Privacy Policy
What we collect
When you submit ratings, we store:
- Your ratings on the policy items shown to you (support level 1–5), along with how long you spent on each and the order you saw them in.
- The demographic answers you choose to provide: age range, US state, party affiliation, and who you voted for in the 2020 and 2024 presidential elections. Every one of these questions is skippable, and skipping records nothing — not a blank string, not an inferred value, just the absence of an answer.
- A device/day tag: a keyed hash of your IP address and browser identifier, valid for roughly 24 hours before the signing key rotates. We use this only to catch obvious same-device resubmission within a day; we never store your raw IP address.
- Your approximate country, from network-level geolocation, used only to check whether submission is allowed from your location (see “Where you’re submitting from,” below). We do not store city- or address-level location.
- The time your submission arrived and a randomly generated 128-bit share token, distinct from any internal record identifier, used only to show you your own results page and let you share a link to it.
What we don’t collect
- No account, no login, no email address, no name.
- No third-party analytics or advertising trackers on this site. There is no ad network, no social-media pixel, and no cross-site tracking cookie.
- No raw IP address is ever written to storage.
The 24-hour unlinkability property
The hash used to tag same-device resubmissions is generated with a secret key that rotates roughly daily. Once a key rotates, hashes produced under the old key can no longer be recomputed or matched against a new submission — so a device/day tag becomes unlinkable to future activity from the same device after about 24 hours. This is why we describe stored data as pseudonymous and time-limited, not “anonymous” outright: a hash of an IP address is theoretically brute-forceable within its 24-hour window, so “unlinkable after 24 hours” is the accurate claim, and it’s a strong one.
Where you’re submitting from
Submitting a rating is blocked for connections from the EU, EEA, and UK, because political opinion combined with demographic detail is treated as special-category personal data under EU/UK data protection law, at a level of regulatory obligation this project isn’t built to meet. Reading the site is open to everyone, everywhere — only the act of submitting ratings is geographically restricted.
How your data is used
Individual submissions are never published or shown to anyone as an individual record beyond your own results page. Aggregate figures — the kind shown on the comparison page — are computed from many submissions folded together, broken out by declared party with the sample size shown per group, never as a single unattributed headline number. See the methodology page for exactly how those aggregates are built and filtered.
We may also share or license these same aggregate figures — never anything at the individual-submission level — with outside parties such as researchers, journalists, or other organizations, including on a paid basis. Anything shared this way is drawn from the identical aggregate dataset shown publicly on the comparison page: broken out by declared party, with sample sizes shown, and filtered the same way described on the methodology page. It is never provided in a form that could be traced back to an individual respondent. The support page explains when this would happen and keeps a public record of any sale.
Deletion requests
You can request deletion of your submission at any time. Because your share link (the URL you got after submitting) is the only identifier we can use to find your specific row without asking for anything else about you, a deletion request must include your share link. Without it, there is no way to locate your submission among everyone else’s.
To request deletion, email privacy@whosepolicyisit.com with your share link. Deletion is a manual process on our end — we don’t yet have a self-serve deletion button — but every verified request results in that row being permanently removed from the database.
Changes to this policy
If what’s collected, how long it’s retained, or how it’s used changes, this page is updated to reflect that before the change takes effect — not after.