Privacy Policy

Research does not require an account. This policy explains the public records we publish and the limited personal data used to operate optional services safely.

Last updated 26 August 2026

Controller and contact

The operator identity has not yet been configured. Paid subscriptions and advertising are disabled by code until a real legal name, address, jurisdiction, email, telephone number, and reviewed disclosures are supplied. Use the contact page for current requests.

Send privacy requests through the contact page. The operator records whether an EU or UK representative and a data protection officer are legally required before enabling monetisation.

Public political records

We collect parliamentary voting records, public-office information, party and political-group affiliation, legislation, lobby-register entries, and official meeting records from the primary or openly licensed sources linked on each research page. We calculate clearly labelled comparisons such as group alignment, rebellions, issue fingerprints, and voting similarity from those records.

This processing supports public accountability, research, civic education, source verification, and correction of the public record. Because political opinions can be specially protected personal data, the operator must maintain a jurisdiction-specific lawful-basis and special-category analysis, legitimate-interests assessment where applicable, and DPIA decision. Publication in an official source does not remove accuracy, fairness, objection, correction, and minimisation duties.

A public official or another affected person may request correction, contextualisation, restriction, or objection review through the contact page. We verify the primary record, preserve an audit trail, and explain the outcome. We do not silently rewrite an official source record; corrections to our ingestion or analysis are labelled and propagated.

Purposes and legal bases

  • Site delivery and security: IP address, browser/user-agent, requested route, time, and security events, used for legitimate interests in service delivery, abuse prevention, incident response, and legal claims. When enabled on account forms, Cloudflare Turnstile also processes limited network, TLS, browser, site-key, and origin signals and returns a one-time challenge token to help distinguish automated requests.
  • Privacy-minimized product measurement: daily totals for a small allowlist of event, research-surface, and acquisition-source categories, used to understand evidence use and improve the service. The product-analytics table contains no user or session identifier, URL, search term, raw referrer, IP address, or browser/user-agent. Network identifiers may still be processed transiently for request security and ordinary platform logs.
  • Operator reporting: read-only server-to-server AdSense and Search Console reports may be reduced to daily account/ad-unit/platform performance, provider-health counts, property-level discovery totals, and one fixed Our Elected brand aggregate. These Super Admin-only tables do not store a visitor identity, page URL, search query, OAuth credential, IP address, or browser/user-agent, and they are not joined to account or first-party event data.
  • Optional account and preferences: authentication email, profile, home country, follows, reactions, and digest choice, used to perform the requested account service and honour consent-based email choices.
  • Ad-free billing: Stripe customer and subscription identifiers, invoices, status, and accounting evidence, used to perform the subscription contract and meet legal, tax, fraud-prevention, and accounting duties. Full card numbers are processed by Stripe and are not stored here.
  • Advertising, only after activation: consent choices and Google advertising/measurement data, based on consent where required and subject to a certified consent platform. Refusing optional advertising storage does not restrict research.
  • Public-record research: official political records and source-linked analysis, under the operator’s documented public-interest, legitimate-interest, manifestly-public, expression/research, or other jurisdiction-specific basis approved before processing at scale.

AI summaries

Anthropic Claude may generate a short plain-language summary from public legislative material. Account and billing data are not included in model prompts. AI text is visibly labelled, carries model/date provenance, and links back to the primary record. Readers should verify the official text and may report an inaccurate summary.

Processors and recipients

  • Supabase — authentication, database, storage, and account infrastructure.
  • Vercel — hosting, delivery, request processing, and scheduled jobs.
  • Stripe — checkout, payment processing, invoices, fraud controls, and subscription management.
  • Google AdSense and the selected Google-certified consent platform — advertising, measurement, fraud prevention, and privacy choices only after activation.
  • Google AdSense Management and Search Console APIs — read-only operator reporting using server-held OAuth credentials; no additional browser analytics tag is installed.
  • Resend — the weekly digest only while a user is affirmatively opted in.
  • Anthropic — processing of public legislative material for labelled summaries.
  • Cloudflare — optional Turnstile abuse prevention on registration, password login, and password-recovery forms. The application does not send form entries to Turnstile or store challenge tokens in its database. See Cloudflare's Turnstile Privacy Addendum.
  • Public authorities, professional advisers, or another recipient only where legally required, necessary for legal claims, or requested by the affected person.

International transfers

Some providers may process data outside your country. Before enabling a provider, the operator records hosting regions, adequacy decisions, Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, Swiss safeguards, supplementary measures, and how a copy can be requested. Contact us for the safeguard applicable to your data.

Retention

  • Rate-limit events: up to 30 days.
  • Security events containing IP/browser data: up to 180 days unless an active incident or legal claim requires a documented hold.
  • Audit records: up to 365 days unless accounting, fraud, litigation, or another legal duty requires longer retention.
  • Ingestion telemetry: up to 90 days; public source records remain while relevant to the historical research record.
  • Aggregate product counters: up to 400 days, without event-level or identifiable behavior.
  • Account preferences: while the account exists, then deleted or de-identified subject to lawful billing/security holds and processor propagation.
  • Billing and tax evidence: for the period required by the operator’s applicable accounting and tax law; Stripe may retain independent legal records.
  • AI summaries: until replaced, corrected, or the underlying research record is removed.
  • Turnstile response tokens: valid for up to five minutes, single-use, and not stored in application tables. Cloudflare signal retention is governed by its terms and must be recorded in the operator’s processor register.

Your rights

Depending on your location, you may access, correct, erase, restrict, object to, or export personal data; withdraw consent without affecting earlier processing; and complain to your local supervisory authority. Signed-in users can export account data and request deletion under Settings → Data & privacy. You can also contact us, including if you cannot sign in.

We may verify identity, preserve information required by law, refuse or limit a request where an exemption applies, and explain that decision and the available complaint route. We do not use account data to make solely automated decisions that produce legal or similarly significant effects.

Children and changes

The optional subscription and account are not directed to children. The operator must set and document a supported minimum age for each offered jurisdiction before targeted child-facing features are introduced.

Material policy changes are dated here. Where a change affects an existing consent or contract, we provide the additional notice or choice required by law.