Privacy Policy

Last updated: October 1, 2026

1. Introduction

Apogee Atlantic LLC ("Apogee," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our legislative intelligence platform and services.

2. Information We Collect

Information You Provide

  • Account Information: Name, email address, organization name, job title
  • Payment Information: Billing address, payment method details (processed by our payment provider)
  • Communications: Messages you send us, support requests, feedback
  • Usage Preferences: Dashboard settings, alert preferences, saved searches
  • Uploaded Files: Documents and files you upload to the Services (for example, client briefs, testimony, or background materials), which we store and process to provide the Services
  • Contacts and Interaction Notes: Contacts, meetings, and commitments you choose to log in the platform (see "Your Private Contact and Relationship Data" below)

Information Collected Automatically

  • Log Data: IP address, browser type, pages visited, time and date of visits
  • API Usage: API calls, queries, response times for service optimization
  • Device Information: Operating system, device type, unique device identifiers

Information We Infer About Your Organization

When you sign up, we use your email domain to identify your organization. For known domain patterns (such as .gov or .edu), classification is instant. For other domains, we use AI (AWS Bedrock) to identify your organization's name and type (for example, nonprofit, law firm, advocacy group, or government agency). We may also collect publicly available information about your organization, and publicly available professional information about you (such as your role at your organization), from web sources to better personalize your experience and inform how we support your account.

This information helps us determine your pricing tier, personalize your briefings, and provide relevant legislative intelligence from your first interaction. You can view and correct this information in your account profile at any time.

Preview Sessions Without an Account

You can try the chat interface without signing up. When you do, we create an ephemeral anonymous session for you. This is not an account: it is identified only by a randomly generated address on a reserved internal domain (anonymous.apog.ai), and we do not ask for or collect your name, email address, or organization.

During a preview session we store the conversation itself, and, if you arrived from an advertisement or a campaign link, the campaign parameters in that link (such as utm_source, utm_campaign, and gclid) so we can measure how our advertising performs. The automatically collected information described above (log, usage, and device data) is also collected.

If you later register, the conversation from your preview session is transferred into your new account and is covered by the rest of this policy from that point on. If you never register, the anonymous session and its conversations are deleted automatically within 7 days by a scheduled sweep. Because a preview session is not an account and is not linked to your identity, we generally cannot locate it to respond to an individual rights request under Section 7 before it is deleted.

Conversations, Memory, and Uploaded Content

When you use our chat interface (or reply to Apogee by email), your conversation content is stored and processed to provide the Services - to answer your questions, maintain your conversation history, generate briefings and drafts, and personalize your experience. Copies of emails exchanged with the Services, and files you upload, are retained the same way. See "Service Operations, Debugging, and Improvement" in Section 3 for how we may access this content internally.

Our platform also includes a Memory feature that captures your preferences, focus areas, and policy interests from your conversations to improve future interactions. We extract structured signals from your usage - such as topics you research, committees you track, and the types of deliverables you generate - to personalize briefings and recommendations. These extracted signals (topics, entities, preferences) are stored separately from your conversations. You can view them on the Memory page in your account and discard individual saved memories there. A discarded memory is hidden from Apogee but an audit record of it is kept, so to have your stored memory erased, delete your account (see Section 7).

Your Private Contact and Relationship Data

If you log contacts, meetings, commitments, or interaction notes in the platform, that information is private to your account. We do not aggregate it across users, share it with or surface it to any other account, or use it to inform any other user's results. It exists solely so the platform can serve you, and it is excluded from the product-improvement uses described in Section 3.

Section 13 describes what is stored about the people you record, including the automatic enrichment of new contacts.

Information We Do Not Collect

  • We do not access your AI provider accounts (Claude, ChatGPT, etc.)
  • We do not collect classified or sensitive government information
  • We do not sell your personal information or conversation data, and we do not share your conversation content or the intelligence you generate with third parties. We do use the advertising and analytics technologies described in Section 8, which share limited browsing activity such as page visits with those platforms to measure and improve our advertising; you can opt out as described there.

Using Apogee through a third-party AI platform: If you access Apogee through a third-party AI platform or MCP-compatible client (for example, claude.ai or Claude Desktop), your conversation with that platform is processed by that provider under its own terms and privacy policy. This Privacy Policy covers the queries and data that reach the Apogee Services.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve our Services
  • Process payments and manage your subscription
  • Send you important updates about the Services
  • Communicate with you: Send you service and account notices, and - unless you opt out - product news and re-engagement emails. Marketing emails include an unsubscribe link; service notices are sent regardless of marketing preferences. Account outreach (for example, a note that a problem you hit has been fixed, or an offer to help) may be informed by your own account's activity
  • Respond to your requests and provide customer support
  • Monitor and analyze usage patterns to improve our platform
  • Personalize your experience: Your organization type, stated interests, and conversation history are used to personalize daily briefings, recommendations, and the intelligence we surface to you
  • Tailor the product, not the price: Your organization type (inferred from your email domain) shapes which briefings, sources, and examples are surfaced to you. It does not affect what you are charged: Apogee is one published price for every organization type
  • Improve briefing relevance: We use aggregate usage patterns across our user base to identify trending topics and improve the quality of intelligence we deliver
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

Service Operations, Debugging, and Improvement

To keep the Services working well, authorized Apogee personnel may access and review individual conversations, account activity, and related content for defined operational purposes: operating and securing the Services, diagnosing and fixing problems, investigating suspected abuse, evaluating and improving answer quality, and improving the product. Access is limited to personnel who need it for these purposes. For example, if the platform gives you a wrong or failed answer, we may review that conversation to find and fix the cause.

We do not use your conversation content to train foundation AI models. AI processing for the Services runs on AWS Bedrock, which does not use customer content to train the underlying models. The one exception is summaries of Congressional Research Service reports, which are written by a DeepSeek model hosted by DeepInfra (see Section 9).

4. Information Sharing

We may share your information with:

  • Service Providers: Third parties who help us operate our Services (hosting, payment processing, analytics)
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

We do not sell your personal information to third parties.

5. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption of data in transit (TLS) and at rest
  • Access controls and authentication requirements
  • Regular security assessments and monitoring
  • Secure cloud infrastructure (AWS)

While we strive to protect your information, no method of transmission over the Internet is 100% secure.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide Services. After account termination, we may retain certain information as required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements).

When you delete your account, billing, subscription, and usage records are kept in a form that no longer includes your name or email, because they support tax, accounting, and dispute handling. Stripe keeps its own payment records under its own policy.

Preview sessions without an account are retained on a shorter, fixed schedule. A scheduled sweep runs daily and permanently deletes anonymous preview sessions older than 7 days, together with their conversations, messages, and sign-in sessions. If you register during a preview, the conversation moves into your account and is retained under the paragraph above instead. See "Preview Sessions Without an Account" in Section 2.

7. Your Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data
  • Export your data in a portable format
  • Opt out of certain data processing
  • Withdraw consent where processing is based on consent

To exercise these rights, contact us through our contact form.

Deleting your account. In the chat app, go to Settings, then Account, then Delete Account. This removes your conversations and, from our database, the memory entries, contacts, interaction notes, whip counts, folios, watches, briefings, saved artifacts, and API keys stored for your account. Content you created inside a shared team organization stays with the team. If you have an active paid subscription, cancel it in billing first. Billing, subscription, and usage records are kept without your name or email (see Section 6).

8. Cookies, Tracking, and Session Recording

We use cookies and similar technologies to:

  • Keep you logged in
  • Remember your preferences
  • Understand how you use our Services
  • Improve our platform

We use PostHog for product analytics and session recording. Session recordings capture how you navigate our web dashboard and chat interface to help us identify usability issues and improve the experience. We take the following measures to protect your privacy in recordings:

  • All text you type into input fields is masked and never recorded
  • All chat message content (queries and AI responses) is masked in recordings
  • Analytics data is routed through our own subdomain (z.apog.ai) rather than directly to PostHog
  • Session data is associated only with your account - not sold or shared with third parties

Email Delivery and Open Tracking

Emails we send (briefings, service notices, product updates) may include standard delivery and open tracking so we can tell whether our email is reaching you and rendering correctly. We use this to monitor deliverability and the health of email-based features such as scheduled briefings; we do not share individual open data with third parties beyond the email infrastructure providers that generate it.

Advertising and Conversion Tracking

We work with advertising platforms to promote Apogee and measure how our advertising performs. These platforms use cookies or similar technologies that record when you visit our site and whether you later take an action such as signing up:

  • LinkedIn Insight Tag - measures the performance of our LinkedIn ads and builds retargeting audiences. You can opt out of LinkedIn-based advertising in your LinkedIn account settings under Ads, and learn more in the LinkedIn Cookie Policy.
  • Google Ads - measures conversions from our Google advertising. You can opt out via Google Ads Settings.

You can also limit interest-based advertising through your browser settings or industry opt-out tools such as the Digital Advertising Alliance and the Network Advertising Initiative.

You can control cookies through your browser settings. Disabling certain cookies may affect functionality of the Services.

9. Third-Party Services and Subprocessors

Our Services integrate with the following third-party services. Each has its own privacy policy:

  • PostHog - Product analytics and session recording (posthog.com/privacy)
  • AWS - Cloud infrastructure, AI processing via Bedrock (aws.amazon.com/privacy)
  • DeepInfra - Hosts the DeepSeek model that writes summaries of Congressional Research Service (CRS) reports. When a customer asks for a CRS summary, DeepInfra receives the report number, title, date and subjects, up to about 30,000 characters of the public report text, and any focus text the customer supplies, such as a topic or question. A summary that is generated is saved with the report record and may be shown to later users who ask for the same report. The focus text is not saved with it (deepinfra.com/privacy)
  • Stripe - Payment processing (stripe.com/privacy)
  • LinkedIn - Advertising conversion tracking and retargeting (linkedin.com/legal/privacy-policy)
  • Google - Advertising conversion tracking (policies.google.com/privacy)
  • Serper - Web search used when answering queries that require current web results, and when enriching a new contact record (see Section 13); the search query text is shared with Serper to retrieve results. For contact enrichment, the query is the name and organization of the contact (serper.dev/privacy)

We also use managed infrastructure providers (such as hosted database and email delivery services) that store or transmit Service data on our behalf. We are not responsible for the privacy practices of third parties. We only work with subprocessors who provide sufficient guarantees of data protection.

10. Children's Privacy

Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

11. International Data Transfers

Your information may be transferred to and processed in the United States, where our servers are located. By using our Services, you consent to this transfer. We ensure appropriate safeguards are in place for international transfers.

12. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know what personal information we collect and to request deletion. Our use of the advertising technologies described in Section 8 may constitute "sharing" for cross-context behavioral advertising under California law. You can opt out of this sharing using the advertising opt-out controls in Section 8, or by contacting us through our contact form to exercise any of these rights. We do not use or disclose sensitive personal information for purposes other than providing the Services.

13. People Named in Customer Records and Public Data

The Services hold some information about people who do not have an Apogee account. These are public officials, legislative staff, registered lobbyists, and other people that a customer chooses to record. This section explains what we hold, where it comes from, who can see it, how long we keep it, and how to ask for access, correction, or removal. In this section, a "customer" is a person or organization with an Apogee account.

Public Records and Licensed Directory Data

The research tools in the Services include information about people in public roles:

  • Legislators and other public officials: Names, offices, party, committee assignments, sponsored bills, votes, and public statements, from official government sources
  • Legislative staff: Name, job title, office, work contact details, position history, and other professional details that the source lists. Where a public payroll record publishes it, this can include salary. This information comes from public government directories, public payroll records, and licensed commercial directory data
  • People named in public filings and documents: For example, registered lobbyists in lobbying disclosure filings, witnesses in hearing transcripts, and people named in press releases and news articles

Contact Records Created by Customers

A customer can keep private records about the people they work with. A record about a person can be created when a customer:

  • Adds a contact or imports a contact list
  • Logs a meeting, call, or other interaction and names the people who took part
  • Pastes meeting notes or similar working text that names people
  • Records a head count on a bill (a "whip count") and names a legislative staff member as the source
  • Forwards meeting notes to Apogee by email, where that feature is turned on

A contact record can hold the name, organization, job title, and email address of the person, the customer's own notes about the person, the dates of interactions, commitments the customer is tracking, and how the person is connected to the customer's other contacts. When the name matches a person in the directory data described above, the record links to that directory entry.

When a customer pastes notes, we store the pasted text as written, and that text can name people. We send up to 8,000 characters of the pasted text to an AI model on AWS Bedrock to identify the people, positions, and commitments in it. A head count stores the customer's own record of where a legislator stands on a bill, with the customer's supporting note. On an API-key connection where the preview feature is turned on, a note is saved in two steps: a preview of the people and records it would create, which saves nothing, and then a confirmation.

Customers can also mention people in conversations and in files they upload. That content is stored as described in Section 2.

Automatic Enrichment of New Contacts

When a customer creates a new contact that has an organization and does not match the directory data, the Services run an automatic web search on the name and organization of the person. The search query goes to Serper, a web search provider (see Section 9). An AI model on AWS Bedrock reads the search results and writes a short profile: a summary, role, organization, and links to public pages. We store that profile on the contact record. If the results include a public biography or staff page that shows a photo of the person, we may store a copy of that photo and the address of the page it came from. A customer can also ask the assistant to research a contact, and the result is stored the same way.

Enrichment uses publicly available web sources only. It can be wrong or out of date, for example when two people share a name.

Who Can See This Information

  • Public record and directory data is available to customers through the research tools.
  • Contact records, pasted notes, interaction logs, head counts, and enrichment profiles are private to the customer account that created them. We do not show them to any other customer account, and we do not combine them across accounts.
  • A stored photo is a copy of a publicly available image. It is served from a web address that contains a random identifier, and that address does not require sign-in.
  • Authorized Apogee personnel may access these records for the operational purposes described in Section 3, and to answer a request made under this section.
  • The service providers listed in Section 9 process this information for us. AWS hosts it and runs the AI models. Serper receives the enrichment search query.

How Long We Keep It

Public record and directory data is refreshed from its sources. A person who leaves a public role can remain in the data as a former holder of that role.

Customer-created records are kept until the customer deletes them or deletes the account. A customer can delete a contact by asking the assistant. That removes the contact record, its enrichment profile, its relationship links, and the commitments recorded for that person from our database. Text that names the person elsewhere, such as a pasted note, an interaction summary, or a conversation, is not removed when a contact is deleted. A customer can delete a single pasted note, from the Notes page or by asking the assistant. Deleting a note removes the stored pasted text and the copies of it kept in meeting-log and head-count excerpts, unless the customer edited those copies. The people, meeting summaries, follow-ups, and head count positions created from the note stay until the customer deletes them separately. Pasted notes that are not deleted are removed when the customer deletes the account. If a person asks us to remove note text that names them, we review the request as described below.

When a customer deletes the account, the contacts, notes, interaction logs, and head counts for that account are deleted from our database (see Section 7). A stored photo, and a copy of a contact name in the private relationship graph for that account, are held outside that database. They are not yet removed automatically when a contact or an account is deleted. We remove them when we delete a contact record in answer to a removal request under this section.

How to Ask for Access, Correction, or Removal

If you are not an Apogee user and you think the Services hold information about you, email privacy@apog.ai. You do not need an account. Tell us your name, and your organization and work email address if you want us to search for them.

A person at Apogee handles each request. The process is manual. We may ask for information to confirm who you are before we act. We then search the contact records, pasted notes, enrichment profiles, and stored photos in customer accounts, and the directory data, for your name and email address.

  • Access: We tell you whether we found records about you, what kinds of information they hold, and where the information came from.
  • Correction: We correct enrichment profiles and directory data that we can confirm are wrong. If an official source is wrong, that source must also make the correction, because we refresh from it.
  • Removal: We delete contact records about you, with their enrichment profiles and stored photos. For text that a customer wrote that names you, such as a pasted note or an interaction record, we review the request. If you ask us to remove your directory entry, we also review the request. Information that is part of the official public record, such as the votes of a public official or a lobbying registration, stays in the Services.

We reply by email to tell you what we did. A removal applies to the records we hold at that time. It does not prevent a customer from recording your name again later.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Services. The "Last updated" date at the top indicates when this policy was last revised.

15. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

Please use our contact form, email us at privacy@apog.ai, or reach out through your account dashboard.
Entity: Apogee Atlantic LLC