Canada Immigration Portal Form Filler · Privacy notice

In one sentence

What you enter stays on your own computer. Four things leave it: the reader, when you choose files and press the button; a problem report (one goes on its own when a run fails, you can also send one yourself, and it can be switched off — when you send one yourself you may attach a screenshot, and none is sent if you do not); that same report when you press “ask us why”; and your email address if you ask for a free beta code on the website. What each one contains, who receives it and what is kept are set out below.

English summary

Everything you type stays in chrome.storage.local on your own computer and is never sent to us. Four things do leave it. One: if you choose files and click the reader button, those files go to our own service (Google Cloud Run, Toronto), which passes them to Anthropic's Claude API to read, returns the values it found with a citation for each one, and keeps no copy. Two: if a run fails, the extension sends us an error report on its own — the page structure and which boxes the portal rejected, never your answers, checked for your answers before it leaves. The panel says when it was sent and has a switch that stops it. Three: you can send that same report yourself and add a note, which goes as you wrote it. Four: if a box was rejected and the page did not say why, you can press a button to ask us to work it out; that sends the same report contents to our service, which passes them to Anthropic's Claude API for that one question. Nothing else is sent anywhere. We never see your portal username or password. We do not upload documents to the government portal and we do not submit your application — you do both yourself.

The information you enter

  • is stored only in your own browser's local storage (chrome.storage.local). Uninstalling the extension deletes all of it.
  • The entry form is a page belonging to the extension itself, not a website. What you type goes from the input box straight into local storage. Nothing is uploaded, relayed or copied.
  • The extension does not read, store or transmit your portal username, password or any sign-in credential. You sign in yourself and we never see it.
  • There is no analytics, no event tracking and no crash reporting.

The one feature that sends files out: reading your documents

This feature is optional, and every time it runs it is because you started it.

How it starts. You choose the files on the entry page yourself and then click the button. Choosing files without clicking sends nothing. Opening the page, switching tabs and saving a draft send nothing. There is no background sync.

What is sent. Only the contents of the files you selected this time, together with the list of fields to look for. The other answers you have already entered are not sent with them.

What you can choose, and how large. Up to 10 files at a time, each no larger than 4 MB, 40 pages in total across the batch. PDF, Word (.docx), Excel (.xlsx), images and plain text (.txt/.md/.csv/.json) are supported; dates in a spreadsheet are restored to a calendar date from the cell's own format. Every value the reader returns has to be checked against the original document.

One note about Word files. A .docx file has no concept of a page (pagination is worked out at print time), so values that came from Word always show page 1 as their source. The original sentence is still shown, and you can search the file for it.

Where it goes.

Who receives itWhat they doDo they keep a copy
Our own reading service (Google Cloud Run, Toronto, in Canada) Passes the files to the model service below and turns what comes back into field values No. Files stay in memory, are gone once processed, and are never written to disk or cached
Anthropic (Claude API, United States) Reads the file contents and answers what value each field has in your documents Handled under Anthropic's commercial terms for the API. We do not use any setting that would allow your documents to be used to train models

The document reader sends the files you choose to a model service in the United States. If you do not use it, what you enter stays on your own computer. Entering information is free; writing into the portal uses one of the applications you bought.

What is in the logs. Only which fields succeeded or failed, and a seven-character licence reference. Values, quoted text, file names and your licence code never go into the logs.

Please do not send bank statements to the reader. What documents your application needs still has to be confirmed for your specific category. The tool can limit the number of files, the size of each and the total page count; it cannot tell whether a file is a bank statement.

⚠️ To be clear about what can actually be enforced: we cannot technically determine what kind of document a file is. The only hard limits are the number of files, the size of each file and the total page count.

Every value the reader writes shows the file name, the page and the original text, so each can be checked. Anything not present in the documents is not inferred; the field is left empty and marked for the applicant to complete.

Problem reports

If you get stuck part way through, you can use "Report a problem" on the entry page to send us a problem report. That report contains none of what you entered. It contains only the page structure (field names, labels, the portal's own dropdown options), the shape of the value in each box (its length, whether it is a date, whether it contains a comma or apostrophe), and which boxes the portal refused. Application numbers are replaced. The sentence you write yourself is sent exactly as written, and the screen says so.

When a run fails, the extension sends one on its own. That is the only case — not a heartbeat, not usage statistics. The contents are identical to the report you send by hand and go through the same pre-send check. Afterwards the panel says it was sent automatically, and the same place has a switch that stops it for good. Apart from that, the extension sends nothing in the background.

You can attach a screenshot yourself. That is the one exception. The report screen has an “Attach a screenshot” button, up to three. Nothing is ever captured on its own: attach nothing and nothing is sent, and the report that goes automatically when a run fails never carries one. A screenshot of a filled form contains your client’s information — the screen says so before you pick a file, and suggests cropping or blacking out anything you would rather not send. Screenshots are stored with the report on the servers below, deleted once the problem is fixed, used for nothing else, and never included in a notification.

Reports are stored on our servers in Canada (Google Cloud, Toronto) and are used to find which box went wrong. To prevent abuse we record a hash of your IP address, not the address itself.

The "ask us why" button. When the portal refuses a box and the page does not say why, the panel offers a button. Only when you press it do we send the same problem report (again with none of what you entered) to the Toronto server above, which passes it to Anthropic’s Claude API in the United States to answer that one question. Nothing goes out unless you press it. It is handled under Anthropic’s commercial terms for the API, and we use no setting that would let it train a model on this.

Your licence code

Licence codes are checked without any network call. The code you paste is stored only on your own computer and validated there (the code carries its own signature and the extension holds only the public key). Your purchase, how many applications you have used, and which application used which one are never sent to us.

There is one exception, tied to the reader above: when you use it, your licence code goes with the request to our reading service to show that you paid. We check the signature and do not store the code.

Clicking "Get a code" opens the purchase page on our website. That is an ordinary visit and carries none of your application information.

Leaving an email on the website for a free beta code: that address is used only to send you the code and to contact you about problems during the beta. There is no marketing and it is not given to anyone else. Reply to the email to have it deleted. So that one address gets one code, we store the address and a hash of it. To prevent abuse we again record a hash of your IP address rather than the address itself.

Licensed consultants requesting per-application pricing: the name, CICC or LSO number and email you provide are used for two things only: sending the prices to your email, and letting us check your licence on the CICC or LSO licensees. There is no marketing, nothing is given to anyone else, and it is not linked to any later purchase or use. We do not create an account for this and do not build a database: the details exist only in the email sent to you and in one notification we receive. Reply to have them deleted. To prevent scripted abuse we again record only a hash of the IP address.

What the extension does and does not do

It writes information you have already prepared into your own portal application, then runs a mechanical check (anything left blank, gaps in your dates, placeholders left in, answers that contradict each other) and shows you, field by field, where each value came from so you can check it.

  • It does not upload documents or submit the application. Both steps must be carried out by the applicant.
  • It does not decide how a question should be answered. Fields the documents do not answer are left empty and marked for the applicant to complete.
  • It does not verify that what you provide is true.
  • It does not assess your application and does not give immigration advice.
  • It does not guarantee any outcome. What to file, whether it is enough, and whether the pathway is right are outside what this tool does.

What each permission is for

PermissionWhat it is for
prson-srpel.apps.cic.gc.caTo fill in your own forms on this one government portal, and to read the completion status the portal itself returns
The address of the reading service (Cloud Run)The optional reader described above. It is used only when you click the button. If you never use the feature, this address is never contacted
storageTo keep your draft, your licence code and how much of it you have used on your own computer, so a portal timeout does not make you type everything again. The data never leaves your computer
sidePanelTo host the entry screen and the checklist
scriptingTo perform the filling actions on the portal page
downloadsTo save files you ask for: blank templates, and a problem report if you choose to save one when you get stuck

The extension requests access to no other website. Content scripts are injected on the portal domain only (no script is injected on the reading service's address).

Contact

Nova Stage Immigration Consulting Ltd.
Yueheng Gao, Regulated Canadian Immigration Consultant, RCIC #R534273 (regulated by the CICC)
CICC public register: https://college-ic.ca/