Privacy policy · last updated 28 July 2026
Your privacy, in plain language.
We ask for very little, we keep less than you would expect, and we tell you exactly where it goes. This page is the whole policy — there is no second document and no fine print somewhere else.
The short version
What we collect, and why
Every item here exists to make one feature work. If a feature does not need it, we do not ask for it.
We do not ask for your name, your phone number, your party registration, or your voter-file record. We do not have them and do not want them.
Your address is the special case
Finding your district is the one moment we touch something genuinely sensitive, so it is the one we engineered hardest.
The address exists only in flight. You type it, it resolves to a district, and it is gone. It is never written to our database, never stored on your device, and never put in a URL.
Most lookups never leave our servers. About four in five addresses resolve against a ZIP-level crosswalk we host ourselves, built from a public Census Bureau file — no outside call at all.
When a lookup does need street-level precision, the address is sent once to the US Census Bureau's public geocoding service, which returns the district. We keep the district. The Census Bureau is a US government agency, and that request lands in their own server logs under their retention rules — that part is theirs, not ours, and we would rather say so than let "we never store your address" quietly imply more than it should.
We filter our own logs so it cannot leak by accident. Our HTTP client writes every outbound request to its log by default, which would have put the address in an ordinary log line. We install a filter that drops those records for the geocoder specifically, and error messages from failed lookups are rewritten to fixed text containing no address.
Device location is optional and works the same way. If you allow it, we use a coarse, only-while-you-are-using-the-app reading to prefill your district. It is not stored and never read in the background.
What we never do
Who else touches your data
The honest list. Everyone here is a processor working on our behalf, doing one job.
Our data sources — Congress.gov, GovInfo, the House Clerk, the FEC — run one way only. They give us the public record. They never receive anything about you.
Ordinary server logs record request metadata such as IP addresses, which we use to keep the service running and to rate-limit abuse. They are kept briefly and are not used to build a profile of you.
Export it or delete it, any time
Export. One action in settings returns your complete record as JSON — every stance, traceable back to the answers that produced it. It is the same data we hold, not a summary of it.
Delete. Deleting your account removes your sign-in identity first, then every row attached to your account ID: your values, saved items, alert rules, and Ask history. We do it in that order on purpose, so an interrupted deletion can never leave you able to sign in to an account with nothing behind it.
We keep your data for as long as your account exists. When you delete it, it is gone — not archived, not retained for analytics.
When this policy changes
We publish the change here and move the date at the top. If a change actually widens what we collect, we will say so plainly rather than hope you re-read the page.
How to reach us
Questions about your data, or about anything on this page: hello@civicherald.app. If you want your account and data deleted and cannot reach the settings screen, email us and we will do it for you.
Your data, your call
Questions about any of this?
Ask us about a specific claim on this page, or get your data exported or deleted. We answer in the open.