This Privacy Policy describes how TomorrowLabs LLC ("TomorrowLabs," "we," "us," or "our") collects, uses, discloses, stores, and retains information when you access or use the Constituent service, including its related applications, websites, and related features (collectively, the "Service").
This Privacy Policy is intended for U.S. users, with additional California-specific disclosures below.
1. Scope
This Privacy Policy applies to information we collect when you:
- create or use an account;
- use civic-data, notification, questionnaire, or AI-assisted features;
- contact us for support; or
- otherwise interact with the Service.
2. Information We Collect
We may collect information you provide directly to us, information generated through your use of the Service, and information received from service providers and public-data sources.
A. Account and profile information
We may collect, as applicable:
- email address;
- password or password hash data handled through our authentication systems;
- display name;
- OAuth account identifiers when third-party login is used;
- account status and related account metadata.
B. Address, district, and civic-context information
We may collect, as applicable:
- street address and related address fields you provide;
- browser or device latitude/longitude and related accuracy information if you choose to use a "detect my location" feature;
- formatted address and district-resolution results;
- jurisdiction and representative matching context;
- geocoding and district lookup outputs.
When location detection is used, coordinates are used to resolve your civic districts and are not stored as separate account-coordinate fields. The Service may retain the resulting district context, geocoder response (which may contain coordinate values), and a generated location-resolution label needed to operate the Service.
C. Questionnaire, preferences, and user settings
We may collect, as applicable:
- questionnaire responses;
- ideology, preference, or civic-interest outputs derived from those responses;
- user settings and feature preferences;
- saved bills, saved representatives, followed topics, and notification preferences.
D. Usage, activity, and in-app engagement information
We may collect, as applicable:
- app interactions and feature usage;
- notification activity;
- bookmarks and follows;
- account activity timestamps;
- limited engagement or event telemetry used to operate and improve the Service.
E. Communications and support
If you contact us, we may collect the contents of your communications, your contact information, and records of our correspondence.
F. Subscription and transaction information
If you purchase the optional, auto-renewing Supporter subscription for $5 per month, Supporters currently receive an allowance of up to 50 new AI-assisted calls to action per day and priority processing for call-to-action generation. Free accounts receive lower, activity-dependent daily generation allowances and standard processing priority. Priority processing does not guarantee any delivery or completion time. Core civic data and call-to-action access remain available without subscribing, subject to free-account limits.
Purchases are currently available through Google Play and, if and when offered, may also be available through the Apple App Store. Billing, renewal, cancellation, and payment details are managed through the store where you purchased the subscription. Refund eligibility is governed by the applicable store's policies and applicable law. For Google Play purchases, Google or TomorrowLabs may process a refund through Google Play. If and when Apple App Store purchasing is offered, refund requests for those purchases will be handled by Apple under its policies and applicable law. We may receive transaction status, subscription state, renewal status, store and product identifiers, and related purchase metadata from Google Play or, if and when Apple App Store purchasing is offered, Apple. Related purchase metadata may include an obfuscated or account-linking identifier used to associate the store purchase with your Constituent account. We do not receive or store your full payment card details.
The Service does not display advertising.
G. Optional configuration data
Depending on how the Service is deployed or used, the Service may store optional configuration data you provide, such as certain API or model settings used to operate supported features.
H. Information from public and third-party sources
The Service also ingests public civic information from upstream legislative, governmental, and related data sources. Those public records may be associated with your account experience when the Service personalizes civic content based on your jurisdiction, settings, or preferences.
3. How We Use Information
We may use information we collect for the following business and operational purposes:
- create, authenticate, maintain, and secure accounts;
- provide the Service and its features;
- match you to relevant jurisdictions, representatives, and civic content;
- operate questionnaires, notifications, bookmarks, and related features;
- provide AI-assisted summaries, categorization, alerts, and calls to action;
- process and manage Supporter subscription status, generation allowances, and processing priority;
- troubleshoot, monitor, secure, and improve the Service;
- detect abuse, fraud, unauthorized access, or misuse;
- comply with legal obligations and enforce our terms; and
- communicate with you about the Service.
4. AI-Assisted Features
The Service may use AI-, machine-learning-, or LLM-assisted systems to generate summaries, classifications, recommendations, alerts, notification matches, and calls to action.
These systems may process public bill text, government source materials, generated summaries, issue/topic classifications, questionnaire questions and your response choices, and preference or category signals derived from those responses where needed to operate bill analysis, matching, and CTA features. Configured external LLM providers may receive those materials and response choices, but we do not intentionally include your name, email address, street address, or other direct account identifiers in those requests.
Depending on deployment and feature configuration, AI processing may use local models, infrastructure we operate, or configurable third-party AI/LLM providers.
Such outputs:
- may be inaccurate, incomplete, biased, delayed, or unavailable;
- may not reflect all relevant legislative developments or source materials; and
- are provided for informational and entertainment purposes only.
The Service and any AI-assisted output are not legal, legislative, political, financial, or professional advice, and must not be relied upon as a substitute for independent review, official source materials, or professional judgment.
To the maximum extent permitted by law, we make no representation, warranty, or guarantee of any kind regarding AI-assisted outputs, including as to their accuracy, completeness, timeliness, reliability, usefulness, or fitness for any purpose.
5. Cookies, Local Storage, and Similar Technologies
We may use cookies, local storage, software development kits, and similar technologies to:
- keep you signed in or maintain session state;
- store preferences and settings;
- support security and fraud prevention;
- support core application functionality; and
- improve reliability and user experience.
We do not use cookies, local storage, SDKs, or similar technologies to sell personal information or to share personal information for cross-context behavioral advertising.
Do Not Track signals: The Service does not currently take separate action in response to browser "Do Not Track" signals because it does not use personal information to track users over time across unaffiliated websites or services and does not knowingly permit third parties to do so through the Service.
6. When We Disclose Information
We may disclose information in the following circumstances:
- to service providers and infrastructure providers that help us operate the Service;
- to app-store subscription platforms, authentication, geocoding, hosting, database, queueing, AI, OCR, and similar vendors used to power supported functionality;
- when you choose to use a feature that requires third-party processing;
- if required by law, regulation, court order, or legal process;
- to protect rights, safety, security, or property;
- in connection with a merger, financing, sale of assets, reorganization, or similar business transaction; or
- with your consent or at your direction.
We may also disclose de-identified, aggregated, or otherwise non-personal information that does not reasonably identify you.
We do not sell personal information.
7. Third-Party Services and Data Sources
Depending on deployment and feature configuration, the Service may use or interact with third parties such as:
- Google Play for Android subscription billing;
- the Apple App Store for subscription billing, if and when offered there;
- Google OAuth for login, if enabled;
- Sign in with Apple for login, if and when enabled;
- U.S. Census geocoding and district-resolution inputs;
- hosting, database, and queueing providers;
- configurable AI or OCR providers;
- public civic-data providers and government information sources.
Third-party services operate under their own terms, policies, and practices, and public-data sources may change, degrade, become inaccurate, or become unavailable over time.
8. Data Retention
We retain information for as long as reasonably necessary to provide the Service, fulfill the purposes described in this Privacy Policy, comply with law, resolve disputes, enforce agreements, and protect the Service and its users.
If you request account deletion:
- your account is disabled promptly, ending access from your perspective;
- the deletion request initiates the permanent-deletion process; and
- certain data may be retained for a limited period while that process is completed.
Based on the Service's current implementation, permanent deletion is generally targeted within 90 days after the deletion request, subject to legal, operational, security, technical, backup, audit, or compliance needs.
Engagement and event telemetry is generally purged on a rolling basis, with a default target retention window of 90 days.
Unverified registration records and verification codes are generally purged after 24 hours.
We may also retain limited logs, security records, backups, subscription records, or legally required records for longer periods where necessary.
9. Your Choices and Rights
Subject to applicable law, platform limitations, verification requirements, and technical feasibility, you may be able to:
- access and update account information;
- manage saved content, followed topics, and settings;
- delete your account;
- cancel your Supporter subscription through the same store where you purchased it (currently Google Play and, if and when offered there, the Apple App Store); and
- contact us regarding privacy questions or requests.
For account deletion, you may use the in-app account deletion feature where available (for example, Profile or Account settings → Delete Account), or contact us at info [at] tomorrowlabs [dot] net to request deletion if you cannot access the app. Deletion requests are subject to verification, legal exceptions, security needs, backup retention, and the retention practices described above.
Deleting your account or uninstalling the app does not cancel a Supporter subscription. You must cancel it separately through the same store where you purchased it.
Because the Service includes public-civic personalization, public-record ingestion, and infrastructure-driven features, certain data may need to be retained to maintain security, legal compliance, records integrity, fraud prevention, or technical functionality.
10. California Disclosures
TomorrowLabs currently does not meet the business thresholds for application of the California Consumer Privacy Act or California Privacy Rights Act, and we do not represent that those statutes apply to the Service. If their applicability changes, we will update this Privacy Policy with the disclosures and rights then required. We do not sell personal information or share personal information for cross-context behavioral advertising. California residents may contact us at info [at] tomorrowlabs [dot] net with questions or requests under applicable law.
11. Security
We use reasonable administrative, technical, and organizational measures designed to help protect information.
However, no service, storage system, or transmission method is completely secure, and we cannot guarantee absolute security.
12. Age Restriction
The Service is intended only for users who are 18 years of age or older. If you are under 18, do not use the Service or provide us with personal information.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated policy at the same public URL and revise the effective date above. For material changes, we will provide additional in-app or email notice where appropriate or required by law. Your continued access to or use of the Service after the updated Privacy Policy becomes effective constitutes your acknowledgment of the updated Privacy Policy.
14. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact:
TomorrowLabs LLC Email: info [at] tomorrowlabs [dot] net