GavelScope

Back to app

Privacy Policy

Operator: Field & Forge Ventures. Last reviewed: July 19, 2026.

Draft, pending review by counsel. This policy describes GavelScope's current data practices in good faith. It is not final and does not yet constitute legal advice or a binding commitment until reviewed and approved by counsel.

GavelScope, operated by Field & Forge Ventures ("GavelScope," "we," "us"), provides legislative intelligence software for government affairs professionals. This Privacy Policy explains how we collect, use, disclose, and protect personal information through gavelscope.com and the GavelScope application (together, the "Services"). It also describes the choices you have. Please read it together with our Terms. If you have signed a subscription agreement with us, that agreement controls where it conflicts with this policy.

Who this policy covers

This policy applies to everyone whose personal information we process through the Services:

How we collect information

We collect information in three ways: directly from you when an administrator creates your account or when you contact us; automatically through your use of the Services (for example, standard server logs); and from public sources such as the Washington State Legislature's public records and other government data.

The information we collect

Personal information. For account holders we collect an email address (your login identifier), a display name entered by the administrator who created the account, login timestamps, and a password stored only as a salted cryptographic hash, never in plain text. A signed-in session is identified by an opaque token stored as a hashed digest.

Customer content. Account holders and administrators enter content into the Services, such as client issue profiles, notes, priorities, and edits to AI drafts. You control this content and decide what to put in it. We process it to provide the Services to you and do not use it for any unrelated purpose.

Public legislative data. We process bills, sponsors, hearing schedules, official actions, and related public records. This is public information about public activities and public officials. It is not sensitive personal data.

Aggregate and anonymous information. We may derive statistics about how the Services are used. This information does not identify any individual.

How we use information

AI processing and how it is labeled

GavelScope uses Anthropic's Claude API to generate bill summaries, relevance scores, and drafts. Only bill text and client issue profiles are sent to that API. Account emails and display names are never sent to it. We do not permit customer content to be used to train third-party AI models, and we do not sell personal information.

AI output is analysis, not official fact. Summaries, scores, and predictions are labeled as AI-generated, and predictive outputs are labeled as model estimates. They are not a substitute for the official legislative record, and they are not legal advice. Every AI claim in the product is presented alongside its source citation.

Public officials and our legal basis

We process information about legislators and public officials because there is a strong and legitimate public interest in their legislative activities, the information is drawn from public records, the individuals are public figures who can reasonably expect this information to be publicly available, and the processing has minimal impact on them. Where required, we rely on this legitimate interest, and on your consent and the performance of our contract with your organization, as our bases for processing.

Cookies and automated collection

GavelScope uses one cookie: a strictly necessary, HttpOnly session cookie that keeps you signed in. It is not used for tracking. We do not use advertising cookies, analytics SDKs, remarketing pixels, or third-party trackers in the application. Our servers keep standard request logs (such as IP address, path, and timestamp) for security and reliability, retained on our hosting provider's default schedule.

Where your data lives

The Services run on Cloudflare's platform. Account data (email, display name, login timestamps, salted password hash) and session digests live in our Cloudflare D1 database. Public legislative data, client issue profiles, AI-generated scores, briefs, and citations also live in that Cloudflare D1 database, in tables separate from account data. If we add a Cloudflare KV namespace or other store for any personal data in the future, we will name it here before storing that data.

When we share information

We do not sell personal information and do not share it with unaffiliated third parties for their own marketing. We share information only as follows:

International users

The Services are operated from the United States and run on Cloudflare's global network, so your information may be processed in the United States. GavelScope is not currently certified under the EU-US Data Privacy Framework. If we begin serving users in the European Economic Area, the United Kingdom, or Switzerland, we will confirm the appropriate safeguards for those transfers with counsel and update this policy before doing so.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. Account holders can ask an administrator to correct a display name, delete an account, or export account data. Deleting an account removes the login and every active session for it in one step. To make a request, or if you believe rights under the GDPR, the CCPA, or another law apply to you, contact us at the address below with "Privacy Request" in the subject line. We will respond as required by applicable law. For CCPA purposes, we do not sell personal information.

Data retention and deletion

Account records persist until an administrator deletes them; there is no automatic expiration on the account itself. Sessions expire after 30 days, or immediately on logout, password change, or administrator reset. Deleting an account (an administrator action) removes the account and every active session for it in one step. Public legislative data, client issue profiles, AI-generated scores, briefs, and citations are retained at the operator's discretion, since none of it identifies a member of the public, and the operator can purge it at any time. Cloudflare's edge request logs age out on Cloudflare's default schedule (up to 7 days) and are not accessible or deletable through the application.

Security

We use commercially reasonable safeguards designed to protect personal information: passwords stored as salted hashes, encryption in transit and at rest, session tokens stored as digests, access limited to authorized routes behind authentication, and monitoring for abnormal activity. No system is perfectly secure, and we cannot guarantee that information will never be accessed by unauthorized parties. If we become aware of a security incident affecting personal information, we will notify affected individuals as required by law.

Children

The Services are for adult professionals. We do not knowingly collect information from anyone under 13. If we learn that we have, we will delete it promptly.

Changes to this policy

We may update this policy. If we make a material change to how we handle personal information, we will post the updated policy here and, where appropriate, provide additional notice. Continued use of the Services after a change takes effect means you accept the updated policy.

Contact

Field & Forge Ventures operates GavelScope. For privacy questions or requests, contact contact@fieldforgeventures.com with "Privacy Request" in the subject line.