ConstituNet

Privacy policy

Effective 27 July 2026

ConstituNet is constituent relationship management software for legislative offices, published by Modern Macro Technologies LLC, doing business as ConstituNet. It comprises the ConstituNet web application at constitunet.com and the ConstituNet add-in for Microsoft Outlook, which lets staff file a constituent email onto a case without leaving their mailbox. This policy covers both, and it covers the service as a whole — not merely the marketing pages.

In this policy, we means Modern Macro Technologies LLC. An office is a legislative office that subscribes to ConstituNet. A constituent is a member of the public whose dealings with that office are recorded in it.

The two kinds of information, and who answers for each

This is the most important thing on the page, because it determines who you should contact about your own information.

  • Staff account information — the people who sign in and use the software. We decide what is collected and why, so we are responsible for it, and this policy governs it.
  • Constituent casework — the records an office keeps about the people it serves. The office decides what to record, why, and for how long. We hold and protect that information on the office’s behalf and act on its instructions. We do not decide what goes into it, and we do not use it for our own purposes.

If you are a constituent and want to know what a legislative office holds about you, or want it corrected or deleted, contact that office directly. We cannot release, amend, or erase an office’s records on a third party’s request — doing so would let anyone alter a public body’s files. If you are unsure which office holds your record, write to us at support@constitunet.com and we will help you identify it.

What we collect about office staff

  • Account details — name, work email address, and the office you belong to. Authentication is handled by Clerk; we receive your name and email from it, and we do not receive or store your password.
  • Your role in the office, which determines what you are permitted to see and do.
  • Activity attribution — when you open a case, log a call, or change a status, the record carries your name and the time. This is the point of the software: a casework file has to show who did what.
  • Operational logs — ordinary server logs recording requests, errors, and timing, used to keep the service running and to investigate faults.

We use this to provide the service, enforce permissions, support you when you ask, and secure the system. We do not sell it, rent it, or share it with advertisers.

What offices record about constituents

An office decides this, and different offices record different things. The software provides fields for:

  • Name, organisation, and the district a person lives in
  • Contact details — email address, telephone number, and postal address
  • Date of birth, where an agency requires it to locate a file
  • The substance of the case: subject, description, topic, priority, status, and the office’s resolution summary
  • A log of every interaction — calls, emails, meetings, and contacts with outside agencies
  • A reference number issued by an outside agency handling the matter

There is no field for a Social Security number, deliberately. The software will not accept one, and offices are advised in our documentation not to record one.

The Outlook add-in

The add-in runs inside Outlook and requests the ReadItem permission, the narrowest of the four permission levels Microsoft offers for Outlook add-ins. In practice that means:

  • It can read only the message you have deliberately opened. It cannot browse your mailbox, search it, read other messages, or read anything after you close that message.
  • It cannot send email, and it cannot alter or delete anything in your mailbox.
  • Nothing leaves Outlook until you press the button to file a message. At that point the sender’s details, the subject, and the message body are written to your office’s own case record — and nowhere else.
  • Connecting the add-in issues a signed token that expires after twelve hours. It carries your staff identifier, name, email address, and role, and nothing more. It is not a password and cannot be used to sign in to the web application.

The add-in requests no Microsoft Graph permissions and no administrative consent, so it has no standing access to your tenant, your mailbox, or your organisation’s directory.

How information is protected

  • Encryption in transit. Every connection to the service uses HTTPS.
  • Encryption at rest, at the field level. The parts of a case that would genuinely harm a constituent if exposed are encrypted with AES-256-GCM before they reach the database: email addresses, telephone numbers, street addresses, dates of birth, case descriptions, resolution summaries, agency reference numbers, notes, and the body of every logged interaction.
  • What is not encrypted, and why. Names, organisation, city, state, postal code, district, case subject, reference number, status, topic, priority, dates, and tags are stored in readable form, because the software must sort, search, and paginate on them. Exact-match lookup on encrypted values uses a keyed one-way index, so a search can find a record by email address without the address being stored in readable form.
  • Separation between offices. Every record belongs to exactly one office, and every query is scoped to the office of the person making it.
  • An append-only history. The interaction log cannot be edited or deleted through the software. A correction is recorded as a new entry, the way a paper file works.

Field encryption defends against a leaked database backup, a compromised copy of the data, or an over-broad query. It does not defend against someone who has legitimately signed in to an office’s account, and no encryption scheme can. Access control inside the office is the office’s responsibility.

Service providers

We keep this list short on purpose. Each of these holds or processes data on our behalf under contract, and each is located in the United States:

  • Vercel — hosts the application and serves it to browsers and to Outlook.
  • Neon — provides the managed PostgreSQL database where records are stored.
  • Clerk — handles sign-in, sessions, and office membership. Clerk holds staff names, email addresses, and credentials. It does not receive constituent casework.

We do not sell personal information, and we do not disclose it to anyone else except where the law requires it, where it is necessary to protect someone’s safety, or where an office instructs us to.

Cookies and tracking

ConstituNet sets cookies for one purpose: keeping you signed in. There is no advertising network, no third-party analytics, no behavioural tracking, and no cross-site profiling on any part of the service. We do not use constituent data to train machine learning models.

Retention and deletion

An office’s records are retained for as long as that office keeps its subscription, and are governed by whatever records schedule applies to that office — legislative casework is frequently subject to a statutory retention period, which the office, not we, must observe.

On termination, an office may export its data. We delete it, including from backups, within ninety days of the office asking us to, unless a legal obligation requires us to keep it longer. Staff account information is deleted when the account is removed from the office.

Public records requests

Constituent casework held by a public body may itself be subject to disclosure under state public records law, and whether it is varies considerably by state. That question is between a constituent and the office. If we receive a public records request for an office’s data we will refer the requester to the office and tell the office we did so, unless we are legally prohibited from doing that.

Children

ConstituNet is a workplace tool and is not directed at children. We do not knowingly create staff accounts for anyone under sixteen. An office may record casework concerning a minor — a school or benefits matter, for instance — and that record belongs to the office under the terms above.

Changes to this policy

When this policy changes materially we will update the effective date above and notify offices by email before the change takes effect. Continuing to use ConstituNet after that date means the revised policy applies.

Contact us

Write to support@constitunet.com with any question about this policy, about information we hold, or to exercise a right you have under the law of Michigan or any other jurisdiction that applies to you. We answer privacy enquiries ahead of ordinary support.

Modern Macro Technologies LLC, doing business as ConstituNet