Privacy Policy
GavelScope, operated by Field & Forge Ventures ("GavelScope," "we," "us"), provides legislative intelligence software for government affairs professionals. This Privacy Policy explains how we collect, use, disclose, and protect personal information through gavelscope.com and the GavelScope application (together, the "Services"). It also describes the choices you have. Please read it together with our Terms. If you have signed a subscription agreement with us, that agreement controls where it conflicts with this policy.
Who this policy covers
This policy applies to everyone whose personal information we process through the Services:
- Visitors who browse our public pages.
- Account holders (subscribers and their client users) who sign in to the application. Every account is created by an administrator. There is no public self-signup.
- Trial users evaluating the Services under a limited arrangement.
- Public individuals, meaning legislators, public officials, and others whose activities are matters of public record and appear in the legislative data we process.
How we collect information
We collect information in three ways: directly from you when an administrator creates your account or when you contact us; automatically through your use of the Services (for example, standard server logs); and from public sources such as the Washington State Legislature's public records and other government data.
The information we collect
Personal information. For account holders we collect an email address (your login identifier), a display name entered by the administrator who created the account, login timestamps, and a password stored only as a salted cryptographic hash, never in plain text. A signed-in session is identified by an opaque token stored as a hashed digest.
Customer content. Account holders and administrators enter content into the Services, such as client issue profiles, notes, priorities, and edits to AI drafts. You control this content and decide what to put in it. We process it to provide the Services to you and do not use it for any unrelated purpose.
Public legislative data. We process bills, sponsors, hearing schedules, official actions, and related public records. This is public information about public activities and public officials. It is not sensitive personal data.
Aggregate and anonymous information. We may derive statistics about how the Services are used. This information does not identify any individual.
How we use information
- To provide the Services: maintain your account, generate bill scores and briefs, and deliver the features you use.
- To provide information about public individuals and their legislative activities to authorized users.
- To respond to your requests and provide support.
- To monitor, secure, operate, and improve the Services, and to diagnose problems.
- To comply with legal obligations and enforce our Terms and rights.
AI processing and how it is labeled
GavelScope uses Anthropic's Claude API to generate bill summaries, relevance scores, and drafts. Only bill text and client issue profiles are sent to that API. Account emails and display names are never sent to it. We do not permit customer content to be used to train third-party AI models, and we do not sell personal information.
AI output is analysis, not official fact. Summaries, scores, and predictions are labeled as AI-generated, and predictive outputs are labeled as model estimates. They are not a substitute for the official legislative record, and they are not legal advice. Every AI claim in the product is presented alongside its source citation.
Public officials and our legal basis
We process information about legislators and public officials because there is a strong and legitimate public interest in their legislative activities, the information is drawn from public records, the individuals are public figures who can reasonably expect this information to be publicly available, and the processing has minimal impact on them. Where required, we rely on this legitimate interest, and on your consent and the performance of our contract with your organization, as our bases for processing.
Cookies and automated collection
GavelScope uses one cookie: a strictly necessary, HttpOnly session cookie that keeps you signed in. It is not used for tracking. We do not use advertising cookies, analytics SDKs, remarketing pixels, or third-party trackers in the application. Our servers keep standard request logs (such as IP address, path, and timestamp) for security and reliability, retained on our hosting provider's default schedule.
Where your data lives
The Services run on Cloudflare's platform. Account data (email, display name, login timestamps, salted password hash) and session digests live in our Cloudflare D1 database. Public legislative data, client issue profiles, AI-generated scores, briefs, and citations also live in that Cloudflare D1 database, in tables separate from account data. If we add a Cloudflare KV namespace or other store for any personal data in the future, we will name it here before storing that data.
When we share information
We do not sell personal information and do not share it with unaffiliated third parties for their own marketing. We share information only as follows:
- Service providers (subprocessors). Cloudflare (hosting and database) and Anthropic (AI processing) receive only the data needed to perform their function. We process public legislative data from sources including the Washington State Legislature and the Washington Public Disclosure Commission.
- Legal requirements. We may disclose information where we reasonably believe the law requires it, and we will attempt to notify you first where permitted.
- Protection and safety. To address suspected fraud, security threats, or violations of our Terms.
- Business transfer. If the business or its assets are transferred, information may transfer with it, subject to protections consistent with this policy.
International users
The Services are operated from the United States and run on Cloudflare's global network, so your information may be processed in the United States. GavelScope is not currently certified under the EU-US Data Privacy Framework. If we begin serving users in the European Economic Area, the United Kingdom, or Switzerland, we will confirm the appropriate safeguards for those transfers with counsel and update this policy before doing so.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. Account holders can ask an administrator to correct a display name, delete an account, or export account data. Deleting an account removes the login and every active session for it in one step. To make a request, or if you believe rights under the GDPR, the CCPA, or another law apply to you, contact us at the address below with "Privacy Request" in the subject line. We will respond as required by applicable law. For CCPA purposes, we do not sell personal information.
Data retention and deletion
Account records persist until an administrator deletes them; there is no automatic expiration on the account itself. Sessions expire after 30 days, or immediately on logout, password change, or administrator reset. Deleting an account (an administrator action) removes the account and every active session for it in one step. Public legislative data, client issue profiles, AI-generated scores, briefs, and citations are retained at the operator's discretion, since none of it identifies a member of the public, and the operator can purge it at any time. Cloudflare's edge request logs age out on Cloudflare's default schedule (up to 7 days) and are not accessible or deletable through the application.
Security
We use commercially reasonable safeguards designed to protect personal information: passwords stored as salted hashes, encryption in transit and at rest, session tokens stored as digests, access limited to authorized routes behind authentication, and monitoring for abnormal activity. No system is perfectly secure, and we cannot guarantee that information will never be accessed by unauthorized parties. If we become aware of a security incident affecting personal information, we will notify affected individuals as required by law.
Children
The Services are for adult professionals. We do not knowingly collect information from anyone under 13. If we learn that we have, we will delete it promptly.
Changes to this policy
We may update this policy. If we make a material change to how we handle personal information, we will post the updated policy here and, where appropriate, provide additional notice. Continued use of the Services after a change takes effect means you accept the updated policy.
Contact
Field & Forge Ventures operates GavelScope. For privacy questions or requests, contact contact@fieldforgeventures.com with "Privacy Request" in the subject line.