Privacy Policy
Quick summary
- What Ledger collects: your email and password, the address you enter to look up your ballot, the answers and result from the values quiz, and the AI chat transcripts you create with Ledger. That's it.
- What Ledger never collects: voter-file data, government IDs, biometric data, location, health data, financial data beyond subscription billing (post-Alpha), and anything from third-party trackers (Ledger doesn't load any).
- Who processes your data: a small set of US-based vendors Ledger uses to run the service — listed below.
- How long Ledger keeps it: for as long as your account exists. When you delete your account, Ledger actually deletes.
- Your rights: you can see, export, and delete your data. Ledger honors California's CCPA rights for every Ledger user regardless of state.
- No behavioral email, no tracking pixels, no data sold.
1. About Ledger and what this covers
This Privacy Policy explains how Ledger, Inc. (placeholder — entity formation pending) handles personal information for the Ledger service at ledger.vote. It applies to everyone who uses Ledger — whether you're a signed-out visitor looking up a public ballot preview or a signed-in user with a saved profile.
Ledger is designed for US-based voters. Ledger treats the California Consumer Privacy Act (CCPA) as its national floor — the rights described below apply to every Ledger user, not just California residents.
2. What Ledger collects
| Data | When Ledger collects it | Where it's stored | Why |
|---|---|---|---|
| Email address | When you sign up | Supabase Auth (US) | Account identity; sending you OTP codes |
| Password (hashed) | When you sign up with a password | Supabase Auth (US) | Log you back in |
| Full name (optional) | When you sign up, or from onboarding | profiles in Supabase (US) | Personalize greetings and shareable artifacts |
| Address | When you enter it to look up your ballot | Signed in: persisted in your profile so you don't have to re-enter it. Signed out: processed transiently for the current lookup, never persisted. | Resolve your federal district so Ledger can show your ballot |
| Date of birth (optional) | When you provide it in onboarding | profiles in Supabase (US) | Confirm 18+ eligibility, compute election-day age for primaries |
| Geocoded coordinates | Derived from your address via Mapbox | Not stored — used transiently to match your district | Ballot lookup |
| Jurisdiction lookup cache | Derived from your address (non-reversible hash) + US Census lookup | jurisdiction_resolution_cache in Supabase (US), server-only access | Speed up repeat lookups without re-storing addresses |
| Values-quiz answers and result | When you take the quiz | Your profiles row, scoped to you via row-level security | Personalize your ballot view, power the shareable quiz card you opt into |
| Quiz history | When you retake the quiz | Append-only history table in Supabase, scoped to you | Show you how your profile has changed; contribute to future aggregated-only civic insights |
| AI chat transcripts | When you send messages in Ledger chat | Server-side log in Supabase, scoped to you | Liability, safety, abuse detection (see §6 below — this is the single most important disclosure in this policy) |
| Mock-ballot selections | When you choose candidates on your ballot | Supabase, scoped to you via row-level security | Your own planning tool; power the mock-ballot public share (post-Alpha) |
| Shareable-card payloads | When you generate a share link | Stored payload + public URL | Render the public share page you asked for |
| Rate-limit counters | Derived from your user ID or IP | Upstash Redis (US), short TTL | Prevent abuse and keep the service fair |
| Authentication cookies | On login | First-party HTTP-only cookie on ledger.vote | Keep you signed in |
| Stripe customer ID + subscription status (post-Alpha) | When you subscribe to Ledger Premium | Supabase, linked to your user | Resolve your Premium entitlement |
| Persistent AI companion memory (Phase 4, opt-in) | When you enable persistent memory and chat | Supabase, scoped to you | Let the AI remember prior conversations across sessions |
3. What Ledger never collects and never does
- Ledger does not collect voter-file data. Ledger is a decision-support tool, not a voter-targeting tool. Ledger doesn't buy, ingest, or cross-reference commercial voter files.
- Ledger does not collect government IDs, biometric data, health data, or location beyond the address you enter.
- Ledger does not load third-party tracking pixels from advocacy organizations, campaigns, ad networks, or analytics vendors. No Google Analytics, no Meta Pixel, no Segment, no Mixpanel, no Hotjar, no FullStory.
- Ledger does not send your personal information to the AI. Chat prompts sent to Ledger's AI provider contain only curated public context (candidate records, ballot-measure text) and, if necessary, minimal non-identifying preference summaries — never your email, address, name, IP, or raw quiz answers.
- Ledger does not share individual-level user data with third parties. Not for analytics, not for research, not for B2B products.
- Ledger does not sell personal information. Not now, not at a later date without first updating this policy and asking you to re-consent.
4. How Ledger uses your data
Ledger uses your data operationally — to run the service for you. Specifically:
- Show you your ballot. Ledger uses your address and state to resolve your federal contests.
- Personalize your experience. Your quiz results inform which candidates surface first, and in what framing.
- Answer your questions. The AI chat feature uses your questions to retrieve relevant public context and synthesize an answer with citations.
- Keep the service running. Rate-limit counters, authentication cookies, and error logs exist so Ledger stays available and fair.
- Send you authentication email. See §10.
What Ledger does not use your data for:
- No behavioral advertising. Ledger doesn't target ads to you based on your behavior on Ledger.
- No model training. Ledger doesn't use your quiz answers, chat messages, or mock-ballot picks to train AI models. Ledger's AI provider (Anthropic) operates under a no-training API posture for Ledger's API traffic.
- No data sales. See §3.
5. Sub-processors
Ledger relies on a small set of US-based service providers ("sub-processors") to run the product. Each vendor is contractually required to process your data only on Ledger's instructions and for the purposes below.
| Sub-processor | Country | Purpose | Privacy policy |
|---|---|---|---|
| Supabase | US | Database, authentication, storage | supabase.com/privacy |
| Vercel | US | Application hosting, server-side rendering | vercel.com/legal/privacy-policy |
| Anthropic | US | AI inference for chat and explain features (no-training posture) | anthropic.com/legal/privacy |
| Mapbox | US | Address autocomplete, geocoding | mapbox.com/legal/privacy |
| Federal Election Commission (FEC) | US government | Federal candidate records and finance data (public data source; data flows from FEC to Ledger only, never the reverse) | fec.gov/about/privacy-and-security-policy |
| US Census Bureau | US government | Federal district boundary lookup | census.gov/privacy |
| Upstash | US | Rate-limit counters, short-lived cache | upstash.com/trust/privacy.pdf |
| Stripe (post-Alpha) | US | Subscription billing for Ledger Premium | stripe.com/privacy |
| Transactional email provider (TBD — Resend, Postmark, or AWS SES) | US | Delivery of OTP and account-security email | Provider-specific, linked here once selected |
Ledger updates this list when it adds or removes a vendor. Material changes trigger the process in §15.
6. AI processing and chat logging
This is the single most important disclosure in this policy. Please read it.
When you chat with Ledger's AI, the full transcript of every conversation — your messages, the AI's responses, timestamps, and a session identifier — is logged on Ledger's servers. The in-browser chat window is ephemeral (it clears when you close the tab), but the backend copy is not ephemeral — it persists for the lifetime of your account.
Ledger logs chat content for three reasons:
- Liability. If someone claims Ledger's AI produced harmful, defamatory, or partisan content, Ledger needs the actual transcript to investigate and respond.
- Safety. Detecting jailbreak attempts, abuse, harassment, and coordinated misuse requires content — not just metadata.
- Accountability. Ledger commits to grounding every substantive AI answer in cited sources. When a user reports a drift or a missing citation, the only way to diagnose the issue is to look at what the AI actually said.
Scope and protections:
- Chat content is not accessible to the general staff. It's reachable only by a server-role operation, for audit or abuse investigation, and those accesses are themselves logged.
- Chat content is not included in any B2B aggregate, never shared with third parties beyond the AI provider for inference, and never used to train models (ours or anyone else's).
- Account deletion purges your chat history. One exception: a specific legal hold (e.g., a subpoena) may require Ledger to preserve content past deletion. Ledger handles those cases individually and as narrowly as possible.
- Ledger never sends your PII to the AI. The prompt templates are reviewed to keep identifying data out of model inputs.
Subpoena and legal-process exposure. Because chat content is retained, it is discoverable by legal process. Ledger will tell you if Ledger receives a legal request for your content, unless legally prohibited from doing so.
AI output can be wrong. The Terms of Service §5 has the full disclaimer — please read it.
7. Shareable artifacts
Ledger lets you generate a public share URL for things like your values-quiz card today, and a mock-ballot card (post-Alpha).
- The public payload contains only what's needed to render the card — a label, the quiz axis scores, a timestamp, and (for mock-ballot shares) your candidate selections. It does not contain your email, your address, or an account identifier.
- You can revoke the share link at any time from your account. Revocation immediately invalidates the public URL and removes the stored payload.
- Ledger doesn't track who views your share page. Ledger may keep an aggregate view count for the product dashboard, but not viewer identity.
- Share URLs are opaque — knowing one share link tells you nothing about the existence of any other user's share link.
8. How long Ledger keeps your data
| Data | Retention |
|---|---|
| Account (email, profile, name) | While the account exists |
| Address | While the account exists; editable and deletable any time |
| Current quiz result | While the account exists, or until you retake |
| Quiz history | While the account exists (individual-level data is never exposed to third parties — contributes only to future aggregated insights) |
| AI chat transcripts | While the account exists (see §6) |
| Mock ballot | While the account exists, or until you clear it |
| Shareable-card payload | While the share link is live (you can revoke at any time) |
| Mock-ballot public share (post-Alpha) | While the share link is live |
| Rate-limit counters | Minutes (Upstash TTL) |
| Stripe customer ID + subscription status (post-Alpha) | While the account exists; purged on account deletion, subject to Stripe's own tax/audit retention |
| Persistent AI companion memory (Phase 4) | While memory is enabled and the account exists; disabling memory or deleting the account purges it |
Default posture: Ledger keeps user data indefinitely for the lifetime of your account. The counterweight is that account deletion is real. When you delete your account from your profile, Ledger purges your profile, address, quiz results and history, mock ballot, chat transcripts, share links, companion memory (if Phase 4 has shipped), and your Stripe linkage (if Premium has shipped).
Certain records may be retained briefly post-deletion for legal, accounting, or fraud-prevention reasons, or preserved under a specific legal hold. Ledger discloses the scope of any such retention in §15 updates.
9. Security
- Row-level security is mandatory. Every Supabase table that stores user data has row-level security policies — users can read and write only their own rows.
- Server-only secrets stay server-only. Keys that can bypass row-level security (like Ledger's Supabase service role key, Anthropic API key, or Stripe secret key) never ship to the browser. Ledger audits client bundles for this.
- Rate limits protect you too. Per-user quotas on AI chat and explain features (documented in Ledger's engineering documentation) prevent a single compromised account from running up costs or abuse.
- Encryption in transit. Every request to
ledger.voteand every connection to Supabase, Anthropic, Mapbox, Upstash, and Stripe is TLS-encrypted.
No system is unbreakable — if Ledger suffers a security incident that affects your personal information, Ledger will disclose it to you per §16.
10. Your rights (CCPA, applied nationally)
California residents have specific rights under the California Consumer Privacy Act (CCPA). Because Ledger's audience is US-wide and California residents are in scope, Ledger extends the same rights to every Ledger user regardless of their state of residence.
You have the right to:
- Know. See the personal information Ledger holds about you.
- Access and export. Get a portable copy of your personal information.
- Delete. Remove your personal information from Ledger's systems, with the purge scope described in §8.
- Non-discrimination. Exercising any of these rights does not change the price or quality of the service Ledger provides to you.
In-product access to these rights ships on Ledger's roadmap (see Ledger's public changelog for the current status). In the meantime, you can exercise any right by contacting Ledger through /contact and Ledger will fulfill the request within 45 days (extendable once by 45 days if your request is complex — Ledger will tell you if that happens).
Sale of personal information. Ledger does not sell personal information. CCPA's "do not sell" opt-out is satisfied by construction — there is no sale to opt out of.
11. Email communications
Alpha v0.1 — authentication email only. Ledger currently emails you only for authentication purposes: a 6-digit code to verify your email when you sign up, a 6-digit code to log in without a password, and a password-reset code. No newsletters, no election-deadline reminders, no "your senator voted on X" alerts, no upgrade pitches, no marketing.
Ledger's signup and login use in-page 6-digit codes rather than magic-link URLs, so you stay on ledger.vote end-to-end.
Post-Alpha — narrow transactional expansion. When Ledger Premium ships Ledger will add narrowly-scoped transactional email: subscription receipts, account-action confirmations (email change, password change, account deletion), and account-security notifications. These are functional, not editorial, and are not an engagement channel.
Behavioral and editorial email are out of scope at this writing. If Ledger ever adds a digest, an alert, or any form of editorial email, that change is a material update to this policy and triggers the process in §15 — including re-consent.
12. Cookies and local storage
- First-party authentication cookie. An HTTP-only, Same-Site=Lax cookie on
ledger.votekeeps you signed in. This is functionally necessary and is exempt from the consent-banner requirement in most jurisdictions. - Theme preference. Your choice of dark or light mode is stored in your browser's
localStorageon your device. It never leaves your browser. - No third-party cookies. Ledger does not set cookies on behalf of ad networks, analytics vendors, or any other third party.
- No fingerprinting. Ledger does not use canvas, font, WebGL, or any other browser-fingerprinting techniques.
Because Ledger loads no third-party trackers, there is no cookie-consent banner to click through.
13. First-party analytics
Ledger measures product usage using a server-side events table in Supabase. Each event records a small enum of action types (signup, address_entered, ballot_viewed, quiz_started, quiz_completed, chat_message_sent, etc.) along with an opaque session ID. Event properties are reviewed at the schema level to keep raw addresses, raw quiz answers, and email addresses out.
No external analytics products. No Google Analytics, no Meta Pixel, no Segment, no Mixpanel, no Amplitude, no Hotjar, no FullStory. Any change to this posture is a material update to this policy.
Deletion. Account deletion purges your events alongside your profile, quiz history, chat transcripts, and mock ballot.
14. Children
Ledger is not directed at children under 18 and Ledger does not knowingly collect personal information from users under 18. If you believe a user under 18 has created a Ledger account, contact Ledger through /contact and Ledger will delete the account.
15. International
Ledger is designed for US voters. Ledger's servers, sub-processors, and compliance posture all assume US residency. If you access Ledger from outside the United States, your request is processed transiently to render the page, and Ledger does not onboard non-US users into an account. If you're outside the US and want Ledger to delete any record Ledger may have inadvertently created, contact Ledger through /contact.
16. Breach disclosure
If Ledger suffers a security incident that affects your personal information, Ledger will:
- Notify you directly at your account email address, typically within 72 hours of confirming the incident.
- Publish an incident note describing what happened, what data was affected, and what Ledger is doing about it.
- Comply with state-law disclosure thresholds (CCPA/CPRA and other state privacy laws apply as Ledger's national floor).
17. Changes to this Privacy Policy
Ledger updates this policy as the product grows. When Ledger makes a material change — anything beyond a typo fix, a clarifying sentence, or a stylistic edit — Ledger will:
- Email you at your account address at least 7 days before the new version takes effect.
- Display an in-product banner while the new version is pending.
- Require re-consent on your next login after the effective date.
The legal changelog tracks every version; prior versions are archived at /legal/privacy/v/<version>. Continuing to use Ledger after the effective date means you accept the new version.
18. Contact
Privacy questions, access and deletion requests, and complaints can reach Ledger through /contact. Ledger responds to verified requests within 45 days.
19. Effective date and version
- Version: v1.0.0
- Effective date: April 20, 2026
- Prior versions: none.
The full version history is in the legal changelog.