Skip to main content
Ledger is nonpartisan. Ledger does not endorse candidates, campaigns, or parties.
LegalPrivacy Policyv1.0.0Archived version
Effective: April 20, 2026View current versionTerms of Service

Privacy Policy

Quick summary

  • What Ledger collects: your email and password, the address you enter to look up your ballot, the answers and result from the values quiz, and the AI chat transcripts you create with Ledger. That's it.
  • What Ledger never collects: voter-file data, government IDs, biometric data, location, health data, financial data beyond subscription billing (post-Alpha), and anything from third-party trackers (Ledger doesn't load any).
  • Who processes your data: a small set of US-based vendors Ledger uses to run the service — listed below.
  • How long Ledger keeps it: for as long as your account exists. When you delete your account, Ledger actually deletes.
  • Your rights: you can see, export, and delete your data. Ledger honors California's CCPA rights for every Ledger user regardless of state.
  • No behavioral email, no tracking pixels, no data sold.

1. About Ledger and what this covers

This Privacy Policy explains how Ledger, Inc. (placeholder — entity formation pending) handles personal information for the Ledger service at ledger.vote. It applies to everyone who uses Ledger — whether you're a signed-out visitor looking up a public ballot preview or a signed-in user with a saved profile.

Ledger is designed for US-based voters. Ledger treats the California Consumer Privacy Act (CCPA) as its national floor — the rights described below apply to every Ledger user, not just California residents.

2. What Ledger collects

DataWhen Ledger collects itWhere it's storedWhy
Email addressWhen you sign upSupabase Auth (US)Account identity; sending you OTP codes
Password (hashed)When you sign up with a passwordSupabase Auth (US)Log you back in
Full name (optional)When you sign up, or from onboardingprofiles in Supabase (US)Personalize greetings and shareable artifacts
AddressWhen you enter it to look up your ballotSigned in: persisted in your profile so you don't have to re-enter it. Signed out: processed transiently for the current lookup, never persisted.Resolve your federal district so Ledger can show your ballot
Date of birth (optional)When you provide it in onboardingprofiles in Supabase (US)Confirm 18+ eligibility, compute election-day age for primaries
Geocoded coordinatesDerived from your address via MapboxNot stored — used transiently to match your districtBallot lookup
Jurisdiction lookup cacheDerived from your address (non-reversible hash) + US Census lookupjurisdiction_resolution_cache in Supabase (US), server-only accessSpeed up repeat lookups without re-storing addresses
Values-quiz answers and resultWhen you take the quizYour profiles row, scoped to you via row-level securityPersonalize your ballot view, power the shareable quiz card you opt into
Quiz historyWhen you retake the quizAppend-only history table in Supabase, scoped to youShow you how your profile has changed; contribute to future aggregated-only civic insights
AI chat transcriptsWhen you send messages in Ledger chatServer-side log in Supabase, scoped to youLiability, safety, abuse detection (see §6 below — this is the single most important disclosure in this policy)
Mock-ballot selectionsWhen you choose candidates on your ballotSupabase, scoped to you via row-level securityYour own planning tool; power the mock-ballot public share (post-Alpha)
Shareable-card payloadsWhen you generate a share linkStored payload + public URLRender the public share page you asked for
Rate-limit countersDerived from your user ID or IPUpstash Redis (US), short TTLPrevent abuse and keep the service fair
Authentication cookiesOn loginFirst-party HTTP-only cookie on ledger.voteKeep you signed in
Stripe customer ID + subscription status (post-Alpha)When you subscribe to Ledger PremiumSupabase, linked to your userResolve your Premium entitlement
Persistent AI companion memory (Phase 4, opt-in)When you enable persistent memory and chatSupabase, scoped to youLet the AI remember prior conversations across sessions

3. What Ledger never collects and never does

  • Ledger does not collect voter-file data. Ledger is a decision-support tool, not a voter-targeting tool. Ledger doesn't buy, ingest, or cross-reference commercial voter files.
  • Ledger does not collect government IDs, biometric data, health data, or location beyond the address you enter.
  • Ledger does not load third-party tracking pixels from advocacy organizations, campaigns, ad networks, or analytics vendors. No Google Analytics, no Meta Pixel, no Segment, no Mixpanel, no Hotjar, no FullStory.
  • Ledger does not send your personal information to the AI. Chat prompts sent to Ledger's AI provider contain only curated public context (candidate records, ballot-measure text) and, if necessary, minimal non-identifying preference summaries — never your email, address, name, IP, or raw quiz answers.
  • Ledger does not share individual-level user data with third parties. Not for analytics, not for research, not for B2B products.
  • Ledger does not sell personal information. Not now, not at a later date without first updating this policy and asking you to re-consent.

4. How Ledger uses your data

Ledger uses your data operationally — to run the service for you. Specifically:

  • Show you your ballot. Ledger uses your address and state to resolve your federal contests.
  • Personalize your experience. Your quiz results inform which candidates surface first, and in what framing.
  • Answer your questions. The AI chat feature uses your questions to retrieve relevant public context and synthesize an answer with citations.
  • Keep the service running. Rate-limit counters, authentication cookies, and error logs exist so Ledger stays available and fair.
  • Send you authentication email. See §10.

What Ledger does not use your data for:

  • No behavioral advertising. Ledger doesn't target ads to you based on your behavior on Ledger.
  • No model training. Ledger doesn't use your quiz answers, chat messages, or mock-ballot picks to train AI models. Ledger's AI provider (Anthropic) operates under a no-training API posture for Ledger's API traffic.
  • No data sales. See §3.

5. Sub-processors

Ledger relies on a small set of US-based service providers ("sub-processors") to run the product. Each vendor is contractually required to process your data only on Ledger's instructions and for the purposes below.

Sub-processorCountryPurposePrivacy policy
SupabaseUSDatabase, authentication, storagesupabase.com/privacy
VercelUSApplication hosting, server-side renderingvercel.com/legal/privacy-policy
AnthropicUSAI inference for chat and explain features (no-training posture)anthropic.com/legal/privacy
MapboxUSAddress autocomplete, geocodingmapbox.com/legal/privacy
Federal Election Commission (FEC)US governmentFederal candidate records and finance data (public data source; data flows from FEC to Ledger only, never the reverse)fec.gov/about/privacy-and-security-policy
US Census BureauUS governmentFederal district boundary lookupcensus.gov/privacy
UpstashUSRate-limit counters, short-lived cacheupstash.com/trust/privacy.pdf
Stripe (post-Alpha)USSubscription billing for Ledger Premiumstripe.com/privacy
Transactional email provider (TBD — Resend, Postmark, or AWS SES)USDelivery of OTP and account-security emailProvider-specific, linked here once selected

Ledger updates this list when it adds or removes a vendor. Material changes trigger the process in §15.

6. AI processing and chat logging

This is the single most important disclosure in this policy. Please read it.

When you chat with Ledger's AI, the full transcript of every conversation — your messages, the AI's responses, timestamps, and a session identifier — is logged on Ledger's servers. The in-browser chat window is ephemeral (it clears when you close the tab), but the backend copy is not ephemeral — it persists for the lifetime of your account.

Ledger logs chat content for three reasons:

  1. Liability. If someone claims Ledger's AI produced harmful, defamatory, or partisan content, Ledger needs the actual transcript to investigate and respond.
  2. Safety. Detecting jailbreak attempts, abuse, harassment, and coordinated misuse requires content — not just metadata.
  3. Accountability. Ledger commits to grounding every substantive AI answer in cited sources. When a user reports a drift or a missing citation, the only way to diagnose the issue is to look at what the AI actually said.

Scope and protections:

  • Chat content is not accessible to the general staff. It's reachable only by a server-role operation, for audit or abuse investigation, and those accesses are themselves logged.
  • Chat content is not included in any B2B aggregate, never shared with third parties beyond the AI provider for inference, and never used to train models (ours or anyone else's).
  • Account deletion purges your chat history. One exception: a specific legal hold (e.g., a subpoena) may require Ledger to preserve content past deletion. Ledger handles those cases individually and as narrowly as possible.
  • Ledger never sends your PII to the AI. The prompt templates are reviewed to keep identifying data out of model inputs.

Subpoena and legal-process exposure. Because chat content is retained, it is discoverable by legal process. Ledger will tell you if Ledger receives a legal request for your content, unless legally prohibited from doing so.

AI output can be wrong. The Terms of Service §5 has the full disclaimer — please read it.

7. Shareable artifacts

Ledger lets you generate a public share URL for things like your values-quiz card today, and a mock-ballot card (post-Alpha).

  • The public payload contains only what's needed to render the card — a label, the quiz axis scores, a timestamp, and (for mock-ballot shares) your candidate selections. It does not contain your email, your address, or an account identifier.
  • You can revoke the share link at any time from your account. Revocation immediately invalidates the public URL and removes the stored payload.
  • Ledger doesn't track who views your share page. Ledger may keep an aggregate view count for the product dashboard, but not viewer identity.
  • Share URLs are opaque — knowing one share link tells you nothing about the existence of any other user's share link.

8. How long Ledger keeps your data

DataRetention
Account (email, profile, name)While the account exists
AddressWhile the account exists; editable and deletable any time
Current quiz resultWhile the account exists, or until you retake
Quiz historyWhile the account exists (individual-level data is never exposed to third parties — contributes only to future aggregated insights)
AI chat transcriptsWhile the account exists (see §6)
Mock ballotWhile the account exists, or until you clear it
Shareable-card payloadWhile the share link is live (you can revoke at any time)
Mock-ballot public share (post-Alpha)While the share link is live
Rate-limit countersMinutes (Upstash TTL)
Stripe customer ID + subscription status (post-Alpha)While the account exists; purged on account deletion, subject to Stripe's own tax/audit retention
Persistent AI companion memory (Phase 4)While memory is enabled and the account exists; disabling memory or deleting the account purges it

Default posture: Ledger keeps user data indefinitely for the lifetime of your account. The counterweight is that account deletion is real. When you delete your account from your profile, Ledger purges your profile, address, quiz results and history, mock ballot, chat transcripts, share links, companion memory (if Phase 4 has shipped), and your Stripe linkage (if Premium has shipped).

Certain records may be retained briefly post-deletion for legal, accounting, or fraud-prevention reasons, or preserved under a specific legal hold. Ledger discloses the scope of any such retention in §15 updates.

9. Security

  • Row-level security is mandatory. Every Supabase table that stores user data has row-level security policies — users can read and write only their own rows.
  • Server-only secrets stay server-only. Keys that can bypass row-level security (like Ledger's Supabase service role key, Anthropic API key, or Stripe secret key) never ship to the browser. Ledger audits client bundles for this.
  • Rate limits protect you too. Per-user quotas on AI chat and explain features (documented in Ledger's engineering documentation) prevent a single compromised account from running up costs or abuse.
  • Encryption in transit. Every request to ledger.vote and every connection to Supabase, Anthropic, Mapbox, Upstash, and Stripe is TLS-encrypted.

No system is unbreakable — if Ledger suffers a security incident that affects your personal information, Ledger will disclose it to you per §16.

10. Your rights (CCPA, applied nationally)

California residents have specific rights under the California Consumer Privacy Act (CCPA). Because Ledger's audience is US-wide and California residents are in scope, Ledger extends the same rights to every Ledger user regardless of their state of residence.

You have the right to:

  • Know. See the personal information Ledger holds about you.
  • Access and export. Get a portable copy of your personal information.
  • Delete. Remove your personal information from Ledger's systems, with the purge scope described in §8.
  • Non-discrimination. Exercising any of these rights does not change the price or quality of the service Ledger provides to you.

In-product access to these rights ships on Ledger's roadmap (see Ledger's public changelog for the current status). In the meantime, you can exercise any right by contacting Ledger through /contact and Ledger will fulfill the request within 45 days (extendable once by 45 days if your request is complex — Ledger will tell you if that happens).

Sale of personal information. Ledger does not sell personal information. CCPA's "do not sell" opt-out is satisfied by construction — there is no sale to opt out of.

11. Email communications

Alpha v0.1 — authentication email only. Ledger currently emails you only for authentication purposes: a 6-digit code to verify your email when you sign up, a 6-digit code to log in without a password, and a password-reset code. No newsletters, no election-deadline reminders, no "your senator voted on X" alerts, no upgrade pitches, no marketing.

Ledger's signup and login use in-page 6-digit codes rather than magic-link URLs, so you stay on ledger.vote end-to-end.

Post-Alpha — narrow transactional expansion. When Ledger Premium ships Ledger will add narrowly-scoped transactional email: subscription receipts, account-action confirmations (email change, password change, account deletion), and account-security notifications. These are functional, not editorial, and are not an engagement channel.

Behavioral and editorial email are out of scope at this writing. If Ledger ever adds a digest, an alert, or any form of editorial email, that change is a material update to this policy and triggers the process in §15 — including re-consent.

12. Cookies and local storage

  • First-party authentication cookie. An HTTP-only, Same-Site=Lax cookie on ledger.vote keeps you signed in. This is functionally necessary and is exempt from the consent-banner requirement in most jurisdictions.
  • Theme preference. Your choice of dark or light mode is stored in your browser's localStorage on your device. It never leaves your browser.
  • No third-party cookies. Ledger does not set cookies on behalf of ad networks, analytics vendors, or any other third party.
  • No fingerprinting. Ledger does not use canvas, font, WebGL, or any other browser-fingerprinting techniques.

Because Ledger loads no third-party trackers, there is no cookie-consent banner to click through.

13. First-party analytics

Ledger measures product usage using a server-side events table in Supabase. Each event records a small enum of action types (signup, address_entered, ballot_viewed, quiz_started, quiz_completed, chat_message_sent, etc.) along with an opaque session ID. Event properties are reviewed at the schema level to keep raw addresses, raw quiz answers, and email addresses out.

No external analytics products. No Google Analytics, no Meta Pixel, no Segment, no Mixpanel, no Amplitude, no Hotjar, no FullStory. Any change to this posture is a material update to this policy.

Deletion. Account deletion purges your events alongside your profile, quiz history, chat transcripts, and mock ballot.

14. Children

Ledger is not directed at children under 18 and Ledger does not knowingly collect personal information from users under 18. If you believe a user under 18 has created a Ledger account, contact Ledger through /contact and Ledger will delete the account.

15. International

Ledger is designed for US voters. Ledger's servers, sub-processors, and compliance posture all assume US residency. If you access Ledger from outside the United States, your request is processed transiently to render the page, and Ledger does not onboard non-US users into an account. If you're outside the US and want Ledger to delete any record Ledger may have inadvertently created, contact Ledger through /contact.

16. Breach disclosure

If Ledger suffers a security incident that affects your personal information, Ledger will:

  • Notify you directly at your account email address, typically within 72 hours of confirming the incident.
  • Publish an incident note describing what happened, what data was affected, and what Ledger is doing about it.
  • Comply with state-law disclosure thresholds (CCPA/CPRA and other state privacy laws apply as Ledger's national floor).

17. Changes to this Privacy Policy

Ledger updates this policy as the product grows. When Ledger makes a material change — anything beyond a typo fix, a clarifying sentence, or a stylistic edit — Ledger will:

  1. Email you at your account address at least 7 days before the new version takes effect.
  2. Display an in-product banner while the new version is pending.
  3. Require re-consent on your next login after the effective date.

The legal changelog tracks every version; prior versions are archived at /legal/privacy/v/<version>. Continuing to use Ledger after the effective date means you accept the new version.

18. Contact

Privacy questions, access and deletion requests, and complaints can reach Ledger through /contact. Ledger responds to verified requests within 45 days.

19. Effective date and version

  • Version: v1.0.0
  • Effective date: April 20, 2026
  • Prior versions: none.

The full version history is in the legal changelog.