This notice explains what information the JCJ Bill Tracker (the "Tracker") collects, why, how long it is kept, and who can see it. The Tracker is an internal tool operated by the Jewish Center for Justice ("JCJ", "we") to follow California legislation. It is intended for JCJ staff, fellows, board members and volunteers, and access requires a passphrase.
In summary. The Tracker has no public accounts, no analytics, no advertising and no cross-site tracking, and we do not sell or share information for marketing. The web server keeps a standard access log, including IP addresses, for security and operations. If you claim an action alert, the name you enter is recorded so colleagues know who is writing it.
1.Information we collect
Information recorded automatically
The web server writes a line to its access log for each request. Each entry contains:
- the IP address the request came from;
- the date and time;
- the page or file requested and the server's response code;
- the browser and operating system your device reports (for example, "Safari on iPhone"); and
- whether a sign-in attempt succeeded or failed.
An IP address usually identifies a network rather than a person, since everyone on the same office or home connection typically shares one, but we treat it as personal information.
Information you choose to enter
- Action Alerts board. When you claim an alert, you enter a name. The board records that name, the bill, the alert's status, the time of each change and, once completed, a link to the published alert. This is visible to anyone with access to the Tracker, so that colleagues do not duplicate work.
- Administrative notes. Administrators record editorial information about bills, such as categories, priorities and reasons for archiving. This concerns legislation, not individuals.
Administrator security records
For the small number of people with administrator access, we also record the information needed to keep that access secure: each signed-in session's device type, IP address and times of use; each time the server console is opened; and the outcome of each sign-in step. Sign-in codes come from an authenticator app or, where that is not set up, are sent by email to the administrator's address.
What we do not collect
- Passphrases or codes. Only whether an attempt succeeded or failed is recorded, never the value entered.
- Accounts or profiles. General access uses a shared team passphrase; there are no individual user accounts.
- Analytics or tracking. There is no Google Analytics, no advertising network, no social media pixel and no cross-site tracking.
2.How we use it
We use the information above only to:
- operate the Tracker and keep it available;
- control access and detect, investigate and block misuse, including automated attempts to guess passphrases;
- coordinate the writing of action alerts among JCJ fellows; and
- diagnose technical problems.
We do not use it for marketing or profiling, and we do not sell it.
3.Cookies and browser storage
The Tracker sets only the cookies needed for sign-in. Each holds a random value and nothing about you, and none is used for tracking.
| Cookie | Purpose | Duration |
|---|---|---|
jcj_access | Remembers that this browser entered the team passphrase. | 30 days |
jcj_admin | Administrators only: keeps an administrator signed in. | Until the browser goes 7 days without opening the administration page |
jcj_2fa | Administrators only: links the two steps of a sign-in. | 10 minutes |
The Tracker also stores a few preferences in your browser's own storage, which stays on your device and is never sent to us: the name you last used on the Action Alerts board, which notices you have dismissed, which newly signed bills you have already been shown, the display theme, and a counter that enforces the limit on failed sign-in attempts. You can clear these at any time through your browser's settings.
4.Service providers
We do not sell or rent information. The following providers process data on our behalf, or are contacted in the course of using the Tracker:
- DigitalOcean hosts the server, including its logs.
- Supabase hosts the database, including the Action Alerts board and administrative notes. Your browser reaches it through jcjtracker.org rather than directly.
- Email delivery. Security alerts, and sign-in codes where an authenticator app is not used, are sent through an email service to the administrator's address.
- LegiScan supplies the legislative data, under a CC BY 4.0 licence. The server fetches it; nothing about visitors is sent to LegiScan.
- Google Docs. The action alert template is a Google document. Google sees your visit only if you open it.
- The California Legislature's websites. Legislator photographs are normally served from the Tracker itself. Where a copy is missing, the Authors page loads the photograph from assembly.ca.gov or senate.ca.gov, which can then see your IP address.
We may also disclose information if required by law, or where necessary to protect the security of the Tracker or the rights of JCJ or others.
5.How long we keep it
| Information | Kept for |
|---|---|
| Server access logs | About 14 days, then deleted by the server's automatic log rotation |
| Action Alerts board entries | For as long as the related bill remains in the Tracker, including after it is archived, unless removed on request |
| Database backups | Taken nightly; the 14 most recent are kept and older ones deleted |
6.How it is protected
- All connections use HTTPS.
- The Tracker requires a passphrase, and repeated failed attempts are rate-limited.
- Administrator access requires a separate passphrase and a one-time code, and opening the server console requires an additional code. Administrator sign-ins and console use generate an alert.
- The database key used by the Tracker's pages can change only JCJ's own records (annotations, the watch list and the Action Alerts board); the legislative data itself is read-only to it.
No system is completely secure, but we limit what is collected and who can reach it.
7.Your choices and requests
- You can clear the Tracker's cookies and browser storage at any time. You will then be asked for the passphrase again.
- You can ask us what information the Tracker holds about you, or ask us to correct or remove your name from the Action Alerts board, using the contact details below.
- Depending on where you live, you may have additional rights under applicable privacy law. We will respond to requests as that law requires.
8.Public legislative records
Bills, votes, authors and legislative calendars shown on the Tracker are public records of the California Legislature, and how a legislator voted is a matter of public record. Summaries labelled as the Legislative Counsel's Digest are the Legislature's own official descriptions, not JCJ's characterisation.
9.Changes to this notice
We will update this notice when the Tracker's handling of information changes, and revise the effective date above. Significant changes are also noted under "Recent changes" on the Tracker's About page.
10.Contact
For questions about this notice, or to make a request about your information, email judahkrauss@gmail.com.
Effective September 27, 2026. This notice describes how the Tracker handles information; it is provided for transparency and is not a contract. Previous version: August 2026.