EADly Privacy Policy
Effective date: September 27, 2026
EADly is operated by Ethos Systems, LLC, a Wyoming limited liability company. This policy explains what information EADly handles, why it is handled, where it is stored, and your choices.
1. The short version
EADly is local first. Immigration records, documents, employment records, travel records, reminders, and app settings are stored on your device. Ethos does not receive them unless you choose an online feature described below.
Optional automatic backups are encrypted on your device before they are stored in the iCloud Drive or Google Drive account you select. Ethos does not receive the backup contents or decryption credentials.
An EADly account is optional. If you create one, we process the identity and session information needed for sign in, minimal backup routing information, and information you choose to send through online features.
We do not sell personal information, show advertising, or use advertising trackers. Analytics is off by default.
2. Information stored on your device
EADly stores the information you enter or attach. This includes immigration and admission history, such as I-94 and extension records; program and authorization records, such as F-1 programs and CPT, OPT, or STEM OPT authorizations; employment or activity records connected to those authorizations; H-1B or O-1 records; travel records; USCIS receipt numbers and case-status history; documents and notes; reminders; settings; and local activity history. These categories are grouped because they receive the same local first treatment.
On iOS and Android, EADly encrypts local records, sensitive session values, and saved account copies automatically, for Free and Plus. Documents stored in the Vault are also encrypted. A device-only record key is protected by iOS Keychain or Android Keystore. It is separate from document and backup keys. Ethos does not receive these local keys or records.
New native device-key protection does not require an extra password, account, or biometric prompt. Existing passphrase-protected vaults still use their original credentials. Your optional app PIN is stored only as a salted cryptographic hash. Face ID, Touch ID, and fingerprint matching are performed by the operating system. Ethos does not receive your PIN or biometric data. The app lock controls access to the interface; it does not erase records already open in app memory.
Browser versions do not use the native device-key protection described above. Ordinary browser records rely on browser and operating system storage protections. Browser document encryption and any existing passphrase-protected vault are separate.
A device-only key is not a backup. Losing the device, its key, or access after a reinstall or device transfer may require a manual encrypted backup or a connected provider backup. Ethos cannot recreate a lost local key. Keep a recoverable backup before replacing or resetting a device.
Local notifications are scheduled on your device. EADly does not operate a push notification server. The operating system receives and may retain reminder titles, details, and timing to deliver them. Those copies are separate from EADly's encrypted records. Notification previews follow your device settings and may be visible on the lock screen. You can change notification permissions and preview settings.
Removing the app normally removes its local data, subject to operating system behavior and any backup or exported copy that you separately retain.
You may add an optional passport country. EADly uses it on your device to show that country's passport renewal steps and official links, and a link to the IRS page for its tax treaty with the United States. It is stored with your other records and is not sent to Ethos.
If you share booking confirmation text, an email file, or a calendar file with EADly from another app, EADly reads it on your device to suggest a trip for you to review. On iOS, the shared text is kept in one protected file in EADly's app storage, excluded from device backups, and removed when EADly opens it. On Android, it is held only in app memory. Nothing is added to your trips until you save, and the shared text is not sent to Ethos. EADly does not connect to your email account.
3. Manual encrypted backup files
You can export a password protected .eadlybackup file and restore it on a supported device. The app encrypts new files on your device using AES 256 GCM. A file key is derived from the password you choose using PBKDF2 SHA 256 with 210,000 iterations.
Ethos does not receive the file, password, or derived key and cannot recover a forgotten password. The file may contain the records and documents stored in EADly. It excludes your account session, one time codes, automatic backup keys and recovery credentials, app PIN, biometric settings, and notification permission.
The operating system picker gives EADly access only to a file you select. A confirmed restore replaces the active local records on that device. When migration or recovery could otherwise lose data, EADly may preserve earlier local copies while it verifies the restored records. Keep a separate backup until you confirm the restore succeeded.
Apple, Google, or another destination you choose may store an exported file under its own terms. Deleting EADly or your EADly account does not delete copies you exported or shared.
4. Optional accounts and cloud backup
You may sign in with an email one time code, Sign in with Apple, or Sign in with Google. Depending on the method, we process your email address, provider identity, user identifier, and short lived rotating session tokens. We do not receive your Apple or Google password.
Automatic backup is off until you enable it. Every new backup is encrypted on your device with a random AES 256 GCM data key before storage in the provider account you select.
For iCloud Drive, EADly stores the backup key in an app private, synchronizable iCloud Keychain item. Recovery requires access to the same Apple Account and iCloud Keychain. This backup key can sync; the local record key cannot.
For Google Drive, EADly wraps the backup key with separate keys derived from your passphrase and recovery code using PBKDF2 SHA 256 at 210,000 iterations. A validated backup key may also be held in protected device storage for later use. Ethos does not receive these credentials and cannot decrypt or recover the backup.
Supabase stores only the account and routing information needed to locate the selected provider backup: your EADly user identifier, provider, random backup set identifier, protocol version, connection state, and timestamps. Supabase does not store the backup contents, provider access token, provider file identifier, decryption key, passphrase, recovery code, or wrapped key.
5. USCIS receipt numbers and case status updates
USCIS considers receipt numbers Personally Identifiable Information (PII). EADly collects a receipt number from you only when you choose to enter or save one. We treat it as personal information.
How we use it. A receipt number you save remains in local app data. When you choose Copy receipt & open USCIS, EADly copies it to your device clipboard and opens the official USCIS Case Status website with the receipt in the link. You may need to paste it into the official form. The receipt goes directly to USCIS, not through EADly's backend. EADly does not retrieve or monitor the result. Clipboard copies follow your operating system's settings and are separate from encrypted app records.
If optional API based tracking is later activated after USCIS production approval, it will require a signed in account. EADly will use the receipt number to query the USCIS Case Status API for matching case status updates and return the response to your device. We will not use it for advertising, analytics, profiling, or any unrelated purpose.
Where we store it. The receipt number and any in-app case status history are stored in OS-protected local app data, with the platform-specific encryption described in Section 2. If you enable automatic backup, they may be included only inside the end-to-end encrypted backup stored in the iCloud Drive or Google Drive account you select. Ethos and Supabase do not receive the backup plaintext or its decryption key. We do not store receipt numbers in the Supabase database.
How we protect a future API query. The app will send the receipt over a TLS encrypted HTTPS connection to an authenticated backend. The backend will process it only long enough to make the matching TLS encrypted request to USCIS and return the response. We do not intentionally write receipt numbers, receipt-bearing request URLs, or USCIS response bodies to our backend database or provider logs. Rate-limit records do not contain receipt numbers.
Retention and deletion. A saved receipt and its local status history remain until you remove them, reset local data, delete the app, or restore different data. Removing a receipt also removes its matching local status history and refresh metadata. If the same receipt is linked to another record, removal clears that matching receipt there too. Independent filing, notice, authorization, or decision dates remain saved because they support the timeline separately, unless you delete them.
USCIS receives the receipt number only when you request a case status check. USCIS handles it under applicable law and its own privacy terms.
6. Purchases and EADly Plus
Apple or Google processes the payment. RevenueCat helps EADly verify purchase and entitlement status for subscriptions and one-time purchases such as Lifetime, where offered. They may process the product, store, transaction, trial or offer status, refund or revocation status, renewal and expiration dates when applicable, and a RevenueCat App User ID.
When you are signed in, EADly may link the RevenueCat identifier to your non email Supabase user identifier so an entitlement can follow your account. EADly does not send RevenueCat your immigration records, documents, employers, schools, receipt numbers, exact immigration dates, or full payment card number.
7. Feedback and optional analytics
If you submit feedback, we process the message, the email linked to your account, any separate reply address you provide, an account reference, and the screen from which you sent it. Resend delivers the message to our support mailbox. Do not include information you do not want to share.
Analytics is disabled by default. If you enable it, PostHog receives a random install identifier and a limited allowlist of product events. EADly blocks names, emails, exact dates, employers, schools, receipt numbers, files, notes, and similar values. We do not use analytics cookies, autocapture, session replay, heatmaps, or advertising profiles. You can withdraw consent at any time in Settings.
8. Service providers and recipients
We use:
- Supabase for authentication, minimal backup routing, and backend functions.
- Apple for Sign in with Apple, App Store purchases, and iCloud services you select.
- Google for Sign in with Google, Google Play purchases, and Google Drive services you select.
- RevenueCat for purchase and entitlement verification.
- Resend for one time sign in codes and feedback delivery.
- PostHog for analytics only when you opt in.
- Netlify for website hosting and waitlist forms.
- USCIS for a receipt lookup only when you request it.
Service providers acting for Ethos are contractually bound to protect personal information consistently with this policy. They may use it only to provide the service we hired them to provide. Apple, Google, and USCIS may instead act under their own terms for a service you select. We may disclose limited information when required by law, legal process, or a valid government request, or when necessary to protect users and the Service.
We do not permit a provider acting for Ethos to use or disclose personal information for an independent purpose without your active consent. This restriction includes information described as de identified, anonymized, or pseudonymized. We do not provide such information for independent advertising, marketing, research, sale, or profiling.
You choose whether to create an account, enable cloud backup, send feedback, enable analytics, check a receipt with USCIS, or export and share a file. These choices can make recovery, support, product improvement, or an official lookup possible. They also send the limited information described in this policy to the named recipient. Encryption limits what a backup provider and Ethos can read, but it cannot prevent loss of access, provider outages, or disclosure by a person with your credentials or an exported copy. You can leave these features off, withdraw optional analytics consent, disconnect backup, or delete your account.
Information may be processed in the United States and other countries where these providers operate. Where required, Ethos uses appropriate safeguards for transfers for which it is responsible.
9. What we do not do
We do not sell, rent, or trade personal information. We do not show ads or use advertising networks or cross app trackers. We do not collect precise device location, contacts, or broad photo or file library access. A location you type into an employment record is part of your local record, not device location data.
EADly does not ask for medical, health, genetic, or family history information. Do not place that information or another person's information in notes or documents unless you are authorized to do so. If you include it, it receives the same local and encrypted backup treatment as your other records.
Your notes or documents can still mention a dependent, family member, employer contact, or another person. Exporting or sharing those records could expose that person's private information and affect their immigration, employment, insurance, or other interests. Get permission or remove their information before sharing.
10. Retention and deletion
Local data remains until you edit it, reset it, remove the app, or replace active records through a restore. Migration and recovery may retain earlier local copies to prevent data loss. Manual files remain wherever you save or share them until you delete those copies.
When you export a history report or calendar, or open or share a document, EADly may create a readable temporary file for the receiving app. New native exports use a dedicated temporary location. On iOS, these files use system file protection and the app attempts to remove them after sharing completes or is canceled. On Android, the temporary copy remains long enough for the receiving app to read it.
EADly checks for inactive temporary exports older than 24 hours when it starts, returns to the foreground, or prepares another export. Cleanup can be delayed while the app is closed or if a file operation fails. It does not remove your saved files, Vault originals, provider backups, or copies held by recipients.
Older app versions, system backups, browser storage, and receiving apps may retain separate copies. Deleting a record or temporary file does not guarantee that every old storage block or backup copy is erased. Exports other than .eadlybackup files are not protected by EADly's backup encryption; choose recipients and destinations carefully.
Use Settings > Delete Account & Data to close an EADly account and request permanent deletion. The app first attempts to verify deletion of the connected provider backup, then deletes routing metadata and the EADly account. When verification succeeds, EADly-held account and routing data are deleted during the same in-app flow, ordinarily within minutes. If provider deletion cannot be verified, the process stops without deleting the account and tells you what remains. Copies outside EADly's managed provider location must be deleted by you.
If you cannot use the in-app flow, email admin@eadly.app from the address linked to the account. After we verify the request, we will complete deletion of EADly-held account and routing data within 30 days unless applicable law requires limited information to be retained. We will tell you if an exception applies.
Feedback is retained as needed to answer and manage the request. Apple, Google, and RevenueCat retain purchase records under their legal, accounting, security, and service requirements. Short lived operational records, such as rate limit counters, are retained only as needed for security and abuse prevention.
We may delete an account and routing data after 24 months without activity, after emailing the account and allowing 30 days to respond. Provider backups may remain if current provider authorization is unavailable.
If Ethos sells or ends the business or EADly changes operator, we will notify you of the ownership or operator change. Where reasonably possible, we will provide notice before it takes effect. EADly-held data will be securely deleted or transferred to a successor that must follow a privacy policy materially consistent with this one. If the successor will not, we will give you a reasonable opportunity to export or permanently delete your data before the change.
Encrypted provider backups remain in the account you selected and are unreadable to Ethos or a successor without your key. USCIS production access is specific to the approved operator and cannot transfer to a successor. API based tracking must stop unless the successor obtains its own approval.
11. Security
We use the local record and document protections described above, device side encryption for backups, TLS for network traffic, encryption at rest for backend account data, row level database security, short lived rotating sessions, rate limits, and a strict content security policy.
No system is perfectly secure. At-rest encryption does not prevent access by malicious code running inside an unlocked app or a compromised operating system. A backend incident could expose account and routing data, but our servers do not hold provider backup contents or their decryption keys.
Report a suspected vulnerability to support@eadly.app. Please do not access another person's data or publicly disclose an unresolved issue before allowing a reasonable opportunity to investigate.
If a personal data breach affects you, we will notify you without undue delay and within any deadline required by law. The notice will explain what happened, what information was involved, what we are doing, and any steps you can take.
12. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to withdraw consent without discrimination. Many choices are available directly in the app through export, reset, account deletion, analytics, and backup controls.
We do not sell or share personal information as those terms are defined by applicable United States state privacy laws. Where the California Consumer Privacy Act, as amended by the CPRA, applies, we honor its access, correction, deletion, portability, and nondiscrimination requirements. Where the GDPR or UK GDPR applies, our legal bases are performance of our agreement for requested online features, legitimate interests for security and abuse prevention, and consent for optional analytics and cloud backup.
Contact us for a request that cannot be completed in the app. We may verify the request and will respond within the time required by law. You may also complain to the relevant data protection authority.
13. Children, website, and changes
EADly is intended for people age 16 or older and is not directed to children under 16. Contact us if you believe a child provided personal information.
Netlify hosts eadly.app and may process standard server logs, including IP addresses, for delivery and security. If you join a waitlist, Netlify Forms stores the email address for us. We use it only for the stated waitlist purpose. You may request deletion at admin@eadly.app.
We will post policy changes with a new effective date. For a material change, the app will provide a plain language summary and request active consent before optional online features continue. You may continue using on device features and official links without accepting a new policy, subject to the prior terms.
14. Immigration and government notice
EADly provides informational organization tools and not legal advice. It does not create an attorney client relationship. Verify dates and requirements with official sources, your Designated School Official, and qualified counsel.
EADly is a private service and is not affiliated with, endorsed by, or connected to USCIS, DHS, ICE, SEVP, the U.S. Department of State, any other government agency, any school, any Designated School Official, or any employer. Government names and data are used only for identification and informational purposes.
15. Contact
Ethos Systems, LLC
Sheridan, Wyoming, United States
Email: admin@eadly.app
Website: https://eadly.app
See also the Terms of Use.