Legal
Privacy Policy
Last updated: 19 August 2026
Frontbench ("we", "us") is a political monitoring and public affairs platform. This policy explains what personal data we collect, why, and the rights you have over it. It covers both visitors to this website and users of the Frontbench application.
Frontbench is operated by Lucy Croxton, trading as Frontbench, who is the data controller for the personal data described in this policy. You can contact us by email at team@frontbench.io(postal address available on request). We are registered with the Information Commissioner's Office (registration reference ICO:00015139495).
1. What we collect from you
- Account details: your name, work email address and password (stored as a secure hash by our authentication provider) when you sign up.
- Organisation details: your organisation's name, website and logo, chosen plan, and the policy interests you configure (priorities, keywords, policy areas).
- Content you create: notes, briefings, risk assessments, engagement records, calendar entries, consultation responses and uploaded documents.
- Team invitations: the email addresses of colleagues you invite.
- Correspondence: emails you send us.
We do not run analytics trackers, advertising pixels, or any third-party tracking cookies, either on this site or in the application.
Visit counts: we count pageviews first-party, and record the approximate city, region and country that our hosting provider derives from the network connection, so we can see which parts of the world our visitors come from. We do not store your IP address, your browser user agent, or any identifier, and we place nothing on your device to do it. That means we cannot link one pageview to another, or to you.
2. Information about elected representatives
Frontbench maintains profiles of Members of Parliament, Members of the House of Lords and other public office holders. This information comes from the official public record rather than from the individuals themselves: the UK Parliament's open data services (used under the Open Parliament Licence), GOV.UK, and publicly available photographs. It includes public roles, committee memberships, constituency details, published contact information, voting records and public contributions such as debates, questions and Early Day Motions.
The platform also produces analytical assessments, for example an estimate of how a member may vote on a bill, based on their party, their published voting history and their public statements. These assessments are derived solely from information the individuals have manifestly made public in the course of their public duties. Our lawful bases are legitimate interests (Article 6(1)(f) UK GDPR: enabling lawful, transparent engagement with the democratic process) and, for data revealing political opinions, Article 9(2)(e) (information manifestly made public by the individual).
If you are an elected representative and have questions about your information on Frontbench, contact team@frontbench.io.
3. How we use your data
- Providing the service (contract): running your account, matching parliamentary activity to your organisation's interests, team collaboration, and transactional emails such as password resets and invitations.
- Security and integrity (legitimate interests / legal obligation): tenant isolation, tamper-evident audit logs of critical actions, and rate limiting.
- AI-assisted features (contract): when you use features such as briefings, relevance matching or note analysis, the relevant text is processed by our AI provider (see section 5). We have a data processing agreement in place with our AI provider, so your content is never used to train AI models.
We do not send marketing email. If that changes, it will be opt-in with a working unsubscribe.
4. Sensitive content and encryption
Notes and briefings you write may contain political opinions, which are special category data under UK GDPR. Stakeholder notes, private notes and briefings are encrypted at rest with AES-256-GCM using keys the database itself never sees, and are only decrypted to show them back to you. Access is restricted to your organisation by row-level database security, and private notes are visible only to their author.
5. Who processes data on our behalf
Sub-processors we use to run Frontbench:
- Supabase: database and authentication (hosted in the EU, Ireland).
- Netlify: website and application hosting (US).
- OpenAI: AI features (US). A data processing agreement is in place and content sent to the API is never used to train their models.
- Resend: transactional email delivery (US).
- GitHub: scheduled data-processing jobs (US).
Where providers are outside the UK/EEA, transfers rely on the UK Extension to the EU-US Data Privacy Framework, Standard Contractual Clauses, or the UK International Data Transfer Addendum, as applicable to each provider.
6. Cookies
- Authentication cookies (strictly necessary): keep you signed in. Exempt from consent requirements.
- Dashboard preferences cookie (functional, opt-in): remembers your widget layout, set only after you enable it in dashboard settings and deleted if you turn it off.
That is the complete list. There are no advertising or analytics cookies.
Product analytics: separately from cookies, we log which features are used (e.g. that a briefing was generated, a bill was tracked) with a timestamp, page path, and your organisation or user id. We never record the content itself, your IP address or your browser user agent. This is first-party, stored only in our own database, and never shared with a third-party analytics provider. It is processed under legitimate interests, to understand how Frontbench is used and improve it.
7. Retention
- Account and organisation data: kept while your account is active.
- Deleted organisations: recoverable for 12 months, then permanently purged, including encrypted content.
- Audit logs: retained for security and compliance integrity.
- Cached public parliamentary data: refreshed continuously from source.
- Product analytics events: kept for 90 days, then pruned; daily aggregate counts (no user identity) are kept indefinitely.
- Visit counts (page, approximate city, timestamp): kept for 90 days, then deleted.
8. Your rights
You have the right to access, correct, export and erase your personal data, to restrict or object to processing, and to withdraw consent where processing is based on it. Account and organisation deletion are available directly in Settings, including the GDPR right to be forgotten; for anything else email team@frontbench.io and we will respond within one month.
You can complain to the Information Commissioner's Office (ico.org.uk) or, in the EU, to your local supervisory authority.
9. Changes
We will update this policy as the product evolves and will note the date of the latest revision above. Material changes will be flagged in the application.