Privacy Policy

What we collect

When you submit ratings, we store:

What we don’t collect

The 24-hour unlinkability property

The hash used to tag same-device resubmissions is generated with a secret key that rotates roughly daily. Once a key rotates, hashes produced under the old key can no longer be recomputed or matched against a new submission — so a device/day tag becomes unlinkable to future activity from the same device after about 24 hours. This is why we describe stored data as pseudonymous and time-limited, not “anonymous” outright: a hash of an IP address is theoretically brute-forceable within its 24-hour window, so “unlinkable after 24 hours” is the accurate claim, and it’s a strong one.

Where you’re submitting from

Submitting a rating is blocked for connections from the EU, EEA, and UK, because political opinion combined with demographic detail is treated as special-category personal data under EU/UK data protection law, at a level of regulatory obligation this project isn’t built to meet. Reading the site is open to everyone, everywhere — only the act of submitting ratings is geographically restricted.

How your data is used

Individual submissions are never published or shown to anyone as an individual record beyond your own results page. Aggregate figures — the kind shown on the comparison page — are computed from many submissions folded together, broken out by declared party with the sample size shown per group, never as a single unattributed headline number. See the methodology page for exactly how those aggregates are built and filtered.

We may also share or license these same aggregate figures — never anything at the individual-submission level — with outside parties such as researchers, journalists, or other organizations, including on a paid basis. Anything shared this way is drawn from the identical aggregate dataset shown publicly on the comparison page: broken out by declared party, with sample sizes shown, and filtered the same way described on the methodology page. It is never provided in a form that could be traced back to an individual respondent. The support page explains when this would happen and keeps a public record of any sale.

Deletion requests

You can request deletion of your submission at any time. Because your share link (the URL you got after submitting) is the only identifier we can use to find your specific row without asking for anything else about you, a deletion request must include your share link. Without it, there is no way to locate your submission among everyone else’s.

To request deletion, email privacy@whosepolicyisit.com with your share link. Deletion is a manual process on our end — we don’t yet have a self-serve deletion button — but every verified request results in that row being permanently removed from the database.

Changes to this policy

If what’s collected, how long it’s retained, or how it’s used changes, this page is updated to reflect that before the change takes effect — not after.