Loading…
Loading…
VoterDecoder · Data & Privacy Methodology
VoterDecoder helps campaigns understand what a communitycares about. We never collect — or store in any form that could be sold — who you are, where you live, or how you intend to vote.
Draft, pending legal review. This page describes how the system is built today and the standard that governs it. The community-insights product is not yet offered for sale.
Effective July 2026 · A VoterDecoder LLC product
The whole idea in one sentence: we sell what a neighborhood cares about, never what a person cares about.
“In this county, housing and water are the top concerns, and the sheriff’s race is drawing the most attention” is useful to a campaign and points at no one. The moment a signal could be tied to your name, address, or ballot choice, it stops being that and becomes surveillance. So the system is built so that connection cannot be made— the pieces needed to make it are never collected together. Privacy here isn’t bolted on at the end. It’s the architecture.
The two layers
We decide which bucket the moment something happens. The line is simple: anything that could reveal a candidate preference stays on your device.
Stays on your device · always
Never reaches us. It lives only in your browser and powers the guide you carry to the booth.
Measured only in aggregate
Tied only to a coarse area and a temporary visit — never to you. The only thing that can become a community insight.
The hard line
Not in any record, raw or aggregated; not “temporarily.”
Your location
When you look up your ballot, your address is used on our serverto find your districts — then discarded from anything analytics sees. What remains is only a coarse area: today, your county. Clicking the map works the same way. The street you type and the pin you drop never enter the measurement pipeline.
No profile of you
Each visit gets a fresh, random, temporary token that rotates and is never linked to an account, email, or address. There is no durable identifier, so building a picture of you across visits is impossible by construction. When we count unique visitors, we use methods that never store an identity.
How aggregation protects you
50
A fact about a place is recorded or shared only if at least 50 different visits stand behind it. Published counts are rounded and slightly randomized, anything below the threshold is dropped entirely, and if only one item in a place would be hidden we hide a second so it can’t be inferred — never stored, never sold.
For example:if 900 visits in Sacramento County viewed the sheriff’s race last month, we may record “~900 visits, Sacramento County.” But if only 30 visits in a small county looked at a local water-board seat, that number is dropped — 30 is below the line, so it never exists in our data.
The insight, precisely
Can be produced
Can never be produced
Your choices
We automatically honor Global Privacy Control — if your browser sends that signal, we collect nothing. You can also opt out directly using the “Do Not Sell or Share My Info” link in the site header. And there are no third parties to opt out of: no Google Analytics, no ad pixels, and no marketing trackers anywhere on the site.
Retention & commitments
Raw signals are short-lived — kept about 90 days, access-controlled, and never sold — used only to compute the anonymized aggregates. Only those aggregates, which can’t be traced to anyone, are kept longer.
We commit, publicly and in our contracts, to never attempt to re-identify anyone, and to require anyone who receives the aggregates to agree to the same — and to never combine them with other data to work back to a person.