Skip to main content
Ledger is nonpartisan. Ledger does not endorse candidates, campaigns, or parties.

Legal

Ledger publishes its Terms of Service, Privacy Policy, and AI Policy in plain English. All three are versioned; the history below lists every version and when it took effect.

Version history

Terms of Service

  • v3.0.0Current
    Effective 2026-09-23

    v2 product boundary. Rewritten for the public poll board: accounts (email + password, email code, Google), answering and emoji reactions, open aggregate results behind a 10-response floor, the founder review process and its AI checks, social posts of published polls, and account deletion by email request. Drops the ballot, quiz, AI assistant, civic activity, Daily Five, shareable cards, feedback, mobile apps, and the post-Alpha donation, subscription, and advertising sections.

    View
  • v2.0.0
    Effective 2026-06-23

    Catch-up rewrite for shipped product surfaces. Adds polls, civic-activity engine (streaks/points/leaderboard), mobile apps and push notifications, explain feature, chat ratings, feedback, tiered chat-abuse enforcement with appeal path, and expanded account-deletion scope. Post-Alpha sections retained.

  • v1.0.0
    Effective 2026-04-20

    Initial published Terms of Service. Covers eligibility, account, acceptable use, AI output disclaimer, user content license, shareable artifacts, donation link-out (post-Alpha), subscription and advertising (post-Alpha), termination, disclaimers, limitation of liability, Delaware governing law, binding individual arbitration with small-claims carve-out, and change-notification policy.

Privacy Policy

  • v4.0.0Current
    Effective 2026-09-23

    v2 product boundary. Collection narrows to email, sign-in method, a display name set from the sign-in identity, poll answers, emoji reactions, and Terms/Privacy acceptances; no location or other profile data. Adds open floor-protected results and social posts; sub-processors are Supabase, Vercel, Anthropic, Upstash, Slack, Sentry, X, and Meta; account deletion and data requests move to email.

    View
  • v3.1.0
    Effective 2026-07-29

    Corrective disclosure of existing practice — no change to collection, use, retention, or sharing. Geocoded coordinates are disclosed as stored on the profile (v3.0.0 said 'not stored'). Collection and retention tables gain citizenship attestation, voter-registration status, poll skips, Daily Five attempts/claims, and Premium subscription state with Stripe identifiers. The first-party `events`-table analytics description is replaced with the actual posture (Vercel server logs and runtime metrics only; no analytics product, no client-side analytics). Sentry is disclosed as a sub-processor for server-side web error reporting and mobile crash reporting. Share-link revocation corrected (the public URL dies immediately; the frozen snapshot row is retained for the user's own share history and cascades on account deletion) and the password-reset email removed (no such flow exists). Deletion, export, and Stripe post-deletion wording corrected to the shipped paths.

  • v3.0.0
    Effective 2026-06-23

    Catch-up rewrite for shipped product surfaces. Adds poll responses, civic-activity engine, mobile push device tokens, chat message ratings, feedback submissions, explain feature disclosure, Expo sub-processor, and expanded retention/deletion/CCPA export scope. Post-Alpha sections retained.

  • v2.0.0
    Effective 2026-04-23

    Chat history policy update. Privacy Policy now discloses user-visible saved chat history, profile-level delete controls, and a 365-day retention window from last activity enforced by scheduled purge instead of lifetime retention.

  • v1.0.0
    Effective 2026-04-20

    Initial published Privacy Policy. Mirrors docs/engineering/privacy.md: address, quiz, chat log, OTP, email; CCPA applied nationally; Supabase/Vercel/Anthropic/Mapbox/FEC/Upstash sub-processors; Stripe and companion memory flagged as post-Alpha; no behavioral email, no third-party trackers.

AI Policy

  • v2.0.0Current
    Effective 2026-09-23

    v2 product boundary. Vera, chat, and explain are removed; the policy now covers Ledger's AI use — grading proposed polls, the advisory stock-photo screen, and choosing which vetted library photograph accompanies a poll, all inside a founder-approved review process, with no personal data sent to a model — and discloses the news-drafting feature, which is off in production. Non-consent-bearing.

    View
  • v1.2.0
    Effective 2026-07-19

    AI Policy coverage update. Ledger now displays official state ballot-measure records — official ballot title, state-designated official summary, and a link to the full official text — on its per-state measures pages; the 'Coverage is federal' quick-summary bullet and the '§1 Ballot measures — does not yet ingest measure text' bullet are corrected and 'Why federal-only' is reframed to 'Why coverage is mostly federal.' Vera itself does not summarize, interpret, or recommend on a measure; state and local races and candidates remain out of scope. Non-consent-bearing.

  • v1.1.0
    Effective 2026-05-08

    AI Policy abuse-handling update. Documents shipped code-level refusal handling, low-cardinality suspicious-attempt metadata, metadata-only internal review, tiered chat suspension, and the appeal path. Non-consent-bearing.

  • v1.0.0
    Effective 2026-05-05

    Initial published AI Policy. Identity and coverage of Vera (Ledger's AI assistant), neutrality standard, source hierarchy and citation rules, what Vera will not do, refusal posture and interim abuse-handling posture, versioning and review. Mirrors the policy decisions inventory established in the C01+C04 prompt rewrite. Non-consent-bearing.

Have a question about Ledger's legal documents? Contact Ledger.