Skip to content
Ballot Clarity
Lookup
Current policy Lookup handling disclosed No targeted advertising

Privacy Policy

This policy describes how Ballot Clarity, currently operated by Jacob Anderson, handles address lookup input, any optional approximate location-guessing configured for the site, browser-stored guide preferences, hosted contact or correction submissions, operational metadata, and direct contact messages. It applies to the public site at https://ballotclarity.org, not to any future product that collects more data than the current public site collects.

Effective Jul 29, 2026, 12:00 AM

Plain-language summary

Ballot Clarity uses address or ZIP input, plus any optional approximate location guess configured for the site, only to match ballot coverage and official verification context. It does not create public user accounts, does not run targeted advertising, and is not designed to sell or share personal data. The app does save selected location labels and ballot-plan preferences locally in your browser so the guide remains usable across refreshes.

What data we handle

What data Ballot Clarity currently handles

Address or ZIP lookup input

When you use the ballot lookup, the address or ZIP code is sent with a POST request so the service can determine a location and ballot guide.

That lookup may also trigger district matching, representative attachment, and official election verification using the civic data providers needed for the requested result.

If ZIP-only operational logging is enabled, Ballot Clarity may record only an exact 5-digit ZIP entered by itself as the lookup input. Full street addresses, ZIP+4 entries, city names, mixed address strings, provider-normalized ZIPs, raw lookup text, IP address, and user agent are not added to that ZIP-only log.

The site may also use coarse geolocation derived from request metadata to make an approximate default location guess before you enter anything manually.

The application is designed not to publish the raw lookup text in public content records. Exact street addresses and address-specific ballot previews or polling logistics are removed from durable browser storage; an exact 5-digit ZIP may be retained for ZIP-based navigation.

Browser storage and cookies

The app stores public area labels and results, compare selections, saved ballot-plan choices, issue filters, and reading mode in local browser storage so the guide remains usable across refreshes. It strips exact street-address input, address-specific ballot previews, and address-specific polling logistics before writing that state.

The site also sets first-party cookies for saved area results, display timezone, and private editorial access sessions. The saved-area result cookie is authenticated ciphertext, is unavailable to browser scripts, and omits exact street-address input.

This browser-side state is tied to the browser on your device. Ballot Clarity does not maintain a public server-side user account for that state.

Operational metadata

Hosting and runtime infrastructure may process technical data such as IP address, user agent, endpoint path, timestamp, and basic error or request metadata needed for security, integrity, and reliability.

On deployed versions of the site, the first-party analytics script loaded from analytics.ballotclarity.org may receive page usage and technical request metadata needed to understand adoption, performance, and reliability.

That operational metadata is different from the election-guide content itself and is handled as infrastructure telemetry rather than published civic data.

Private editorial authentication also creates limited operational records such as last-login timestamps and failed-login throttling signals.

Messages you send us

The public site now offers a hosted contact and correction form in addition to protected email links.

If you submit the form, the project receives your name, email address, subject, page URL, message, and any supporting links you provide so the issue can be reviewed and answered.

If you email the project directly, the message, attachments, and any source links you send may be handled in the project inbox so the team can review, verify, and respond.

Editorial access accounts

The site includes private editorial and operations accounts used to review corrections, source health, and local-guide publication status.

Those access accounts are not public user accounts, but they do use authentication cookies and server-side account records for access control and auditability.

Current third-party recipients

Current third-party processors and civic-data recipients

Lookup and official verification providers

Full-address lookups may be sent to the U.S. Census Geocoder and Google Civic Information API to normalize geography, verify address handling, and return official election logistics where available.

ZIP-only lookups may be resolved through the current ZIP-location service and then enriched with district and official-tool context.

If optional ballot-content providers such as CTCL BIP, Ballotpedia, BallotReady CivicEngine, or Democracy Works are configured later, full-address or location-derived area details may be sent to the configured provider only to return ballot, contest, candidate, measure, or election-logistics data for the requested lookup.

Provider-returned ballot previews are shown as informational previews until Ballot Clarity completes local review. Users should verify the exact ballot with the linked official state or local voter/ballot tool before relying on provider ballot content.

Representative and district matching providers

District and representative attachment may use Open States together with Ballot Clarity's reviewed local-officeholder records.

These requests support district matching, officeholder identity, chamber or jurisdiction context, and representative pages.

Federal office, finance, and disclosure providers

Representative profile enrichment may query Congress.gov, OpenFEC, and LDA.gov once a page or lookup has already resolved a person or officeholder record.

Those requests are used for federal office context, campaign-finance detail, and lobbying or disclosure context. They are not used for advertising or profiling.

Infrastructure and external destinations

Ballot Clarity also relies on hosting, delivery, logging, database providers, and the analytics service hosted at analytics.ballotclarity.org to serve the site, understand usage, process correction submissions, and operate the private editorial workspace.

When you follow external links, the destination site operates under its own privacy practices.

How we use data

Why the site uses data

  • Provide location-based ballot guides and related civic-information pages.
  • Preserve local usability features such as saved ballot-plan choices, compare state, and reading preferences.
  • Operate, secure, debug, and improve the website and its reliability.
  • Review and respond to correction requests, privacy questions, public-interest inquiries, and publication workflow.

How we share or disclose data

Service providers, external links, and current limits

  • Ballot Clarity discloses lookup or page-derived data only to the service providers and public-interest civic-data systems needed to produce the requested page or official verification result.
  • Third-party recipients in active flows include the U.S. Census Geocoder, Google Civic Information API, Open States, Congress.gov, OpenFEC, LDA.gov, and the analytics service hosted at analytics.ballotclarity.org, plus hosting, logging, and delivery providers needed to run the service. Optional ballot-content providers are disclosed on the data-sources page and are active recipients only when configured.
  • Ballot Clarity does not disclose address lookup input to advertising networks and is not designed to sell or share personal data for cross-context behavioral advertising.
  • When you follow external source links, official agencies, filing systems, campaigns, or other third-party sites operate under their own privacy practices.
  • If Ballot Clarity materially changes the current provider stack or starts sharing data for a new purpose, this policy will be updated before that change goes live.

Cookies and tracking

No sale, sharing, or targeted advertising

  • Ballot Clarity does not use an advertising-cookie stack and is not designed for targeted advertising or sale or sharing of personal data.
  • The site currently uses first-party cookies for saved area-result continuity, display timezone, and private editorial access sessions, and it uses local browser storage for public-facing preference state.
  • Infrastructure providers may also use technical cookies or similar mechanisms needed for delivery, security, and basic functionality.
  • Deployed versions of the site load the first-party analytics script loaded from analytics.ballotclarity.org to understand usage and performance. This service may receive technical request data and pageview metadata, but it is not used for targeted advertising.

Address lookup sensitivity

An address lookup can reveal precise household or location context. Ballot Clarity therefore treats the lookup flow as a narrow, high-sensitivity feature and keeps the explanation near the lookup form instead of burying it only in legal copy.

Retention and deletion

How long information lasts and who can access it

Category Scope Retention Access Removal path
Raw ballot lookup inputStreet address or ZIP entered into the lookup.Request-time processing, plus up to 7 days for encrypted normalized-address cache data when that optional backend cache is enabled.Request-time handling, provider processing, and—when the encrypted cache is enabled—restricted backend access to authenticated ciphertext.The current app flow avoids adding an exact street address to published source records, URLs, the saved-area cookie payload, or durable browser preference state. Encrypted backend cache records expire automatically; provider-side retention depends on the recipient's system and policy.
Saved lookup cookieAuthenticated encrypted first-party cookie containing public area-result continuity details such as an exact 5-digit ZIP when applicable, matched districts, representative matches, official actions, and lookup timing. Exact street-address input is omitted.Up to 7 days.Sent automatically to the backend as a first-party HttpOnly cookie; browser scripts cannot read it.Clear browser cookies or submit a new lookup that replaces or clears the stored context.
Encrypted address lookup cacheProvider-normalized address geography, district matches, representative matches, and lookup metadata needed to avoid repeating the same provider calls.Up to 7 days when the optional Postgres cache and its dedicated encryption key are configured.Restricted backend database access; the payload is stored as authenticated ciphertext and the lookup identifier is keyed.Records expire automatically after 7 days and are deleted on later cache access or replacement. Legacy plaintext rows are removed during schema migration.
ZIP-only lookup operations logTimestamp, exact normalized 5-digit ZIP input, lookup result, guide-availability status, and whether a ZIP area selection was required. The log does not include raw lookup text, full street addresses, ZIP+4 entries, city names, mixed address strings, provider-normalized ZIPs, IP address, or user agent.Short-term operational retention, generally days to weeks rather than permanent publication.Operational access only for reliability, coverage planning, and abuse monitoring.Removed through operational log rotation or retention cleanup; not published as civic content.
Display timezone cookieFirst-party cookie containing the browser-reported timezone used for SSR-safe date display.Up to 1 year.Stored in your browser on the current device.Clear browser cookies or override the stored timezone with a later visit.
Saved guide preferencesSelected public location label, compare list, ballot plan, issue filters, reading mode, and sanitized area-result details. Exact street addresses, address-specific ballot previews, and address-specific polling logistics are excluded.Until you clear it or replace it on your device.Stored in your browser on the current device.Clear browser storage, use a private session, or overwrite the saved state.
Editorial access session cookiePrivate editorial authentication cookie for editorial and operations access.Up to 12 hours per session.Stored in the editor's browser and private access-control layer.Sign out, clear browser cookies, or allow the session to expire.
Operational request metadataIP address, user agent, endpoint path, referrer, timestamps, pageview metadata, and similar request metadata.Short-term operational retention, generally days to weeks rather than permanent publication.Hosting, operations, security tooling, and the analytics service hosted at analytics.ballotclarity.org.Managed through service settings, with longer retention permitted for active abuse handling, incident response, or legal obligations.
Contact form rate-limit metadataConnection-derived rate-limit key, request count, and reset time for repeated contact or correction form submissions.Short-lived in-memory retention, defaulting to about 10 minutes unless the operator changes the rate-limit window.Backend memory only, for public form abuse prevention.Cleared automatically when the short rate-limit window expires or the server process restarts.
Civic lookup rate-limit metadataConnection-derived rate-limit key, request count, and reset time for repeated civic lookup requests. This does not add raw addresses to the ZIP-only operational lookup log.Short-lived in-memory retention, defaulting to about 10 minutes unless the operator changes the rate-limit window.Backend memory only, for lookup abuse prevention.Cleared automatically when the short rate-limit window expires or the server process restarts.
Contact and correction submissionsName, email address, subject, page URL, message, attachments, and source links you provide through email or the contact form.Until the issue is resolved and the supporting review record is no longer operationally needed.Project inbox, review store, and editorial reviewers handling the issue.Archived or deleted when no longer needed for support, verification, auditability, or the public corrections process.

Your choices and requests

Rights requests and no-account limits

  • You can browse much of the site without using the ballot lookup.
  • You can clear browser storage and cookies on your device to remove saved ballot-plan state, selected location labels, timezone state, and area-result cookies kept locally by the app.
  • Because Ballot Clarity does not create public self-service accounts and is designed to keep some data ephemeral, the project may have limited ability to associate a privacy request with operational logs or transient lookup activity.
  • If applicable law gives you rights to request access, deletion, correction, or appeal, contact the project and describe the data or interaction as specifically as possible.

Children and families

Children's privacy

  • Ballot Clarity is a general-audience civic-information site and is not designed for children under 13.
  • The site does not offer child-directed accounts, community posting, or other features intended to collect personal information from children.
  • If you believe a child has sent personal information to the project through email or another channel, contact the project so the issue can be reviewed.

Security

How Ballot Clarity approaches privacy and security controls

  • Ballot Clarity aims to use reasonable administrative, technical, and organizational safeguards appropriate to the service.
  • Those safeguards are intended to reduce unnecessary data collection, limit retention, and protect the integrity of the service and its operational systems.
  • The service also uses staff login throttling, signed editorial-access session cookies, authenticated encryption for saved lookup continuity and optional address caching, and structured request logging that excludes URL query strings.
  • No internet service can guarantee absolute security. If the project's data practices or incident posture changes materially, this policy will be updated as well.

Changes and contact

How to reach the project and when this policy changes

Questions, privacy concerns, and correction requests can be sent through the contact page or the protected email link below.

Email link loads in your browser.

If Ballot Clarity materially changes how lookup input, browser storage, analytics, vendors, or future account-based features work, this Privacy Policy will be updated before those changes go live.

Read this page together with the on-page explanation near the ballot lookup form, the contact and corrections workflow, and the public methodology notes.

Open contact page Review methodology

Ballot Clarity

Ballot Clarity is a public-interest civic-information site built to help people look up their area, review the public record, and verify details with official sources.

Contact

Questions, corrections, and volunteer help welcome.

Email link loads in your browser.

Open contact page

Start with lookup

  • Location lookup
  • District pages
  • Representatives
  • Search

Learn and verify

  • About
  • Coverage profile
  • Source directory
  • Voting FAQ

Standards

  • Methodology
  • Data sources
  • Neutrality policy
  • Accessibility
  • Privacy
  • Terms

Not an official election website. Ballot Clarity aims to provide nonpartisan civic information and cite sources where possible. Content can change, so verify critical election details with the official authorities linked throughout the site.

Public status Corrections log

© 2026 Ballot Clarity