The Trump administration has launched America.gov as a centralized AI-powered portal for federal information and services, accompanied by a privacy promise. The portal will utilize Login.gov for authentication, which has recently integrated code that introduces a long-lived browser identifier into its analytics. America.gov is designed to serve as the interface for federal services, while Login.gov will function as the underlying identity and authentication system. Currently, America.gov does not require user identification and claims to avoid advertising cookies, third-party trackers, and precise location data.
An executive order signed by President Donald Trump directs the General Services Administration (GSA) to establish America.gov as the federal government's primary digital entry point and mandates the integration of Login.gov as its authentication service. Federal agencies are instructed to connect their services and digital forms to this platform. The administration asserts that these integrations will be conducted in a secure and privacy-preserving manner, emphasizing that only the originating agency can access individual records, in accordance with the Privacy Act.
However, the code for Login.gov reveals that the National Design Studio's (NDS) work has introduced a browser identifier, known as nds_experiment_uuid, which has not been publicly clarified regarding its privacy implications. This identifier is generated upon the first page load for visitors and is stored in a cookie that is set to expire in 20 years. It is used to track user preferences and analytics events, raising concerns about the potential for long-term tracking of users' interactions with government services.
On September 4, Login.gov merged the new code that created the identifier, and on September 9, it was integrated into analytics events. The identifier allows Login.gov to recognize whether a browser has opted out of the NDS interface on subsequent visits. However, the identifier remains even after users opt out, which has led to questions about the necessity of retaining such a long-lived identifier for an experiment.
The GSA's existing Privacy Impact Assessment (PIA) for Login.gov, revised in March 2026, primarily addresses the retention and use of information by its anti-fraud team but does not account for the new identifier or its implications. The PIA indicates that Login.gov uses a segmented identity system, assigning users a master UUID that remains internal and agency-specific UUIDs that are shared only with user consent.
The NDS experiment UUID, however, is a browser identifier created for an interface experiment, distinct from the authenticated identifiers described in the PIA. As America.gov evolves into a platform for managing federal benefits and services, it is crucial to address the privacy concerns surrounding the long-term retention of the nds_experiment_uuid and its association with analytics records. The GSA and NDS are urged to clarify the purpose of this identifier, its intended duration, and the privacy assessments that govern its use.