Plainvote

Privacy Policy

Plainvote LLC. Last updated August 3, 2026.

Plainvote runs elections whose results anyone can independently recount. That design shapes this policy: some election data is public and permanent on purpose, and some data is engineered so that we cannot read it at all. This page says plainly which is which.

Data we hold about election organizers

If you create an account, we store your email address, your organization's name, the elections you set up, and an audit log of the actions you take. Sign-in uses one-time email links; we never store a password. Payments are processed by Stripe, and card numbers never touch our systems; we keep the payment status and amount for your elections. We use a session cookie to keep you signed in. We run no advertising trackers and no third-party analytics.

Data about voters

Organizers upload a voter roll: names and email addresses of their members. We process that roll on the organizer's behalf, to send each voter a link for retrieving their voting code and to show the organizer delivery status. Organizers are responsible for having the right to share their members' contact details with us for this purpose.

Voting codes are engineered so we cannot read them after delivery. We store only a cryptographic hash of each code, and the code itself is held encrypted under a key that exists only inside the voter's personal link, which we do not keep. We record whether and when a retrieval link was opened, so organizers can spot a link that may have reached the wrong hands.

What is public and permanent

Ballots are published to a public, replicated, append-only record under anonymous one-time keys. This is the product: it is what lets anyone recount the result. Entries on that record cannot be edited or deleted, by us or anyone else. Nothing on the record identifies a voter: ballot keys are authorized through a blind-signature protocol, so neither Plainvote nor the organizer can link a ballot to a person. What our systems can see is participation: which codes obtained a voting credential for an election, similar to a poll book. They cannot see which ballot is whose.

Election titles, questions, schedules, and results are also public on that record once an election is published. Do not put personal information in election text.

Service providers

We use a small set of providers to run the service: Railway (hosting), Stripe (payments), Resend (email delivery), and Cloudflare (domain and email routing). Each receives only what its role requires; none receives ballot contents linked to identities, because no such link exists.

Retention and deletion

Account and roll data is kept while your account is active and deleted on request, subject to records we must keep for payments and fraud prevention. Public record entries are permanent by design and are not personal data we can trace to anyone. To make a request, email [email protected].

Security

Voting codes are stored hashed, retrieval links are single-purpose, signing keys are held encrypted, and the engine that records and counts ballots is open source and publicly auditable. We describe what the system protects and what it does not, honestly, in our published security posture. No online system is beyond compromise, and we will notify affected users of any breach involving their data as the law requires.

Other things the law asks us to say

The service is for organizations and is not directed at children. We do not sell personal information. We operate from the United States; by using the service you consent to processing there. If we change this policy we will update the date above, and material changes will be announced to account holders by email.

Contact

Plainvote LLC · [email protected]