Privacy Policy

Last updated: 3 September 2026

This policy describes the information CongressMCP receives, why we use it, who can see it, the service providers involved, and the choices you have. It also explains an important boundary: CongressMCP does not sign in to or continuously scan your inbox or third-party subscription accounts. An AI client you choose may do that under your authorization and send selected material to CongressMCP.

1. What We Collect

Account information

Workspace content

Policy-inbox content

If you use the policy-inbox feature, CongressMCP stores the material that you or your authorized AI client selects and submits, including:

CongressMCP receives source content only when the AI client sends selected material through the import tool. The begin and completion tools separately receive and persist the bounded-scan metadata described above. CongressMCP does not request mailbox or subscription credentials, and it rejects common secret-bearing fields, headers, and URLs before database writes. You and the AI client must still remove credentials and private account links before submission. Deleting a message from the original inbox does not by itself delete the copy previously submitted to CongressMCP.

Usage, audit, and security data

Generic policy-inbox activity and audit records use operational metadata such as provider, record identifiers, and counts; they are not intended to copy the selected message evidence or subject. The submitted, credential-redacted subject and evidence remain in the private policy-inbox record and authenticated evidence response.

Billing data (paid plans)

2. How We Use It

We use the data you provide to:

We do not sell your data. CongressMCP does not use workspace or policy-inbox content to train a CongressMCP model. Third-party AI clients and optional AI providers process data under their own terms and account settings, as described below.

3. AI Clients, Inbox Access, and Workspace Visibility

Claude, Codex, Cursor, Hermes, Grok, or another AI client may access an inbox or logged-in browser only through a connection and permissions you provide to that client. The client reads and evaluates material before choosing what to submit to CongressMCP. Its provider may therefore process inbox content under its own privacy policy; CongressMCP does not control that provider's retention or model-training settings.

After selected material is submitted, it becomes private workspace content in CongressMCP. People who are authorized to read that workspace, and connected AI clients granted workspace-read permission, can see the derived intelligence. Submitted, credential-redacted message evidence and metadata are available through dedicated, authenticated evidence views and tools; an authorized user or connected AI that invokes those views can receive that evidence. Review workspace membership and connected-AI permissions before placing confidential material in a shared workspace.

Revoking an AI connection stops that connection from making later requests, but it does not automatically delete material already stored in the workspace.

4. Service Providers and External Services

We use the following providers to operate CongressMCP. A provider receives only the categories needed for the applicable service or feature. Some entries are optional and apply only when that feature is configured or used.

SubprocessorPurposeData shared
SupabaseManaged database and related infrastructureAccount, workspace, policy-inbox, derived intelligence, and audit data stored by the service
DigitalOceanApplication and worker hostingRequests, content processed to serve a request, and operational logs
Stripe, Inc.Subscription and payment processingEmail, customer and subscription details, billing information, and payment details collected directly by Stripe
ResendTransactional email deliveryRecipient email address and the transactional message, such as a login link or invitation
AnthropicOptional CongressMCP AI features, including in-app chat and certain extraction, matching, or playbook workflowsThe prompt, requested workspace context, and tool results needed for the feature; policy evidence only when an authorized workflow requests it
SentryOptional error monitoring when configuredTechnical error and request context; default personally identifying data collection is disabled in our configuration
Google FontsWeb-font delivery on public pagesStandard browser request data, such as IP address and user agent

Public and licensed legislative-data providers are data sources rather than inbox processors. CongressMCP does not send private policy-inbox evidence to those providers as part of legislative-data ingestion. Separately, any AI, email, browser, or subscription service you choose to connect acts under its own terms and privacy policy.

5. Retention and Deletion

To request deletion of an account, workspace, or selected policy-inbox material, email [email protected]. We verify that the requester is authorized to control the affected data before acting. After deletion from active systems, residual copies may remain temporarily in a service provider's backup or recovery systems until they are overwritten under that provider's ordinary schedule, or where retention is required by law.

6. Your Rights

You have the right to:

To exercise any of these, email [email protected]. We respond within 30 days.

7. Children

CongressMCP is a professional tool. We do not knowingly collect data from anyone under 18. If you believe we have, contact us and we will delete it.

8. International Users

The service is hosted in the United States. By using it, you understand that your data will be processed in the U.S. If you are in the EU/UK and want to discuss a data-processing agreement, contact us.

9. Security

We use safeguards including HTTPS in transit, access controls, secrets kept out of browser code, one-way hashes for stored login tokens and API keys, HttpOnly and Secure session cookies in production, rate limiting, and audit records for sensitive actions. No system is perfectly secure. We will notify affected users of a material incident when required by applicable law.

10. Changes to This Policy

We may update this policy. Material changes will be announced by email and posted here at least 14 days before taking effect.

11. Contact

Privacy questions: [email protected].