Privacy Policy

Last updated: July 27, 2026

OpenCongress (“we”) is committed to protecting your privacy. This policy describes the data we collect, how we use it, and your rights.

1. Data we collect

1.1 Usage data

  • Anonymous session identifier (generated locally, kept in sessionStorage for the tab only — no cross-visit tracking cookie, and only once you have accepted analytics)
  • Pages viewed and actions taken
  • Device and browser type
  • Approximate location (country/region via IP address)
  • If you are signed in: your account id, email address and name are attached to that profile and sent to PostHog. This data is therefore identifying, not anonymous, for signed-in users.

1.2 Account data (if you sign in)

  • Name and email address (via Google OAuth or email sign-up)
  • Google profile photo (if applicable)
  • Preferences (followed council members, notifications)
  • Address and council district (if provided, to find your representative)

1.3 AI conversation data

  • Messages exchanged with the AI assistant
  • Results of tools used by the assistant
  • Usage statistics (token counts, model used)

AI conversations are sent to third-party AI providers (see section 4) to generate responses. Those providers keep prompts and responses for a limited period, solely to detect abuse: up to 30 days at Anthropic, OpenAI and Mistral, and for a period Google does not publish. Anthropic keeps exchanges flagged under its usage policy for up to two years. None of them use these exchanges to train their models.

1.4 Payment data

If you subscribe, your payment information is processed directly by Stripe. We never store your card numbers — only your Stripe customer identifier and subscription status.

1.5 Technical data

  • Server logs, kept by our hosting provider (Railway) for the period its service provides. We do not set that period and we apply no anonymization of our own.
  • Error reports (Sentry), including on-error session replay — a buffer of the page activity leading up to an error is uploaded so the bug can be reproduced. All text is masked and media is blocked before it leaves your browser, there is no continuous recording, and nothing runs before you accept.
  • Session cookies (authentication only — see section 6)

2. How we use data

  • Running the service: authentication, personalization, following representatives, AI assistant
  • Improving the service: product analytics (PostHog) and error diagnostics (Sentry), both of which run only on your consent and can be withdrawn in one click
  • Communication: daily and weekly email recaps (opt-out in settings)
  • Security: abuse detection and protection

3. Data retention

  • Analytics and diagnostics events:errors and session replays are held by Sentry for 90 days, the period that applies to our plan. PostHog's retention is set by our plan with them rather than by us, so we point at their policy rather than restate a figure — see the cookie policy. Non-identifying aggregates may be kept indefinitely.
  • Account data: kept while the account is active, deleted within 30 days of account deletion
  • AI conversations: kept while the account is active, deleted with the account
  • Server logs: kept by our hosting provider (Railway) for the period its service provides; we do not set that period
  • Payment data: we hold no invoices or payment card details ourselves; invoices are kept by our payment processor (Stripe) as required by law

4. Data sharing

We do not sell or share your personal data with third parties for commercial purposes. The following technical processors may handle your data:

  • Vercel (USA) — frontend hosting
  • Railway (USA) — backend and database hosting
  • Google (USA) — OAuth authentication
  • Stripe (USA) — payment processing
  • PostHog (USA) — product analytics, stored in sessionStorage for the tab. Receives your account id, email address and name when you are signed in. Only after you accept.
  • Resend (USA) — transactional and recap emails
  • Sentry (USA) — error diagnostics, including on-error session replay (text masked, media blocked), only after you accept
  • Anthropic, OpenAI, Google and Mistral AI — AI providers. Your chat messages go to the provider of the model you select; editorial summaries are generated by Google and OpenAI. Each keeps prompts and responses for a limited period to detect abuse (see section 1.3), and none use them to train their models. Mistral AI is established in France; the other three are in the United States.

4.1 International transfers

Every processor listed above except Mistral AI is established in the United States, so using this service involves transferring your data there. Where that transfer is subject to EU or UK data protection law, the safeguards differ by processor:

  • PostHog, Sentry, Vercel, Stripe, Resend and Google are certified under the EU-US Data Privacy Framework (and its UK and Swiss extensions), and additionally carry the European Commission's standard contractual clauses as a fallback.
  • Anthropic, OpenAI and Railway rely on the standard contractual clauses, incorporated into their respective data processing agreements.

We list only the mechanisms we have verified with each processor.

5. Your rights

You can:

  • Access a copy of your personal data
  • Correct inaccurate data
  • Delete your data
  • Export your data in a structured format (JSON)

Exercising your rights: You can export your data and delete your account directly from your profile settings. For any other request, contact us at privacy@opencongress.app.

Deleting your account: when you ask us to delete your account, we cancel any active subscription with our payment processor (Stripe) immediately, then erase your personal data from our systems — profile, chat history, follows and notification preferences. An active subscription does not block deletion and does not have to be cancelled first. We keep no invoices or payment card details of our own; invoices issued while you were subscribed are retained by Stripe to meet accounting and tax obligations (see section 3). That retention rests on the legal-obligation exception to the right to erasure and does not prevent the rest of your data from being erased. Immediate cancellation does not entitle you to a pro-rata refund for the current period.

6. Cookies and trackers

The only things read from or written to your device without your consent are strictly necessary to run the service or to record your own choice:

  • NextAuth session cookie — keeps you signed in. Duration: 30 days of inactivity, extended each time you use the site, or until you sign out.
  • oc_consent_v1 (localStorage) — records whether you accepted or refused. Expires after 6 months, after which you are asked again.
  • theme (localStorage) — remembers your light/dark choice.

No advertising or profiling cookies are set. Analytics and diagnostics — PostHog (session-scoped sessionStorage), Sentry (error diagnostics, including on-error session replay) and Vercel Analytics — are never initialized before you accept, and withdrawing is a single click.

Every item we store or read is listed — with its name, storage mechanism, purpose, retention and processor — in our cookie policy, which is also where you can change or withdraw your choice.

7. Changes

We may update this policy at any time. Changes are published on this page with a revised update date. For material changes, we will notify you by email or via an in-app notification.

8. Contact

  • Email: privacy@opencongress.app
  • Data controller: Pierre Pariente Dimitrov

You can also review our Terms of Service.