Privacy Policy

Last updated 19 July 2026

The short version

You can vote without an account, and we never publish who voted for what. We keep the data needed to count votes honestly, run accounts, and stop abuse — nothing more. You can delete your account and your personal data from inside the app at any time.

1. Who we are

Optants is operated by Wrad Labs Inc. (“we”, “us”). We are responsible for the personal information described here. This is version 1.0 of this policy.

2. Voting without an account

You do not need an account to vote. So that a vote can be counted once and changed later, we set a first-party cookie called vote_fp containing a random identifier.

This is not device fingerprinting. It is a random value we generate, not a profile assembled from your browser, screen, fonts or hardware. It is set httpOnly, so page scripts cannot read it, and it lasts one year. It tells us nothing about you except that the same browser cast a particular vote.

3. Accounts

If you create an account we collect your email address and a display name. We do not use passwords at all — you sign in with a one-time link sent to your email, or with Google. If you use Google, Google tells us your email address; we never receive your Google password.

When you sign up we record which versions of this policy and our Terms you accepted, and when, as proof of consent.

Creating an account links the votes already cast in that browser to your account, so your record follows you.

4. Your votes

We store each vote you cast, the option you chose, and when. Votes are attached to your account, or to the anonymous identifier above if you have no account.

We never publicly attribute a vote to a person. Published results are always aggregate counts and percentages, and the underlying vote records are not readable by other users.

5. Analytics

We use PostHog to understand how the product is used — which pages are viewed, which debates get votes, how far people scroll. It stores identifiers in your browser (local storage and a cookie) to recognise return visits.

These analytics identifiers are set when you visit the site; we do not currently show a cookie banner. You can block or clear them using your browser’s cookie and site-data controls or a content blocker, and the product will still work. We are reviewing whether to move analytics behind an explicit opt-in, and will update this policy if we do.

6. Security and anti-abuse

To keep results honest we need to resist automated and repeated voting. We use Cloudflare Turnstile, an invisible bot check on the vote path, and we rate-limit requests. This involves your IP address and basic request metadata. Publishing counts that are not trivially faked is what justifies it.

7. Who processes data for us

We do not sell personal information and we do not share it for advertising. We use these providers to run the service, each handling data only on our instructions:

  • Supabase — database and authentication
  • Vercel — application hosting
  • PostHog — product analytics
  • Cloudflare — Turnstile bot protection
  • Upstash — rate limiting
  • Resend — sending sign-in and account emails
  • Google — only if you choose to sign in with Google

These providers operate in various countries, including the United States, so your information may be stored and processed outside the country you live in, and may be subject to the laws of those countries. We may also disclose information where the law requires it, or to protect the rights and safety of our users and the service.

8. How long we keep it

Account data is kept while your account exists. Votes are kept as part of the permanent record of results — they are what the product measures. The anonymous voting cookie expires after one year. Consent records and security logs are kept as long as we need them to show that consent was given and to investigate abuse.

9. Your rights and how to use them

You can ask us to access, correct or delete your personal information, to withdraw consent, or to object to how we use it. You can edit your display name and delete your account yourself from the Account page. For anything else, email privacy@optants.com.

Depending on where you live you may also have the right to complain to a privacy regulator, such as the Office of the Privacy Commissioner of Canada or your local data protection authority.

10. What deletion actually does

You should know exactly what happens, because “delete” means different things on different services.

Deleting your account removes you from the data: your profile and any comments are scrubbed, your email is removed from our authentication records so the address is free to use again, and your authorship of anything you created is severed.

Your votes are not deleted. They stay in the aggregate counts, detached from you — a result that changed retroactively every time someone left would not be an honest record. We also delete the anonymous voting cookie described in section 2, so the browser you deleted from stops carrying the identifier those votes were cast under and starts fresh. Between that and the scrubbing above, the retained votes are no longer linked to an identifiable person. We also keep consent records and security logs, which we need to show that consent was given and to investigate abuse.

11. Children

Optants is not directed at children and is not intended for anyone under 13, or under the minimum age of digital consent where you live if that age is higher. If you believe a child has given us personal information, email us and we will delete it.

12. Changes

If we materially change this policy we will update the date and version above and — where the change affects what you agreed to — ask you to accept the new version.

Questions? Email privacy@optants.com.