Privacy Policy
Effective Date: March 1, 2026 · Last Updated: September 22, 2026
1. Introduction
ChamberLight ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your personal data when you use our civic transparency platform.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your email address, display name, and password (stored in hashed form). You may optionally provide a profile photo.
2.2 Location Data
We collect your zip code to determine your congressional district and display relevant representatives. We do not collect precise geolocation data.
2.3 User-Generated Content
We collect the content you submit to the Platform, including article submissions, votes, comments, and reports.
2.4 Browsing and Usage Data
We collect information about how you interact with the Platform, including pages visited, features used, timestamps of activity, device type, browser type, and IP address. IP addresses are recorded with analytics events for abuse detection and rate limiting; we never publish or sell them.
2.5 Civic Stances (Votes)
Your civic stances on bills, amendments, and congressional votes (support / oppose / unsure) are private. They are visible only to you. Public surfaces show only aggregate counts — never per-user attribution. This is enforced at the database level via row-level security.
3. How We Use Your Information
- Personalization: Displaying representatives and content relevant to your congressional district.
- Notifications: Sending email notifications about activity on your submissions, moderation decisions, and platform updates you opt into.
- Analytics: Understanding usage patterns to improve the Platform, fix bugs, and develop new features.
- Security: Detecting and preventing fraud, abuse, and violations of our Terms of Service.
- Legal compliance: Meeting applicable legal obligations and responding to lawful requests.
4. Third-Party Services
ChamberLight relies on the following third-party services to operate. Each has its own privacy policy governing data they process:
- Supabase: Database hosting and user authentication. Stores your account data and platform content.
- Vercel: Application hosting and edge delivery. Processes request metadata such as IP addresses.
- OpenAI: AI-powered analysis of article content (summaries, credibility and neutrality scoring) and plain-English explanations of bills, amendments, votes and candidate profiles. The text of that content is sent for processing; no personally identifiable user data is included.
- Google (Gemini): Backup AI provider, used when OpenAI is unavailable or does not return a usable answer in time, for the same purposes and on the same terms.
- Google Civic Information API: Congressional district lookup based on your zip code.
- Resend: Transactional email delivery for authentication emails, notifications, and platform communications. Resend also delivers webhook events for sent / delivered / bounced / complained outcomes; we use these to build a suppression list (see Section 6).
- Sentry: Error monitoring and release-tag tracking. Processes IP address, user-agent metadata, and the deploy commit SHA to deduplicate error reports and align source maps with the running release.
- Congress.gov & GovInfo: Public legislative data sources. We pull bills, votes, amendments, hearings, Congressional Record statements, treaties, CRS reports, and committee reports. No user data is sent to these services.
- FEC OpenFEC: Public campaign-finance data. We pull totals, donor information (Schedule A), independent expenditures (Schedule E), and itemized disbursements (Schedule B). No user data is sent.
4a. Data Residency
Application data is hosted by Supabase in the United States. AI processing requests are sent to provider endpoints which may process the request in the United States or other jurisdictions listed in their respective sub-processor pages.
5. Cookies and Local Storage
ChamberLight uses the following client-side storage. The consent banner shown on first visit lets you accept all or reject non-essential storage; the banner re-prompts when this policy is materially updated.
- Session cookies (essential): Authentication and logged-in state via Supabase. Required to use the site.
- Consent cookie (essential):
chamberlight_consent— records your choice on the cookie banner so you are not prompted again. 13-month lifetime. - Local storage (preferences): Search history, dashboard tab preferences, and theme selection. Stored in your browser, never transmitted.
- Analytics events (opt-in): When you accept non-essential cookies, anonymized usage events (page path, referrer, event type) are recorded. Retained for 90 days and used only to improve the platform.
We do not use advertising or third-party tracking cookies.
6. Data Retention
We retain your personal data for as long as your account is active. If you delete your account, we will delete your personal information within 30 days, except where retention is required by law or for legitimate business purposes such as maintaining audit logs of moderation actions.
- Account deletion grace period: 30 days. You can cancel deletion any time during this window by signing in and confirming your password.
- Soft-deleted comments: Comments you delete are hidden immediately. The body is replaced with a tombstone (
[deleted]) and the row is preserved for thread continuity. When your account is purged, the body of any comments you authored is replaced with[deleted by user]and your user_id is severed via cascade. - Analytics events: 365 days, then automatically purged by a daily cron (
purge-analytics-events). - Cron run logs: 90 days for run summaries; 30 days for per-item audit logs. Purged daily.
- Dead-letter queue records: 30 days, then automatically purged by
purge-dlq. - Email events: Records of sends, deliveries, bounces, complaints, opens, and clicks are retained as long as the account is active so that the platform can suppress future sends to addresses that have hard-bounced or filed a spam complaint. The suppression list itself is retained indefinitely until the recipient unsubscribes via Resend or contacts us at the address below.
- Moderation audit logs: Retained indefinitely with user identifiers replaced by anonymous IDs after account purge.
- Anonymized / aggregated data: May be retained indefinitely for analytical purposes.
7. Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete personal data.
- Deletion: Request deletion of your account and associated personal data.
- Export: Request a machine-readable export of your data, including your submissions, comments, and votes.
To exercise any of these rights, contact us at privacy@chamberlight.com. We will respond to your request within 30 days.
8. California Consumer Privacy Act (CCPA)
If you are a California resident, you have additional rights under the CCPA:
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purposes for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain legal exceptions.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- No Sale of Personal Information: ChamberLight does not sell your personal information to third parties.
To submit a CCPA request, email privacy@chamberlight.com with the subject line "CCPA Request."
9. Children's Privacy
ChamberLight is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete that information as quickly as possible. If you believe a child under 13 has provided us with personal information, please contact us at privacy@chamberlight.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users via email and update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically.
11. Service Scope and Contact
ChamberLight is a U.S.-based civic transparency service intended exclusively for U.S. residents. The Platform tracks the U.S. Congress and U.S. elected officials, and we do not market or direct the service to users outside the United States. We do not maintain GDPR Article 27 / UK GDPR representatives. If you are accessing the Platform from outside the United States, you do so on your own initiative and remain responsible for complying with your local laws.
If you have questions or concerns about this Privacy Policy, please contact us at privacy@chamberlight.com.