Visa Grep Sign in

Privacy Policy

Last updated September 30, 2026

Who we are

Visa Grep (visagrep.com) is a free site that shows each U.S. employer's public H-1B, green card and E-Verify records from the Department of Labor and USCIS. This policy explains what we collect when you use it, and why. “We” means Visa Grep.

Browsing and searching

You can search and read every page without an account, and when you do we collect nothing about you.

  • We set no cookie.
  • We never write down what you search for.
  • Our server's access log keeps one line per request: the method, the page's path, the response status, its size and how long it took. Never the search text, your IP address, your browser or the page you came from.
  • If you switch between light and dark mode, the choice is kept in your own browser (its local storage) and never sent to us.
  • There are no ads, no analytics and nothing loaded from another website: every script, font and stylesheet comes from Visa Grep itself.

If you create an account

You only need an account for API keys, to use the JSON API or connect Claude over MCP. When you sign in with Google, we keep:

  • Your Google account ID, name and email address, and when you first and last signed in.
  • For each API key: the name you give it, a one-way hash of the key, its first seven and last four characters, and when it was created, last used and revoked. Never the key itself.
  • How many requests each key made each day, through the API and through MCP, and a count of this minute's requests for the per-minute limit.
  • One cookie, vg_session, which keeps you signed in. We store only a hash of its value. While you sign in, the same cookie briefly holds a random sign-in state, for up to 10 minutes.

How we use it

Only to sign you in, show you and manage your keys, and enforce the free limits of 1,000 requests a day and 60 a minute per account. Nothing else.

  • We never sell or share your information.
  • We don't show ads or use analytics.
  • We don't send you marketing email.

Google

Google is the only other company involved, and only for signing in. You sign in on Google's own page, so we never see your password. Google then tells us your account ID, name and email address, and whether the address is verified. What Google itself does is covered by Google's privacy policy.

How long we keep it

  • A sign-in lasts 30 days, or until you sign out.
  • Your account, keys and daily request counts are kept for as long as your account exists. A revoked key stops working at once; its name, hash and characters stay with your usage history.
  • When you delete your account, we delete your account, every key, all usage counts and every sign-in at once.

Your choices

  • Use Visa Grep without an account: every page is open to everyone.
  • Revoke any key, sign out, or delete your account, on your account page.
  • Remove Visa Grep's access from your Google Account's security settings.

Security

  • API keys and session cookies are stored only as SHA-256 hashes.
  • The session cookie is HttpOnly and SameSite=Lax, and Secure whenever the site is served over HTTPS.
  • Every form that changes something carries a token that only your session has.
  • Sign-in uses Google's OpenID Connect with PKCE, and checks that each sign-in is the one your browser began.
  • Keys, cookies, sign-in codes and email addresses are never written to a log.

No system is perfectly secure, but we keep as little as we can.

Children

Visa Grep isn't directed at children under 13, and we don't knowingly collect information from them.

Changes to this policy

If this policy changes, we'll update this page and the date at the top of it.

Contact

Questions about this policy or your data: write to hello@visagrep.com. Signed in, you can manage or delete everything yourself on your account page.