Privacy Policy
Last updated: 3 September 2026
This policy describes the information CongressMCP receives, why we use it, who can see it, the service providers involved, and the choices you have. It also explains an important boundary: CongressMCP does not sign in to or continuously scan your inbox or third-party subscription accounts. An AI client you choose may do that under your authorization and send selected material to CongressMCP.
1. What We Collect
Account information
- Email address (required for magic-link authentication)
- Name (required at signup)
- Session and connected-application identifiers, plus one-way hashes of login tokens or API keys where applicable
Workspace content
- Content you create or import, such as signals, notes, reports, scorecards, saved research, tasks, and contact or organization records
- Workspace settings, priorities, tracked people, issues, bills, and access-control information
Policy-inbox content
If you use the policy-inbox feature, CongressMCP stores the material that you or your authorized AI client selects and submits, including:
- The selected original message body, as submitted after required credential redaction, plus provided metadata such as provider, source type, sender, subject, received time, labels, and other supplied metadata. When the AI supplies an external message identifier for exact deduplication, CongressMCP converts it to a source-bound pseudonym before durable storage and does not retain the raw provider identifier.
- AI-derived story intelligence, including titles, summaries, priority scores and reasons, suggested actions, citations, and links to tracked people, organizations, issues, or bills
- Import and deduplication information used to avoid storing the same selected message or story repeatedly
- Source-registry settings you ask the AI to save, limited to a non-secret source key and display label, source type, cadence, initial lookback, overlap, priority, active or paused state, and operational timestamps
- Bounded-scan bookkeeping, including a non-secret source label and source type, client-generated run identifier, submitting user and AI-client channel, requested and covered time windows, overlap, run status, aggregate message counts, a one-way source-bound identity hash plus one-way content and payload hashes for selected records (which may be derived from a supplied external identifier), and operational timestamps
CongressMCP receives source content only when the AI client sends selected material through the import tool. The begin and completion tools separately receive and persist the bounded-scan metadata described above. CongressMCP does not request mailbox or subscription credentials, and it rejects common secret-bearing fields, headers, and URLs before database writes. You and the AI client must still remove credentials and private account links before submission. Deleting a message from the original inbox does not by itself delete the copy previously submitted to CongressMCP.
Usage, audit, and security data
- Actions taken through the website, API, or MCP, including state-changing actions and access to submitted, credential-redacted policy-inbox evidence
- Timestamps, request identifiers, the workspace and record involved, and, when available, the AI client or mediator used
- Technical request and diagnostic data, such as IP address, user agent, route, response status, and error information
Generic policy-inbox activity and audit records use operational metadata such as provider, record identifiers, and counts; they are not intended to copy the selected message evidence or subject. The submitted, credential-redacted subject and evidence remain in the private policy-inbox record and authenticated evidence response.
Billing data (paid plans)
- Stripe customer, subscription, plan, invoice, and transaction identifiers. Stripe collects payment-method details directly; CongressMCP does not receive your full card number.
2. How We Use It
We use the data you provide to:
- Authenticate you and maintain your sessions
- Deliver the workspace, legislative research, tracking, collaboration, and AI-tool features you request
- Store, deduplicate, rank, search, and display selected policy alerts and the intelligence derived from them
- Relate selected alerts to your tracked people, organizations, issues, and bills
- Show authorized workspace users and connected AI clients the current intelligence and, when explicitly requested, its submitted, credential-redacted evidence
- Maintain security and audit records, including a record when submitted evidence is accessed
- Detect abuse and enforce rate limits
- Communicate service-related messages (magic links, billing notifications, major product changes)
We do not sell your data. CongressMCP does not use workspace or policy-inbox content to train a CongressMCP model. Third-party AI clients and optional AI providers process data under their own terms and account settings, as described below.
3. AI Clients, Inbox Access, and Workspace Visibility
Claude, Codex, Cursor, Hermes, Grok, or another AI client may access an inbox or logged-in browser only through a connection and permissions you provide to that client. The client reads and evaluates material before choosing what to submit to CongressMCP. Its provider may therefore process inbox content under its own privacy policy; CongressMCP does not control that provider's retention or model-training settings.
After selected material is submitted, it becomes private workspace content in CongressMCP. People who are authorized to read that workspace, and connected AI clients granted workspace-read permission, can see the derived intelligence. Submitted, credential-redacted message evidence and metadata are available through dedicated, authenticated evidence views and tools; an authorized user or connected AI that invokes those views can receive that evidence. Review workspace membership and connected-AI permissions before placing confidential material in a shared workspace.
Revoking an AI connection stops that connection from making later requests, but it does not automatically delete material already stored in the workspace.
4. Service Providers and External Services
We use the following providers to operate CongressMCP. A provider receives only the categories needed for the applicable service or feature. Some entries are optional and apply only when that feature is configured or used.
| Subprocessor | Purpose | Data shared |
|---|---|---|
| Supabase | Managed database and related infrastructure | Account, workspace, policy-inbox, derived intelligence, and audit data stored by the service |
| DigitalOcean | Application and worker hosting | Requests, content processed to serve a request, and operational logs |
| Stripe, Inc. | Subscription and payment processing | Email, customer and subscription details, billing information, and payment details collected directly by Stripe |
| Resend | Transactional email delivery | Recipient email address and the transactional message, such as a login link or invitation |
| Anthropic | Optional CongressMCP AI features, including in-app chat and certain extraction, matching, or playbook workflows | The prompt, requested workspace context, and tool results needed for the feature; policy evidence only when an authorized workflow requests it |
| Sentry | Optional error monitoring when configured | Technical error and request context; default personally identifying data collection is disabled in our configuration |
| Google Fonts | Web-font delivery on public pages | Standard browser request data, such as IP address and user agent |
Public and licensed legislative-data providers are data sources rather than inbox processors. CongressMCP does not send private policy-inbox evidence to those providers as part of legislative-data ingestion. Separately, any AI, email, browser, or subscription service you choose to connect acts under its own terms and privacy policy.
5. Retention and Deletion
- Account and workspace data is retained while needed to provide the service and maintain the account or workspace
- Selected, credential-redacted policy-inbox evidence and AI-derived story intelligence remain stored with the workspace until they are deleted; deleting the source email or revoking an AI connection does not delete these stored copies
- Archived records: archiving hides or removes a record from active views but is not deletion
- Minimized audit, security, billing, and transaction records may be retained after workspace content is deleted when reasonably needed for security, fraud prevention, dispute resolution, accounting, or legal compliance
To request deletion of an account, workspace, or selected policy-inbox material, email [email protected]. We verify that the requester is authorized to control the affected data before acting. After deletion from active systems, residual copies may remain temporarily in a service provider's backup or recovery systems until they are overwritten under that provider's ordinary schedule, or where retention is required by law.
6. Your Rights
You have the right to:
- Access the data we hold about you
- Request an export of workspace content, including stored policy intelligence and associated evidence where applicable
- Correct inaccurate account information
- Delete your account and associated content, subject to the retention exceptions above
- Revoke connected AI applications and API keys
- Object to specific uses (contact support to discuss)
To exercise any of these, email [email protected]. We respond within 30 days.
7. Children
CongressMCP is a professional tool. We do not knowingly collect data from anyone under 18. If you believe we have, contact us and we will delete it.
8. International Users
The service is hosted in the United States. By using it, you understand that your data will be processed in the U.S. If you are in the EU/UK and want to discuss a data-processing agreement, contact us.
9. Security
We use safeguards including HTTPS in transit, access controls, secrets kept out of browser code, one-way hashes for stored login tokens and API keys, HttpOnly and Secure session cookies in production, rate limiting, and audit records for sensitive actions. No system is perfectly secure. We will notify affected users of a material incident when required by applicable law.
10. Changes to This Policy
We may update this policy. Material changes will be announced by email and posted here at least 14 days before taking effect.
11. Contact
Privacy questions: [email protected].