them before continuing or submitting. New AI drafts are not generated merely by loading a page or by Continuous filling. Choosing Remember my answer stores the question and current answer in your account for later matching reuse; this is separate from the encrypted private-answer record. AI cover-letter generation also sends job and resume information to our AI provider and requires review before attachment. Saved private answers and portal credentials are not used to prompt these AI features. Information you include yourself in a resume, job description, or screening answer may still be processed as part of that content.

You may also save one default job-portal login in the encrypted private-data record. The same default email address and password may be offered across third-party employer and applicant-tracking portals, regardless of hostname. Saved portal login details, including password confirmation, fill when you click Prefill this application on a supported secure login or create-account page. No extra confirmation is required. Existing entries stay unchanged; review them before continuing. Portal credentials are fetched only for an explicit Prefill click on a supported HTTPS top-level page. They are not reused by Continuous filling or delivered to application frames. The extension uses password-type controls and never displays the saved password in its status messages. Reusing one login across unrelated portals increases the potential impact if any one portal is compromised. The extension never uses this credential on TrackMyOPT pages or places it in browser sync storage. Because TrackMyOPT's server must decrypt a saved portal password to provide autofill, this is not end-to-end encryption. Do not save your TrackMyOPT password or a primary password used for sensitive accounts. Credential filling skips password-change, security-answer, financial, SSN, date-of-birth, authentication-code, OTP, MFA, PIN, and uncertain password-type fields. It never clicks Login, Continue, Next, Create Account, or Submit.

Filling an answer or credential discloses it to the employer or applicant-tracking system operating the page, which may read fields before you submit. Saving private application data is optional and requires consent when saving. The encrypted record is retained while you keep it in your account; edit or delete it on the Chrome Job Prefill page. Private answers and credentials are not included in autofill logs or analytics. Autofill analytics use bounded counts, feature states, adapter and mode identifiers, navigation outcomes, and content-free error categories, not resume, answer, field, employer, school, job-title, URL, hash, file content, credentials, or private application answers.

The extension does not replace non-empty fields or existing files, answer Social Security number questions, or retrieve verification codes from an email inbox. Enter OTP, MFA, and other verification codes yourself. Unsupported or uncertain controls may remain blank. Opt-in Guided Autopilot may click narrowly allowlisted non-submit Next, Continue, or Done controls after required fields are complete; it pauses for unresolved or review-needed answers and stops before Review, Submit, Apply, Finish, or another final application action. Press Escape or Stop to stop an active run. TrackMyOPT never submits an application; review every field and attachment yourself.

2.9 Chrome extension job tracking and Limited Use

On supported job pages, the assistant reads the job URL, company, role, and available posting content. It sends the job identity to TrackMyOPT to show whether the job is already in your tracker. Saving a job, or recognizing an application-success page, can store its details and application status in your account. This access supports the visible job-tracking feature; it is not a collection of unrelated browsing history. Extension feedback includes the message you choose to send, rating, and technical request information such as IP address and browser type.

TrackMyOPT's use and transfer of information received through the Chrome extension comply with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use extension data only to provide or improve the extension's disclosed user-facing features. We do not sell extension data or use or transfer it for personalized, retargeted, or interest-based advertising, creditworthiness, or lending. The website advertising described elsewhere in this policy does not authorize use of extension data for advertising.

Transfers of extension data are limited to those necessary to provide or improve these features, security purposes, legal requirements, or a merger, acquisition, or sale of assets consistent with the policy. Human access is limited to your explicit consent for specific data, necessary security or legal purposes, or aggregated and anonymized data used for internal operations.

3. How we use information

  • Provide, operate, and improve the Service
  • Calculate timelines, unemployment tracking, and reminders
  • Check USCIS case status when you provide a receipt number
  • Process subscriptions and send billing-related communications
  • Authenticate users and protect against fraud or abuse
  • Respond to support requests and enforce our Terms
  • Comply with law and protect our rights

4. How we share information

We do not sell personal information for money. We disclose information to service providers and other parties only as described below. Some U.S. privacy laws may define disclosures for personalized advertising as "sharing" even when no money changes hands. You can prevent AdSense from loading by choosing Essential Only and use Google's U.S. state privacy control where it is available.

  • Supabase — Authentication, database, and file storage (privacy policy)
  • Stripe — Payment processing and subscription billing (we do not store full card numbers) (privacy policy)
  • Google OAuth — Optional sign-in with Google (privacy policy)
  • Email delivery (SMTP) — Transactional emails (e.g. ZeptoMail, Resend, or other configured SMTP provider)
  • PostHog — Optional browser analytics with consent, plus limited server-side service events for security, billing, reliability, and core feature operation (privacy policy)
  • Google Analytics (GA4) — Website analytics when you accept analytics cookies in the cookie banner (privacy policy)
  • Google AdSense — Advertising on free content pages when you accept cookies in the cookie banner (privacy policy)
  • Vercel Analytics & Speed Insights — Aggregated site performance and usage metrics (privacy policy)
  • Google Gemini — Optional AI features (e.g. resume tools) when you use those features (privacy policy)
  • USCIS Case Status API — Case status lookups using receipt numbers you provide (USCIS Case Status API access) (privacy policy)

We may also disclose information if required by law, court order, or to protect safety and rights.

If TrackMyOPT is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your personal information becomes subject to a materially different privacy policy, and you will retain any applicable privacy rights.

5. Legal bases (EEA/UK users)

Where GDPR applies, we rely on consent, contract performance, legitimate interests (security, improvement), and legal obligations as applicable.

6. Data retention

  • Account data: retained while your account is active
  • After account deletion: we delete or anonymize personal data within a reasonable period (typically within 30 days), subject to backups and legal holds
  • Billing records: retained as needed for tax, accounting, and dispute resolution
  • Consent and checkout audit logs: retained for dispute evidence and compliance

For accounts inactive for 24 months with no subscription activity, we may send notice to the email address on your account. If you do not reactivate or respond within 30 days, we may delete account data, subject to legal, billing, security, fraud-prevention, and audit-retention requirements.

7. Security

We use industry-standard measures including TLS in transit, access controls, and Row Level Security on our database where configured. No method of transmission or storage is 100% secure. See our Security page for an overview.

If we become aware of a security breach that may have compromised personal information, we will notify affected users by email and notify applicable authorities as required by applicable law.

8. Your choices and rights

  • Browser analytics and advertising: Use Privacy choices in the site footer, your dashboard profile menu, or the shield button on public pages to choose Accept All or Essential Only
  • Access / correction: Update profile and OPT data in Settings
  • Private application answers: Review, change, or delete your saved private answers and portal login on Chrome Job Prefill
  • Deletion: Delete your account in Settings (or email privacy@trackmyopt.com)
  • Email opt-out: Unsubscribe links in marketing emails; manage notification preferences in Settings
  • Applicable U.S. state laws: Rights may include access, deletion, correction, and opting out of sale, sharing, or targeted advertising, subject to the law's coverage and exceptions
  • EEA/UK (GDPR): Rights to access, rectification, erasure, restriction, portability, and objection where applicable

To exercise rights or request opt-out assistance, email privacy@trackmyopt.com. We may verify your identity before responding.

9. Children

The Service is intended for users 18 and older (typical F-1/OPT audience). We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided data.

10. International transfers

We are based in the United States. If you access the Service from outside the U.S., your information may be processed in the U.S. and other countries where our providers operate.

11. Changes to this policy

We may update this Privacy Policy. We will update the date and version at the top. For material changes, we will provide notice (e.g. email or in-app) when appropriate. For material changes to this Privacy Policy or our Terms that require consent, we may request active consent before the changes apply to your continued use of TrackMyOPT.

12. Related policies

Terms of Service · Disclaimer · Cookie Policy · Refund Policy