Privacy Policy
Effective date: August 6, 2026 · Last updated: August 6, 2026
This Privacy Policy explains how Votesphere LLC, a Wyoming limited liability company ("Votesphere," "we," "our," or "us"), collects, uses, discloses, and protects information in connection with the Votesphere websites, applications, and related services (the "Service"). Votesphere is the controller of personal information processed through the Service. Our contact details, including our privacy contact, appear in Section 15.
The short version. You can participate anonymously. Your geography is by declaration — a ZIP code and district, never a street address. Positions and quiz responses are political-opinion data, and we treat them with the heightened protection that sensitive data deserves everywhere, not only where the law requires it. We never sell participant data, we do not use advertising trackers, analytics runs only with your consent, and public reporting is aggregate and de-identified with honest sample sizes. Sharing a quiz result card is your choice, cards carry no identity, and you can revoke a share at any time.
1. Scope; Beta Availability
This Policy covers personal information processed through the Service, including the marketing site at votesphere.com, the application, quizzes reached through shared links, and communications with us. It does not cover third-party sites we link to. During the current invitation-only beta, the Service is available only to residents of the United States; this Policy is nonetheless written to the standard of the EU/UK General Data Protection Regulation ("GDPR") and U.S. state privacy laws, and Sections 11 and 12 describe rights we extend in anticipation of broader availability.
2. Information We Collect
2.1 Information you provide. (a) Account information: an email address and authentication credentials when you register, and account settings. (b) Positions and quiz responses: the positions you record, your responses to quiz instruments (including recurring and topical quizzes), and attributes you assign to positions. These reveal political opinions and are treated as sensitive information under Section 3. (c) Declared geography: the ZIP code you declare and the electoral district derived from it. We do not collect your street address and ask that you not enter it. Changes to declared geography are kept as an append-only history. (d) Optional demographics: demographic questions are optional, are marked as such, and declining them does not limit the Service. (e) Text you submit to interactive features such as classification and civic chat. (f) Communications you send us, including feedback and support requests, and your email-signup information on the marketing site.
2.2 Shared result artifacts. If you elect to share a quiz result, we create a share record containing a display-layer result payload only: result labels, archetype or placement names, match percentages, and editorial text. The record and the rendered card contain no raw quiz responses, no position coordinates, and no name, handle, or other identifier; cards are deliberately anonymous. Rendered card images are generated server-side within our own infrastructure and stored with our hosting processor. Access to a shared card is through an unlisted link containing a long, unguessable token; there is no public browsing or enumeration of shared results. Section 5 explains the public nature of sharing and how revocation works.
2.3 Information collected automatically. (a) First-party participation events: we record, in our own systems and without any third-party analytics processor, events measuring quiz participation and sharing — quiz started and completed; share initiated and completed, and the medium chosen; arrival on a share link; and conversion of an anonymous session to a registered account, which carries a referral token identifying the shared result that brought the new participant. Because each share is associated with the account that created it, this referral token creates a first-party record linking a sharer's account to a recipient's arrival; we use it only for the measurement purposes in Section 4 and it is never displayed to any participant. (b) Technical data: log and device data ordinarily generated by use of a web service, such as IP address, browser type, and timestamps, used for security and operations. (c) Consent-gated analytics: with your consent, Google Analytics 4 measures aggregate site traffic on the marketing site, as described in Section 8. (d) Security challenges: Cloudflare Turnstile processes limited technical signals to distinguish people from bots at authentication.
2.4 Anonymous sessions. You may use parts of the Service, including quizzes reached from a shared link, in an anonymous session identified only by a session identifier. The disclosures in this Policy apply equally to anonymous sessions, including arrival through a shared link and the referral token described above. If you register, your anonymous-session data is carried into your account; if you do not, it is retained and deleted as described in Section 10.
3. Sensitive Information: Political Opinions
Positions, quiz responses (including responses to every quiz instrument on the Service, whether one-time, recurring, or topical), and comparable expressions reveal political opinions. Political opinions are special-category data under GDPR Article 9 and sensitive personal information under the California Privacy Rights Act and comparable U.S. state laws. We process this information only: (a) with your explicit consent, which you give by affirmatively recording positions or completing quizzes after notice, and which you may withdraw at any time by deleting the relevant content or your account; (b) to provide the Service you request; and (c) in aggregated, de-identified form as described in Section 6. We do not use sensitive information to infer characteristics for advertising, we do not disclose it except to the processors in Section 7 acting on our instructions, and we never sell it. Where state law grants a right to limit the use of sensitive personal information, our practices already conform to that limitation, and Section 11 explains how to exercise the right.
4. How We Use Information; Legal Bases
We use personal information to: (a) provide, secure, and maintain the Service, including persistence of your positions and portrait (performance of our contract with you; for sensitive data, your explicit consent); (b) generate aggregated, de-identified civic reporting with honest sample sizes and visible uncertainty (legitimate interests in publishing aggregate civic information, applied only to de-identified outputs; the underlying sensitive-data processing rests on explicit consent); (c) measure quiz participation and sharing through the first-party events in Section 2.3(a), including attribution of new registrations to shared results (legitimate interests in understanding and improving the Service); (d) operate consent-gated site analytics (consent); (e) communicate with you about the Service, respond to inquiries, and send administrative notices (performance of contract; legitimate interests); (f) send optional updates you sign up for, which you may stop at any time (consent); (g) protect the security and integrity of the Service, prevent fraud and abuse, and enforce our Terms (legitimate interests; legal obligation); and (h) comply with law (legal obligation). We do not use personal information for targeted advertising, we do not engage in profiling that produces legal or similarly significant effects, and we do not make solely automated decisions of that character about you.
5. Shared Results: Public Nature and Revocation
5.1 Public once shared. A shared result card is visible to anyone holding its link, including people outside the Service. Share links are unlisted — they are not indexed by us, not browsable, and protected by unguessable tokens — but unlisted is not private: anyone to whom a link is forwarded, or who otherwise obtains it, can view the card. Because cards carry no identity, what such a viewer sees is an anonymous result; whether to associate a card with yourself (for example, by posting it from your own social account) is entirely your choice.
5.2 Revocation. You may revoke any share at any time in the Service. Upon revocation we stop serving the card and its link. We want to be honest about the limits: copies already downloaded, screenshotted, or cached by third-party platforms are outside our systems and cannot be recalled.
5.3 Retention of share artifacts. Share records and rendered images persist until you revoke the share or delete your account, whichever comes first; on either event, database records are deleted by cascade and stored images are removed on a scheduled cleanup, as described in Section 10.
6. Aggregated and De-Identified Data
We create aggregated and de-identified data from participation on the Service — for example, the distribution of positions on an issue within a district, presented with the number of participants and visible uncertainty. De-identified data does not identify and cannot reasonably be linked to you. We maintain it in de-identified form, we commit not to attempt to re-identify it, and we contractually require the same commitment from any recipient. We may use and retain aggregated and de-identified data for any lawful purpose, including published civic reporting and research, indefinitely.
7. How Information Is Shared
7.1 No sale; no advertising sharing. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done either in the preceding 12 months. There are no advertising trackers on the Service.
7.2 Service providers (processors). We disclose personal information to service providers who process it on our documented instructions, under contracts that restrict their use of it: Supabase, Inc. (database, authentication, and storage; hosted on Amazon Web Services in the United States, us-west-2 (Oregon)); Vercel, Inc. (web hosting and content delivery); Anthropic, PBC (AI processing of text you submit to classification and chat features, under commercial API terms providing that your submissions are not used to train Anthropic's models); Google LLC (consent-gated site analytics under Google Analytics 4); Microsoft Corporation (business email under Microsoft 365); and Cloudflare, Inc. (Turnstile bot protection). An updated list of processors is available on request to privacy@votesphere.com.
7.3 Legal and safety disclosures. We may disclose information if we reasonably believe disclosure is required by law or legal process, or is necessary to protect the rights, safety, or property of participants, Votesphere, or others. Given the sensitivity of the data we hold, our practice is to require valid legal process, to construe requests narrowly, to object where we have a good-faith basis, and, unless legally prohibited, to notify affected participants before disclosure.
7.4 Corporate transactions. If Votesphere is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy's commitments. Any successor will be required to honor the commitments in Sections 3, 6, and 7.1 or to provide notice and an opportunity to delete your data before materially changing them.
8. Cookies, Analytics, and Global Privacy Control
8.1 Cookies. We use strictly necessary cookies for authentication, session integrity, security (including Turnstile), and remembering your consent choices. These operate without consent because the Service cannot function without them. All other cookies and similar technologies — currently limited to Google Analytics 4 on the marketing site — are set only after you consent through our cookie banner, and analytics tags do not fire before consent. You can change or withdraw your consent at any time through the "Your Privacy Choices" link in the site footer, and withdrawing consent is as easy as giving it.
8.2 Analytics configuration. Where enabled by consent, GA4 is configured for aggregate traffic measurement: IP-level location is truncated by Google, we do not use advertising features or audience sharing, and analytics identifiers are not joined to your account or positions.
8.3 Global Privacy Control. We honor the Global Privacy Control signal. A browser sending GPC is treated as declining consent for analytics and as opting out of any "sale" or "sharing" as those terms are defined by state law — which, as stated above, we do not engage in regardless.
8.4 Do Not Track. Because no uniform standard for legacy "Do Not Track" signals exists, we respond to GPC as described above and treat DNT identically where our systems can recognize it.
9. Security
We maintain administrative, technical, and organizational safeguards appropriate to the sensitivity of the data we process, including encryption in transit and at rest, row-level access controls on participant data, multi-factor authentication for administrative access, server-side confinement of credentials and API keys, bot protection at authentication, security review of changes, and the principle that we minimize what we collect in the first place — anonymous-by-default participation and declared-ZIP geography exist so that the most sensitive database is also the least identifying one. No system is perfectly secure; if a breach affecting your personal information occurs, we will notify you and regulators as required by applicable law.
10. Retention
We retain personal information as follows, and otherwise no longer than needed for the purposes described in this Policy: (a) account data, positions, quiz responses, and position history — for as long as your account exists; (b) upon account deletion — personal information is deleted from production systems within 30 days, and from backups as backups age out within 90 days, except information we must retain to comply with law, resolve disputes, or enforce agreements, which is retained only as long as necessary for that purpose; (c) anonymous sessions — deleted after 12 months of inactivity; (d) share records and rendered card images — until revocation or account deletion, then removed as described in Section 5.3; (e) first-party participation events — retained in identifiable form no longer than 24 months, after which they are deleted or de-identified; (f) marketing-site analytics — per Google Analytics 4 retention settings of 14 months; and (g) support communications — up to 24 months after resolution. Aggregated and de-identified data may be retained indefinitely under Section 6.
11. Your Privacy Rights (United States)
11.1 Rights. Depending on your state, you may have the right to: know and access the personal information we hold about you, including in a portable format; correct inaccuracies; delete your personal information; opt out of sale, sharing for targeted advertising, and certain profiling (none of which we engage in); limit the use of sensitive personal information (our practices already conform, and we will honor the request); and not be discriminated against for exercising rights. We extend these rights to all U.S. participants regardless of state.
11.2 How to exercise. You may exercise rights directly in the Service (including deleting individual positions, revoking shares, and deleting your account — revoking a share or deleting content within the Service is itself a deletion request as to that content, honored as described in Sections 5 and 10) or by emailing privacy@votesphere.com. We verify requests using the email associated with your account or, for anonymous sessions, evidence of control of the session; we respond within 45 days, extendable once by 45 days with notice. Authorized agents may submit requests with proof of authority. If we decline a request, you may appeal by replying to our decision; we will respond to appeals within 45 days, and if your appeal is denied you may contact your state attorney general.
11.3 California notice at collection. The categories of personal information we collect are described in Section 2 (identifiers; internet activity; declared geographic data; sensitive personal information in the form of political opinions; and inferences limited to the editorial quiz characterizations you generate); purposes appear in Section 4; retention in Section 10; and recipients in Section 7. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes beyond those permitted by § 7027(m) of the CCPA regulations.
12. Your Privacy Rights (EEA, United Kingdom, and Other Jurisdictions)
Although the beta is limited to U.S. residents, we apply GDPR-standard practices globally. When the Service becomes available in the EEA or UK: our legal bases are those stated in Section 4, with special-category processing based on explicit consent under GDPR Article 9(2)(a); you will have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting prior processing; and you will have the right to lodge a complaint with your supervisory authority. Personal information is processed in the United States; for transfers from the EEA or UK we will rely on adequacy decisions where applicable and on Standard Contractual Clauses (and the UK Addendum) with our processors, and details will be available from privacy@votesphere.com.
13. Children
The Service is not directed to children under 16, and the minimum age to use the Service is 16 everywhere. We do not knowingly collect personal information from anyone under 16; if we learn that we have, we will delete it. If you believe a child under 16 has provided personal information to the Service, contact privacy@votesphere.com.
14. Changes to This Policy
We may update this Policy from time to time. If a change is material — in particular, any change to the commitments in Sections 3, 6, or 7.1 — we will provide prominent notice through the Service or by email at least 14 days before it takes effect and, where the change concerns processing based on consent, we will seek fresh consent. The "Last updated" date reflects the current version, and prior versions are available on request.
15. Contact Us
Votesphere LLC — Attn: Privacy30 N. Gould St., Ste. 42834
Sheridan, WY 82801, USA
privacy@votesphere.com · legal@votesphere.com · (771) 251-6100
If you have a question, concern, or complaint about this Policy or our practices, contact us and we will respond promptly. This is the platform's standing commitment: built to be checked.