01 Overview
This Privacy Policy explains how GovGreed ("we," "us," "our") collects, uses, stores, and shares information when you use govgreed.com and the GovGreed API. By using the Service, you agree to the practices described here.
GovGreed is operated as a small team. We are not a data broker and do not monetize user data. Our business model is API subscriptions and premium access — not advertising.
02 What We Collect
| Category | Data Collected | When | Required? |
|---|---|---|---|
| Account Data | Email address, display name, password (hashed), account creation date | When you register | Yes (to register) |
| Usage Data | Pages visited, features used, search queries, session timestamps | Automatically during use | Yes (for platform operation) |
| API Data | API key, request logs (endpoint, timestamp, response status), usage counts | When using the API | Yes (for API subscribers) |
| Watchlist / Alerts | Politicians, tickers, and alert rules you configure | When you use these features | No (optional features) |
| Paper Trading | Simulated trade positions, portfolio history (not real trades) | When you use paper trading | No (optional feature) |
| Chat History | Queries sent to the AI chat interface, conversation history | When you use AI chat | No (optional feature) |
| Waitlist | Email address, access type requested, submission timestamp | When you join the waitlist | No (voluntary) |
| Technical Data | IP address (hashed for rate limiting), browser type, referrer URL | Automatically | Yes (security/abuse prevention) |
We do not collect: payment card data (handled by payment processors), government ID, social security numbers, or any sensitive personal data.
03 How We Use Data
We use collected data only for the following purposes:
- Operate the platform — authenticate accounts, serve your watchlists, deliver API responses, and persist your preferences
- Enforce rate limits — track API usage against your tier limits and prevent abuse
- Send notifications — trade alerts, signal triggers, and account notifications you configure
- Security & fraud prevention — detect and block unauthorized access, scraping, and abuse
- Improve the platform — aggregate, anonymized usage analytics to understand which features are useful
- Communications — transactional emails (account confirmations, API key delivery). We do not send marketing emails without explicit opt-in.
We do not: sell data to advertisers, build behavioral profiles for ad targeting, share data with data brokers, or use your data to train AI models without consent.
04 Third-Party Services
GovGreed uses the following third-party infrastructure providers:
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Supabase | Database, authentication, edge functions | All user account and platform data | supabase.com/privacy |
| Vercel | Static hosting, CDN, privacy-friendly Web Analytics | IP addresses, request logs (analytics only after you opt in) | vercel.com/legal/privacy-policy |
| Google Analytics 4 | First-party product analytics (which features get used) | Hashed/anonymized IP, pages visited — only after you accept cookies | policies.google.com/privacy |
| Stripe | Payment processing for paid subscriptions | Name, email, billing details (card data goes directly to Stripe — we never see it) | stripe.com/privacy |
| OpenRouter / Anthropic | AI chat and brief generation | Chat queries you submit | openrouter.ai/privacy |
| Resend | Transactional & account email delivery | Email address, message content | resend.com/legal/privacy-policy |
| Beehiiv | Newsletter distribution (opt-in only) | Email address, subscription status | beehiiv.com/privacy |
| Discord | Community server & signal bot (if you join) | Your Discord handle & messages in our server | discord.com/privacy |
| TradingView | Embedded price charts | IP address, ticker viewed | tradingview.com/privacy-policy |
We do not embed advertising networks or social media tracking pixels, and we do not sell or share your data with data brokers. We use Google Analytics and Vercel Web Analytics purely as first-party product analytics — only after you opt in via our cookie banner, with IP anonymization enabled, and never for cross-site ad profiling.
05 X (Twitter) API Data Usage
GovGreed uses the X API v2 to:
- Publish posts from the official @GovGreed account about congressional trading data and signals
- Read mentions and replies directed at the @GovGreed account for human review and engagement decisions
- Monitor search results for @GovGreed account mentions (for engagement monitoring only)
What we do NOT do with X API data:
- We do not store X user data beyond what is temporarily needed to display our own mentions dashboard
- We do not build profiles of X users or track individuals across tweets
- We do not sell, transfer, or share X API data with third parties
- We do not use X API data to infer sensitive personal characteristics (race, health, political views, etc.) of individual users
- We do not use X API data to train machine learning models
- We do not use X API data for advertising targeting
- We do not aggregate X user data for purposes beyond managing our own account
- We do not auto-reply to users — all responses to mentions are reviewed by a human before posting
All content posted via the X API by GovGreed is based on publicly available U.S. government data. Automated posts are clearly associated with the @GovGreed account.
X API data obtained by GovGreed is retained only as long as necessary to display account engagement. We do not maintain archives of third-party X user data.
For questions about X data usage, contact: team@govgreed.com
06 Data Storage & Security
All user data is stored in Supabase PostgreSQL databases hosted on AWS infrastructure. Data is encrypted at rest and in transit (TLS 1.2+).
- Passwords are hashed using bcrypt — we cannot recover your password
- API keys are hashed — we display only the key prefix (e.g.,
gg_live_xxxx...****) - Database access is restricted by row-level security policies — users can only access their own data
- IP addresses used for rate limiting are hashed and not stored in plaintext
International data transfers
GovGreed is operated from the United States and uses U.S.-based infrastructure providers (Supabase/AWS, Vercel, Stripe, Google, OpenRouter/Anthropic). If you access the Service from the European Economic Area, the United Kingdom, or Switzerland, your personal data is transferred to and processed in the United States.
For these transfers we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) incorporated into our processors' data-processing agreements, and — where applicable — our processors' certification under the EU–U.S. Data Privacy Framework. These safeguards are designed to give your data a level of protection comparable to that required under EU/UK law. You may request a copy of the relevant transfer mechanism by emailing team@govgreed.com.
07 Cookies & Local Storage
| Type | Name / Key | Category | Purpose | Expires |
|---|---|---|---|---|
| localStorage | sb-*-auth-token |
Strictly necessary | Authentication session | Session / 7 days |
| localStorage | gg-cookie-consent |
Strictly necessary | Remembers your cookie choice | 12 months |
| localStorage | gg-sidebar-collapsed, gg-info-panel-collapsed |
Preferences | Remember sidebar / info-panel state | Persistent (until cleared) |
| Cookie (Google) | _ga, _ga_*, _gid |
Analytics — consent required | Google Analytics 4 usage measurement (set only after you accept) | Up to 2 years / 24 hours |
We do not use third-party advertising cookies or tracking pixels. Vercel Web Analytics is cookieless and also only runs after you opt in. The TradingView widget embedded on some pages may set its own cookies — refer to TradingView's privacy policy for details.
You can clear localStorage and cookies through your browser settings at any time. Clearing auth cookies will log you out of GovGreed.
08 Your Rights
You have the following rights regarding your personal data:
- Access — Request a copy of the personal data we hold about you
- Correction — Request correction of inaccurate personal data
- Deletion — Request deletion of your account and associated personal data. Note: data derived from public government records (congressional trades, bills, etc.) cannot be deleted as it is not your personal data.
- Portability — Request an export of your watchlists, alert rules, and paper trading history in JSON format
- Opt-out — Unsubscribe from any marketing communications at any time using the unsubscribe link in emails
To exercise any of these rights, email team@govgreed.com with the subject "Privacy Request." We will respond within 30 days (45 days for U.S. state-law requests, extendable once where permitted). We will not discriminate against you for exercising any privacy right. You may use an authorized agent to submit a request on your behalf; we may ask you to verify your identity before acting.
California residents (CCPA / CPRA). In the preceding 12 months we have not sold and have not "shared" (as those terms are defined under the CCPA/CPRA, including for cross-context behavioral advertising) any personal information, and we do not knowingly sell or share the personal information of consumers under 16. Because we do not sell or share, no "Do Not Sell or Share My Personal Information" link is required — but you may still exercise the rights to know/access, delete, correct, and limit the use of sensitive personal information. The categories of personal information we collect, our purposes, and the third parties we disclose to are described in Sections 02–04 above. We do not use or disclose sensitive personal information beyond the purposes permitted by the CPRA.
Other U.S. state residents (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws): you have comparable rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of any sale or targeted advertising. We do not sell personal data or engage in targeted advertising. Where a state provides an appeal process for a denied request, you may appeal by replying to our decision email.
EU / EEA / UK / Switzerland residents (GDPR / UK GDPR). Our legal bases for processing are: performance of a contract (operating your account and API subscription), legitimate interests (securing the platform, preventing abuse, and understanding aggregate feature usage), consent (optional analytics cookies and any marketing email — withdrawable at any time), and legal obligation (tax/accounting records). You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right not to be subject to solely automated decisions with legal effects (we make none). International transfers of your data are described in Section 06. You may lodge a complaint with your local data protection supervisory authority at any time.
09 Data Retention
- Account data: Retained for the lifetime of your account plus 30 days after deletion request
- API logs: Request logs retained for 90 days for billing and abuse detection
- Chat history: Retained until you delete it or delete your account
- Waitlist entries: Retained until access is granted or the waitlist is closed
- Anonymized usage analytics: Retained indefinitely (no personal identifiers)
10 Children's Privacy
GovGreed is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at team@govgreed.com and we will delete it.
11 Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Effective" date above. Material changes that reduce your privacy protections will be communicated via email (to registered users) or a prominent site notice at least 30 days before taking effect.
12 Contact
Privacy questions, data requests, and concerns:
- Email: team@govgreed.com
- Subject line: "Privacy Request" for all data rights requests
- We respond within 30 days