Solutions
School Boards City & County Commissions Nonprofit Boards · Roadmap
Platform
Governly overview Agenda Prep Meeting Prep
Company
PricingAboutFAQLog in
Schedule a Demo
Privacy

Privacy Policy.

We take your data and privacy seriously. This page explains how we handle your information.

Effective June 1, 2026 · Last updated June 26, 2026

01 Who we are and what this covers

Governly, Inc. (“Governly,” “we,” “us”) provides software that helps organizations and their staff prepare for board and public meetings. Our customers include public bodies — such as school boards and districts and city and county commissions — and other organizations such as nonprofit boards (each, a “Customer”).

This policy describes two kinds of information, governed differently:

  • Account & Site Information Information about people who visit our website, request a demo, or hold a Governly account. We act as a controller for this information, and this policy governs it.
  • Customer Content Everything a Customer loads into Governly (agendas, packets, attachments, adopted policies) and everything created within the product (prep notes, drafted remarks, packet chat, generated analysis), together with any personal information any of it contains. We handle Customer Content as a service provider, on the Customer’s instructions, under the Customer’s agreement with us (see Section 04).

02 Account & Site Information we collect

  • You provide Name, organization, role, email, phone, and message content when you request a demo, contact us, or hold an account; and authentication details.
  • Collected automatically Usage and log data, IP address, device and browser information, and cookies and similar technologies. We use cookies that are (a) strictly necessary to operate the site, (b) analytics cookies that help us understand usage and improve the product, and (c) marketing cookies that support our advertising. You can control non-essential cookies as described in Section 10.
  • From others From the Customer that provisions your account, and from any identity/SSO provider it uses.

03 How we use Account & Site Information

To provide, secure, and support the service; create and manage accounts and roles; respond to inquiries and demos; send service communications; monitor and improve performance; prevent fraud and abuse; and meet legal obligations.

We use analytics and marketing cookies (Section 02). Because our marketing cookies share identifiers with advertising partners, some of this activity may be considered a “sale” or “sharing” of personal information under California law. We do not sell personal information for money, and you can opt out of our marketing cookies as described in Section 10.

04 Customer Content

We process Customer Content only to provide the service to the Customer that loaded it, on that Customer’s instructions and under its agreement with us.

  • We do not use Customer Content to train third-party or public AI models, do not use one customer’s content to benefit another, and do not sell or share it for advertising or any unrelated purpose.
  • Access is restricted by the role-based permissions the customer configures. Governly staff access is limited to what is needed to deliver and support the service.
  • The Customer remains the owner of its Customer Content and, where it is a public body, its records custodian.

If you are an individual whose information appears in a Customer’s documents, your rights run against that Customer, not against Governly.

  • Education records (FERPA) To the extent Customer Content includes “education records” as defined by the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g and 34 CFR Part 99, Governly handles those records as a “school official” with a “legitimate educational interest” under 34 CFR § 99.31(a)(1)(i)(B). Governly performs an institutional service the Customer would otherwise perform with its own employees; remains under the direct control of the Customer with respect to the use and maintenance of education records; uses those records solely to provide the service to that Customer and for no other purpose; does not re-disclose them except as permitted under 34 CFR § 99.33 and on the Customer’s instructions; and does not use education records to train any AI model.
  • Health information (PHI) Governly is not designed to receive or process “protected health information” (PHI) as defined under the Health Insurance Portability and Accountability Act (HIPAA), is not a HIPAA business associate, and does not enter into business associate agreements. Customers should not load PHI into Governly.

05 How AI is used

Governly informs human decisions; it does not make them. Every AI output is grounded in the Customer’s own documents and traceable to source material; the board, commission, or other governing body deliberates and votes.

To generate analysis, Governly sends relevant content to third-party LLM providers under terms that prohibit using your content to train their models and limit retention to what is needed to return a result.

For a full account, see our AI Transparency page.

06 How we share information

Only with: service providers and sub-processors that host, operate, secure, or support the service under contract; within your organization per its configured roles; as required by law or valid legal process; and in a business transfer subject to this policy. We do not sell personal information. A current list of sub-processors is available via request by emailing privacy@governly.com.

07 Security

We protect information with administrative, technical, and organizational safeguards, including encryption in transit and at rest, multi-tenant isolation that stores and segregates data by customer, role-based access control, regular backups for restoration, and limited staff access.

Governly is hosted on Heroku which operates on Amazon Web Services (AWS) infrastructure and uses other industry standard 3rd party services, which maintains SOC 2 and similar certifications. Governly has not yet completed its own SOC 2 examination; an independent assessment is on our roadmap. Security documentation is available to customers and prospects under NDA on request at privacy@governly.com.

08 Retention and deletion

We retain Account & Site Information for as long as your organization uses Governly and as needed for the purposes above, then delete or de-identify it. Customer Content is retained for as long as your organization uses Governly. On termination of your agreement, Governly will, at the Customer’s election, return or delete Customer Content within 30 days, except where a limited retention period is required by law. Backups containing Customer Content are purged on our standard rotation cycle, no later than 90 days after deletion. Customers may also request deletion of specific Customer Content at any time at privacy@governly.com.

09 Customer responsibilities

The Customer decides what to load into Governly and remains responsible for ensuring it is appropriate to process and for its own legal and organizational obligations. Where the Customer is a public body, those obligations may include open-meetings, public-records, confidentiality, and student-privacy requirements that apply to it; other Customers, such as nonprofit boards, remain responsible for the obligations that apply to them. Governly is a preparation tool and is designed to support, not replace, those obligations.

10 Your choices and rights

These rights apply to the Account & Site Information that Governly controls (Section 02). If your personal information appears in a Customer’s documents, requests about that content go to the Customer, not to Governly (see Section 04).

  • Managing cookies You can refuse or delete non-essential (analytics and marketing) cookies through your browser settings. To opt out of our use of marketing cookies specifically, email privacy@governly.com and we will honor your request.
  • California residents If you are a California resident, you may have the right to: know and access the personal information we have collected about you; correct inaccurate personal information; delete your personal information; opt out of the “sale” or “sharing” of your personal information for cross-context behavioral advertising; and be free from discrimination for exercising these rights. To opt out of the sale/sharing of your information, refuse marketing cookies in your browser or email, or any other request, please contact privacy@governly.com.
  • How we handle requests We will acknowledge your request, verify your identity before acting on it, and respond within the time the law requires (in California, generally within 45 days, with one permitted extension). You may use an authorized agent. We may decline or limit a request where the law allows — for example, where we must retain information to complete a transaction, maintain security, or comply with a legal obligation — and we will tell you when we do. We will not retaliate against you for exercising your rights.

11 Changes

We may update this policy and will revise the “Last updated” date when we do and will communicate them via email and on the website.

12 Contact