Privacy Policy
wevote.tech
Effective date: Not yet effective
Last updated: August 14, 2026 (counsel-review draft)
Operator: WeVote Foundation ("WeVote," "we," "us," or "our")
Contact: support@wevoteproject.org
This Policy explains how WeVote handles information in WeVote Base (the "Service"). It applies to account holders, workspace members, and visitors. Official voter records concern people who generally are not Service users and are addressed separately below.
1. Information We Handle
Account and workspace information
- name, email address, hashed password, Google sign-in identifiers if used, and optional phone-verification status;
- organization, campaign, office, state, district, account role, team membership, profile, and social-link information;
- data-access requests, approval decisions, source/provenance information, attestations, and the authorized state or district scope;
- lists, tags, notes, contact updates, canvassing activity, imports, exports, maps, filters, support requests, and other workspace content;
- subscription and payment status from Stripe. We do not receive full payment-card numbers;
- session, device, IP address, browser, request, security, error, and usage information needed to operate and protect the Service; and
- AI questions, recent conversation context, responses, generated SQL, usage totals, and campaign-profile context when AI Insights is used.
Voter and public-record information
The Service maintains a shared master voter-data system assembled from official voter files and permitted public or licensed sources. It may include identity, registration status, party, address, geography, districts, voting history, contactability, donor/public campaign-finance information, geocoding, and derived fields. State files may contain pre-registered voters under 18.
Users do not receive an unrestricted copy of the shared master. An authenticated user's current, administrator-approved data grant determines the records visible to that user. Workspace-created lists, tags, notes, and corrections are stored as workspace-specific overlays and do not change the underlying official record.
2. Sources
We receive information from users and workspace administrators; state and local election officials; public campaign-finance records, including FEC and Nevada records; Census and other public geographic sources; Google sign-in; Stripe; and service-generated activity. A user may also upload data only when authorized to do so and subject to review.
3. How We Use Information
- to authenticate users, review and administer data-access grants, and enforce each user's approved dataset scope;
- to provide search, filtering, maps, lists, exports, contact management, analytics, support, and billing;
- to operate AI Insights and execute read-only analysis inside the user's current authorized scope;
- to maintain data quality, geocode addresses, match permitted public records, and produce derived analytics;
- to detect abuse, investigate incidents, debug failures, enforce agreements, and comply with law; and
- to communicate about the Service and, where permitted, optional product updates.
We do not sell account or workspace information for behavioral advertising, and we do not use voter records for targeted advertising. Access to voter information is not permission to use it for any purpose prohibited by the source agreement or applicable law.
4. Dataset Access and Separation
Production currently uses a shared voter-data master with authorization enforced by application policy and database controls—not a physically separate voter database for every customer. Every user-facing query must begin with the authenticated user and narrow the shared master to the user's current persistent data grant. Filter choices, maps, saved lists, list replay, exports, and AI analysis must use that same boundary.
Administrators may approve, change, suspend, or revoke a grant. A grant change takes effect on the next authorization check. Workspace members may see data available to the workspace subject to their role. Users are responsible for inviting only authorized team members.
5. AI Insights
When a user invokes AI Insights, WeVote sends Anthropic the user's question, up to ten recent conversation messages, relevant account and campaign-profile context, and instructions describing the available fields. Anthropic returns text or proposed SQL. SQL executes on WeVote-controlled infrastructure through a restricted, read-only database role against only the user's current authorized dataset. Raw voter tables are not directly accessible to that role. Query results are formatted by WeVote and are not sent back to Anthropic in the current workflow.
AI outputs may be incomplete or wrong and may reflect information in the prompt. Users should not enter unnecessary sensitive information. AI conversations and usage records are currently stored with the user's account; the retention schedule described in Section 9 applies.
6. When We Disclose Information
- Workspace members: according to workspace membership and role.
- Service providers: Fly.io for the application, Anthropic for AI requests, Stripe for payments, Google for optional sign-in, and Twilio for verification features when used. Address information may be sent to the U.S. Census geocoder for geocoding. The primary database is operated on WeVote-controlled U.S. infrastructure connected through Tailscale.
- Support and administration: authorized WeVote administrators may access or impersonate an account when reasonably necessary for support, security, access administration, or investigation. The API impersonation workflow records the administrator and uses a one-hour, revocable credential; the legacy web-session workflow records the administrator in the active session but does not currently create the same durable impersonation record.
- Legal and safety: when reasonably necessary to comply with valid legal process, protect rights or safety, investigate fraud or abuse, or enforce our agreements.
- Organizational change: as part of a merger, financing, reorganization, or asset transfer, subject to appropriate confidentiality and legal requirements.
We do not claim that a separate subprocessor page or executed DPA exists unless one is expressly provided and signed.
7. Security
Controls include encrypted network transport; authenticated sessions; role and data-grant checks; restricted database connectivity; scoped, read-only AI database access; query time and row limits; administrative access controls; and security/usage logging. No system is perfectly secure. Users must protect credentials, remove departed team members, use exports carefully, and promptly report suspected unauthorized access.
8. Cookies and Local Storage
We use session cookies, CSRF protections, authentication storage, and similar technologies needed for sign-in, security, preferences, and core functionality. We do not currently operate a third-party behavioral-advertising cookie program. Third-party sign-in and payment pages may apply their own policies.
9. Retention and Deletion
Current production does not implement the previously stated automatic 30-day account deletion, 13-month AI deletion, or seven-year audit-log schedule. Until a counsel-approved retention schedule and automated deletion controls are deployed, account, workspace, AI conversation, access-review, security, and usage records may remain in active systems and backups after they are no longer in regular use, unless deleted through a verified request or required to be retained by law, security, billing, dispute, or source-record obligations.
We minimize retention when operationally practical and will document any deletion or legal hold. Deleting a workspace overlay does not delete or amend an official voter record in the shared master. Contact support@wevoteproject.org for a verified account-data or workspace-data request.
10. Choices and Requests
Depending on applicable law, an account holder may request access, correction, export, or deletion of account and workspace information. We may verify identity, authority, workspace ownership, and legal obligations before acting.
If you are a voter seeking to correct or suppress an official registration record, contact the election official that maintains that record. You may also contact us to report a possible display or suppression issue. We will investigate the Service record, but cannot alter the official voter file on the election official's behalf.
11. Children and United States Processing
Accounts are intended for users age 18 or older. Official voter files may lawfully include pre-registrants under 18; those records are handled under the source rules and are not used to market the Service to children. The Service and its primary infrastructure operate in the United States.
12. Changes and Contact
We will post revisions here and update the date above. Material changes to an effective policy will be communicated as required by law and, where appropriate, require renewed acceptance. Questions and privacy requests may be sent to support@wevoteproject.org.
Publication blockers: counsel approval; confirmation of the contracting entity, notice address, vendor terms, retention schedule, state acquisition documents, and whether provisioned voter-data access is permitted under each source agreement. This draft must not be represented as a legal opinion or final compliance certification.