Privacy Policy

Effective Date: January 1, 2026
Last Updated: July 27, 2026 at 11:00 AM

OnGov is operated by 2Vita, Inc., a Delaware corporation (“2Vita,” “OnGov,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, and protect information in connection with the OnGov platform, the ongov.ai website, and related services (collectively, the “Services”).

Contact: privacy@ongov.ai
Mailing address: 2Vita, Inc., 2204 South St. #579, Philadelphia, PA 19146

1. Two Different Roles — Please Read This First

OnGov is sold to government agencies. That means we handle information in two distinct capacities, and your rights depend on which one applies.

When we act on our own behalf (as a “controller”). This covers information we collect from visitors to ongov.ai, people who request a demo or contact us, and the individual administrators who create accounts with us. We decide how that information is used, and this Policy governs it directly.

When we act on behalf of a government customer (as a “processor” or “service provider”). This covers everything a government agency and its residents put into the platform: permit applications, grant applications, uploaded documents, correspondence, case records, and similar content (“Customer Data”). The government agency — not 2Vita — determines what is collected, how long it is kept, who may see it, and how it is used. We process that information only on the agency’s documented instructions and under our contract with that agency.

If you are a resident who submitted an application, document, or request to your local government through OnGov, your relationship is with that government agency. Direct questions about your records, corrections, or deletion to the agency. We will support any agency that asks us to help fulfill such a request, but we cannot act on it unilaterally.

2. Information We Collect

2.1 Information you provide directly

Website visitors and prospects: name, email address, organization, job title, phone number, and anything else you include in a demo request or contact form.

Account users (government staff): name, work email address, organization and department, role and permission level, authentication credentials, and profile settings.

Resident and applicant users: name, contact information, and the contents of any application, form, document, attachment, or message you submit through a government agency’s OnGov portal. The specific fields collected are determined by the agency, not by us.

2.2 Information collected automatically

  • IP address, browser type, device type, and operating system

  • Session data, login history, and authentication events

  • Feature usage, page views, and interaction patterns

  • Audit logs recording access to and changes made to records in the platform

  • Diagnostic and error data

2.3 Information from connected services

If a user chooses to connect a Google account, we receive data from that account as described in Section 6. All such integrations are optional and require explicit authorization.

3. How We Use Information

We use information to:

  • Create, authenticate, and secure accounts

  • Provide the platform’s core functions: document management, permit and application workflows, search, scheduling, collaboration, and reporting

  • Provide AI-assisted features such as summarization, semantic search, routing, and drafting assistance

  • Generate analytics and reporting for the government agency that owns the account

  • Maintain audit logs for accountability and compliance

  • Detect, investigate, and prevent fraud, abuse, and security incidents

  • Provide customer support and communicate about the Services

  • Improve the reliability, performance, and security of the platform

  • Comply with legal obligations

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use Customer Data to serve advertising.

3.1 Access by OnGov personnel

Authorized OnGov personnel may access limited Customer Data when necessary for technical support, debugging, security investigations, or service maintenance. This access is not routine. It is restricted to personnel whose role requires it, granted on a least-privilege basis, and logged. Where a support request originates from a Customer, access is limited to what is needed to resolve that request.

3.2 Product improvement

We use aggregated or de-identified operational data — such as feature usage rates, error rates, latency, and performance metrics — to improve the security, reliability, and performance of the Services. This data does not identify any Customer, Authorized User, Resident User, or the contents of any record.

We do not use Customer Data for advertising, and we do not use it to train shared or general-purpose AI or machine learning models.

4. AI Processing

The platform uses artificial intelligence to analyze documents, answer questions, generate summaries, and recommend actions.

We do not use Customer Data to train foundation models, and we have contractually configured our AI providers so that they do not use it to train their models either. AI processing is performed in real time to produce a result for the requesting user, and the underlying content is not retained by the model provider for training purposes.

AI outputs are generated automatically and may be incomplete or incorrect. They are not a substitute for professional or legal judgment, and no AI-generated output should be treated as a final government decision without human review.

5. Subprocessors and Service Providers

A “subprocessor” is a third-party vendor that processes data on our behalf in order to deliver the Services. Each is bound by written obligations of confidentiality and security, may use the data only to provide services to us, and may not use it for its own purposes.

  • Amazon Web Services, Inc. (United States): Cloud hosting and compute, object storage, message queuing, database services, transactional email delivery, and AI model inference, all provided through AWS services and subsidiaries.

  • Google LLC (Google Analytics) (United States): Aggregate traffic measurement on the ongov.ai marketing website only. Not used inside the authenticated application, and no Customer Data is sent to it.

Amazon Web Services is our sole subprocessor for Customer Data. All hosting, storage, email delivery, and AI inference occur within AWS.

Where a user connects a Google account under Section 6, data flows between OnGov and that user’s own Google account. Google is the source of that data rather than a subprocessor acting for us.

We maintain a current list of subprocessors and will make it available to government customers on request. We will provide advance notice to customers of material changes to this list.

6. Google Integrations

Where a user elects to connect a Google account, OnGov requests only the scopes needed for the features that user has enabled.

Gmail (gmail.modify) — read messages for communication tracking; compose, draft, and send messages on the user’s behalf; manage read/unread status and labels; download attachments.

Google Contacts (contacts, directory.readonly, contacts.other.readonly) — read and display contacts and organizational directory entries for constituent and contact management, and synchronize changes made in OnGov.

Google Calendar (calendar.events, calendar.readonly) — read, create, and update calendar events for scheduling and coordination.

Profile (userinfo.email, userinfo.profile, profile.emails.read, openid) — identify the connected account.

Your control. Every integration is optional and separately connectable. You may disconnect any integration at any time from account settings, and synchronization stops immediately upon disconnection.

Limited Use. OnGov’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as necessary to provide or improve the Services, for security purposes, or to comply with applicable law. We do not use Google user data for advertising, and we do not use it to train generalized AI models.

7. Disclosure of Information

We disclose information only as follows:

  • To the government customer whose account the information belongs to, in accordance with the roles and permissions that customer configures

  • To subprocessors, as described in Section 5

  • When required by law — in response to a valid subpoena, court order, or other lawful demand. Where we are legally permitted to do so, we will notify the affected government customer before disclosing Customer Data so that it may seek a protective order

  • In a corporate transaction — in connection with a merger, acquisition, or sale of assets, subject to the successor being bound by commitments no less protective than those in this Policy

  • With your consent

We do not sell, rent, or trade personal information.

8. Security

We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, including:

  • Encryption of data in transit using TLS 1.2 or higher

  • Encryption of data at rest using AES-256

  • Logical isolation of each government customer’s data, so that no customer can access another customer’s records, documents, or conversations

  • Role-based access controls and support for multi-factor authentication

  • Session management and timeout controls

  • Audit logging of access and administrative events

  • Least-privilege internal access, granted only to personnel who need it to provide support, maintain the platform, or investigate a security issue, and logged when exercised (see Section 3.1)

  • Periodic security review and monitoring

No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting Customer Data, we will notify the affected government customer without undue delay and will cooperate with that customer’s own breach-notification obligations under applicable law.

9. Data Location

Customer Data is stored and processed in data centers located in the United States. We do not transfer Customer Data outside the United States in the ordinary course of providing the Services.

10. Retention and Deletion

Account data is retained while the account is active and deleted within 30 days after account closure.

Customer Data is retained according to the government customer’s configuration and its own records-retention schedule. Government records are frequently subject to mandatory retention periods under state law; the agency, not 2Vita, determines those periods. On termination, we make Customer Data available for export for the period specified in the agency’s agreement, then delete it.

Backups are retained on a rolling basis and expire within 7 days. Data deleted from the live system may persist in backups until those backups expire.

Logs and security records are retained as needed for security, audit, and legal compliance.

We may retain information longer where required by law, to resolve disputes, or to enforce our agreements.

11. Public Records Laws

Records that a government agency maintains in OnGov may be subject to disclosure under the Pennsylvania Right-to-Know Law, the Freedom of Information Act, or comparable state open-records statutes. 2Vita is not the custodian of those records. Requests for public records must be directed to the agency. We will assist an agency in responding to a records request at its direction, but we do not evaluate, grant, or deny such requests.

12. Your Privacy Rights

Depending on where you live and which role applies, you may have the right to access, correct, delete, or obtain a copy of your personal information, and to opt out of certain processing.

If your information is in a government agency’s OnGov account — including any application, permit, document, or message you submitted to that agency — contact the agency directly. The agency controls those records and its own retention obligations. We will support the agency in responding.

If your information was collected by us directly — for example through a demo request, contact form, or your own OnGov administrator account — email privacy@ongov.ai and we will respond within the time required by applicable law. We will verify your identity before acting on a request. We will not discriminate against you for exercising these rights.

We do not sell personal information or share it for cross-context behavioral advertising, so there is no opt-out to exercise on those grounds.

13. Children’s Privacy

The Services are designed for use by government staff and by adult residents conducting business with their government. We do not knowingly collect personal information from children under 13. Account registration requires that you be at least 18 years old.

If a person under 18 needs to submit information to a government agency through OnGov, that submission should be made by a parent, legal guardian, or the agency itself. If we learn that we have collected personal information from a child under 13 other than at the direction of a government agency acting within its own legal authority, we will delete it.

14. Cookies and Analytics

We use cookies and similar technologies that are strictly necessary for authentication, session management, and security. These cannot be disabled without breaking the Services.

On the ongov.ai marketing website we use Google Analytics to measure aggregate traffic — visitor counts, page views, and referral sources. We do not use Google Analytics inside the authenticated application. You can opt out using the Google Analytics Opt-out Browser Add-on.

We do not use advertising cookies, retargeting pixels, or third-party behavioral trackers.

15. Changes to This Policy

We may update this Policy. When we make material changes, we will update the “Last Updated” date above and provide notice through the platform or by email to account administrators. Where a signed agreement with a government customer specifies a different change-notification process, that agreement controls. Continued use of the Services after an update constitutes acceptance of the revised Policy.

16. Contact Us

Questions, requests, or complaints about this Policy or our data practices:

2Vita, Inc.
Email: privacy@ongov.ai
Mail: 2204 South St. #579, Philadelphia, PA 19146

Run Government Smarter, Not Harder.

Book a demo to see how OnGov helps governments cut delays, reduce paperwork, and deliver better service to residents.

Run Government Smarter, Not Harder.

Book a demo to see how OnGov helps governments cut delays, reduce paperwork, and deliver better service to residents.

Run Government Smarter, Not Harder.

Book a demo to see how OnGov helps governments cut delays, reduce paperwork, and deliver better service to residents.