Optants

Privacy Policy

Last updated 2 October 2026

The short version

You can vote without an account, and voting alone never publishes how you voted β€” only choosing to write a comment does that. We keep the data needed to count votes honestly, run accounts, and stop abuse β€” nothing more. You can delete your account and your personal data from inside the app at any time.

1. Who we are

Optants is operated by Wrad Labs Inc. (β€œwe”, β€œus”). We are responsible for the personal information described here. This is version 1.6 of this policy.

2. Voting without an account

You do not need an account to vote. So that a vote can be counted once and changed later, we set a first-party cookie called vote_fp containing a random identifier.

This is not device fingerprinting. It is a random value we generate, not a profile assembled from your browser, screen, fonts or hardware. It is set httpOnly, so page scripts cannot read it, and it lasts one year. It tells us nothing about you except that the same browser cast a particular vote.

3. Accounts

If you create an account we collect your email address. There is no display name or username. We do not use passwords at all β€” you sign in with a one-time link sent to your email, or with Google. If you use Google, Google tells us your email address; we never receive your Google password.

When you sign up we record which versions of this policy and our Terms you accepted, and when, as proof of consent.

Creating an account links the votes already cast in that browser to your account, so your record follows you.

4. Your votes and comments

We store each vote you cast, the option you chose, and when. Votes are attached to your account, or to the anonymous identifier above if you have no account.

Voting alone never discloses how you voted. Published results are aggregate counts and percentages, and the underlying vote records are not readable by other users.

There is one exception, and you choose it. If you weigh in on a matchup β€” writing a comment, which is a separate act taken after you have voted and seen the result β€” that comment is published with a marker showing which option you picked, and with no name, profile or account identifier. Every comment on the floor visibly carries this marker, so the practice is in view where it happens. Other visitors see what was argued and for which side, never who argued it, and nothing we publish links one comment to another by the same person. We still know which account wrote each comment, because moderating it and deleting it on request both need that; only our moderators can see it. The marker applies only to the matchup you wrote on, and only while the comment stands and you still hold that vote: if you change your vote, the comment comes off the floor until you edit it or switch back.

How comments are checked. We check every comment when it is written or edited. A comment carrying a phone number, an email address or a web link is refused and not stored. One containing a word on a list we keep is hidden from the floor until a moderator has looked at it. Reports never hide a comment on their own. To slow down abuse we limit how often an account can post, and a new account waits ten minutes before its first comment.

The automated check. Before anyone else sees a comment, we send its text and the title of the matchup it answers to Anthropic, whose AI model reads it against our Terms. Nothing else goes with it: not your account, your email or how you voted. Until the check has passed, only you can see the comment. If the model finds a clear breach, the comment is refused and not stored, and you are told what kind of breach it found; you can post it anyway, and then a moderator looks at it before anyone else can see it. If the model cannot tell, a moderator looks at it first too. If the model cannot be reached, the comment waits, seen only by you, until it can be checked. A comment written before we started this check is sent to it the first time someone reports it. The model never removes a comment; only a moderator does. A refused comment leaves nothing behind β€” we keep no record of it β€” though each refusal counts toward how often you can post.

Anthropic processes comments in the United States, does not use them to train its models, and deletes them within 30 days β€” except that one its own safety systems flag as breaking its usage policy may be kept by Anthropic for up to two years.

Reporting a comment. If you report one, we record your account and a copy of the comment as it read when you reported it, so a moderator sees what you saw. We ask for no reason and keep none. The author is never told who reported them. The copy is deleted 90 days after the report is closed. If you delete your account, the report stays but is no longer linked to you.

When a moderator acts. A moderator can remove a comment; its author then sees that it was removed and under which category, never who removed it, and can write a new one in its place. A moderator can also stop an account posting for 7 days, 30 days or indefinitely. That is recorded on the account, with its reason and when it ends, and it ends if the account is deleted: nothing about it carries over to a new one. We keep a log of every moderation decision β€” what was done, to which comment, by which moderator, and when β€” and the log never contains what the comment said.

Comments we preserve. When a comment is removed as a threat of violence, we keep a separate copy of it: its text, the email address of the account that wrote it, the reports filed about it (without who filed them) and our record of the decision. We do the same for a comment named in a request from the police or a court, or one our lawyers tell us to keep. Only our administrators can see a preserved copy. One made after a threat is kept for 12 months, unless we have a specific reason to keep it longer, which we record; one made for a legal request is kept until that request is resolved. Then it is deleted. A preserved copy is not changed when its author edits the comment or deletes their account β€” it exists so that the person who made a threat cannot erase the evidence of it. Keeping a copy is not handing it over: we disclose it only where the law requires, as section 8 says.

5. Analytics

We use PostHog to understand how the product is used β€” which pages are viewed, which matchups get votes, how far people scroll.

Analytics is off until you allow it. We do not load analytics or store any analytics identifier β€” no cookie, no local-storage entry β€” unless you accept analytics when we ask. Declining, or simply never choosing, leaves analytics off. Voting and the rest of the site work fully either way, and this choice never affects your vote.

To decide how we ask, we use the country our hosting provider (Vercel) works out from your IP address when a page loads: in the European Economic Area, the UK and Switzerland, or if the country can’t be determined, the question includes a one-click β€œNo thanks”. We use the country only for that, and we do not store it.

Your analytics choice is its own setting, separate from anything you agree to when you create an account. If you are signed in, you can turn it on or off at any time from your Account page, under Settings. If you are not signed in, the choice you make on this browser stands until you sign in and change it there, or until you clear this browser’s cookies, which resets it to off β€” the same as before you ever answered.

Searches that find nothing. When a search returns no results, we record the words that were searched for β€” so we know what to add to the site. It is stored on our own systems, never sent to PostHog or anyone else, and it is kept as a daily tally of how many times each phrase came up empty. There is nothing attached to say who searched, and no record of the order searches happened in, so it cannot be traced back to a person or a session. Searches that do find something are not recorded at all, and anything that looks like personal information β€” an email address, a long number, a web address β€” is discarded rather than stored. We keep this for 180 days.

6. Optional information about you

If you have an account you may optionally tell us the year you were born, your gender and your country. Every field is optional, you are never asked for any of it in order to vote, and leaving it blank changes nothing about how the site works for you.

We do not ask for the month or day you were born, and we could not store either if you tried. The year is used for one thing: to work out which age range you are in β€” 18–24, 25–34, and so on. Since we only hold a year, we assume everyone has a birthday in the middle of the year (June 15) to do that arithmetic β€” which means for a few months around your real birthday you may be counted in the range just above or just below the one you are actually in. A breakdown only ever shows the range, never your birth year. We ask this way round because a range you picked yourself would be wrong the moment you had a birthday, and a published number that quietly stops being true is worse than one that is a little imprecise. If you are under 18, there is no range for you to be in, so your votes are not counted into an age breakdown at all.

We use it for one purpose only: to break aggregate results down into groups. We do not build a profile of you, and we never guess any of it β€” nothing here is inferred from your IP address or your device. It is only what you chose.

A breakdown is only ever published once every side within a group has at least 50 votes. Groups below that are withheld entirely, so a published number can never be traced back to one person’s ballot.

This is its own separate consent, recorded separately from the rest of this policy. You can clear this information at any time from your account page; doing so removes the values and drops your votes out of every breakdown, and affects nothing else. We do not collect special-category information here β€” no ethnicity, religion, health, disability, sexual orientation, or precise location.

We used to ask for a province or state as well. We stopped on 21 September 2026 and deleted the field: it was the only one you typed rather than picked, and a place that small is easier to recognize a person by than a country is. No account had ever filled it in, so nothing was ever published from it.

7. Security and anti-abuse

To keep results honest we need to resist automated and repeated voting. We use Cloudflare Turnstile, an invisible bot check on voting and on the contact form, and we rate-limit requests, including how often an account can post a comment. This involves your IP address and basic request metadata. Publishing counts that are not trivially faked is what justifies it.

8. Who processes data for us

We do not sell personal information and we do not share it for advertising. We use these providers to run the service, each handling data only on our instructions:

  • Supabase β€” database and authentication
  • Vercel β€” application hosting
  • PostHog β€” product analytics
  • Cloudflare β€” Turnstile bot protection
  • Upstash β€” rate limiting
  • Sentry β€” error monitoring, so we notice when something breaks
  • Anthropic β€” the AI model that checks a comment before it is published (section 4)
  • Resend β€” sending sign-in and account emails, and delivering messages sent through the contact form
  • Google β€” sign-in, only if you choose to sign in with Google; and Google Workspace, which hosts our email, so it holds any message you send us

These providers operate in various countries, including the United States, so your information may be stored and processed outside the country you live in, and may be subject to the laws of those countries. We may also disclose information where the law requires it, or to protect the rights and safety of our users and the service.

9. How long we keep it

Account data is kept while your account exists. Votes are kept as part of the permanent record of results β€” they are what the product measures. The anonymous voting cookie expires after one year. Any optional information you gave us under section 6 is kept only until you clear it or delete your account, whichever comes first. Consent records and security logs are kept as long as we need them to show that consent was given and to investigate abuse. The tally of searches that found nothing (section 5) is kept for 180 days and then deleted. Messages you send us are kept as section 12 describes. The copy kept with a report is deleted 90 days after the report is closed, and a preserved comment is kept for 12 months, or for as long as a legal request requires (section 4).

Backups. So that a mistake or a failure can be undone, our database provider, Supabase, takes a backup of our database once a day and keeps each one for 7 days. A backup is a copy of everything as it was when it was taken, so something you delete β€” including your account β€” stays in the backups taken before you deleted it until they expire, at most 7 days later. Backups are not used to run the site. If we ever have to restore one, we delete again every account that was deleted after that backup was taken, before the site reopens.

10. Your rights and how to use them

You can ask us to access, correct or delete your personal information, to withdraw consent, or to object to how we use it. You can download your data and delete your account yourself from the Account page. For anything else, email privacy@optants.com.

Depending on where you live you may also have the right to complain to a privacy regulator, such as the Office of the Privacy Commissioner of Canada or your local data protection authority.

11. What deletion actually does

You should know exactly what happens, because β€œdelete” means different things on different services.

Deleting your account removes you from the data: your profile and any comments are scrubbed, any optional information from section 6 is cleared, your email is removed from our authentication records so the address is free to use again, and your authorship of anything you created is severed. This happens in our live database straight away; the copies in our backups expire within 7 days (section 9).

One exception. If a comment you wrote was removed as a threat, or was named in a legal request, the separate copy we preserved (section 4) is not deleted with your account. It keeps the comment’s text and your email address as they were when it was preserved, for 12 months, or for as long as the legal request requires. Everything else about your account is still deleted.

Your votes are not deleted. They stay in the aggregate counts, detached from you β€” a result that changed retroactively every time someone left would not be an honest record. Because the account they were attached to has been scrubbed, nothing in those rows identifies you. We also keep consent records and security logs, which we need to show that consent was given and to investigate abuse.

We do not delete the anonymous voting cookie described in section 2, and we used to. That browser keeps the same vote_fp identifier it had before, which is what stops a deleted-and-recreated account from voting a second time on something it has already voted on. Our results are the whole product, and a delete button that doubled as a way to vote twice was a worse trade than this one. Two consequences you should know about: in that browser the site will still show the choices made before you deleted, and if you share the browser, so will it. Clearing your cookies removes it, and always could β€” the change is that we no longer do it for you.

12. Writing to us

If you write to us β€” through the form on the Contact page or by email β€” we receive your email address, what you wrote, and the topic you chose. We use them only to reply and to deal with what you asked. A message is not linked to your account or your votes, even if you are signed in, and is never used for marketing.

The form does not store your message in Optants. It is delivered to our inbox, which Google Workspace hosts, by Resend, which keeps a copy in its delivery logs for 30 days. We keep correspondence as long as we need it to deal with your message, and delete it within 12 months of our last reply unless the law requires us to keep it longer. Sending the form also involves the bot check and rate limiting in section 7.

13. Children

Optants is not directed at children and is not intended for anyone under 13, or under the minimum age of digital consent where you live if that age is higher. If you believe a child has given us personal information, email us and we will delete it.

14. Changes

If we materially change this policy we will update the date and version above and β€” where the change affects what you agreed to β€” ask you to accept the new version.

Questions? Email privacy@optants.com.