This Data Processing Policy describes how DigitalTreehouse LLC, d/b/a OmniLegislation™ (“we,” “us,” or “our”) collects, processes, stores, and manages data in connection with the OmniLegislation™ platform at omnilegislation.com (the “Service”). This policy should be read alongside our Privacy Policy, Terms of Service, and Cookie Policy.
1. Scope
This policy covers two categories of data:
- Platform Data: Publicly available legal information, including legislation, federal and state regulatory materials, and court opinions, that OmniLegislation™ aggregates, processes, and delivers to subscribers. These are public records published by government bodies.
- Subscriber Data: Information connected to your account, principally your account details, your Practice Area Monitor configurations (including the monitoring profile that describes what you follow), your alert history, and your billing information.
2. Platform Data: How We Collect and Process Legal Information
Data Sources
OmniLegislation™ collects legal data from publicly available sources, including government legislative databases, federal and state regulatory publications, and state and federal court systems, across all 50 US states and the federal government. Collection runs daily.
All legal data collected by OmniLegislation™ is derived from public records. We do not collect private, sealed, or restricted court records.
Processing
After collection, legal data undergoes automated processing, which includes:
- Deduplication: Records from multiple sources covering the same legal event are identified and merged into a single record to prevent duplicate alerts.
- Summarization: Each record is processed by AI to generate a concise plain-English summary of the legal development, along with topic keywords used for matching.
- Relevance Analysis: New records are evaluated against each subscriber's Practice Area Monitors, using keyword matching and AI relevance analysis against the monitor's profile, so digests carry only what is relevant to that monitor.
Storage
Processed legal data is stored in a secure database hosted by Supabase (PostgreSQL). Data is retained to support subscriber search, alert history, AI relevance analysis, and bill tracking features. Raw source data is retained for quality assurance and deduplication purposes.
Delivery
Processed data is delivered to subscribers through email alerts and the customer portal (search and the dashboard alert feed). There is no public API access or webhook delivery. Alert content is matched to each subscriber's Practice Area Monitors, state coverage, and content type preferences.
3. Subscriber Data: How We Handle Your Information
What We Collect
We collect the following subscriber data:
- Account Information: Name, email address, company or organization name, and subscription plan.
- Billing Information: Payment details are processed and stored securely by Stripe. OmniLegislation™ does not store credit card numbers or full payment credentials on our systems.
- Monitor Configurations: Practice Area Monitor names, keywords, state and content type filters, delivery frequency, and the monitoring profile describing what each monitor should follow, including what you write in the onboarding chat.
- Alert History: A record of the items evaluated and delivered for each of your monitors, including your feedback (such as dismissing an item as not relevant). This powers your dashboard feed and keeps you from receiving the same item twice.
- Search and Usage Data: Search queries and filters used in the portal, login history, and pages visited.
How We Process Subscriber Data
Subscriber data is processed for the following purposes:
- Service Delivery: Matching new legal records against your Practice Area Monitors and delivering email alerts and your portal feed.
- Billing: Processing subscription payments through Stripe and handling plan-change requests made through your Account page.
- Platform Improvement: Analyzing aggregate usage patterns to improve search, alert matching, and overall platform performance.
- Security and Anti-Abuse: Monitoring for suspicious activity and protecting the integrity of the Service.
- Customer Support: Responding to inquiries and resolving account issues.
How We Store Subscriber Data
Subscriber data is stored in a secure database hosted by Supabase with the following protections:
- Encrypted data transmission (TLS/SSL) between your browser and our servers
- Database storage encrypted at rest
- Database access restricted to authorized systems and personnel
- Payment data handled entirely by Stripe (PCI-DSS compliant) and never stored on our servers
How Long We Keep Subscriber Data
- Active Accounts: Subscriber data is retained for as long as your account is active.
- Cancelled Accounts: After cancellation, your account information and monitor configurations are retained for 90 days so you can resubscribe and pick up where you left off (your monitors reactivate automatically when you return). After 90 days, personal information is scheduled for deletion unless retention is required by law or for legitimate business purposes (such as resolving billing disputes).
- Search and Usage Logs: Retained for up to 12 months for analytics and anti-abuse purposes, then purged.
- Billing Records: Retained for 7 years in accordance with standard accounting and tax requirements.
4. AI Processing
OmniLegislation™ uses artificial intelligence throughout the platform. Specifically:
- Summarization and deduplication: The text of publicly available legal records is sent to Anthropic (Claude models) to generate plain-English summaries and topic keywords, and to help identify duplicate records.
- Relevance analysis: To decide what belongs in your digest, we send the text of legal records together with your monitoring profiles and monitor configurations to Anthropic (relevance judgment) and to Voyage AI (text embeddings used for semantic matching). This is the only subscriber data shared with our AI providers.
Your data is not used to train AI models under our agreements with these providers. All transmission to AI providers is encrypted. AI-generated summaries are provided for informational purposes only and do not constitute legal advice.
5. Data Sharing and Third-Party Processors
We use the following third-party service providers to operate the Service. Each provider receives only the data necessary to perform its function:
| Provider | Purpose | Data Shared |
|---|---|---|
| Anthropic | AI relevance analysis and summarization (Claude models) | Public legal record text, monitoring profiles and monitor configurations |
| Voyage AI | Text embeddings for semantic relevance matching | Public legal record text, monitoring profiles and monitor configurations |
| Supabase | Database hosting and account authentication | All platform and subscriber data (encrypted); sign-in credentials |
| Resend | Email delivery (alerts, welcome and account emails) | Subscriber email address, alert content |
| Stripe | Payment processing, billing portal | Billing name, email, payment method |
| DigitalOcean | Backend and data pipeline hosting | All platform data (encrypted in transit and at rest) |
| Vercel | Website and customer portal hosting | Usage data, IP address (standard web hosting logs) |
| Google Analytics | Website traffic and usage analytics | Usage data, IP address, browser info (see Cookie Policy) |
We do not sell, rent, or trade subscriber data to third parties.
We may disclose data if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of OmniLegislation™, our subscribers, or the public.
6. Data Exports
The Service does not currently offer bulk data export. Processed data is delivered to subscribers through email alerts and the customer portal, subject to the reasonable use and abuse-prevention measures described in our Terms of Service.
7. Data Security
We implement reasonable administrative, technical, and physical safeguards to protect data, including:
- TLS/SSL encryption for all data in transit
- Encrypted database storage with restricted access
- Payment processing through Stripe (PCI-DSS Level 1 compliant)
- Paginated portal access with no bulk listing or export
- Monitoring for suspicious access patterns
Our Security page describes these measures in more detail. While we take data security seriously, no system is completely immune to risk, and we cannot guarantee absolute security of your data.
8. Cross-Border Data Transfers
OmniLegislation™ is based in the United States, and subscriber data is stored and processed in the United States. The website is served through a global content delivery network for performance, but your stored data resides in the United States. If you access the Service from outside the United States, you acknowledge that your data will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your personal data, subject to legal and contractual retention requirements
- Export your personal data in a commonly used format
- Object to certain types of processing, such as marketing-related tracking
To exercise any of these rights, contact us at hello@omnilegislation.com. We will respond within 30 days.
For California residents, additional rights under the CCPA are described in our Privacy Policy.
10. Changes to This Policy
We may update this Data Processing Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make changes, we will revise the “Last Updated” date at the top of this page. Material changes will be communicated via email or a notice on our website.
Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Data Processing Policy or how we handle your data, contact us at:
DigitalTreehouse LLC, d/b/a OmniLegislation™
Email: hello@omnilegislation.com
Website: omnilegislation.com