The Ledger iOS app is covered by its own policies: iOS app Terms of Service · iOS app Privacy Policy
Privacy Policy
Quick summary
- What Ledger collects: your email address, a password if you set one, a display name, your poll answers, your emoji reactions, and a record of which version of the Terms and this policy you accepted. See the full table in §2.
- What Ledger never collects: your address, zip code, location, date of birth, voter-registration details, government IDs, payment details, or anything from third-party trackers (Ledger loads none).
- Your answers stay private. Nobody else sees your individual answer or reaction. Public results are aggregates, and none is shown until a poll has at least 10 responses.
- No personal data goes to an AI model. Ledger uses AI only inside its own review and publishing process: grading proposed polls, screening stock photographs before a person vets them, and choosing which already-vetted library photograph accompanies a poll.
- How long Ledger keeps it: while your account exists. To delete your account, email the support address on the contact page.
- No analytics product, no marketing email, no tracking pixels, no data sold.
1. About Ledger and what this covers
This Privacy Policy explains how Ledger, Inc. (placeholder — entity formation pending) handles personal information for the Ledger service at ledger.vote: a public board of public-policy polls that anyone can read and signed-in users can answer. Ledger has no mobile app.
Ledger is designed for US residents. Ledger treats the California Consumer Privacy Act (CCPA) as its national floor — the rights described below apply to every Ledger user, not just California residents.
2. What Ledger collects
| Data | When Ledger collects it | Where it's stored | Why |
|---|---|---|---|
| Email address | When you sign up | Supabase Auth and your profiles row (US) | Account identity; sending you sign-in codes |
| Password (hashed) | When you sign up with a password | Supabase Auth (US) | Sign you back in |
| Google account link | When you sign in with Google | Supabase Auth (US). Google supplies your name and profile-picture link, which Supabase Auth stores with the account | Sign you in with Google |
| Authentication sessions | Each time you sign in | Supabase Auth (US), in its own authentication records: sign-in times, and the IP address and browser user-agent string of each sign-in session. Supabase's authentication audit log also records your email address and IP address for each sign-in event. Both the session records and the audit-log entries for your account are deleted when your account is deleted | Keep your sign-in working and secure |
| Display name | Set automatically when you sign up — from your Google profile name if you sign in with Google, otherwise the part of your email address before "@" — and whenever you edit it on your profile page | profiles in Supabase (US) | Show your name on your own profile |
| Terms and Privacy Policy acceptances | When you sign up, and when you accept a new material version | legal_acceptances in Supabase (US): the document, the version, the time, how the acceptance happened, your browser's user-agent string, and a salted hash of your IP address | A record of which text you agreed to |
| Poll answers | When you answer a poll | poll_responses in Supabase (US): the poll, your account, and your answer | Count your answer into the poll's results and show you your own answer |
| Emoji reactions | When you react to a poll | poll_reactions in Supabase (US): the poll, your account, and the emoji | Count your reaction into the poll's reaction totals and show you your own |
| Rate-limit counters | Derived from your account ID or IP address | Upstash Redis (US), expiring within minutes | Prevent abuse and keep the service fair |
| Authentication cookies | When you sign in | First-party cookies on ledger.vote | Keep you signed in (§12) |
| Server logs and runtime metrics | Automatically, as Ledger's servers handle requests | Vercel, Ledger's hosting provider (US), short-lived | Keep the service running and debug failures (§13) |
Tables that hold no information about you. Ledger's other tables hold the polls themselves (polls), the review pipeline's records (poll_generation_runs), time-series of each poll's aggregate counts (poll_trend_snapshots, poll_trend_hourly), the stock-photograph library (poll_stock_photos), social-post records (poll_social_posts), and the list of Ledger staff who can use the review tools (admin_users). None of them records a user's answer or reaction. The staff records name Ledger's own founders, not you.
3. What Ledger never collects and never does
- Ledger does not collect location. No address, zip code, district, coordinates, or device location.
- Ledger does not collect voter-file data, government IDs, biometric data, health data, or payment details.
- Ledger does not load third-party tracking pixels from advocacy organizations, campaigns, ad networks, or analytics vendors. No Google Analytics, no Meta Pixel, no Segment, no Mixpanel, no Hotjar, no FullStory.
- Ledger does not send your personal information to an AI model (§6).
- Ledger does not share individual-level user data with third parties. Not for analytics, not for research, not for any product.
- Ledger does not sell personal information.
4. How Ledger uses your data
- Run your account. Your email and sign-in method let you sign in; your display name appears on your profile.
- Count results. Your answers and reactions are counted into each poll's public aggregates (§7).
- Show you your own activity. The board shows you which answer and reaction you chose.
- Record consent. Your acceptances show which version of the Terms and this policy you agreed to.
- Keep the service running. Rate-limit counters, authentication cookies, server logs, and error reports exist so Ledger stays available and fair.
- Send sign-in codes. See §11.
What Ledger does not use your data for: no advertising, no model training, no data sales, and no profiling.
5. Sub-processors
Ledger relies on a small set of US-based service providers ("sub-processors") to run the product. Each processes data only on Ledger's instructions and for the purposes below.
| Sub-processor | Country | Purpose | Privacy policy |
|---|---|---|---|
| Supabase | US | Database, authentication (including sign-in code email), storage | supabase.com/privacy |
| Vercel | US | Application hosting, server-side rendering | vercel.com/legal/privacy-policy |
| Anthropic | US | AI grading of proposed polls, advisory screening of stock photographs, and choosing which vetted photograph accompanies a poll. Receives poll text, photographs, and photograph descriptions only — no user data | anthropic.com/legal/privacy |
| Upstash | US | Rate-limit counters | upstash.com/trust/privacy.pdf |
| Slack | US | Ledger's internal review of proposed polls and social posts. Receives poll content and staff identities — no user data | slack.com/trust/privacy/privacy-policy |
| Sentry | US | Server-side error reporting. Scrubbed before transport: no user account information, no request bodies, no query strings, no cookies or authorization headers. Ledger does not run Sentry in the web browser. | sentry.io/privacy |
| X | US | Publishing Ledger's own posts of published polls and aggregate results — no user data | x.com/en/privacy |
| Meta (Instagram, Facebook) | US | Publishing Ledger's own posts of published polls and aggregate results — no user data | privacycenter.instagram.com/policy |
Ledger updates this list when it adds or removes a vendor. Material changes follow the process in §18.
6. AI use
Ledger uses AI models (Anthropic's Claude) in three places, all inside Ledger's own review and publishing process:
- Checking proposed polls. Before a poll can be published, a model checks the draft against Ledger's editorial rules and gives the reviewing founder a recommendation. A Ledger founder decides; the model never publishes.
- Screening stock photographs. When Ledger adds a photograph to its library, a model gives an advisory check and a one-line description. A person vets every photograph before it can be used.
- Choosing a poll's photograph. When a proposed poll reaches founder review, a model chooses which photograph from Ledger's library accompanies it. The model sees the poll's text and the photographs' one-line descriptions, and a person has already approved every photograph it can choose from.
A news-drafting feature is switched off. Ledger's code contains a feature that drafts candidate poll questions from news feeds with an AI model. It is switched off in production. If Ledger turns it on, a new version of the AI Policy will say so first, and every drafted poll still passes the check above and a founder's publish decision.
Ledger has no AI assistant, chat, or explain feature. Nothing you enter on Ledger — your email, name, answers, or reactions — is sent to an AI model. Anthropic receives only poll text, photographs, and photograph descriptions. Ledger's editorial rules for its AI use are in the AI Policy.
7. Poll data
Poll answers and reactions are political-opinion data, and Ledger handles them accordingly.
- An answer row holds the poll, your account, your answer, and when you answered and last changed it. Nothing else about you is recorded with it — no location and no demographic group.
- Your individual answer and reaction are never shown to anyone else and never shared outside Ledger.
- Results are public aggregates. Every visitor, signed in or not, sees each poll's aggregate results: the split between the two answers, the number of responses, charts of the split over time, and reaction counts.
- A minimum-response floor protects small counts. A poll's split, chart, and movement are not shown until it has at least 10 responses; below that only the number of responses shows. Each emoji's count is shown only once at least 10 people have chosen it, and the reaction total counts only those emoji, so a small group cannot be worked out by subtraction.
- Closed polls keep their final result on the board.
- Account deletion removes your answers and reactions, and they drop out of every result.
8. Social posts
Ledger mirrors published polls to its own accounts on X, Instagram, and Facebook, and may post a poll's aggregate results there. A Ledger founder approves every post. A results post is made only once a poll has at least 50 responses, and it shows whole-poll aggregates only. Social posts never contain individual answers, reactions, or anything that identifies a user.
9. How long Ledger keeps your data
| Data | Retention |
|---|---|
| Account (email, sign-in method, display name) | While the account exists |
| Terms and Privacy Policy acceptances | While the account exists |
| Authentication sessions and sign-in audit entries | While the account exists; deleted with the account |
| Poll answers | While the account exists; deleted with the account |
| Emoji reactions | While the account exists, or until you remove the reaction; deleted with the account |
| Aggregate count history for each poll | Kept with the poll; holds counts only, never an individual answer. Ten-minute snapshots are deleted after 8 days; hourly totals are kept |
| Server logs and runtime metrics | Short-lived, per Vercel's hosting log retention. Not an account-scoped store |
| Error reports | Per Sentry's retention for Ledger's project. Scrubbed of account information before transport |
| Rate-limit counters | Minutes |
Deleting your account. Email the support address on the contact page from the address on your account. Deleting your account removes your authentication record (including its sign-in sessions and audit-log entries), your profile, your acceptances, your poll answers, and your reactions. Aggregate counts already recorded in a poll's history are not rewritten, because they hold no individual answer.
Certain records may be retained briefly after deletion for legal or fraud-prevention reasons, or preserved under a specific legal hold.
10. Your rights (CCPA, applied nationally)
Ledger extends the rights California residents have under the California Consumer Privacy Act to every Ledger user, regardless of state. You have the right to:
- Know what personal information Ledger holds about you.
- Get a copy of it.
- Delete it, with the scope described in §9.
- Non-discrimination. Exercising these rights does not change the service Ledger provides to you.
How to exercise them. Email the support address on the contact page from the address on your account. Ledger responds within 45 days (extendable once by 45 days for a complex request — Ledger will tell you if that happens).
Sale of personal information. Ledger does not sell personal information, so there is no sale to opt out of.
11. Email
Ledger sends no marketing, newsletters, reminders, or notifications. The only email is the 6-digit code Ledger's authentication provider sends to confirm your email address at signup and to sign you in without a password. Ledger does not send password-reset email; the email sign-in code is the way back into your account.
If Ledger ever adds another kind of email, that is a material change to this policy under §18.
12. Cookies and browser storage
- Authentication cookies. First-party cookies on
ledger.vote, set by Supabase's sign-in library, keep you signed in. Ledger's own page scripts can read them; no other site can. - Acceptance cache. A signed, HTTP-only first-party cookie records that your account has accepted the current Terms and Privacy Policy, so Ledger does not have to look it up on every page.
- Sign-up cookie. While you finish signing up, a signed, HTTP-only, first-party cookie on the
/signuppath carries your email address and pending account id. It lasts up to one hour and is removed when sign-up completes. - Google sign-in marker. When you start a Google sign-in, a short-lived marker is kept in your browser's session storage for that tab and removed when the sign-in completes.
- No third-party cookies and no fingerprinting. Ledger does not set cookies for ad networks, analytics vendors, or any other third party.
Because every cookie Ledger sets is necessary to run the service, there is no cookie-consent banner.
13. Analytics and error reporting
Ledger runs no analytics product. There is no analytics script and no behavioral event store. Ledger does not record which pages you viewed or how long you stayed.
What exists instead. Vercel, Ledger's hosting provider, keeps ordinary server logs and runtime metrics so the service can stay up and be debugged. They are not assembled into user profiles and not shared.
Error reporting. Ledger uses Sentry to learn when its code fails, and only from its servers — Sentry does not run in your browser. Before an error leaves Ledger's servers it is scrubbed: no user account information, no request bodies, no query strings, no cookies, no authorization headers. Performance tracing and session replay are off. Because error reports carry no account identifier, they cannot be looked up and removed per person.
14. Security
- Row-level security on every table. Your answers, reactions, profile, and acceptances can be read only by your own account.
- Writes go through checked paths. Answers and reactions are recorded through database functions that accept them only while a poll is open.
- Server-only secrets stay server-only. Keys that can bypass row-level security never ship to the browser.
- Encryption in transit. Every request to
ledger.voteand every connection to Ledger's sub-processors is TLS-encrypted.
15. Children
Ledger is not directed at children under 18 and does not knowingly collect personal information from anyone under 18. If you believe someone under 18 has created a Ledger account, contact Ledger through the contact page and Ledger will delete the account.
16. International
Ledger is designed for US residents, and its servers and sub-processors are in the United States. If you are outside the US and want Ledger to delete any record it may hold, contact Ledger through the contact page.
17. Breach disclosure
If Ledger suffers a security incident that affects your personal information, Ledger will notify you at your account email address, typically within 72 hours of confirming the incident, publish a note describing what happened and what Ledger is doing about it, and comply with applicable state disclosure law.
18. Changes to this Privacy Policy
When Ledger makes a material change — anything beyond a typo fix, a clarifying sentence, or a stylistic edit — Ledger will publish the new version at /legal/privacy, list it with a summary at /legal, and ask you to accept it the next time you sign in after it takes effect.
Ledger publishes only the current version. The version history is summarized at /legal, and the full text of any earlier version is available on request to the support address on the contact page.
19. Contact
Privacy questions, access and deletion requests, and complaints can reach Ledger through the contact page.
20. Effective date and version
- Version: v4.0.0
- Effective date: September 23, 2026
- Prior versions: v3.1.0, v3.0.0, v2.0.0, v1.0.0.
What changed in v4.0.0. Ledger's product is now the public poll board and nothing else, and Ledger collects far less. Ledger no longer collects your address, coordinates, districts, date of birth, citizenship attestation, voter-registration status, quiz answers, chat transcripts, chat ratings, Daily Five results, civic-activity records, mock-ballot selections, share links, feedback submissions, mobile push tokens, or subscription data — those features are gone. This version adds emoji reactions and the open, floor-protected public results; lists Slack, X, and Meta as sub-processors and drops Mapbox, the FEC, the US Census Bureau, Expo, Stripe, and the planned transactional email provider; and moves account deletion and data requests to email.