Skip to main content

Privacy

What we do, and what we don’t, with your data.

Last updated April 29, 2026

In one paragraph

OpenComment exists to help ordinary people participate in federal rulemaking. To do that we ask you for context about your life: your occupation, state, household, topics, optional stories, and optional context you choose to add. We use that context to rank what you see, explain why a rule matched, and draft comments anchored to your real situation. We don’t sell that data, we don’t share it, and we don’t train models on it. You can delete every byte of it with one click.

What we don’t do

  • We never auto-submit. Every comment is submitted manually by you, on regulations.gov, under your name. We don’t POST anything to the federal docket on your behalf.
  • We don’t sell your data. Not to advertisers. Not to data brokers. Not to political operations. Not to anyone.
  • We don’t train models on you. Your profile, your stories, and the comments we draft for you are not used to train any model, ours or anyone else’s. Our AI provider has the same commitment in their data policy.
  • We don’t generate identical text across users. Astroturf comments are exactly the problem we’re trying to fix. Every draft is anchored to your specific profile, the specific rule, and the variant you choose.
  • We don’t track you across the web. No third-party advertising trackers. No cross-site profiles. Analytics is privacy-first and aggregated.

What we do collect

The data you give us during onboarding: age range, occupation, state of residence, additional states you care about, income bracket, household status, topics of interest, and optional free-text context. Optionally: short personal stories you choose to share. We also keep an account-level record of the rules you save, the rules you mark as commented on, and thumbs up/down feedback you give to improve ranking.

We do not collect: your real name (unless you put it in a story), your address, your phone number, your race, your political affiliation, your immigration status (you may choose to mention this in a story; we never require it), or any biometric or behavioral data.

How we use it

  • Ranking your feed. We use your topics, occupation, state, optional context, stories, and feedback to score open federal rules against your situation. We also store derived matching signals, such as embeddings, so free-text stories can improve matches without reprocessing all of your text on every visit.
  • Drafting your comments and explanations. When you open a rule, we send the rule’s text and your profile context to Google’s Gemini API to draft a comment in your voice or explain why a rule matched you. Google’s commercial terms prohibit them from training on or retaining that content.
  • Sending email you’ve asked for. Weekly digests, closing-soon reminders, and final-rule notices, only at the cadence you’ve set in your email preferences. You can opt out of any one of those, or all of them.

Where it lives

Your data is stored in a Postgres database hosted by Supabase in the United States. It is encrypted at rest and in transit. We also store generated summaries, personalized match explanations, and derived matching signals used to rank your feed. API keys for any third-party service we use (AI provider, email sender, federal docket) are stored server-side only and never exposed to your browser.

Your controls

From your settings, you can:

  • See every field we have stored about you, in plain English.
  • Delete any individual field, or your entire account.
  • Export everything we have as a JSON file.
  • Turn off any email channel, or all of them, at any time. Every email we send also has a one-click unsubscribe link.

Account deletion is a single click plus one confirmation. It runs within 24 hours and removes your profile, saved rules, commented history, stories, ranking feedback, cached explanations, derived matching signals, and email preferences from our database, plus your account from our auth provider.

Cookies and tracking

We use only the cookies needed to keep you signed in. We don’t use third-party advertising cookies. If we ever add anything beyond essential cookies, we’ll add a banner asking first.

Children

OpenComment is for adults. We don’t knowingly collect data from anyone under 13. If you believe we’ve received data from a minor, contact us and we’ll delete it.

Changes to this policy

If we materially change how we collect or use data, we’ll update this page and email everyone with an active account before the change takes effect.

Contact

Questions, concerns, or a data request you can’t do self-serve? Reach us at privacy@opencomment.org.