Legal

Privacy Policy

This describes what Our Elected Portfolios actually does today, not what a policy of this kind usually says. The site is early: there are no accounts, no analytics and no advertising running, so most of the things a privacy policy normally has to account for do not exist here yet. Where something is planned rather than built, this page says so.

Effective · Applies to ourelectedportfolios.com

What this site is right now

Our Elected Portfolios publishes the stock trades that members of Congress disclose under the STOCK Act of 2012, read from the filings the US House Clerk publishes. The Senate’s Electronic Financial Disclosure system is not read, so nothing here covers the Senate. These are public documents about public officials.

What has been read is calendar year 2025, the House only, and not all of it: 66 of the 515 periodic transaction reports the run found are scanned paper with no readable text, and the site records those as unread rather than dropping them. The figures on the sector page are counts drawn from the filings that could be read.

None of that is data about you, which is what bounds the privacy question here. The filings describe public officials; this site still has no reader accounts and keeps no record of who reads it, and this policy should not imply otherwise in either direction.

What we collect from you

Nothing that we store and nothing that identifies you. Concretely, as of the effective date above, this site does not:

  • set any cookie on the public pages, for any purpose;
  • use an analytics or product-measurement service — there is no Google Analytics, Plausible, PostHog, Segment, Vercel Analytics or equivalent in the codebase;
  • embed a third-party pixel, advertising tag, social widget, video player, comment system or embedded map;
  • load fonts, scripts or images from another company’s servers — the typefaces are compiled into this site at build time and served from this domain, so your browser does not contact a font provider;
  • offer registration, login, newsletter signup, a contact form, or any other field for you to type into;
  • ask for, receive or process a payment. The site is free, there is no paid tier, and the billing routes in the codebase are unfinished and return an error if called.

There is no advertising identifier, no fingerprinting, no cross-site tracking and no data broker relationship, because there is no advertising.

Cookies and local storage

No cookie is set when you read a public page here. This is a property of how the application is built rather than a promise we are making about future restraint: the code that could set a session cookie is only reached on the sign-in and account routes, and there is no working sign-in — those routes are unimplemented placeholders that issue nothing. The database query behind the sector page is made by our server, without a session, and never reaches your browser.

If accounts are ever added, signing in will require a session cookie — that is a strictly necessary cookie, not a tracking one, and this policy will be updated to describe it before any such page ships.

Our hosting providers, and what they see

Two companies are involved in serving you this page, and each unavoidably observes some information about the request:

  • Vercel hosts and serves the site. Every request you make passes through Vercel’s network, which records the ordinary contents of a web server log: your IP address, the time, the URL requested, the response status, and the user-agent string your browser sends.
  • Supabase hosts our database. It sees the queries our server makes on your behalf. Those queries carry no information about you — the public pages are identical for every visitor — and your browser does not connect to Supabase directly when reading a public page.

We do not export, aggregate, enrich or profile these logs, and we do not combine them with anything else. We also have not configured a retention schedule of our own for them: they are retained by those providers under their own policies and plan defaults, and we would rather tell you that than print a confident number we do not control. Both companies act as processors for us and have their own privacy documentation.

Other vendors are wired into the codebase for features that do not exist yet, and none of them observes anything about a reader today: a rate limiter for our API endpoints (Upstash), an email sender used only to alert us to security problems (Resend), and a payment processor (Stripe) that no page can reach because there is nothing to buy. Related: our own database has a rate-limiting table, and it records an IP address in one case only — when a caller to one of our API endpoints is throttled for making too many requests. Nothing you can click on this site makes such a call, and those endpoints all require an account.

Browser security reports

The site sends a strict Content Security Policy, and asks your browser to report violations of it back to an address on this same domain. If your browser sends such a report — usually because something tried to inject a script, or because we misconfigured a rule after an update — it contains the page URL, the rule that was broken and the resource that was blocked. We write a truncated copy to our server log, rate-limited, and never to the database. It is a security signal, not a measurement of you, and it is not used to build any profile.

Advertising: intended, not running

The plan is for this site to be free to read and funded by advertising. That is not running today. There is no ad network integrated, no ad slot on any page, no advertising cookie and no audience segment.

This policy will need to change before a single advert is served. Ad delivery normally brings third-party cookies or device identifiers, a consent mechanism for readers in the EU, UK and several US states, and a genuine question about whether data is being shared or sold. Rather than pre-authorise all of that with vague language now, we have written this page to describe only what is true. If you return and find advertising on the site, this page should have a later effective date and a section describing it. If it does not, that is our mistake and we would like to hear about it.

Accounts and email

There are no user accounts. We hold no email addresses for readers, operate no mailing list, and send no marketing email. If accounts are built later they will collect at minimum an email address and will be described here first.

Information about members of Congress

Worth separating from the above: the filings this site reads contain personal information about members of Congress and, in some cases, their spouses and dependent children, because federal law requires those disclosures to be filed and published. That information comes from the official public record, not from us. Today the site publishes counts drawn from those filings rather than the filings themselves; as more pages are built, more of the filed detail will appear on them.

It is not reader data, and none of this policy — which is about you — governs it.

Your rights, and what we can honestly do

Privacy law in several jurisdictions gives you the right to see, correct, delete or port the personal data an operator holds about you. We take those rights seriously, and we also want to be straight about the limits here: we hold no file on you to show you, and no record to delete. A request would truthfully be answered “we have nothing.”

The exception is the request logs described above, which sit with our hosting providers. If you want those addressed, tell us and we will pass the request on, though we cannot promise an outcome we do not control. You can also ask us questions about anything on this page and we will answer them.

Children

This site is a public-records reference and is not directed at children. We do not knowingly collect personal information from anyone, of any age, because we do not collect personal information at all. This section will need real substance if accounts are ever introduced.

Changes to this policy

We will update this page when the site changes, and the effective date at the top will move. Two changes in particular require a rewrite rather than an edit, and we have committed to doing them before the change ships rather than after: introducing advertising, and introducing accounts.

Contacting us

We do not have a general enquiries address yet, and we would rather say so than print one that bounces. The one monitored inbox is:

security@ourelectedportfolios.com

It was set up for security reports, and security reports take priority there, but privacy questions about this page are welcome at the same address until a dedicated one exists. Please do not include sensitive personal information in your message — there is no need to identify yourself to ask us a question about this policy.