Privacy
What 52 knows
about you.
Reading 52 needs no account. An account exists to hold your topics and your saved research, and this page says exactly what that stores, what it never collects, and how to erase it.
Last updated September 14, 2026
In short
- Reading the public preview requires no account and no cookie.
- An account holds your name, email, a hashed password, your followed topics, and your saved reports. Nothing else.
- 52 sends no email of any kind and uses no third-party sign-in.
- Analytics count pageviews on public pages only — no session recording, no autocapture, no ad networks.
- Deleting your account erases all of it immediately.
What an account stores
Reading 52 needs no account. If you create one, these are the only fields we hold about you:
- The name you type and your email address. The email is your sign-in identifier. It is stored in lowercase.
- A hash of your password, derived with scrypt. Your password itself is never written to disk and cannot be read back by anyone, including us.
- A hash of your recovery code. The code is shown to you once at signup and never stored in a form we can read, which is why we cannot recover it for you.
- Hashes of your active sign-in sessions, each expiring 30 days after it is issued.
- The topics you follow — the topic text, an optional jurisdiction, and when you last looked at it. Up to 20.
- The reports you save — a title and a snapshot of the legislative records that matched your topic at the moment you saved it. Up to 100.
- The date your account was created.
That is the whole record. There is no profile, no activity log of what you read, and no history of your searches attached to your account.
What 52 never collects or does
- No email is ever sent. No verification mail, no password resets, no notifications, no marketing. Password recovery works from the code you saved, which is why 52 needs no mailing list.
- No third-party sign-in. There is no Google, Apple, Microsoft, or social login, so no identity provider learns that you use 52.
- No payment details. 52 is free and holds no card, bank, or billing information.
- No phone number, mailing address, or location tracking.
- No sale or sharing of personal information, no advertising networks, no data brokers, and no use of your account data to train machine-learning models.
How your research is used
Your followed topics and saved reports exist to render your own briefing when you return. They are scoped to your account: every read and write is filtered by your session, and the service has no endpoint that accepts another person’s account identifier.
Staff access to the database is limited to operating the service — fixing a fault, restoring data, or responding to a legal obligation. We do not read saved reports for product analytics.
Analytics and cookies
52 measures which public pages get read, and nothing finer than that. Analytics run through PostHog with autocapture disabled, session recording disabled, and form fields excluded from capture. Pageviews are not recorded at all on the signup, sign-in, recovery, account, briefing, following, or reports pages. Vercel Analytics counts aggregate traffic.
The site sets two things in your browser:
- civic52_session — the cookie that keeps you signed in. It is HTTP-only, secure, SameSite Lax, and expires after 30 days. Signing out deletes it.
- A random analytics identifier, which is not linked to your account and carries no information about you.
There are no advertising or cross-site tracking cookies, which is why 52 shows no cookie banner. Our hosting provider records standard request logs, including IP addresses, for a limited period as part of serving and protecting the site.
Public records published on 52
Most of what 52 shows is not about its readers. Bills, sponsors, votes, committee membership, lobbying positions, and campaign contributions come from federal, state, and District of Columbia disclosure systems that publish them as public records. If your name appears in a contribution record or a sponsor list, it is there because a government body published it, and 52 reproduces it with a link to that source.
52 does not add inferences about the people in those records. A contribution does not establish a policy motive, and the site says so where the records are shown.
If a record on 52 misstates what the official source says — a mismatched name, a wrong amount, a record attached to the wrong person — write to privacy@52.report with the link, and we will correct or remove it. Where the official source itself is wrong, the correction has to be made with that agency; we will point you to the right one.
Keeping and deleting your data
Account data is kept until you delete it. Sessions expire on their own after 30 days. You can remove a followed topic or a saved report at any time, and deleting either erases it from the database.
Deleting your account from your account page requires your password and immediately removes the account row and, with it, every session, followed topic, and saved report. It cannot be undone, and we cannot restore an account after deletion.
Copies may survive briefly in encrypted operational backups, which roll over within 30 days, and in request logs held for a short retention window by our hosting provider.
Security
Traffic is served over TLS. Passwords are hashed with scrypt using deliberately expensive parameters. Sessions are opaque random tokens stored only as hashes, so a leaked database row cannot be replayed as a sign-in. Signup, sign-in, and recovery are rate limited per account and per address, and the sign-in response is identical whether or not an email exists.
No system is perfect. If you find a vulnerability, report it to privacy@52.report before disclosing it publicly, and we will work the fix.
Your choices and your rights
You can see everything your account holds from inside the product, change your password with your recovery code, and delete the account outright. For anything you cannot do in the interface — a copy of your data in machine-readable form, a correction, or a question about how a record reached the site — write to privacy@52.report.
California residents. Under the CCPA you have the right to know what personal information is collected and how it is used, to have it corrected or deleted, and not to be treated differently for exercising those rights. 52 does not sell or share personal information, and it runs no financial incentive program. Note that the CCPA excludes lawfully available government records, which is what the legislative and campaign finance data on 52 is; the rights above apply to your account.
We answer requests within 45 days and may ask you to confirm control of the account email first.
Children
52 is a research tool for adults and is not directed to children. Do not create an account if you are under 13. If we learn that an account belongs to a child under 13, we delete it.
Changes to this policy
When this policy changes, the date at the top of the page changes with it. If a change materially expands what we collect or what we do with it, we will say so on the site before it takes effect. This version is dated September 14, 2026.
Who to contact
52 is operated by HeyYou, Inc.. For privacy questions, corrections, data requests, or security reports, write to privacy@52.report. See also the terms of use.