VOSU — Vote or Shut Up
Member Zone
PRIVACY

Your politics are yours. We built the product that way.

This is not a legal shield written to be unreadable. It is a plain inventory of every piece of data VOSU touches, why it exists, and how to get rid of it.

Last updated 29 July 2026
THE SHORT VERSION
01
Browsing needs no account
Searching a ZIP, reading races, and comparing candidate records require no sign-in. With no account, nothing about you is stored in our database — your ZIP and answers stay in your own browser.
02
Nothing is sold or brokered
No data sales, no data sharing for marketing, no advertising networks, and no third-party analytics or tracking pixels anywhere on this site.
03
Your answers are row-locked
The Clear-the-Fog answers of a signed-in user are readable only by that user. The database enforces it row by row, not the app politely asking.
04
Identifiers are stripped before analysis
Before your answers are analyzed, links, emails, phone numbers, ID-like number runs, and street addresses are replaced with placeholders. Only the redacted text is analyzed or logged.
WHAT WE NEVER DO
  • Sell, rent, or broker your data. Not to campaigns, not to parties, not to data brokers, not to advertisers — at any price.
  • Build a political profile of you. Your answers personalize how your own ballot is ordered. They are not used to target, score, or segment you.
  • Run ad or analytics trackers. There is no advertising SDK, no third-party analytics, and no tracking pixel in this application.
  • Nudge your vote. No persuasive copy, no psychological targeting. Any urgency you see in the product refers to a real, verifiable deadline.
  • Store a password. Sign-in is handled by Google, Apple, or a one-time emailed link. We never see or hold a password.
WHAT WE STORE

Everything VOSU holds, in four groups.

1. When you browse without an account

Your ZIP and reflection answers — in your browser only
Kept in this browser’s local storage so the app remembers where you were. Not sent to our database and not attached to any identifier. Clearing site data erases it completely.
Your ZIP — sent out to look up races
When you search, the ZIP goes to our election API and on to the data providers that answer it (BallotReady/CivicEngine for races, the Google Civic Information API for polling places and deadlines). Results are cached at the edge for up to an hour. The ZIP is not stored against a person.
Standard delivery logs
Like every website, our host processes request metadata (IP address, timestamp, page requested) to serve pages and block abuse. We do not join that to an account or use it for profiling.

2. When you create an account

Sign-in identity
Google or Apple sign-in returns your email address and, if the provider supplies it, your name. A magic link stores only the email address you typed. Authentication is handled by Supabase Auth.
Your profile
A display name, the last ZIP you entered, whether you have confirmed your values, and the resulting list of priority categories (for example “Housing & Transport”). Readable and writable by you alone.
Ballots you track
Which races you are tracking and their research status (needs research, researched, undecided). Yours alone.

3. Clear the Fog (the reflection questions)

Your two answers, as you wrote them
Stored on your own row and protected by database row-level security: no other user, and no unauthenticated request, can read them. You can overwrite them any time by re-running Clear the Fog from Settings.
The analysis itself
Runs inside our own infrastructure on a built-in embedding model — there is no third-party AI vendor and no external AI API involved. Before it runs, links, email addresses, phone numbers, ID-like digit runs, and street addresses are stripped from the text and replaced with placeholders.
An append-only audit record
For accountability, every analysis writes one entry: the redacted text, the model identifier, the categories returned, a timestamp, and success or failure. You can read your own entries; no client can edit or delete any entry, by design. This is what makes the neutrality claim auditable rather than promised.

4. Cohorts, War Rooms, and notifications

What fellow members can see
Joining a cohort is a social act. Your display name, the tasks you own, the signature counts you log, your activity entries, photos you post to the wall, and Black Book records you add are visible to that cohort’s members — and to nobody outside it.
Photo wall
Photos live in a private storage bucket. They are served through short-lived signed links that only a member of that cohort can obtain. They are not public and not indexable.
Meeting attendance
A per-cohort count, used only to unlock the Black Book at three meetings attended.
Push notifications (opt-in)
If you enable them, a device token from Firebase Cloud Messaging is stored on your own row so the platform can notify you about deadlines and cohort activity. Revoking notification permission in your browser or OS stops delivery immediately.
WHO ELSE SEES IT

Six processors, each with one job.

VOSU shares data with service providers that operate part of the platform, and with nobody else. Each is listed with the only thing it receives.

Supabase — database, authentication, file storage, analysis
Holds the account and cohort data described above, and runs the Clear-the-Fog analysis.
Cloudflare — hosting and edge delivery
Serves the site and caches election lookups. Processes standard request logs.
BallotReady / CivicEngine — ballot data
Receives the ZIP you search in order to return the races on that ballot.
Google Civic Information API — voting logistics
Receives the ZIP you search in order to return polling places, drop boxes, early-vote sites, and deadlines.
Firebase Cloud Messaging — push delivery
Only if you opt in. Receives the device token and the notification content.
Google or Apple — sign-in
Only if you choose that sign-in method. They confirm your identity to us; they learn that you signed in to VOSU.
One more disclosure, stated plainly
We would disclose data if compelled by valid legal process. We have built the product so there is as little as possible to compel: no browsing profile, no political scoring, no ad-tech exhaust, and reflection text that has already had personal identifiers stripped before it is logged.
COOKIES & LOCAL STORAGE

Four keys, no advertising cookies.

VOSU sets no advertising or cross-site tracking cookies. What it does use:

Session cookie (Supabase Auth)
Set only after you sign in, and refreshed as you navigate so your session does not drop. Signing out clears it. Without it, staying signed in is impossible.
vosu-state
Local storage. Your working state — ZIP, reflection answers, tracked items, screen state — so a refresh does not lose your place. Wiped on sign-out.
vosu-last-user
Local storage. Records which account the local cache belongs to, so switching accounts on a shared device wipes the previous person’s state instead of showing it to you.
vosu-theme
Local storage. Whether you chose the light or dark theme. Nothing else.
YOUR CONTROLS

What you can do right now.

01
Browse without an account
The strongest control is the default: no sign-in means no server-side record of you.
02
Sign out to wipe local state
Signing out clears the session cookie and erases the local cache from the device, including your ZIP and reflection answers.
03
Rewrite or replace your answers
Re-run Clear the Fog from Settings at any time. The new answers overwrite the old ones on your row.
04
Leave a cohort
Leaving removes your membership immediately, which ends your access to that cohort’s War Room and its members’ view of you as a member.
05
Turn off notifications
Revoke notification permission in your browser or OS and delivery stops. Ask us and we will delete the stored device token as well.
06
Get a copy, or get deleted
Email team@voteorshutup.org from your account address to request a copy of your data or full deletion of your account.
RETENTION & DELETION

What is gone, and what honestly is not.

When your account is deleted, everything that is personally yours goes with it: your profile, your reflection answers, your tracked ballots, your cohort memberships, and your stored notification tokens are removed by the database itself.

Two things survive, and you should know about both before you sign up:

Your cohort’s shared record stays with the cohort — without your name
Tasks, logged signature counts, activity entries, photos, and Black Book research contributed to a group remain part of that group’s work, but the link to you is severed: the contribution no longer resolves to any account. A twelve-week sprint cannot be silently rewritten by one member leaving.
Audit entries remain, de-identified
The append-only analysis log keeps its redacted input, model identifier, and output — the record that makes the neutrality claim verifiable — but the account reference is cleared, so the entry no longer points to you.
HOW IT IS PROTECTED

The mechanisms, not the adjectives.

01
Row-level security on every user table
Access is enforced in the database. A request without your session cannot read your rows even if the application layer is wrong.
02
Cohort data gated by membership
Tasks, signature logs, activity, photos, and Black Book records are readable only by members of that cohort, checked server-side on every query.
03
Private files, short-lived links
Uploaded photos live in a private bucket and are reachable only through expiring signed URLs issued to members.
04
Append-only audit log
Update, delete, and truncate privileges on the audit log are revoked for application roles and blocked by database triggers. It can be added to, not edited.
05
Redaction before analysis
Personal identifiers are stripped from reflection text before it is analyzed or logged. Over-redaction is accepted; leakage is not.
06
No password to steal
Authentication is delegated to Google, Apple, or a one-time emailed link. There is no password database here to breach.
CHILDREN, CHANGES & CONTACT

Children

VOSU is built for voters and for people preparing to vote. It is not directed to children under 13, and we do not knowingly collect their information. If you believe a child has created an account, write to us and we will remove it.

Changes to this page

When the product changes what it stores, this page changes in the same release, and the date at the top moves. Material changes to how existing data is used will be announced in the app, not quietly edited in.

Contact

Questions, data requests, and deletion requests go to team@voteorshutup.org. If you are writing about an account, send it from that account’s email address so we can verify the request without asking you for more personal information.

Email team@voteorshutup.orgFind your elections

Related: how the platform is built and the Mission Lock that binds it, including the zero-knowledge privacy and immutable-audit clauses this page implements.