Stratovisa
常见问题登录

Privacy Policy

Stratovisa — operated by VISA FLOW AI LTD ("we", "us", "our")
Last updated: 14 July 2026
ICO registration number: ZC177689


1. Who we are

Stratovisa is a document organisation tool for UK visa applicants. It is operated by VISA FLOW AI LTD, registered in England and Wales (company number: 17277625), trading as Stratovisa.

Data controller contact:
Email: privacy@stratovisa.com
Address: Rivers Lodge, West Common, Harpenden, England, AL5 2JD

We are registered with the UK Information Commissioner's Office (ICO) as a data controller. Our ICO registration number is ZC177689.

Users in the EU/EEA: see §15 for the supervisory authority complaint route in your member state, and §16 for our position on the EU representative requirement.


2. What this policy covers

This policy explains what personal data we collect when you use Stratovisa, why we collect it, how long we keep it, and what rights you have over it. It applies to all personal data we process about you in connection with your use of the service.

This policy applies under the UK GDPR and the Data Protection Act 2018. Where you are resident in the European Economic Area (EEA), it also applies under the EU General Data Protection Regulation (Regulation (EU) 2016/679). Where the two regimes grant different rights, the more protective regime applies to you.

It does not cover data processed by third-party websites we may link to.


3. What personal data we collect

3.1 Account data

  • Email address (collected at signup)
  • Full name, date of birth, nationality, and country of current residence (collected in your profile — optional until package generation)

3.2 Visa application documents

When you upload supporting documents for your visa application package, we process the contents of those files. Depending on your visa type, this may include:

  • Passport and identity documents
  • Bank statements and payslips
  • Tenancy agreements, utility bills, and other proof of address
  • Relationship evidence (photographs, correspondence, messaging exports)
  • Employer letters, certificates of sponsorship references, and immigration health surcharge receipts
  • Any other documents you choose to upload

These documents may contain special-category personal data and highly sensitive identifiers including: passport numbers, national insurance numbers, sort codes, and bank account numbers. We take specific technical steps before any such data is passed to AI processing services — see section 5.

3.3 Intake and application answers

  • Visa type selected
  • Country you are applying from
  • Employment sector
  • Whether you have dependants, and their number and relationship type
  • Answers to financial intake questions (income sources, savings amounts)

3.4 Billing and access data

  • Your email address, linked to a Stripe customer record
  • Payment status (paid / unpaid) and the date your 12-month access expires
  • Payment history and invoice references retained by Stripe
  • Payment card details are handled directly by Stripe; we never receive or store your full card number

Stratovisa is sold as a one-time purchase granting 12 months of access. We do not auto-renew or charge a recurring subscription.

3.5 Technical data

  • IP address and browser type, retained in Supabase infrastructure logs
  • Session authentication token, stored as a secure browser cookie (see section 10)

3.6 Referral data

We generate a unique 8-character referral code for your account. If you sign up via a friend's referral link, we record that friend's code against your account for the purpose of applying a one-time discount at checkout. Referral codes are random identifiers that do not, on their own, reveal who shared the link.

3.7 Feedback submissions

If you use the in-app feedback widget, we store the message you submit, the URL of the page you were on when submitting, and your user ID. We use this only to improve the service.

3.8 Chat import data (Family visa relationship evidence)

If you use the chat import feature, the chat export file you upload (WhatsApp, Line, KakaoTalk) is processed in memory. Before any AI processing, message bodies are scanned for personal identifiers (phone numbers, email addresses, NI numbers, passport numbers, sort codes, bank account numbers) and these are replaced with placeholders. We store only the structured milestone extraction — dates and short evidence quotes — in our database, not the raw chat file. Evidence quotes may still contain partner names, locations, and personal details from your conversation; you can review and edit these before they are used to draft your supporting statement.


4. Why we process your data and our legal basis

PurposeData categories usedLegal basis (UK GDPR / EU GDPR)
Providing the document organisation serviceAccount data, application documents, intake answersArt. 6(1)(b) — performance of contract
Managing your account and session authenticationAccount data, session tokenArt. 6(1)(b) — performance of contract
Processing one-time payments and tracking 12-month accessBilling dataArt. 6(1)(b) — performance of contract
Applying a referral discount at checkoutReferral dataArt. 6(1)(b) — performance of contract
Keeping the service secure and preventing fraudTechnical data, session dataArt. 6(1)(f) — legitimate interests
Complying with tax and accounting obligationsBilling recordsArt. 6(1)(c) — legal obligation
Responding to your support requestsData relevant to the requestArt. 6(1)(f) — legitimate interests
Generating documents within your package (cover letter, supporting statements)Profile data, intake answers, PII-stripped field dataArt. 6(1)(b) — performance of contract
Improving the service from user feedbackFeedback submissionsArt. 6(1)(f) — legitimate interests
Anonymous, cookieless audience measurement (pageview counts via Vercel Analytics)Aggregate counts — no cookies, no identifiersArt. 6(1)(f) — legitimate interests, relying on the first-party audience-measurement exemption in PECR as amended by the Data (Use and Access) Act 2025. On by default; opt out any time (see §10)
Cookie-based analytics (Google Analytics via Google Tag Manager)Aggregate usage data; sets first-party analytics cookiesArt. 6(1)(a) — consent (off by default; see §10)
Error monitoring in the browserStack traces, scrubbed for PIIArt. 6(1)(a) — consent (off by default; see §10)
Error monitoring on our serversStack traces, scrubbed for PIIArt. 6(1)(f) — legitimate interests

We do not use your data for marketing, profiling, automated decision-making, or any purpose not listed above.

Where we rely on legitimate interests, we have assessed that our interests do not override your interests or fundamental rights. You may object to legitimate-interests processing at any time — see section 9.


5. AI processing and PII stripping

Two AI pipelines apply pre-transmission PII stripping with shared regex rules:

Chat import (used when you upload a chat export for Family visa relationship evidence) — before milestone extraction, message bodies are stripped of: NI numbers, passport numbers, sort codes, bank account numbers, UK and international phone numbers, and email addresses. Sender names and timestamps are preserved so the AI can attribute milestones correctly.

Cover letter generation — intake data, financial intake data, chat milestones, and known field values are stripped of the same identifiers before transmission to Anthropic Claude.

The following fields are passed to Anthropic unstripped because they are required for the AI to draft narrative sections: applicant name, sponsor name, dates of birth, dependant children names and dates of birth, nationality, address, employer name, marriage date and location. These are necessary inputs to a contractually requested document and are processed under Art. 6(1)(b) (performance of contract).

Uploaded document files (PDFs, images) are never transmitted to any external AI service. AI providers do not retain inputs or outputs beyond the abuse-detection window described in their own policies (typically 30 days for Anthropic).


6. How we share your data

We do not sell your personal data. We do not share it with advertisers, data brokers, or any party other than the processors listed below. Each processor operates under a data processing agreement.

Supabase, Inc.

Role: Database, authentication, and file storage
Data shared: All personal data listed in section 3, including uploaded documents
Storage location: Ireland (eu-west-1)
Transfer mechanism: UK adequacy decision for EEA countries — no additional mechanism required for UK → EU transfers
Supabase legal: supabase.com/legal/dpa

Uploaded documents are stored in a private, access-controlled storage bucket. No third party can access them. All documents are deleted when you delete your account (see section 8).

Anthropic, Inc.

Role: AI text generation (cover letters, personal statements, relationship evidence processing)
Data shared: PII-stripped text only, plus the unstripped narrative fields listed in §5. Uploaded document files are never transmitted to Anthropic.
Storage location: United States
Transfer mechanism: International Data Transfer Agreement (IDTA) under UK GDPR; EU–US Data Privacy Framework Standard Contractual Clauses for EEA-resident users
Anthropic legal: anthropic.com/legal

Stripe, Inc.

Role: Payment processing (one-time purchases)
Data shared: Email address, payment amount, payment status. Payment card details are processed directly by Stripe and are never seen by us.
Storage location: United States / Ireland
Transfer mechanism: UK Extension to the EU–US Data Privacy Framework (UK Data Bridge); EU–US Data Privacy Framework for EEA-resident users
Stripe legal: stripe.com/en-gb/legal/dpa

We do not share visa application documents with Stripe. Stripe may set its own cookies on its own checkout domain — those are governed by Stripe's privacy policy and are outside our control.

Vercel, Inc.

Role: Frontend hosting (web application)
Data shared: IP addresses and session tokens transmitted via HTTP headers in the course of serving web pages. No personal data is stored persistently by Vercel.
Storage location: United States
Transfer mechanism: UK Extension to the EU–US Data Privacy Framework (UK Data Bridge)
Vercel legal: vercel.com/legal/privacy-policy

Vercel Analytics: Pageview counts are collected via Vercel Analytics for product improvement. Vercel Analytics does not set cookies or store any identifier on your device — it uses anonymous, aggregate beacons. Because it is cookieless first-party audience measurement, it runs by default under our legitimate interest (relying on the PECR audience-measurement exemption introduced by the Data (Use and Access) Act 2025). You can opt out at any time via "Cookie preferences" in the footer or by choosing "Essential only" in our banner (see §10).

Google LLC (Google Tag Manager / Google Analytics)

Role: Usage analytics tag management
Data shared: Standard analytics data — pages viewed, approximate location (derived from IP, which Google does not retain in full), device and browser type. No account identifiers, uploaded documents, or application data are sent to Google.
Consent: The Google Tag Manager container is off by default and loads only after you accept analytics in our consent banner (see §10). Until then, no Google tags run and no Google cookies are set. We use Google Tag Manager solely to operate Google Analytics for aggregate usage measurement — not for advertising, remarketing, or profiling.
Storage location: United States
Transfer mechanism: UK Extension to the EU–US Data Privacy Framework (UK Data Bridge)
Google legal: business.safety.google/privacy/ · policies.google.com/privacy

Render Inc.

Role: Backend API hosting
Data shared: All API request data passes through Render's infrastructure in memory during request processing. No personal data is stored persistently by Render.
Storage location: United States
Transfer mechanism: UK Extension to the EU–US Data Privacy Framework (UK Data Bridge)
Render legal: render.com/privacy

Sentry (Functional Software, Inc.)

Role: Error and performance monitoring
Data shared: Error stack traces and request context. Only a user ID (not email or name) is sent as user context. Personal data in error payloads is scrubbed via custom regex filters (see §12) before transmission. Session replay is disabled.
Consent: Browser-side Sentry is off by default and only activates after you accept analytics in our consent banner (see §10). Server-side error monitoring runs without consent under our legitimate interest in maintaining service security and stability.
Storage location: United States
Transfer mechanism: UK Extension to the EU–US Data Privacy Framework (UK Data Bridge)
Sentry legal: sentry.io/legal/dpa/

Resend, Inc.

Role: Transactional email delivery (account confirmation, password reset)
Data shared: Email address and the contents of the email being sent
Storage location: United States
Transfer mechanism: UK Extension to the EU–US Data Privacy Framework (UK Data Bridge)
Resend legal: resend.com/legal/privacy-policy


7. International data transfers

Your personal data is primarily stored in the EU via Supabase. The UK has issued an adequacy decision for EEA countries, meaning UK → EU transfers do not require any additional legal mechanism.

The following processors operate in the United States. UK GDPR Chapter V and EU GDPR Chapter V both require a legal transfer mechanism for transfers out of their respective territories:

ProcessorTransfer mechanism (UK → US)Transfer mechanism (EEA → US)
StripeUK Data BridgeEU–US Data Privacy Framework
VercelUK Data BridgeEU–US Data Privacy Framework
Google (Tag Manager / Analytics)UK Data BridgeEU–US Data Privacy Framework
RenderUK Data BridgeEU–US Data Privacy Framework
SentryUK Data BridgeEU–US Data Privacy Framework
ResendUK Data BridgeEU–US Data Privacy Framework
AnthropicInternational Data Transfer Agreement (IDTA)EU–US Data Privacy Framework Standard Contractual Clauses

If you are an EU/EEA resident, the legal basis for transfers out of the EEA mirrors the UK regime — the UK Data Bridge sits within the EU–US Data Privacy Framework.


8. How long we keep your data

Data typeRetention period
Account data, intake answers, and application documents (active account)For the duration of your account
Account data, intake answers, and application documents (after account deletion)Deleted within 30 days of account deletion
Inactive accounts (no login for 12 months)We will email a warning to your registered address. If you do not log in within 30 days of that warning, your account and all associated data are deleted.
Supabase Storage bucket files (uploaded documents)Deleted as part of account deletion; may persist in Supabase automated backups for up to 30 days after deletion from the live database
Billing records (invoices, payment events)7 years from the date of the transaction (UK tax and accounting legal obligation)
Feedback submissionsRetained for 2 years from submission, then deleted, unless you delete your account first (in which case the message is retained but your user ID is set to NULL — the message is no longer linkable to you)
Authentication and access logs90 days (Supabase-managed)
Sentry error events90 days
Stripe webhook event log (idempotency ledger — event IDs only, no personal data)30 days

The 30-day grace period after account deletion exists to allow recovery if you delete in error. After 30 days, deletion is permanent and cannot be reversed.

Billing records exception: Transaction records are retained for 7 years regardless of account status. These contain only: date, amount, currency, and your email address. They do not contain visa application documents, intake answers, or profile data.


9. Your rights

Under UK GDPR and (where applicable) EU GDPR, you have the following rights. To exercise any of them, email privacy@stratovisa.com. We will respond within one calendar month.

Right of access (Article 15) — Request a copy of the personal data we hold about you.

Right to erasure (Article 17) — Delete your account at any time from Account Settings. This triggers deletion of all your personal data subject to the retention schedule in section 8. You may also request erasure by email.

Right to rectification (Article 16) — Correct your name, date of birth, nationality, or other profile data at any time from Account Settings.

Right to data portability (Article 20) — Request a machine-readable export (JSON) of your personal data. This right applies to data you provided to us and that we process by automated means on a contractual or consent basis. Initially, portability requests are handled manually within 30 days of request — email privacy@stratovisa.com.

Right to restriction (Article 18) — Ask us to restrict processing in certain circumstances (for example, while a dispute about accuracy is resolved).

Right to object (Article 21) — Object to processing based on legitimate interests (section 4). We will stop unless we can demonstrate compelling legitimate grounds that override your interests.

Right to withdraw consent — Where processing is based on consent (analytics and browser-side error monitoring — see §10), you may withdraw it at any time by clicking "Cookie preferences" in the site footer. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

EU/EEA residents: All rights above apply to you under both UK GDPR and EU GDPR. In addition, you have the right to lodge a complaint with the supervisory authority of your member state of residence — see §15 for contact details.


10. Cookies and local storage {#cookies}

We use a small number of browser storage technologies. They fall into three categories — strictly necessary (always active), cookieless audience measurement (on by default, opt-out), and consent-based analytics (off by default, opt-in).

Strictly necessary (no consent required):

NameTypePurpose
sb-[project-ref]-auth-tokenHTTP cookie (HttpOnly, Secure, SameSite=Lax)Authenticates your session with Supabase
stratovisa-statelocalStorageUI theme preference (no personal data)
stratovisa-pending-intakesessionStorageTemporary buffer when redirecting unauthenticated users from intake to login
stratovisa-consentlocalStorageRecords your cookie consent choice (essential / analytics) so we do not re-prompt you

Cookieless audience measurement (on by default — you may opt out):

NameTypePurposeProvider
Anonymous pageview beaconNetwork request (no cookie, no stored identifier)Aggregate visitor and page countsVercel Analytics

This measurement sets no cookies and stores nothing on your device. Under the first-party audience-measurement exemption in PECR (as amended by the Data (Use and Access) Act 2025) it runs by default, but you can turn it off at any time — choose "Essential only" in the banner or "Cookie preferences" in the footer.

Consent-based analytics (off by default — opt-in):

NameTypePurposeProvider
Sentry browser SDKIn-memory only (no cookie)Capture JavaScript errors for diagnosisSentry
_ga, _ga_*HTTP cookieDistinguish visitors for aggregate usage measurementGoogle Analytics (via Google Tag Manager)

These technologies are off by default. They activate only after you click "Allow analytics" in our consent banner. If you accept and later change your mind, click "Cookie preferences" in the footer to withdraw consent — this also re-opens the banner so you can pick again.

Stripe may set its own cookies when you proceed to checkout — these are on Stripe's own domain (checkout.stripe.com), governed by Stripe's privacy policy, and not under our control.

This implementation reflects UK PECR, the Data (Use and Access) Act 2025, and updated ICO guidance (April 2026) on storage technologies (which covers beacons and fingerprinting in addition to cookies).


11. Children

Stratovisa is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child under 18 has registered an account, please contact us at privacy@stratovisa.com and we will delete it promptly.

Dependants (including minor children) may be named in your visa application documents — for example, in dependant visa sections. Where you upload documents naming dependant children (Family visa applications), you confirm that you are the parent or legal guardian of those children and have authority to process their personal data for the purpose of your visa application. Children's data is processed as part of your account and is subject to the same retention and deletion rules as your own data.


12. Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • HTTPS encryption in transit
  • Supabase row-level security (RLS) policies ensuring users can only access their own data
  • Private storage bucket with access controls scoped to the authenticated user
  • PII stripping before any data reaches external AI services
  • Custom Sentry filters that scrub NI numbers, passport numbers, sort codes, and bank account numbers from error payloads before they leave your browser or our server
  • Regular review of access controls

No method of transmission or storage is completely secure. If you have reason to believe your data has been compromised, contact us immediately at privacy@stratovisa.com.


13. Changes to this policy

We will notify you of material changes by email to your registered address at least 14 days before they take effect. The "last updated" date at the top of this page reflects the current version.


14. How to complain (UK)

If you have a concern about how we handle your personal data, please contact us first at privacy@stratovisa.com. We take privacy complaints seriously and will respond within one calendar month.

If you are not satisfied with our response, you have the right to complain to the UK Information Commissioner's Office:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk/make-a-complaint


15. How to complain (EU/EEA)

If you have a concern about how we handle your personal data, please contact us first at privacy@stratovisa.com. We will respond within one calendar month.

If you are not satisfied with our response and are resident in the European Economic Area, you may complain to the supervisory authority of your member state of residence. A full directory is published by the European Data Protection Board at:

edpb.europa.eu/about-edpb/about-edpb/members_en

You may also complain to the Irish Data Protection Commission (dataprotection.ie), which acts as the lead supervisory authority for several US-based sub-processors operating in the EU.

Lodging a complaint with a supervisory authority does not affect any other administrative or judicial remedy available to you.


16. EU representative (Article 27 EU GDPR)

We currently do not have a designated EU representative under Article 27 EU GDPR. We are a UK-established controller offering a service that may incidentally be used by EU residents; we monitor the proportion of EU users and will appoint a representative before offering the service in the EEA at scale, and update this policy accordingly.

EU residents may contact us directly at privacy@stratovisa.com in the meantime. We will respond within one calendar month, in accordance with Article 12(3) EU GDPR.