Our data & AI practices
What this page is. We spend all day writing down what other companies have to do about AI and data. It would be odd not to write down what we do. This page describes our practices. It deliberately makes no compliance claims — you will not find “GDPR compliant” or “CCPA compliant” anywhere on it, because that is a conclusion for a regulator or a lawyer, not a badge a vendor gives itself. We are not lawyers, and this is not legal advice. Everything below is a description of something the site actually does, and most of it you can check yourself in a browser rather than take on trust.
1. Everything we collect, and why
One row per thing we actually touch. If something is not in this table, either we do not collect it or this page is out of date — tell us and we will fix whichever it is. The formal version of this lives in the privacy policy.
| What | Data | Why | How long | Where |
|---|---|---|---|---|
| Comment you post | Comment text, the display name you type, your email address, a one-way hash of your IP | To publish the comment, to reply to you, and to rate-limit abuse | Until you or we remove the comment | Supabase (our database)Name and comment are public. Your email is never shown to anyone and never published. Your IP is stored only as an irreversible hash — we cannot turn it back into an IP address. |
| Up/down vote | A one-way hash of (a random browser id + your IP), and the direction of the vote | So one visitor counts once, and to cap vote brigading | Until the vote is removed or the target is deleted | SupabaseNo account, no name, no email, no plaintext IP. We cannot tell who voted — only that the same hash voted twice. |
| API key request | Your email address, an optional label, the plan tier, a hash of the key, per-key request counters | To issue and support the key and to enforce the rate limits published on /pricing | For as long as the key exists | Supabase; the key email is delivered via ResendAsk us and we revoke the key and delete the record. |
| Payment for a paid plan | Handled by Polar: billing identity, payment method, invoices | To take payment and provision the plan | Per Polar’s retention; we hold only the subscription id and plan tier | Polar and its payment processorsWe never see or store your card details. |
| Newsletter signup | Email address, the exact consent wording, the timestamp, the page you signed up from, a hashed IP | To send the weekly email, and to keep evidence of what you agreed to | Until you unsubscribe; the consent record is kept unless you ask us to delete it outright | SupabaseCurrently switched OFF — the list is not provisioned in production, so no signups are being stored today. |
| Business outreach we send | Work email address, company, send/reply history, suppression flag | To contact companies about the AI-law API, and to make sure we never contact anyone twice who said no | Suppressed addresses are kept indefinitely — for the sole purpose of not emailing them again | Supabase; sent via ResendEvery message carries an opt-out. Say no once and it is permanent. |
| Analytics | Google Analytics 4: pages viewed, referrer, approximate location, device — under Google’s own terms | To see which pages are useful | Per Google Analytics retention settings | GoogleConsent-gated. In the EU/EEA, the UK and Switzerland the script is not loaded at all until you accept; decline and there is nothing to switch off, because nothing was fetched. Everywhere else it loads and “Cookie settings” in the footer turns it off. |
| Advertising | Google advertising cookies and identifiers — under Google’s own terms | A funding option for the free site | Per Google | Google and its ad partnersNo ads are being served on the site today. The tag is consent-gated on the same terms as analytics, and the ad slots render nothing without consent. We do not sell personal information. |
| Server logs | IP address, user agent, URL, timestamp — standard hosting logs | To run and debug the site | Typically rotated within 90 days | Vercel (our host)Every website has these. We do not mine them. |
| Public MCP connector | The search term your AI assistant sends | To answer that lookup | Not stored beyond the standard request log above | VercelRead-only. No account, no key, and no tool on it that accepts an email, takes a payment, or writes anything. |
Two things we want to be explicit about, because they are the ones people assume go the other way: we never store a plaintext IP address for comments, votes or newsletter signups — only an irreversible keyed hash — and we do not sell personal information to anyone.
2. Who else touches it
Six companies, and what each one is for. Each processes data under its own terms; several process data in the United States and elsewhere.
- Vercel — hosting and request logs.
- Supabase — the database. Anything you submit lives here.
- Resend — outbound email (API keys, reports, our outreach).
- Polar — payments and subscriptions.
- Google Analytics 4 — aggregate traffic measurement.
- Google AdSense — the ads that partly fund the free site.
We also use web-fetching infrastructure and language-model providers. Those touch public government source material only — no visitor data, no comment, no email address is sent to them.
3. Where our AI use starts and stops
We are an AI-law tracker that uses AI. Pretending otherwise would be the exact failure we write about, so here is the boundary in both directions.
Where we do use it.
- Drafting news stories and bill summaries from primary government sources.
- Generating explainer prose on jurisdiction and sector pages.
- Classifying whether an instrument is in scope as an “AI law” — with anything ambiguous routed to a human queue rather than guessed. The rules are published in the AI scope definition.
- Drafting the business outreach emails we send. A human reads and sends every one.
- Automated checks that re-verify published claims against their cited sources.
Where we do not.
- We do not make automated decisions about you. Nothing here scores, ranks, profiles or filters an individual.
- We do not use AI on your comments, your email, or anything else you submit.
- We do not train models on visitor data.
- We do not publish raw machine output. Every record traces back to a primary source, and no claim is stronger than the source it links to.
- We do not present any of it as legal advice, and no AI here gives any.
News stories carry that disclosure on the story itself, not only here — the full pipeline is in the methodology, and what we check and how we correct it is in accuracy & sources.
4. Where the data comes from, and how we credit it
Our records are built from primary government sources — legislature sites, official gazettes, regulators — plus aggregators such as Open States for US state bills. Every record keeps its official_url so you can check us against the source rather than trusting us.
The dataset we publish is licensed CC BY 4.0 — reuse it commercially, with attribution. Where a record came from an aggregator, that aggregator is named on the record. We collect from public pages, at a deliberate pace, and we honour the access rules a source publishes. If you operate a source and want us to change how we read it, email us and we will.
6. How it is secured
- All traffic is served over TLS.
- Database access is restricted to service-role credentials, with row-level security on every publicly reachable table.
- IP addresses and API keys are stored as irreversible keyed hashes, not in plaintext.
- Secrets live in the host’s encrypted environment store and are never committed to source control.
- Access to production is limited to the operator and protected by multi-factor authentication.
- Data at rest is encrypted by our infrastructure providers.
What we do not claim: we hold no SOC 2, ISO 27001 or equivalent audit, and nothing on this site implies we do. Our data processing agreement repeats that in writing, because a buyer should learn it before signing rather than after.
7. For business customers
If you use the API or an embedded widget and we process data on your instructions, our data processing agreement covers it — published in full, with the sub-processor list, the security measures above, a 48-hour breach notification commitment, and a downloadable copy for your files. You do not have to ask for it, and you do not have to sign ours: if your legal team prefers their own paper, email us.
8. How to ask us for your data — or to delete it
There is a form for this now: ai-law-tracker.com/data-request. Pick what you want, say which address to look under, and send — nothing is stored anywhere until you press send in your own email client. Plain email to support@ai-law-tracker.com works just as well. You do not need to cite a law or explain why. Tell us what you want:
- A copy of what we hold about you.
- A correction to anything wrong.
- Deletion — a comment, your email address, an API key and its record, or all of it.
- Never contact me again — we add the address to a permanent suppression list.
- A complaint, which you can also take to your local data-protection authority.
We aim to answer within 30 days. To find your record we may have to ask you which comment or which address you mean — that is the only verification step, and we do not ask for ID.
One honest caveat: for votes and hashed IPs there is genuinely nothing to look up. The hash is one-way, so we cannot search for “your” votes even if we wanted to.
9. Corrections to this page
If something here is inaccurate — including anything you think we have described too generously — email support@ai-law-tracker.com and we will correct it and update the date at the top. Same standard we hold our legal records to on the accuracy page.
See also: privacy policy · data requests · data processing agreement · imprint · terms · methodology · accuracy & sources · about & funding