Privacy Policy
Quick summary
- What Ledger collects: your email and password, the address you enter to look up your ballot, values-quiz answers and history, poll votes, civic-activity records (streaks, points, events), AI chat transcripts, chat ratings, mock-ballot selections, mobile push device tokens (if you enable notifications), and feedback you submit. See the full table in §2.
- What Ledger never collects: voter-file data, government IDs, biometric data, location beyond the address you enter, health data, financial data beyond subscription billing (post-Alpha), and anything from third-party trackers (Ledger doesn't load any).
- Who processes your data: a small set of US-based vendors Ledger uses to run the service — listed below.
- How long Ledger keeps it: most account data is kept while your account exists. AI chat transcripts are retained for up to 365 days from a session's last activity, unless you delete them sooner or a legal hold applies.
- Your rights: you can see, export, and delete your data. Ledger honors California's CCPA rights for every Ledger user regardless of state.
- No behavioral email, no tracking pixels, no data sold.
1. About Ledger and what this covers
This Privacy Policy explains how Ledger, Inc. (placeholder — entity formation pending) handles personal information for the Ledger service at ledger.vote and in Ledger's mobile apps (iOS and Android). It applies to everyone who uses Ledger — whether you're a signed-out visitor looking up a public ballot preview or a signed-in user with a saved profile.
Ledger is designed for US-based voters. Ledger treats the California Consumer Privacy Act (CCPA) as its national floor — the rights described below apply to every Ledger user, not just California residents.
2. What Ledger collects
| Data | When Ledger collects it | Where it's stored | Why |
|---|---|---|---|
| Email address | When you sign up | Supabase Auth (US) | Account identity; sending you OTP codes |
| Password (hashed) | When you sign up with a password | Supabase Auth (US) | Log you back in |
| Full name (optional) | When you sign up, or from onboarding | profiles in Supabase (US) | Personalize greetings and shareable artifacts |
| Address | When you enter it to look up your ballot | Signed in: persisted in your profile so you don't have to re-enter it. Signed out: processed transiently for the current lookup, never persisted. | Resolve your federal district so Ledger can show your ballot |
| Date of birth (optional) | When you provide it in onboarding | profiles in Supabase (US) | Confirm 18+ eligibility, compute election-day age for primaries |
| Geocoded coordinates | Derived from your address via Mapbox | Not stored — used transiently to match your district | Ballot lookup |
| Jurisdiction lookup cache | Derived from your address (non-reversible hash) + US Census lookup | jurisdiction_resolution_cache in Supabase (US), server-only access | Speed up repeat lookups without re-storing addresses |
| Values-quiz answers and result | When you take the quiz | Your profiles row, scoped to you via row-level security | Personalize your ballot view, power the shareable quiz card you opt into |
| Quiz history | When you retake the quiz | Append-only history table in Supabase, scoped to you | Show you how your profile has changed; contribute to future aggregated-only civic insights |
| Poll responses | When you vote in a daily poll | poll_responses in Supabase, scoped to you via row-level security | Your poll history and privacy-safe aggregate breakdowns; frozen state, district, and quiz-label fields at vote time for aggregation |
| Civic-activity events, streaks, and points | When you take qualifying in-product civic actions | civic_activity_event, civic_streak, civic_points in Supabase, scoped to you via row-level security | Engagement, streak tracking, local leaderboard (civic_points denormalizes state and congressional district for bucketing) |
| AI chat transcripts | When you send messages in Ledger chat | Server-side log in Supabase, scoped to you and visible to you in-product | Liability, safety, abuse detection, and resuming your most recent saved chat (see §6 below — this is the single most important disclosure in this policy) |
| Chat message ratings | When you thumbs-up or thumbs-down a Vera turn | chat_message_ratings in Supabase, scoped to you and your session via row-level security | Vera accuracy telemetry; you can change a rating but not delete the row yourself |
| Mock-ballot selections | When you choose candidates on your ballot | Supabase, scoped to you via row-level security | Your own planning tool; power the mock-ballot public share (post-Alpha) |
| Shareable-card payloads | When you generate a share link | Stored payload + public URL | Render the public share page you asked for |
| Feedback submissions | When you submit the in-product feedback form | Supabase, written via server-only path | Bug reports, product feedback, content concerns |
| Mobile push device tokens | When you register a device for push notifications | mobile_push_devices in Supabase, scoped to you via row-level security | Deliver push notifications to your Ledger mobile app (expo_push_token, platform, registration timestamps) |
| Rate-limit counters | Derived from your user ID or IP | Upstash Redis (US), short TTL | Prevent abuse and keep the service fair |
| Authentication cookies | On login (web) | First-party HTTP-only cookie on ledger.vote | Keep you signed in |
| First-party analytics events | As you use Ledger (see §13) | Server-side events table in Supabase | Product measurement without third-party trackers |
| Stripe customer ID + subscription status (post-Alpha) | When you subscribe to Ledger Premium | Supabase, linked to your user | Resolve your Premium entitlement |
| Persistent AI companion memory (Phase 4, opt-in) | When you enable persistent memory and chat | Supabase, scoped to you | Let the AI remember prior conversations across sessions |
3. What Ledger never collects and never does
- Ledger does not collect voter-file data. Ledger is a decision-support tool, not a voter-targeting tool. Ledger doesn't buy, ingest, or cross-reference commercial voter files.
- Ledger does not collect government IDs, biometric data, health data, or location beyond the address you enter.
- Ledger does not load third-party tracking pixels from advocacy organizations, campaigns, ad networks, or analytics vendors. No Google Analytics, no Meta Pixel, no Segment, no Mixpanel, no Hotjar, no FullStory.
- Ledger does not send your personal information to the AI. Chat and explain prompts sent to Ledger's AI provider contain only curated public context (candidate records, ballot-measure text) and, if necessary, minimal non-identifying preference summaries — never your email, address, name, IP, or raw quiz answers.
- Ledger does not share individual-level user data with third parties. Not for analytics, not for research, not for B2B products.
- Ledger does not sell personal information. Not now, not at a later date without first updating this policy and asking you to re-consent.
4. How Ledger uses your data
Ledger uses your data operationally — to run the service for you. Specifically:
- Show you your ballot. Ledger uses your address and state to resolve your federal contests.
- Personalize your experience. Your quiz results inform which candidates surface first, and in what framing.
- Run polls and show aggregates. Your poll votes are stored for your history; aggregate results apply privacy thresholds before showing local breakdowns.
- Track civic engagement. Streaks, points, and leaderboard standings are derived from your in-product civic actions.
- Answer your questions. The AI chat and explain features use your questions to retrieve relevant public context and synthesize an answer with citations.
- Resume your latest saved chat. Ledger restores your most recent saved session when you return, unless you deleted it or it aged out under the retention policy in §8.
- Improve Vera. Chat ratings (thumbs up/down) help Ledger measure response quality. Ratings are not sent to third-party model trainers.
- Deliver push notifications (mobile). If you register a device, Ledger uses your push token to send notifications you've opted into through the mobile app.
- Keep the service running. Rate-limit counters, authentication cookies, and error logs exist so Ledger stays available and fair.
- Send you authentication email. See §11.
What Ledger does not use your data for:
- No behavioral advertising. Ledger doesn't target ads to you based on your behavior on Ledger.
- No model training. Ledger doesn't use your quiz answers, poll votes, chat messages, or mock-ballot picks to train AI models. Ledger's AI provider (Anthropic) operates under a no-training API posture for Ledger's API traffic.
- No data sales. See §3.
5. Sub-processors
Ledger relies on a small set of US-based service providers ("sub-processors") to run the product. Each vendor is contractually required to process your data only on Ledger's instructions and for the purposes below.
| Sub-processor | Country | Purpose | Privacy policy |
|---|---|---|---|
| Supabase | US | Database, authentication, storage | supabase.com/privacy |
| Vercel | US | Application hosting, server-side rendering | vercel.com/legal/privacy-policy |
| Anthropic | US | AI inference for chat and explain features (no-training posture) | anthropic.com/legal/privacy |
| Mapbox | US | Address autocomplete, geocoding | mapbox.com/legal/privacy |
| Federal Election Commission (FEC) | US government | Federal candidate records and finance data (public data source; data flows from FEC to Ledger only, never the reverse) | fec.gov/about/privacy-and-security-policy |
| US Census Bureau | US government | Federal district boundary lookup | census.gov/privacy |
| Upstash | US | Rate-limit counters, short-lived cache | upstash.com/trust/privacy.pdf |
| Expo | US | Push notification delivery infrastructure for Ledger mobile apps | expo.dev/privacy |
| Stripe (post-Alpha) | US | Subscription billing for Ledger Premium | stripe.com/privacy |
| Transactional email provider (TBD — Resend, Postmark, or AWS SES) | US | Delivery of OTP and account-security email | Provider-specific, linked here once selected |
Ledger updates this list when it adds or removes a vendor. Material changes trigger the process in §17.
6. AI processing and chat logging
This is the single most important disclosure in this policy. Please read it.
When you chat with Ledger's AI, the full transcript of every conversation — your messages, the AI's responses, timestamps, and a session identifier — is logged on Ledger's servers. Ledger also restores your most recent saved chat when you come back to the chat page, and Profile lets you delete an individual saved session or clear all saved chat history. The explain feature uses the same AI provider and enforcement model but does not create a persistent multi-turn chat session in the same way; explain requests are still subject to abuse detection and rate limits. For Ledger's editorial rules governing how the AI assistant Vera behaves in chat — including neutrality standards, sourcing, and refusal posture — see the AI Policy.
Retention window. Saved chat sessions are retained for up to 365 days from the session's last activity. Ledger runs a scheduled database job every day to purge expired chat sessions automatically. You can also delete saved chat sessions yourself before that window ends. A specific legal hold may require Ledger to preserve content past the normal retention window, but that is an exception, not the default.
Ledger logs chat content for three reasons:
- Liability. If someone claims Ledger's AI produced harmful, defamatory, or partisan content, Ledger needs the actual transcript to investigate and respond.
- Safety. Detecting jailbreak attempts, abuse, harassment, and coordinated misuse requires content — not just metadata. Tiered chat-abuse enforcement (temporary and permanent chat suspension) relies on this logging posture.
- Accountability. Ledger commits to grounding every substantive AI answer in cited sources. When a user reports a drift or a missing citation, the only way to diagnose the issue is to look at what the AI actually said.
Chat ratings. When you rate a Vera response, Ledger stores the rating value linked to the message and session. You can change a thumbs-up to thumbs-down (or vice versa) but cannot delete the rating row yourself; account deletion and session deletion cascade the rows.
Scope and protections:
- Your saved chat history is visible only to you in-product. Other users cannot access it. The same row-level security that scopes your profile data also scopes your saved chat sessions and messages.
- Chat content is not accessible to the general staff. Investigatory or audit access requires a narrowly scoped server-role operation.
- Chat content is not included in any B2B aggregate, never shared with third parties beyond the AI provider for inference, and never used to train models (Ledger's or anyone else's).
- Account deletion purges your chat history and chat ratings. One exception: a specific legal hold (e.g., a subpoena) may require Ledger to preserve content past deletion. Ledger handles those cases individually and as narrowly as possible.
- Ledger never sends your PII to the AI. The prompt templates are reviewed to keep identifying data out of model inputs.
Subpoena and legal-process exposure. Because chat content is retained, it is discoverable by legal process. Ledger will tell you if Ledger receives a legal request for your content, unless legally prohibited from doing so.
AI output can be wrong. The Terms of Service §5 has the full disclaimer — please read it.
7. Poll data
Poll responses are political-opinion data, similar in sensitivity to Values Quiz answers. When you vote in a poll, Ledger stores your support/oppose answer plus frozen segmentation metadata from your profile at vote time — state, congressional district fields when resolved, and your current Values Quiz label when available — so aggregate breakdowns remain stable even if you later move or retake the quiz.
- Poll responses never write into your quiz result and never affect quiz scoring.
- Individual poll rows are never shared externally or shown to other users.
- Aggregate displays apply minimum bucket thresholds. Local or district-level breakdowns require at least 10 votes in the bucket; below that threshold, Ledger shows a broader aggregate instead.
- Account deletion cascades your poll responses.
Any future B2B or research use of poll-derived insights must be aggregate-only, opt-in where required, and subject to the same k-anonymity posture as quiz-derived insights described in Ledger's engineering privacy documentation.
8. Civic-activity engine
Ledger records civic-activity events when you complete qualifying actions (such as finishing the quiz or voting in a poll). These events feed streak counters, points totals, and a local leaderboard bucketed by state and congressional district.
- All civic-activity rows are scoped to your account via row-level security. Other users see only aggregate leaderboard standings, not your individual event log.
civic_pointsdenormalizes state and congressional-district identifiers for leaderboard bucketing — not your street address.- No automated time-based purge exists today; rows remain while your account exists and cascade on account deletion.
- Points and streaks carry no cash value and are not sold or shared with third parties.
9. Mobile apps and push notifications
When you use Ledger's iOS or Android apps, Ledger may store:
- An Expo push token (
expo_push_token) — a device identifier used solely to deliver notifications to that device. - Platform (iOS or Android) and registration timestamps.
Push tokens are scoped to your account via row-level security. You can remove a device registration from your profile or delete your account to purge tokens. Ledger does not use push tokens for cross-app tracking or advertising.
Delivery depends on Apple, Google, Expo, and your device — Ledger does not guarantee that every notification reaches you.
10. Shareable artifacts
Ledger lets you generate a public share URL for things like your values-quiz card today, and a mock-ballot card (post-Alpha).
- The public payload contains only what's needed to render the card — a label, the quiz axis scores, a timestamp, and (for mock-ballot shares) your candidate selections. It does not contain your email, your address, or an account identifier.
- You can revoke the share link at any time from your account. Revocation immediately invalidates the public URL and removes the stored payload.
- Ledger doesn't track who views your share page. Ledger may keep an aggregate view count for the product dashboard, but not viewer identity.
- Share URLs are opaque — knowing one share link tells you nothing about the existence of any other user's share link.
11. How long Ledger keeps your data
| Data | Retention |
|---|---|
| Account (email, profile, name) | While the account exists |
| Address | While the account exists; editable and deletable any time |
| Current quiz result | While the account exists, or until you retake |
| Quiz history | While the account exists (individual-level data is never exposed to third parties — contributes only to future aggregated insights) |
| Poll responses | While the account exists; cascade on account deletion |
| Civic-activity events, streaks, points | While the account exists; cascade on account deletion |
| AI chat transcripts | Up to 365 days from the session's last activity, unless you delete sooner or a legal hold applies |
| Chat message ratings | While the account exists; cascade on account and session deletion |
| Mock ballot | While the account exists, or until you clear it |
| Shareable-card payload | While the share link is live (you can revoke at any time) |
| Mock-ballot public share (post-Alpha) | While the share link is live |
| Feedback submissions | While the account exists for signed-in submissions; anonymous feedback may be retained for operational review |
| Mobile push device tokens | While the account exists and the device remains registered; cascade on account deletion |
| First-party analytics events | While the account exists; purged on account deletion |
| Rate-limit counters | Minutes (Upstash TTL) |
| Stripe customer ID + subscription status (post-Alpha) | While the account exists; purged on account deletion, subject to Stripe's own tax/audit retention |
| Persistent AI companion memory (Phase 4) | While memory is enabled and the account exists; disabling memory or deleting the account purges it |
Default posture: most account-scoped data remains while your account exists. AI chat transcripts are the current exception — they age out automatically after 365 days of inactivity even if your account stays open. Account deletion is real: when you delete your account from your profile, Ledger purges your profile, address, quiz results and history, poll responses, civic-activity records, mock ballot, chat transcripts, chat ratings, share links, mobile push registrations, first-party analytics events tied to your account, companion memory (if Phase 4 has shipped), and your Stripe linkage (if Premium has shipped).
Certain records may be retained briefly post-deletion for legal, accounting, or fraud-prevention reasons, or preserved under a specific legal hold. Ledger discloses the scope of any such retention in §17 updates.
12. Security
- Row-level security is mandatory. Every Supabase table that stores user data has row-level security policies — users can read and write only their own rows.
- Server-only secrets stay server-only. Keys that can bypass row-level security (like Ledger's Supabase service role key, Anthropic API key, or Stripe secret key) never ship to the browser. Ledger audits client bundles for this.
- Rate limits protect you too. Per-user quotas on AI chat and explain features prevent a single compromised account from running up costs or abuse.
- Encryption in transit. Every request to
ledger.voteand every connection to Supabase, Anthropic, Mapbox, Upstash, Expo, and Stripe is TLS-encrypted.
No system is unbreakable — if Ledger suffers a security incident that affects your personal information, Ledger will disclose it to you per §18.
13. Your rights (CCPA, applied nationally)
California residents have specific rights under the California Consumer Privacy Act (CCPA). Because Ledger's audience is US-wide and California residents are in scope, Ledger extends the same rights to every Ledger user regardless of their state of residence.
You have the right to:
- Know. See the personal information Ledger holds about you.
- Access and export. Get a portable copy of your personal information — including quiz snapshots and history, poll responses, civic-activity records, chat transcripts, and chat ratings.
- Delete. Remove your personal information from Ledger's systems, with the purge scope described in §11.
- Non-discrimination. Exercising any of these rights does not change the price or quality of the service Ledger provides to you.
In-product access to these rights ships on Ledger's roadmap (see the public changelog for the current status). In the meantime, you can exercise any right by contacting Ledger through /contact and Ledger will fulfill the request within 45 days (extendable once by 45 days if your request is complex — Ledger will tell you if that happens).
Sale of personal information. Ledger does not sell personal information. CCPA's "do not sell" opt-out is satisfied by construction — there is no sale to opt out of.
14. Email and push communications
Alpha v0.1 — authentication email only. Ledger currently emails you only for authentication purposes: a 6-digit code to verify your email when you sign up, a 6-digit code to log in without a password, and a password-reset code. No newsletters, no election-deadline reminders, no "your senator voted on X" alerts, no upgrade pitches, no marketing.
Ledger's signup and login use in-page 6-digit codes rather than magic-link URLs, so you stay on ledger.vote end-to-end.
Mobile push notifications are a separate channel from email. If you enable push on a Ledger mobile app, Ledger uses your registered device token to deliver notifications you've opted into through that app. Push is not used for behavioral advertising or cross-app tracking. You can disable push in your device settings or remove the device from your Ledger profile.
Post-Alpha — narrow transactional expansion. When Ledger Premium ships, Ledger will add narrowly-scoped transactional email: subscription receipts, account-action confirmations (email change, password change, account deletion), and account-security notifications. These are functional, not editorial, and are not an engagement channel.
Behavioral and editorial email are out of scope at this writing. If Ledger ever adds a digest, an alert, or any form of editorial email, that change is a material update to this policy and triggers the process in §17 — including re-consent.
15. Cookies and local storage
- First-party authentication cookie. An HTTP-only, Same-Site=Lax cookie on
ledger.votekeeps you signed in. This is functionally necessary and is exempt from the consent-banner requirement in most jurisdictions. - Theme preference. Your choice of dark or light mode is stored in your browser's
localStorageon your device. It never leaves your browser. - No third-party cookies. Ledger does not set cookies on behalf of ad networks, analytics vendors, or any other third party.
- No fingerprinting. Ledger does not use canvas, font, WebGL, or any other browser-fingerprinting techniques.
Because Ledger loads no third-party trackers, there is no cookie-consent banner to click through on the web app.
16. First-party analytics
Ledger measures product usage using a server-side events table in Supabase. Each event records a small enum of action types (signup, address_entered, ballot_viewed, quiz_started, quiz_completed, poll_response_submitted, chat_message_sent, etc.) along with an opaque session ID. Event properties are reviewed at the schema level to keep raw addresses, raw quiz answers, and email addresses out.
No external analytics products. No Google Analytics, no Meta Pixel, no Segment, no Mixpanel, no Amplitude, no Hotjar, no FullStory. Any change to this posture is a material update to this policy.
Deletion. Account deletion purges your events alongside your profile, quiz history, poll responses, civic-activity records, chat transcripts, and mock ballot.
17. Children
Ledger is not directed at children under 18 and Ledger does not knowingly collect personal information from users under 18. If you believe a user under 18 has created a Ledger account, contact Ledger through /contact and Ledger will delete the account.
18. International
Ledger is designed for US voters. Ledger's servers, sub-processors, and compliance posture all assume US residency. If you access Ledger from outside the United States, your request is processed transiently to render the page, and Ledger does not onboard non-US users into an account. If you're outside the US and want Ledger to delete any record it may have inadvertently created, contact Ledger through /contact.
19. Breach disclosure
If Ledger suffers a security incident that affects your personal information, Ledger will:
- Notify you directly at your account email address, typically within 72 hours of confirming the incident.
- Publish an incident note describing what happened, what data was affected, and what Ledger is doing about it.
- Comply with state-law disclosure thresholds (CCPA/CPRA and other state privacy laws apply as Ledger's national floor).
20. Changes to this Privacy Policy
Ledger updates this policy as the product grows. When Ledger makes a material change — anything beyond a typo fix, a clarifying sentence, or a stylistic edit — Ledger will:
- Email you at your account address at least 7 days before the new version takes effect.
- Display an in-product banner while the new version is pending.
- Require re-consent on your next login after the effective date.
The legal changelog tracks every version; prior versions are archived at /legal/privacy/v/<version>. Continuing to use Ledger after the effective date means you accept the new version.
21. Contact
Privacy questions, access and deletion requests, and complaints can reach Ledger through /contact. Ledger responds to verified requests within 45 days.
22. Effective date and version
- Version: v3.0.0
- Effective date: June 23, 2026
- Prior versions: v2.0.0, v1.0.0.
The full version history is in the legal changelog.