Legal
Privacy Policy
Last updated June 12, 2026
1. Who we are
Civitas provides plain-language summaries of United States government documents at joincivitas.org and app.joincivitas.org. This policy describes what personal information we collect, why, and what we do with it. Contact: support@joincivitas.org
2. What we collect
- Email address, when you join the waitlist, create an account, or subscribe. We sign you in with email magic links, so your email is your account.
- IP address, recorded transiently for rate limiting and in standard server logs to protect the Service from abuse.
- Error and usage telemetry, such as error reports and page analytics, collected to keep the Service working.
- Cookies: we use session cookies for sign-in and a preference cookie for dark mode. We do not use advertising cookies or cross-site trackers.
If you subscribe to a paid plan, payment details (card number, billing address) are collected and processed by Polar, our merchant of record, not by us. We receive subscription status and a customer identifier, never your card number.
3. How we use it
- to provide the Service and sign you in;
- to send transactional email such as magic links and waitlist confirmations;
- to manage subscriptions and billing status;
- to protect the Service from abuse; and
- to diagnose errors and improve the product.
We do not sell personal information and we do not share it for advertising.
4. Service providers
We use a small set of processors to run the Service:
- Supabase (database, authentication, file storage)
- Vercel (hosting and basic analytics)
- Resend (transactional email)
- Sentry (error monitoring)
- Cloudflare (DNS and network security)
- Polar (payments, as merchant of record, once paid plans launch)
- Anthropic (AI summarization). Only the text of public government documents is sent to the AI model. No user data is ever sent to it.
5. Retention
Account and waitlist emails are kept while your account or signup is active. Rate limiting records are pruned automatically within hours. Error and log data is retained on our providers' standard short-term schedules. Backups are retained on a rolling basis.
6. Your choices and rights
You can ask us to delete your account and associated personal information, or to export what we hold about you, by emailing support@joincivitas.org. Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act; we honor verified requests regardless of state.
7. Children
The Service is not directed to children under 16 and we do not knowingly collect their information. If you believe a child has provided us personal information, contact us and we will delete it.
8. Security
We use industry-standard measures: encrypted connections, hosted infrastructure with access controls, and secrets management. No system is perfectly secure; we will notify affected users of a breach as required by law.
9. Changes to this policy
We may update this policy. For material changes we will give notice on the site or by email before the changes take effect.