Back to home

Privacy Policy

How the Jena Band of Choctaw Indians handles the data you provide to the JBCI portal.

Last updated: August 20, 2026

  1. 1. Information We Collect
  2. 2. How We Use Your Information
  3. 3. Artificial Intelligence and Your Information
  4. 4. Council Meeting Recordings
  5. 5. Social Security Numbers
  6. 6. Where Your Information Is Stored
  7. 7. What We Record About Your Activity
  8. 8. Who Can See Your Information
  9. 9. Text Message Communications (SMS)
  10. 10. Viewing and Correcting Your Record
  11. 11. Sovereignty
  12. 12. Contact Information

1. Information We Collect

In plain language

We collect what is needed to serve tribal members and run the portal: your name, enrollment number, contact details, family record, and property records. Employee records include payroll and HR details.

Depending on who you are and how you use the Portal, we collect:

Personal identity: your name, date of birth, tribal enrollment (roll) number, blood quantum, and, for some employees, a Social Security Number. See section 5 for exactly where and how.

Contact information: phone numbers, email addresses, and your mailing or home address.

Family and lineage information: your family tree, including the names of parents, spouse, guardian, and children on file, and any corrections you or a relative submit to it.

Property information: for members with tribal land or housing records, land parcel boundaries, ownership, tenancy, and mapping coordinates.

Documents: enrollment paperwork, per-capita statements, and other documents you upload or that staff assign to your file.

Employment and financial information, for employees: position, payroll and grant-compliance records tied to your role, and scanned finance documents, which can contain a Social Security Number.

Communications: messages you send through the Portal’s chat, support, or text-messaging features, and anything said about you during a council meeting you attend or are discussed in.


2. How We Use Your Information

In plain language

Your data is used to verify benefits, issue ID cards, send emergency and community text messages, manage tribal land, and track work staff are accountable for. It is never used for advertising and never sold.

Your information is used to verify your eligibility for tribal enrollment and benefits, issue tribal ID cards, send emergency alerts and community updates by text message, manage tribal land and property records, track administrative work and task completion, answer your questions through the Portal’s AI-assisted chat feature, and produce a written record of council meetings. It is never used for advertising.


3. Artificial Intelligence and Your Information

In plain language

Some features use Google AI models, running on the tribe's own Google Cloud project through Vertex AI, not the free public Gemini app. Only the part of your record a question actually needs is sent. The member chat feature has never been used to date.

The Portal uses Google’s Gemini AI models to help answer questions and draft some reports. This runs on Google Cloud’s Vertex AI service, inside a Google Cloud project the tribe itself owns and controls. No AI company other than Google receives your information through the Portal.

That distinction matters, because the word “Gemini” names two different things. Gemini is the model. Vertex AI is the tribe’s own service on Google Cloud through which the Portal reaches it. The free Gemini app and Google AI Studio are a separate consumer service, and the Portal does not use them. This was checked on August 20, 2026 rather than assumed: every place in the Portal that calls an AI model was examined, all of them use the tribe’s own Vertex AI project, and none uses the consumer service. An automated check now runs before every release and blocks it if code is added that would reach the consumer service instead.

If you are a tribal member and use the Portal’s member chat feature, the information that can be sent about you includes your name, roll number, enrollment status, complete home address, both phone numbers on file, your birthday, and your parents, spouse, guardian or household members on file, including their names and their roll numbers, along with a summary of your documents. Note what that means: the information that can be sent is not only yours. A relative’s roll number can go with it.

Only the part needed to answer your question is sent. The Portal first works out what kind of question was asked, in a separate step that includes none of your information, and then sends only the categories that question needs. A question about your address does not send your enrollment history or your family. A question about your documents sends only who you are and what documents exist. Asking whether someone is enrolled does not send their address or phone numbers at all. Only a question the Portal cannot categorize falls back to sending the full profile. Every query is recorded in the Portal’s audit log, along with which kind of question it was and whether a full profile was sent, so the amount of information disclosed can be reviewed and not just the fact that something was. The AI’s answer is shown to you on screen and is not saved anywhere else.

As of August 20, 2026 this feature has never been used. The Portal’s audit log holds no record of any member chat query, across its entire history.

The Portal also uses Gemini, in more limited ways, to help staff draft council and department reports, summarize support tickets, and search uploaded reference documents. When Gemini drafts a report from staff work logs, it is instructed not to include Social Security Numbers or other personal identifiers that are not already part of the underlying task record. That instruction is now checked and not merely given: on the surfaces that draft report text for Council, the Portal examines what the AI actually wrote before anything is stored, and if it contains something formatted like a Social Security Number the text is refused and nothing is saved. The staff member is told why and can generate it again or write the section themselves.

Two AI features are deliberately outside that check, and it is worth saying why. A meeting transcript and an uploaded document are records of what was actually said or submitted. Refusing to store one because it contains a number would destroy the record rather than protect it.


4. Council Meeting Recordings

In plain language

Council meeting audio is sent to the tribe's AI service to produce a written transcript for the official record. Recordings and transcripts can include discussion of individual members, employees, health matters and finances.

Audio recorded during a council meeting is sent to Gemini to produce a written transcript for the official record. Council meetings can include discussion of individual members, tribal employees, health matters, and financial matters. Both the recording and the transcript generated from it can contain any of that information. Meeting transcripts are visible to Council members and to Portal administrators.


5. Social Security Numbers

In plain language

A Social Security Number is collected in one place by design, the employee demographics form, and is encrypted when stored. The previous notice said one was collected for ID card generation. That was not accurate and is corrected here.

The Portal collects a Social Security Number in one place by design: the Employee Demographics form, used by Human Resources during employee onboarding. When one is entered, it is encrypted before it is stored, using a dedicated encryption key separate from other Portal data, and only the Human Resources and Staff roles assigned to review that form can decrypt and view it. As of August 2026 no Social Security Number has been submitted through that form, so the Portal is not currently storing one.

Separately, when a scanned finance document contains a Social Security Number, the Portal’s document-scanning process reads the entire document, including that number, using Google’s Cloud Vision service. Staff normally see a version of the scanned text with the Social Security Number and other sensitive numbers blacked out. The original, unredacted scanned text, including the Social Security Number exactly as it appeared on the document, would also be kept, in a separate, restricted location. Only staff granted a specific finance-records permission could view that unredacted text, and every time someone did, it would be recorded in the Portal’s audit log. As of August 2026 no finance document has been scanned, so no unredacted scanned text is stored anywhere in the Portal. This section describes what the scanning process will do once it is used, so that nobody is surprised by it later.

The notice this document replaces stated that a Social Security Number was collected “for ID Card Generation.” That was not accurate. No Social Security Number field exists anywhere in the Portal’s ID card process. This notice corrects that.


6. Where Your Information Is Stored

In plain language

Everything runs inside a Google Cloud project the tribe owns and controls. A limited copy of task, work-log, audit and account records is mirrored to BigQuery for reporting, with personal details removed first.

The Portal runs on Google Cloud, inside a Google Cloud project the tribe owns and controls. Your information does not leave that project when the Portal’s own features, including the AI features described above, use it.

A copy of some Portal information is also automatically mirrored into a second Google Cloud service, BigQuery, so staff can build reports and run analysis. What is copied is limited to task records, work-log records, audit-log records and user-account records. Personal details such as your name, email address, phone number and any free-text notes are deliberately removed before the copy is written. As of this notice, nothing in the Portal actually reads from or reports on this copy; it exists, but nothing uses it yet.


7. What We Record About Your Activity

In plain language

The portal logs who did what and when, along with the internet address the request came from. Most of those records currently have no expiration date and are kept indefinitely. That is a known problem and a decision on it is before Tribal Council.

The Portal keeps an audit log of actions taken in it: who did what, and when. Alongside each entry it records the internet address (IP address) the request came from and the browser you used. The address recorded is the full forwarding chain, which means it includes the address your internet provider assigned you as well as the Google servers the request passed through on its way.

An IP address is not your name, but over time it can indicate roughly where you were and which connection you used, so we treat it as information about you rather than as a technical detail.

It is kept for as long as the audit record itself, and that is longer than it should be. Measured on August 20, 2026 across all 87,634 audit records: only 11,998 carry an expiration date. The other 75,636, which is 86 percent of the log, carry none at all and are kept indefinitely rather than for six years. This is a known problem, it is recorded in the tribe’s internal retention policy, and a decision on it is before Tribal Council. We are telling you here rather than describing a six-year limit that does not currently apply to most records.

The forwarding chain recorded today contains three addresses, of which two are the Portal’s own hosting infrastructure and identify nobody. A correction that records only your own address is written and awaiting release.

We use it only to investigate a security or access question, such as an unexpected sign-in or a report that somebody saw something they should not have. It is not used to track your movements, and it is not shared with anyone outside the tribe’s own cloud account.


8. Who Can See Your Information

In plain language

Access is limited by role. Members see only their own record; staff see only what their role permits. Viewing sensitive records is itself logged. Telzio, the text-messaging provider, is the only outside company that regularly receives portal information.

The Portal restricts access by role. Security rules limit most personal data so that a tribal member can see only their own record, and a Portal employee can see only what their assigned role permits. Administrators can see more, and the Portal keeps an audit log of who views sensitive records, such as enrollment files and per-capita statements.

The tribe does not sell your information to advertisers or any other third party. The only outside company that regularly receives Portal information is Telzio, the tribe’s text-messaging provider, described below. Google, as the tribe’s cloud provider, receives and processes the data described in this notice under Google’s enterprise cloud agreement with the tribe.


9. Text Message Communications (SMS)

In plain language

Giving us your phone number opts you in to tribal communications. Reply STOP to any message to unsubscribe, or call 318-992-2717 and staff will remove you. Reply START to opt back in.

If you provide the Portal with a phone number, you may receive text messages from the tribe, sent through Telzio, a text-messaging company the tribe contracts with. Telzio receives your phone number and the text of each message sent to you. Message frequency depends on Tribal Council activity and emergency or community-update needs.

To stop receiving messages, reply STOP to any message. The Portal receives that reply from the messaging provider and records the opt-out when it arrives, normally within moments. STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT and OPTOUT are all recognized. You can also call 318-992-2717 and ask to be removed from the notification list, which staff can do for you. Once you have opted out, your number is checked against the opt-out list before every future message is sent. If you later want messages again, reply START.


10. Viewing and Correcting Your Record

In plain language

Sign in to view your enrollment profile, family record, ID card and documents. Enrollment details are corrected through the Enrollment Office; family and lineage corrections can be submitted from the My Family page.

Viewing your record: sign in to the Member Portal to view your enrollment profile, family record, digital ID card, and any documents assigned to you or submitted by you.

Correcting enrollment details: your name, date of birth, roll number, and address on file are entered by the tribe’s Enrollment Office and shown to you as read-only. If any of it is wrong, contact the Enrollment Office directly to have it corrected.

Correcting family and lineage information: you can submit a correction request for your family tree from the My Family page in the Member Portal. Staff review every submitted correction, and you can track its status from the same page.

Requesting deletion: the Portal does not currently have an automated way for you to request that your record be deleted. If you believe a record should be removed or corrected outside the paths above, contact the Tribal Administration Office and your request will be reviewed.


11. Sovereignty

In plain language

The data in the portal belongs to the Jena Band of Choctaw Indians, not to any vendor, contractor or cloud provider. This notice is tribal policy and does not waive the tribe's sovereign immunity.

The data held in the Portal belongs to the Jena Band of Choctaw Indians. It is not the property of any vendor, contractor, cloud provider or employee. This notice is a statement of tribal policy and does not waive the tribe’s sovereign immunity.


12. Contact Information

In plain language

Questions about this notice, or requests to correct your record, go to the Tribal Administration Office at jenachoctaw.org, or 318-992-2717 for text-message requests.

For questions about this notice, to request a correction to your record, or to raise a concern about how your information is handled, contact the Tribal Administration Office at jenachoctaw.org, or call 318-992-2717 for text-message-related requests.