Candidate Alerts

Public-only compliance

The Candidate Alerts public post archive is a paid, multi-tenant service operated by Advocacy Lab LLC. Each customer gets a private archive of communications that were published to the open web. It is a factual archive, not a dossier, and it does not collect private messages or authenticated content.

In scope (paid MVP)

  • Public X, Facebook, Instagram, and YouTube profile URLs from the FairElections / MEM social data.
  • ScreenshotOne captures of those public pages when the rendered content is new or changed.
  • Official websites as a secondary monitor on a paid campaign.
  • Opt-in alert channels: campaign filings, personal finance disclosures, stock trades reported to the Clerk of the House (with corporate PAC donors, trades by year and most-traded tickers), meetings A/V, voting history, campaign email/RSS, official email/RSS. Third-party estimates such as net worth and portfolio holdings are not published.
  • Optional historical Reddit / Wayback backfill into the campaign archive.

Out of scope

  • Login walls, paywalls, DMs, follower-only posts, and private subreddits.
  • Bypassing CAPTCHA, robots.txt, or newsletter terms. Those signups are marked needs-manual-subscribe.
  • Credential stuffing, session cookies, or “view as logged-in user” tricks.
  • TV / news mention integrations (later).
  • Anonymous public dump of Quiver tables. Paying campaigns see and email Quiver finance for their own seats; archive APIs still require a campaign session.

Tenant isolation

Watches, captures, alerts, and usage are private to a workspace. Two customers can watch the same politician; each sees only their own archive. Page-state hashes are shared so ScreenshotOne is not billed twice for the same public URL in the same poll window.

Third-party terms and limits

  • ScreenshotOne — authenticated from the environment as SCREENSHOTONE_ACCESS_KEY (required for live captures) and optionally SCREENSHOTONE_SECRET_KEY when the ScreenshotOne dashboard requires signed requests. Keys are sent as X-Access-Key on POST or as a signed GET; they are never committed, logged, or shown in the UI. Billed per capture. See current docs and pricing before running large jobs.
  • Stripe — Checkout, Customer Portal, and signed webhooks use STRIPE_SECRET_KEY, STRIPE_PUBLISHABLE_KEY, STRIPE_WEBHOOK_SECRET, and STRIPE_PRICE_SEAT from the environment. Keys are never invented or shown. Without them, billing stays a local stub. invoice.paid enables monitoring; failed invoices set past_due.
  • archive.org / Wayback CDX — public API, rate-limited. Workers sleep between requests and cap snapshots per URL.
  • Arctic Shift and PullPush — community Reddit archives with incomplete coverage and no SLA.
  • X, Facebook, Instagram, YouTube, Reddit live sites — we do not scrape behind authentication. Pages that present a login wall are flagged and not bypassed.

Positioning

Records are labeled with politician, office, jurisdiction, platform, URL, and capture time. The product does not editorialize. Attribution of a Reddit account to an officeholder is only as strong as the reddit_username supplied in Isaac’s import file.