Privacy

What we hold, and what we don’t.

Immigration Timeline is an independent project run from British Columbia by Manoj Kumar, who is the person accountable for the personal information described here. Last updated 28 July 2026.

The short version

  • Your dates are readable only by you. No screen in this product shows one person’s file to another.
  • Published figures are aggregates, and none is computed below 25 people.
  • Nothing is sold, rented or shared for advertising. There is no advertising, and no third-party analytics or tracking on this site.
  • You can download everything we hold, or delete the account and all of it, from Settings.

What we collect

Your email address, because sign-in is a link sent to it. There is no password.

What you tell us about your application: the program and stream, the province and country you selected, sponsor status where it applies, and the dates you record for each stage. Corrections are kept alongside the original rather than replacing it, so the history is honest about what changed and when.

Chat: a handle we generate for you — never your email or name — and the messages you send in your cohort room.

Settings and delivery: your notification preferences and time zone, and, if you turn on push, the subscription your browser issues for that device.

We do not ask for your name, your application number, your passport, your address, or any document. Please do not put them in a chat message either.

Why we hold it, and the only lawful basis we rely on

To run the service you asked for: to show your timeline, to estimate what is ahead, to put you in a room with people who filed the same month, and to send the daily summary if you have asked for it. Consent is given when you create an account and can be withdrawn by deleting it.

How your dates become a published figure

This is the part most worth understanding. Aggregate statistics are computed across applicants and published — on the public timeline pages, and in the comparisons shown to signed-in users. Two rules govern all of it.

Nothing is computed below 25 people. A cohort or segment with fewer than 25 contributors produces no figure at all, rather than a suppressed or rounded one. On the public pages a band must additionally rest on measured timelines rather than an assumed prior before it is shown.

The model only ever learns aggregates. Retraining reads grouped statistics, never individual rows, and the served model is a table of percentiles per segment and stage. As of 28 July 2026 no live user’s dates have entered a served model at all: the current run was built entirely from a corpus of community-reported timelines gathered before launch, which the methodology page reports on directly.

Where it is stored, and who else processes it

The database is hosted by Supabase in Oregon, United States, so your information is stored outside Canada and is subject to the laws of that country, including lawful access requests by its authorities. The site runs on Vercel. Rate limiting uses Upstash. Sign-up is protected from automated abuse by Cloudflare Turnstile. Those four are the only third parties that process anything, and each processes it only to provide that function.

Raw rows live in a private database schema that is not reachable by the public API at all. The browser can read aggregates and your own rows, and nothing else.

How long we keep it

While your account exists. When you delete it, everything described above is erased immediately and permanently — applications, every date, your handle, your messages, your settings and your push subscriptions. There is no grace period and no backup restore of an individual account.

Encrypted database backups are taken for disaster recovery and are cycled out on a rolling basis, so a copy of deleted data can persist in a backup for a short period before ageing out. Aggregate figures already published do not identify anyone and are not recalculated when an account is deleted.

Your rights, and where to exercise them

Get a copy — Settings → Your data → Download my data returns a JSON file with everything this account holds.

Correct it — every date is editable on your timeline, and “I don’t know the date’” is a valid answer.

Delete it — Settings → Your data → Delete my account. Immediate and irreversible.

Ask a person — questions, complaints and anything the buttons do not cover go to analystkumar29@gmail.com. If you are not satisfied with the answer you can complain to the Office of the Privacy Commissioner of Canada, or to the Commission d’accès à l’information if you are in Quebec.

Cookies

Only what sign-in needs: a session cookie so the site knows you are you, and a small preference for your light or dark theme. No advertising cookies, no analytics cookies, no third-party trackers of any kind.

Children

This is not intended for people under 16, and we do not knowingly hold their information. A dependent child named on an application is not a user of this site — we never ask for anything about them.

Changes

If this notice changes in a way that affects what we collect or why, the change will be announced in the app before it takes effect, not published quietly here.

See also the terms of use, which cover what these estimates are and are not, and who publishes this.