1 · What we collect
| Category | Examples | Source |
|---|---|---|
| Account | Name, work email, role, organisation | You, at signup |
| Company profile | Industry classification (NAICS), states and counties of operation, employee band, legal entities, regulators | You, during onboarding |
| Usage | Which briefings were opened, tasks acknowledged, features used | Automatic |
| Technical | IP address, browser/app version, timestamps, error logs | Automatic |
| Billing | Billing contact and invoice records | You / our payment processor |
We do not want your documents. Federal Index reads government publications, not your files. We do not ask for your contracts, filings, or internal records, and the product does not require them. What we need is your footprint — enough to know which government bodies reach you.
Payment details
Card details are handled by our payment processor and are never transmitted to or stored by Federal Index. We see the fact of a payment, not the instrument.
2 · Why we collect it
- To configure your workspace. Your industry and footprint determine which regulators apply and which dashboard each role receives. This is the core of the product.
- To route obligations to the right people. Roles determine who is told what.
- To operate and secure the Service — authentication, abuse prevention, debugging.
- To meet our notification obligation under the Coverage Commitment §6, which requires us to hold current contacts for your senior executives.
- To bill you.
Our legal bases, where applicable: performance of our contract with you, our legitimate interest in operating and securing the Service, and compliance with law.
3 · What we never do
We never sell your personal or company data.
We never rent or share it for advertising.
We never use your content to train AI models without your opt-in consent.
We never let one customer's data appear in another customer's account.
We never aggregate your compliance posture into a product we sell to anyone else —
including your competitors, insurers, or regulators.
4 · AI processing
The Service uses large language models to interpret government documents. What that means concretely:
- What the models read: public government publications, plus enough of your footprint (industry, states, counties, roles) to decide whether a rule applies to you and who should hear about it.
- Where processing happens: at our AI provider, under a commercial agreement that prohibits training on our data.
- Retention at the provider: content is processed to serve your request under a commercial agreement that prohibits training on it, and is not retained to improve their models.
- Human review: our staff may review outputs to fix defects. Access is limited to what is needed and is logged.
5 · Sub-processors
We use a small number of third parties to run the Service. Each is bound to protect your data.
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, storage |
| Anthropic | AI interpretation of government documents |
| Vercel | Web hosting and delivery |
| Railway | Application and ingestion infrastructure |
| Stripe | Payment processing (they handle card data; we do not) |
| Resend | Transactional email — invitations, notices under the Coverage Commitment |
We will give notice of new sub-processors and, on request, provide a standard Data Processing Agreement (with EU Standard Contractual Clauses for any transfer outside your region) that allocates controller/processor roles and lets you object to a new sub-processor. For EU/UK personal data, that DPA governs and controls over this Policy on data-protection matters.
6 · Security
- Tenant isolation at the database layer. One organisation's data is structurally unable to appear in another's account — enforced by row-level security, not by application code that could be bypassed by a bug.
- Individual credentials. Every person gets their own; shared logins are prohibited so that access is attributable.
- Role locking. People see the dashboards their job requires, not everything.
- Encryption in transit (TLS) and at rest.
- Least privilege for staff access, with logging.
Honest about our stage: we are a beta-stage company and are not yet SOC 2 certified. If you need a completed security questionnaire or a formal certification today, ask us and we will tell you exactly where we stand rather than imply otherwise.
Breach notification
If we confirm a security incident that has compromised your personal data, we will notify your account's administrative and legal contacts without undue delay, and in any event within 72 hours of confirmation — the same commitment made in Terms §7.1.
7 · Retention & deletion
- Account and profile data: kept while your account is active.
- On termination: deleted within 90 days, except where law requires retention (e.g. tax records).
- Backups age out on their own cycle; deletion propagates as backups expire, within a further 90 days.
- Government documents we ingest are public records and are retained independently of any customer.
8 · Your rights
Depending on where you are (including under the GDPR and the CCPA/CPRA), you may have the right to:
- access the personal data we hold about you;
- correct it if it is wrong;
- delete it;
- export it in a portable format;
- object to or restrict certain processing;
- not be discriminated against for exercising any of these.
Email 1officecorporate@gmail.com and we will respond within 30 days. We do not sell personal information, so there is nothing to opt out of.
9 · Cookies & third-party requests
This website uses no advertising or third-party tracking cookies, and sets no cookies that require consent. The application uses strictly necessary cookies to keep you signed in.
For transparency: our pages currently load web fonts from Google Fonts, which means your browser makes a request to Google's servers (exposing your IP address to Google) when a page loads. This is a font request, not tracking, and sets no cookie — but it is a third-party request, so we name it here rather than pretend it does not happen. We intend to self-host these fonts to remove it.
10 · Children
The Service is for businesses. It is not directed at anyone under 16 and we do not knowingly collect their data.
11 · Changes
We will post material changes here and notify your account's administrative contacts at least 30 days before they take effect. The version and date at the top identify the operative version.
12 · Contact
Privacy questions, requests, or complaints: 1officecorporate@gmail.com
Federal Index is an independent, privately operated service. Not a government agency; not affiliated with or endorsed by any authority. Nothing here is legal advice.