Skip to main content
Ledger is nonpartisan. Ledger does not endorse candidates, campaigns, or parties.
LegalPrivacy Policyv3.1.0
Effective: July 29, 2026View current versionTerms of Service

Privacy Policy

Quick summary

  • What Ledger collects: your email and password, the address you enter to look up your ballot and the map coordinates that address resolves to, values-quiz answers and history, poll votes and poll skips, civic-activity records (streaks and points), Daily Five results, AI chat transcripts, chat ratings, mock-ballot selections, the citizenship attestation and voter-registration status you enter, mobile push device tokens (if you enable notifications), feedback you submit, and — if you subscribe to Ledger Premium — your subscription state and Stripe identifiers. See the full table in §2.
  • What Ledger never collects: voter-file data, government IDs, biometric data, location beyond the address you enter, health data, card numbers, and anything from third-party trackers (Ledger doesn't load any).
  • Who processes your data: a small set of US-based vendors Ledger uses to run the service — listed below.
  • How long Ledger keeps it: most account data is kept while your account exists. AI chat transcripts are retained for up to 365 days from a session's last activity, unless you delete them sooner or a legal hold applies.
  • Your rights: you can see, export, and delete your data. Account deletion is self-service in your profile; export is fulfilled on request. Ledger honors California's CCPA rights for every Ledger user regardless of state.
  • No analytics product, no behavioral email, no tracking pixels, no data sold.

1. About Ledger and what this covers

This Privacy Policy explains how Ledger, Inc. (placeholder — entity formation pending) handles personal information for the Ledger service at ledger.vote and in Ledger's mobile apps (iOS and Android). It applies to everyone who uses Ledger — whether you're a signed-out visitor looking up a public ballot preview or a signed-in user with a saved profile.

Ledger is designed for US-based voters. Ledger treats the California Consumer Privacy Act (CCPA) as its national floor — the rights described below apply to every Ledger user, not just California residents.

2. What Ledger collects

DataWhen Ledger collects itWhere it's storedWhy
Email addressWhen you sign upSupabase Auth (US)Account identity; sending you OTP codes
Password (hashed)When you sign up with a passwordSupabase Auth (US)Log you back in
Full name (optional)When you sign up, or from onboardingprofiles in Supabase (US)Personalize greetings and shareable artifacts
AddressWhen you enter it to look up your ballotSigned in: persisted in your profile so you don't have to re-enter it. Signed out: processed transiently for the current lookup, never persisted.Resolve your federal district so Ledger can show your ballot
Date of birth (optional)When you provide it in onboardingprofiles in Supabase (US)Confirm 18+ eligibility, compute election-day age for primaries
Geocoded coordinatesWhen Ledger geocodes the address you entered, via MapboxSigned in: stored on your profiles row (lat and lng, at the precision Mapbox returned), scoped to you via row-level security. Signed out: processed transiently for the current lookup, never persisted.Resolve your districts, and re-resolve them later from the address Ledger already holds when a stored district goes stale
Citizenship attestationWhen you tell Ledger whether you are a US citizen during onboardingprofiles.is_us_citizen in Supabase (US), scoped to you via row-level securityConfirm eligibility for the voter-facing parts of the product
Voter-registration statusWhen you tell Ledger whether you are registered to voteprofiles.registration_status plus the timestamp of your last answer (registration_status_updated_at) in Supabase (US), scoped to youShow you registration-relevant guidance without asking again every visit. Self-reported only — Ledger never verifies it against any voter file
Poll skipsWhen you choose to skip a daily poll rather than answer itpoll_skips in Supabase, scoped to you via row-level securityKeep a skipped poll from reappearing, and credit civic-activity streaks. A skip is political-opinion-adjacent — it records which question you declined — and is handled with the same care as a poll answer (§7)
Daily Five attempts and claimsWhen you play the Daily Five civics quizdaily_five_attempts (the questions served, the answers you gave, the graded result, one row per day) and daily_five_claims (states claimed by a perfect day) in Supabase, scoped to youGrade the day, show your history, and track claimed states
Jurisdiction lookup cacheDerived from your address (non-reversible hash) + US Census lookupjurisdiction_resolution_cache in Supabase (US), server-only accessSpeed up repeat lookups without re-storing addresses
Values-quiz answers and resultWhen you take the quizYour profiles row, scoped to you via row-level securityPersonalize your ballot view, power the shareable quiz card you opt into
Quiz historyWhen you retake the quizAppend-only history table in Supabase, scoped to youShow you how your profile has changed; contribute to future aggregated-only civic insights
Poll responsesWhen you vote in a daily pollpoll_responses in Supabase, scoped to you via row-level securityYour poll history and privacy-safe aggregate breakdowns; frozen state, district, and quiz-label fields at vote time for aggregation
Civic-activity events, streaks, and pointsWhen you take qualifying in-product civic actionscivic_activity_event, civic_streak, civic_points in Supabase, scoped to you via row-level securityEngagement, streak tracking, local leaderboard (civic_points denormalizes state and congressional district for bucketing)
AI chat transcriptsWhen you send messages in Ledger chatServer-side log in Supabase, scoped to you and visible to you in-productLiability, safety, abuse detection, and resuming your most recent saved chat (see §6 below — this is the single most important disclosure in this policy)
Chat message ratingsWhen you thumbs-up or thumbs-down a Vera turnchat_message_ratings in Supabase, scoped to you and your session via row-level securityVera accuracy telemetry; you can change a rating but not delete the row yourself
Mock-ballot selectionsWhen you choose candidates on your ballotSupabase, scoped to you via row-level securityYour own planning tool; power the mock-ballot public share (post-Alpha)
Shareable-card payloadsWhen you generate a share linkStored payload + public URLRender the public share page you asked for
Feedback submissionsWhen you submit the in-product feedback formSupabase, written via server-only pathBug reports, product feedback, content concerns
Mobile push device tokensWhen you register a device for push notificationsmobile_push_devices in Supabase, scoped to you via row-level securityDeliver push notifications to your Ledger mobile app (expo_push_token, platform, registration timestamps)
Rate-limit countersDerived from your user ID or IPUpstash Redis (US), short TTLPrevent abuse and keep the service fair
Authentication cookiesOn login (web)First-party HTTP-only cookie on ledger.voteKeep you signed in
Server logs and runtime metricsAutomatically, as Ledger's servers handle requestsVercel, Ledger's hosting provider (US), short-livedKeep the service running and debug failures. Ledger runs no analytics product — see §16
Premium subscription state + Stripe identifiersWhen you subscribe to Ledger Premiumpremium_entitlements in Supabase (US), linked to your user: Stripe customer ID, Stripe subscription ID, status, plan identifier, and current period end. Card numbers and CVVs never reach Ledger — they stay with StripeResolve your Premium entitlement server-side
Persistent AI companion memory (Phase 4, opt-in)When you enable persistent memory and chatSupabase, scoped to youLet the AI remember prior conversations across sessions

About the coordinates Ledger stores. When you save an address to your profile, Ledger stores the latitude and longitude that address geocodes to, alongside the address itself. Two things follow from that:

  • Ledger keeps them for as long as your account exists, and they are deleted with your account. They are part of the portable copy you can request under §13.
  • Changing your address changes them. Editing your address in your profile replaces the stored coordinates and clears the districts Ledger had derived from the old address, so a stale district can never stay attached to a new address. Ledger re-derives the districts server-side from the address on file — a district is always Ledger's own answer for your address, never a value a browser or app can assert on your behalf.

Ledger does not track your device location. These coordinates are the address you typed, expressed as a point.

3. What Ledger never collects and never does

  • Ledger does not collect voter-file data. Ledger is a decision-support tool, not a voter-targeting tool. Ledger doesn't buy, ingest, or cross-reference commercial voter files. The citizenship attestation and registration status in your profile are what you told Ledger; they are never verified against, or enriched from, a voter file or a government registry.
  • Ledger does not collect government IDs, biometric data, health data, or location beyond the address you enter. The coordinates described in §2 are that address geocoded — not device location, not movement history.
  • Ledger does not load third-party tracking pixels from advocacy organizations, campaigns, ad networks, or analytics vendors. No Google Analytics, no Meta Pixel, no Segment, no Mixpanel, no Hotjar, no FullStory. Ledger's error reporting (§16) is a separate thing: it reports crashes and exceptions, not your behavior.
  • Ledger does not send your personal information to the AI. Chat and explain prompts sent to Ledger's AI provider contain only curated public context (candidate records, ballot-measure text) and, if necessary, minimal non-identifying preference summaries — never your email, address, name, IP, or raw quiz answers.
  • Ledger does not share individual-level user data with third parties. Not for analytics, not for research, not for B2B products.
  • Ledger does not sell personal information. Not now, not at a later date without first updating this policy and asking you to re-consent.

4. How Ledger uses your data

Ledger uses your data operationally — to run the service for you. Specifically:

  • Show you your ballot. Ledger uses your address and state to resolve your federal contests.
  • Personalize your experience. Your quiz results inform which candidates surface first, and in what framing.
  • Run polls and show aggregates. Your poll votes are stored for your history; aggregate results apply privacy thresholds before showing local breakdowns.
  • Track civic engagement. Streaks, points, and leaderboard standings are derived from your in-product civic actions.
  • Answer your questions. The AI chat and explain features use your questions to retrieve relevant public context and synthesize an answer with citations.
  • Resume your latest saved chat. Ledger restores your most recent saved session when you return, unless you deleted it or it aged out under the retention policy in §8.
  • Improve Vera. Chat ratings (thumbs up/down) help Ledger measure response quality. Ratings are not sent to third-party model trainers.
  • Deliver push notifications (mobile). If you register a device, Ledger uses your push token to send notifications you've opted into through the mobile app.
  • Keep the service running. Rate-limit counters, authentication cookies, and error logs exist so Ledger stays available and fair.
  • Send you authentication email. See §11.

What Ledger does not use your data for:

  • No behavioral advertising. Ledger doesn't target ads to you based on your behavior on Ledger.
  • No model training. Ledger doesn't use your quiz answers, poll votes, chat messages, or mock-ballot picks to train AI models. Ledger's AI provider (Anthropic) operates under a no-training API posture for Ledger's API traffic.
  • No data sales. See §3.

5. Sub-processors

Ledger relies on a small set of US-based service providers ("sub-processors") to run the product. Each vendor is contractually required to process your data only on Ledger's instructions and for the purposes below.

Sub-processorCountryPurposePrivacy policy
SupabaseUSDatabase, authentication, storagesupabase.com/privacy
VercelUSApplication hosting, server-side renderingvercel.com/legal/privacy-policy
AnthropicUSAI inference for chat and explain features (no-training posture)anthropic.com/legal/privacy
MapboxUSAddress autocomplete, geocodingmapbox.com/legal/privacy
Federal Election Commission (FEC)US governmentFederal candidate records and finance data (public data source; data flows from FEC to Ledger only, never the reverse)fec.gov/about/privacy-and-security-policy
US Census BureauUS governmentFederal district boundary lookupcensus.gov/privacy
UpstashUSRate-limit counters, short-lived cacheupstash.com/trust/privacy.pdf
ExpoUSPush notification delivery infrastructure for Ledger mobile appsexpo.dev/privacy
SentryUSError and crash reporting — server-side errors from the Ledger web application, and crashes in the Ledger mobile apps. Scrubbed before transport: no user account information, no request bodies, no query strings, no cookies or authorization headers, no addresses, no chat content. Ledger does not run Sentry in the web browser.sentry.io/privacy
StripeUSSubscription billing for Ledger Premium. Engaged only if you subscribe; card data is collected by Stripe, never by Ledger.stripe.com/privacy
Transactional email provider (TBD — Resend, Postmark, or AWS SES)USDelivery of OTP and account-security emailProvider-specific, linked here once selected

Ledger updates this list when it adds or removes a vendor. Material changes trigger the process in §17.

6. AI processing and chat logging

This is the single most important disclosure in this policy. Please read it.

When you chat with Ledger's AI, the full transcript of every conversation — your messages, the AI's responses, timestamps, and a session identifier — is logged on Ledger's servers. Ledger also restores your most recent saved chat when you come back to the chat page, and Profile lets you delete an individual saved session or clear all saved chat history. The explain feature uses the same AI provider and enforcement model but does not create a persistent multi-turn chat session in the same way; explain requests are still subject to abuse detection and rate limits. For Ledger's editorial rules governing how the AI assistant Vera behaves in chat — including neutrality standards, sourcing, and refusal posture — see the AI Policy.

Retention window. Saved chat sessions are retained for up to 365 days from the session's last activity. Ledger runs a scheduled database job every day to purge expired chat sessions automatically. You can also delete saved chat sessions yourself before that window ends. A specific legal hold may require Ledger to preserve content past the normal retention window, but that is an exception, not the default.

Ledger logs chat content for three reasons:

  1. Liability. If someone claims Ledger's AI produced harmful, defamatory, or partisan content, Ledger needs the actual transcript to investigate and respond.
  2. Safety. Detecting jailbreak attempts, abuse, harassment, and coordinated misuse requires content — not just metadata. Tiered chat-abuse enforcement (temporary and permanent chat suspension) relies on this logging posture.
  3. Accountability. Ledger commits to grounding every substantive AI answer in cited sources. When a user reports a drift or a missing citation, the only way to diagnose the issue is to look at what the AI actually said.

Chat ratings. When you rate a Vera response, Ledger stores the rating value linked to the message and session. You can change a thumbs-up to thumbs-down (or vice versa) but cannot delete the rating row yourself; account deletion and session deletion cascade the rows.

Scope and protections:

  • Your saved chat history is visible only to you in-product. Other users cannot access it. The same row-level security that scopes your profile data also scopes your saved chat sessions and messages.
  • Chat content is not accessible to the general staff. Investigatory or audit access requires a narrowly scoped server-role operation.
  • Chat content is not included in any B2B aggregate, never shared with third parties beyond the AI provider for inference, and never used to train models (Ledger's or anyone else's).
  • Account deletion purges your chat history and chat ratings. One exception: a specific legal hold (e.g., a subpoena) may require Ledger to preserve content past deletion. Ledger handles those cases individually and as narrowly as possible.
  • Ledger never sends your PII to the AI. The prompt templates are reviewed to keep identifying data out of model inputs.

Subpoena and legal-process exposure. Because chat content is retained, it is discoverable by legal process. Ledger will tell you if Ledger receives a legal request for your content, unless legally prohibited from doing so.

AI output can be wrong. The Terms of Service §5 has the full disclaimer — please read it.

7. Poll data

Poll responses are political-opinion data, similar in sensitivity to Values Quiz answers. When you vote in a poll, Ledger stores your support/oppose answer plus frozen segmentation metadata from your profile at vote time — state, congressional district fields when resolved, and your current Values Quiz label when available — so aggregate breakdowns remain stable even if you later move or retake the quiz.

  • Poll responses never write into your quiz result and never affect quiz scoring.
  • Skips are recorded too. Choosing "skip" on a poll writes a row identifying which poll you declined, so the question does not come back and your civic-activity streak still gets credit. A skip is not counted in any published aggregate. It is treated with the same care as an answer: scoped to you via row-level security, never shared, and deleted with your account.
  • Individual poll rows are never shared externally or shown to other users.
  • Aggregate displays apply minimum bucket thresholds. Local or district-level breakdowns require at least 10 votes in the bucket; below that threshold, Ledger shows a broader aggregate instead.
  • Account deletion cascades your poll responses.

Any future B2B or research use of poll-derived insights must be aggregate-only, opt-in where required, and subject to the same k-anonymity posture as quiz-derived insights described in Ledger's engineering privacy documentation.

8. Civic-activity engine

Ledger records civic-activity events when you complete qualifying actions (such as finishing the quiz or voting in a poll). These events feed streak counters, points totals, and a local leaderboard bucketed by state and congressional district.

  • All civic-activity rows are scoped to your account via row-level security. Other users see only aggregate leaderboard standings, not your individual event log.
  • civic_points denormalizes state and congressional-district identifiers for leaderboard bucketing — not your street address.
  • No automated time-based purge exists today; rows remain while your account exists and cascade on account deletion.
  • Points and streaks carry no cash value and are not sold or shared with third parties.

9. Mobile apps and push notifications

When you use Ledger's iOS or Android apps, Ledger may store:

  • An Expo push token (expo_push_token) — a device identifier used solely to deliver notifications to that device.
  • Platform (iOS or Android) and registration timestamps.

Push tokens are scoped to your account via row-level security. You can remove a device registration from your profile or delete your account to purge tokens. Ledger does not use push tokens for cross-app tracking or advertising.

Delivery depends on Apple, Google, Expo, and your device — Ledger does not guarantee that every notification reaches you.

10. Shareable artifacts

Ledger lets you generate a public share URL for things like your values-quiz card today, and a mock-ballot card (post-Alpha).

  • The public payload contains only what's needed to render the card — a label, the quiz axis scores, a timestamp, and (for mock-ballot shares) your candidate selections. It does not contain your email, your address, or an account identifier.
  • You can revoke the share link at any time from your account. Revocation is immediate — the public URL stops resolving on the very next request. The underlying record is kept, not erased: Ledger retains the frozen snapshot the card was built from so you can see your own share history, including what you had already shared and when you revoked it. Nobody else can reach it. It is deleted with your account.
  • Ledger doesn't track who views your share page. Ledger may keep an aggregate view count for the product dashboard, but not viewer identity.
  • Share URLs are opaque — knowing one share link tells you nothing about the existence of any other user's share link.

11. How long Ledger keeps your data

DataRetention
Account (email, profile, name)While the account exists
AddressWhile the account exists; editable and deletable any time
Geocoded coordinates for that addressWhile the account exists; replaced when you change your address, deleted with the account
Citizenship attestation, voter-registration status (and the date you last answered)While the account exists; editable any time
Current quiz resultWhile the account exists, or until you retake
Quiz historyWhile the account exists (individual-level data is never exposed to third parties — contributes only to future aggregated insights)
Poll responsesWhile the account exists; cascade on account deletion
Poll skipsWhile the account exists; cascade on account deletion (removing a skip also deletes the row)
Daily Five attempts and state claimsWhile the account exists; cascade on account deletion
Civic-activity events, streaks, pointsWhile the account exists; cascade on account deletion
AI chat transcriptsUp to 365 days from the session's last activity, unless you delete sooner or a legal hold applies
Chat message ratingsWhile the account exists; cascade on account and session deletion
Mock ballotWhile the account exists, or until you clear it
Shareable-card payloadWhile the account exists. Revoking a share link stops the public URL immediately but does not delete the frozen snapshot behind it — that row is kept for your own share history and cascades on account deletion
Mock-ballot public share (post-Alpha)While the share link is live
Feedback submissionsWhile the account exists for signed-in submissions; anonymous feedback may be retained for operational review
Mobile push device tokensWhile the account exists and the device remains registered; cascade on account deletion
Server logs and runtime metricsShort-lived, per Vercel's hosting log retention. Not an account-scoped store and not keyed to your identity
Error and crash reportsPer Sentry's retention for Ledger's project. Scrubbed of account information before transport (§5)
Rate-limit countersMinutes (Upstash TTL)
Premium subscription state + Stripe identifiersWhile the account exists. On account deletion, the row is deleted with your account and the Stripe-side deletion is carried out as described below
Persistent AI companion memory (Phase 4)While memory is enabled and the account exists; disabling memory or deleting the account purges it

Default posture: most account-scoped data remains while your account exists. AI chat transcripts are the current exception — they age out automatically after 365 days of inactivity even if your account stays open. Account deletion is real: when you delete your account from your profile, Ledger purges your profile, address and its coordinates, citizenship attestation and registration status, quiz results and history, poll responses and poll skips, Daily Five attempts and claims, civic-activity records, mock ballot, chat transcripts, chat ratings, share links, mobile push registrations, Premium subscription state, companion memory (if Phase 4 has shipped), and the Stripe linkage described below.

One record outlives your account, by necessity. If you subscribed to Ledger Premium, Ledger must also ask Stripe to delete the customer record it holds for you. That request can fail — Stripe can be unreachable at the moment you delete your account. So before deleting your account, Ledger writes a single queued instruction containing only the Stripe customer identifier, and no link back to you: your user ID, email, and every other field are already gone by the time the queue is read. Ledger retries that instruction until Stripe confirms the deletion, then keeps the completed record for 90 days as proof the deletion happened, after which it is purged. Stripe's own tax and audit retention applies on its side and Ledger cannot override it.

Certain records may be retained briefly post-deletion for legal, accounting, or fraud-prevention reasons, or preserved under a specific legal hold. Ledger discloses the scope of any such retention in §17 updates.

12. Security

  • Row-level security is mandatory. Every Supabase table that stores user data has row-level security policies — users can read and write only their own rows.
  • Server-only secrets stay server-only. Keys that can bypass row-level security (like Ledger's Supabase service role key, Anthropic API key, or Stripe secret key) never ship to the browser. Ledger audits client bundles for this.
  • Rate limits protect you too. Per-user quotas on AI chat and explain features prevent a single compromised account from running up costs or abuse.
  • Encryption in transit. Every request to ledger.vote and every connection to Supabase, Anthropic, Mapbox, Upstash, Expo, Sentry, and Stripe is TLS-encrypted.

No system is unbreakable — if Ledger suffers a security incident that affects your personal information, Ledger will disclose it to you per §18.

13. Your rights (CCPA, applied nationally)

California residents have specific rights under the California Consumer Privacy Act (CCPA). Because Ledger's audience is US-wide and California residents are in scope, Ledger extends the same rights to every Ledger user regardless of their state of residence.

You have the right to:

  • Know. See the personal information Ledger holds about you.
  • Access and export. Get a portable copy of your personal information — including your profile and address, the coordinates and districts derived from it, quiz snapshots and history, poll responses and skips, Daily Five results, civic-activity records, chat transcripts, chat ratings, mock-ballot selections, feedback, push registrations, and Premium subscription state.
  • Delete. Remove your personal information from Ledger's systems, with the purge scope described in §11.
  • Non-discrimination. Exercising any of these rights does not change the price or quality of the service Ledger provides to you.

How to exercise them today. Deletion is self-service: the delete-account control in your profile performs the purge described in §11 immediately — no request, no waiting period. Export is fulfilled on request: ask through /contact and Ledger assembles the portable copy for you with a single versioned tool that reads every account-linked table for exactly one account. A self-service export button is on the roadmap; until it ships, the request path is the route. Ledger fulfills within 45 days (extendable once by 45 days if your request is complex — Ledger will tell you if that happens).

What the export leaves out, and why. The copy Ledger produces carries a manifest listing every table included and every account-linked record deliberately withheld, with the reason. An omission is never silent. Today the withheld set is internal integrity records: abuse-enforcement state and internal abuse-review cases opened about the account — disclosing those would expose the detection posture to the account it constrains, and the review rows name the staff who handled them. Your Supabase authentication record is also excluded; the account email it holds is already in the export via your profile.

Sale of personal information. Ledger does not sell personal information. CCPA's "do not sell" opt-out is satisfied by construction — there is no sale to opt out of.

14. Email and push communications

Alpha v0.1 — authentication email only. Ledger currently emails you only for authentication purposes, and every one of those emails is a 6-digit code: one to verify your email when you sign up, one to log in without a password, and one to confirm it is really you before your account is deleted. No newsletters, no election-deadline reminders, no "your senator voted on X" alerts, no upgrade pitches, no marketing.

Ledger does not send password-reset email. Earlier versions of this policy listed a password-reset code. No such flow exists in the product — if you cannot remember your password, the email login code is the way back into your account.

Ledger's signup and login use in-page 6-digit codes rather than magic-link URLs, so you stay on ledger.vote end-to-end.

Mobile push notifications are a separate channel from email. If you enable push on a Ledger mobile app, Ledger uses your registered device token to deliver notifications you've opted into through that app. Push is not used for behavioral advertising or cross-app tracking. You can disable push in your device settings or remove the device from your Ledger profile.

Post-Alpha — narrow transactional expansion. When Ledger Premium ships, Ledger will add narrowly-scoped transactional email: subscription receipts, account-action confirmations (email change, password change, account deletion), and account-security notifications. These are functional, not editorial, and are not an engagement channel.

Behavioral and editorial email are out of scope at this writing. If Ledger ever adds a digest, an alert, or any form of editorial email, that change is a material update to this policy and triggers the process in §17 — including re-consent.

15. Cookies and local storage

  • First-party authentication cookie. An HTTP-only, Same-Site=Lax cookie on ledger.vote keeps you signed in. This is functionally necessary and is exempt from the consent-banner requirement in most jurisdictions.
  • Theme preference. Your choice of dark or light mode is stored in your browser's localStorage on your device. It never leaves your browser.
  • No third-party cookies. Ledger does not set cookies on behalf of ad networks, analytics vendors, or any other third party.
  • No fingerprinting. Ledger does not use canvas, font, WebGL, or any other browser-fingerprinting techniques.

Because Ledger loads no third-party trackers, there is no cookie-consent banner to click through on the web app.

16. Analytics and error reporting

Ledger runs no analytics product. There is no analytics script in the web app, no analytics SDK in the mobile apps, and no behavioral event store on Ledger's servers. Ledger does not record which pages you viewed, which candidates you looked at, or how long you stayed.

What exists instead. Ledger's hosting provider, Vercel, produces ordinary server logs and runtime metrics — the request-level record any web server keeps in order to stay up and be debuggable. Ledger reads those to keep the service running. They are not assembled into user profiles, not queried per-person for product measurement, and not shared.

No external analytics products. No Google Analytics, no Meta Pixel, no Segment, no Mixpanel, no Amplitude, no Hotjar, no FullStory. Any change to this posture is a material update to this policy.

Error and crash reporting is separate — and it is a vendor. Ledger uses Sentry to learn when its code fails:

  • On the web, only server-side errors are reported. Ledger does not run Sentry in your browser. Before an error leaves Ledger's servers it is scrubbed: no user account information, no request bodies, no query strings, no cookies, no authorization headers. Performance tracing and session replay are switched off.
  • In the mobile apps, crashes and JavaScript errors are reported through the same scrubbing discipline: auth tokens, addresses, questions you typed, request bodies, and raw backend responses are removed before transport, and native-level capture is off.

What Sentry receives is a stack trace and the shape of the failure — not your data. Error reports are not used for measurement, personalization, or advertising.

Deletion. There is no per-account analytics store to purge, so nothing of this kind is part of account deletion (§11). Scrubbed error reports carry no account identifier, which also means they cannot be looked up and removed per person — a direct consequence of collecting no identity in them.

17. Children

Ledger is not directed at children under 18 and Ledger does not knowingly collect personal information from users under 18. If you believe a user under 18 has created a Ledger account, contact Ledger through /contact and Ledger will delete the account.

18. International

Ledger is designed for US voters. Ledger's servers, sub-processors, and compliance posture all assume US residency. If you access Ledger from outside the United States, your request is processed transiently to render the page, and Ledger does not onboard non-US users into an account. If you're outside the US and want Ledger to delete any record it may have inadvertently created, contact Ledger through /contact.

19. Breach disclosure

If Ledger suffers a security incident that affects your personal information, Ledger will:

  • Notify you directly at your account email address, typically within 72 hours of confirming the incident.
  • Publish an incident note describing what happened, what data was affected, and what Ledger is doing about it.
  • Comply with state-law disclosure thresholds (CCPA/CPRA and other state privacy laws apply as Ledger's national floor).

20. Changes to this Privacy Policy

Ledger updates this policy as the product grows. When Ledger makes a material change — anything beyond a typo fix, a clarifying sentence, or a stylistic edit — Ledger will:

  1. Email you at your account address at least 7 days before the new version takes effect.
  2. Display an in-product banner while the new version is pending.
  3. Require re-consent on your next login after the effective date.

The legal changelog tracks every version; prior versions are archived at /legal/privacy/v/<version>. Continuing to use Ledger after the effective date means you accept the new version.

21. Contact

Privacy questions, access and deletion requests, and complaints can reach Ledger through /contact. Ledger responds to verified requests within 45 days.

22. Effective date and version

  • Version: v3.1.0
  • Effective date: July 29, 2026
  • Prior versions: v3.0.0, v2.0.0, v1.0.0.

What changed in v3.1.0, and why there is nothing to re-accept. This version is a corrective disclosure: it makes this policy match what Ledger's systems have actually been doing. Nothing here widens what Ledger collects, what it uses your data for, how long it keeps it, or who it shares it with. Six corrections:

  1. Coordinates. v3.0.0 said the coordinates derived from your address were "not stored." They are stored, on your profile, and always have been — §2 now says so, explains what they are for, and explains what happens to them when you change your address.
  2. Data Ledger collects but had not listed. Citizenship attestation, voter-registration status, poll skips, Daily Five results, and Premium subscription state now appear in the collection and retention tables.
  3. Analytics. v3.0.0 described a first-party events table and an opaque session ID. No such store was ever built. §16 now describes the actual position, which collects less: no analytics product at all.
  4. Sentry. Error and crash reporting is a vendor relationship and is now disclosed as one, in §5 and §16, with the scrubbing rules that govern it.
  5. Revoking a share link. v3.0.0 said revocation "removes the stored payload." It does not. Revocation stops the public link immediately, but Ledger keeps the frozen snapshot behind it so you can audit your own share history. §10 and §11 now say so. The record is still deleted with your account.
  6. Password-reset email. v3.0.0 listed a password-reset code among the emails Ledger sends. Ledger has no password-reset flow. §14 now lists only the codes actually sent.

Because a corrective disclosure narrows the gap between the text and the practice rather than changing the practice, this version does not carry a material change under §20 and does not ask you to accept anything again. Prior versions stay published at /legal/privacy/v/<version> so the earlier text remains readable in full.

The full version history is in the legal changelog.