Security and privacy, in plain English.

We're built for live audiences — so we collect only what a vote needs and hand it right back to you. We're early-stage: this page says plainly what's in place and what isn't.

The privacy ledger.

Plain-language claim on the left, the mechanism that makes it true on the right. If a mechanism changes, the claim changes with it.

Voters never make an account.
no signup to vote · no audience emails collected · no voter profiles
We never store a raw voter IP.
one-way salted SHA-256 hash, used only for duplicate-vote protection
Anti-fraud without surveillance.
per-poll dedup strictness: one vote per device hash, per account, or open
Encrypted in transit and at rest.
TLS on all traffic · managed Postgres with at-rest encryption
Payment details never touch our servers.
checkout and card storage happen entirely on Stripe
Your results are yours — to take or destroy.
CSV export per poll · delete removes the rows, it doesn't flag them
Nothing tracks your audience before consent.
essential cookies only until the banner is accepted · analytics off by default

Compliance posture.

Where we are today, and where we're going. No hand-waving.

SOC 2not started — we're too early
GDPR certificationnone; we minimize collection by design
DPA / BAAnot offered yet
SSO (SAML)not available — Google/GitHub sign-in only
Data residency optionsnone — single region
Uptime SLAnone published
Penetration testingnot yet commissioned
Voter anonymityactive — no voter accounts, salted-hash IPs

Sub-processors.

The vendors we use to run QR Polls. Updated when things change.

VendorPurposeRegion
VercelApplication hosting & edge networkGlobal
Managed PostgresPrimary databaseSingle region (US)
SupabaseCreator authenticationUS
StripePayment processingUS/EU per payment method
PostHogProduct analyticsUS cloud

Questions about how we handle data?

We don't have DPAs, BAAs, or pen-test reports to send yet — but we'll answer any question about what we store and why, straight from the people who built it.