Privacy
cgi-usvisa-public stores portal credentials, security answers, booking preferences, and bounded delivery-retry state in Chrome. Extension Crate receives the normalized CGI account email, extension version, and payment state for access management. It never receives portal passwords, cookies, security answers, applicant identity, or page HTML.
When an official schedule-day response contains dates, the extension may send one routine availability observation containing a random observation ID, original IST timestamp, complete visible date list, OFC or consular stage, provider location ID and label, and visa type. Extension Crate verifies active access and removes the email before relaying the observation to the private operations service. Raw availability facts are kept for 90 days and then consolidated into permanent daily aggregate counts.
Only after the official confirmation page visibly matches the submitted date, time, location, applicant count, and visa class does the extension send a minimal booking summary. That summary may create a sanitized public alert with the location, date, time, and visa category. It never includes an email, account, applicant, or payment identity.
Paddle processes payment details under its own privacy terms.