Skip to content
CIVIC HERALD

Privacy policy · last updated 28 July 2026

Your privacy, in plain language.

We ask for very little, we keep less than you would expect, and we tell you exactly where it goes. This page is the whole policy — there is no second document and no fine print somewhere else.

The short version

  • We store your district, never your address. You type an address to find out who represents you; we keep the district and throw the address away.
  • Your stated values power your scores and nothing else. They are never sold, never shared, and never used to advocate for a candidate or a cause.
  • No ads, no trackers, no data sale. There is no third-party analytics SDK in the app or on this site.
  • You can take everything with you, or delete it outright, from your settings, without asking us.
  • You can look up your ballot without an account at all.

What we collect, and why

Every item here exists to make one feature work. If a feature does not need it, we do not ask for it.

  • Your email address — only if you create an account. It signs you in and lets us send account mail. Guests who continue without an account never give us one.
  • A random account ID — the number your saved data hangs on. It is not derived from anything about you.
  • Your state and congressional district — the coarse location that produces your ballot. District-level, never street-level. The next section is entirely about this.
  • Your stated values — the issues you pick, where you stand on them, any hard lines you set, and your answers to the onboarding scenarios. These compute your personal match scores.
  • What you follow — bills and races you save, the alert rules you set, and the alerts sitting in your in-app inbox.
  • Your questions in Ask — the questions you ask about a bill or a race and the answers we gave, kept together with their citations so any answer stays checkable back to its sources.
  • Anything you email us — ordinary email, kept as ordinary email.

We do not ask for your name, your phone number, your party registration, or your voter-file record. We do not have them and do not want them.

Your address is the special case

Finding your district is the one moment we touch something genuinely sensitive, so it is the one we engineered hardest.

The address exists only in flight. You type it, it resolves to a district, and it is gone. It is never written to our database, never stored on your device, and never put in a URL.

Most lookups never leave our servers. About four in five addresses resolve against a ZIP-level crosswalk we host ourselves, built from a public Census Bureau file — no outside call at all.

When a lookup does need street-level precision, the address is sent once to the US Census Bureau's public geocoding service, which returns the district. We keep the district. The Census Bureau is a US government agency, and that request lands in their own server logs under their retention rules — that part is theirs, not ours, and we would rather say so than let "we never store your address" quietly imply more than it should.

We filter our own logs so it cannot leak by accident. Our HTTP client writes every outbound request to its log by default, which would have put the address in an ordinary log line. We install a filter that drops those records for the geocoder specifically, and error messages from failed lookups are rewritten to fixed text containing no address.

Device location is optional and works the same way. If you allow it, we use a coarse, only-while-you-are-using-the-app reading to prefill your district. It is not stored and never read in the background.

What we never do

  • No advertising, and no advertising identifiers.
  • No sale of your data, in any form, to anyone. There is no version of this product where your data is the product.
  • No tracking you across other apps or websites. Our App Store privacy declaration says exactly the same thing.
  • No third-party analytics or attribution SDKs. Not Google Analytics, not Firebase, not an ad network. None are installed in the app or on this site.
  • No stored personal scores. How a bill matches you is computed fresh every time you open it and never written onto the bill or the politician, because the same bill matches different people differently.
  • No tracking who you share with. Share cards increment a plain counter per card type and state. That table has no column for a user or a recipient — there is nothing to look up.
  • No push notifications and no email blasts. Alerts appear in your in-app inbox, and only the ones you asked for.

Who else touches your data

The honest list. Everyone here is a processor working on our behalf, doing one job.

  • Supabase — sign-in and identity: your email address and your session tokens.
  • Render — runs our API and hosts our database, which is where everything above lives.
  • Netlify — hosts this website.
  • AI model providers — when you use Ask, your question goes to the model that answers it, along with the public bill or race material it reasons over. The same applies to the single sentence you write if you set a hard line. We route these calls under zero-retention terms: the provider may not keep your text after answering it, and may not train on it.
  • The US Census Bureau — the address slow path described above, and nothing else.
  • Langfuse — operational telemetry: how long a request took and what it cost. The content of your messages is deliberately never attached to those traces.

Our data sources — Congress.gov, GovInfo, the House Clerk, the FEC — run one way only. They give us the public record. They never receive anything about you.

Ordinary server logs record request metadata such as IP addresses, which we use to keep the service running and to rate-limit abuse. They are kept briefly and are not used to build a profile of you.

Export it or delete it, any time

Export. One action in settings returns your complete record as JSON — every stance, traceable back to the answers that produced it. It is the same data we hold, not a summary of it.

Delete. Deleting your account removes your sign-in identity first, then every row attached to your account ID: your values, saved items, alert rules, and Ask history. We do it in that order on purpose, so an interrupted deletion can never leave you able to sign in to an account with nothing behind it.

We keep your data for as long as your account exists. When you delete it, it is gone — not archived, not retained for analytics.

When this policy changes

We publish the change here and move the date at the top. If a change actually widens what we collect, we will say so plainly rather than hope you re-read the page.

How to reach us

Questions about your data, or about anything on this page: hello@civicherald.app. If you want your account and data deleted and cannot reach the settings screen, email us and we will do it for you.

Your data, your call

Questions about any of this?

Ask us about a specific claim on this page, or get your data exported or deleted. We answer in the open.