VoterDecoder

Privacy Policy

Effective date: to be set at publication · Operator: VoterDecoder LLC

Draft, pending legal review. This copy describes how the system works today; qualified privacy counsel will finalize it before it is published.

VoterDecoder helps you find the districts, offices, and measures on your ballot, and helps campaigns understand — only in aggregate — what a community cares about. The short version: we never collect, or store in any sellable form, who you are, where you live, or how you intend to vote.

1. Information we collect

An address or map point, to look up your ballot. We use that location on our servers to find your districts. The address and coordinates are not stored in our analytics; only a coarse area (your county) is kept (see §3).

Interest signals, in aggregate. Which topics and races you view, and whether you click a cited source — tied only to a coarse county and a temporary session token, never to your name, address, or a candidate choice.

Basic technical context (a coarse device category and how you arrived). Your IP is used transiently to deliver the service and is not stored alongside interest signals.

Information that stays on your device. Candidates you add to your guide or star live only in your browser and never reach us.

2. How we use information

We do not use your information to profile or target you, or to infer your political views as an individual.

3. How your location is handled

Your address or map point is resolved to districts on our server, then discarded from anything analytics sees. What remains is a coarse area — today, your county. The precise address or pin never enters the measurement pipeline.

4. What we do NOT do

5. Cookies & local storage

First-party browser storage only: a temporary, rotating session token and local storage for the guide you build. No advertising or cross-site tracking cookies.

6. Service providers

We share data only with providers that process it to run the service: the U.S. Census Geocoder (address lookup), Vercel (website hosting), Render (API hosting), Supabase (database), and Sentry (error monitoring, scrubbed of address and coordinates).

7. Aggregate community insights

We produce aggregate insights such as “in this county this month, housing and public safety are the most-viewed topics.” Every published figure is k-anonymized (at least 50 distinct visits), rounded, and slightly randomized; smaller figures are dropped. These contain no individual, address, or vote-intent data, and—if offered—are offered to every campaign, party, and committee on equal terms. Details on our methodology page. As of this draft, the insights product is not offered for sale.

8. Data retention

9. Your choices & California rights

Global Privacy Control. If your browser sends a GPC signal, we treat it as an opt-out and collect no analytics from you, automatically.

Opt out anytimewith the “Do Not Sell or Share My Info” link in the site header.

California residents (CCPA/CPRA) have rights to know, access, delete, correct, opt out of sale/sharing, limit sensitive-data use, and non-discrimination. Two honest notes: because our analytics is de-identified by design and carries no name, account, or address, we generally hold no personal information about you to retrieve, correct, or delete; and we do not sell or share personal information in the CCPA sense. The controls above still let you switch off all analytics.

10. Sensitive information

Political opinions can be “sensitive” under California law. We are built to avoid collecting it: candidate preferences and vote intent stay on your device, and we do not infer your political views as an individual.

11. Children’s privacy

VoterDecoder is intended for adults and is not directed to children; we do not knowingly collect personal information from children under 16.

12. Changes & contact

We may update this policy; material changes will be noted here with a new effective date. Questions or requests: privacy@voterdecoder.org.

A VoterDecoder LLC product · Data & privacy methodology