The record isn't a feed

American Voices

Your district. The record. What changed.

Legal · operational

Privacy Policy

Last updated September 6, 2026

The civic record is never for sale. Votes, money, attendance, effects, and officials are assembled from public government and open sources. User posts, ads, opinions, and subscriptions never rewrite that index.

Who we are

American Voices is a civic sunlight product. It publishes a public-record index of officials, votes, money, attendance, and effects, and it optionally hosts identified opinion on a district-first civic feed. The operator is the person or organization running this host — currently Nick, doing business as American Voices. This policy describes how this software actually treats data. It is not a law-firm letter.

You can use the civic record without an account. Saving a ZIP personalizes the digest. Creating a profile is optional and is for identified speech, not for rewriting the index.

The record isn’t a feed

The civic record — sitting officials, roll calls, finance totals, attendance, effects, agencies, and sourced alerts — is assembled from public government and open sources (Clerk of the House, Senate roll calls, FEC, Census Geocoder, congress-legislators, OpenStates, GovInfo, Federal Register, and similar). That index is a public artifact. It is not your personal diary, and it is not a social feed.

User posts, comments, verdicts, influencer speech, marketplace ads, and opinions never write officials, votes, finance, or scores. The thesis is literal: the record isn’t a feed. If a source is missing, the field stays blank. We do not invent numbers to fill a hole.

What we collect

Only what the product actually uses:

  • Public civic data. Government and open-source files about officials and recorded acts. This is not “your” personal data in the consumer-app sense. It is the sunlight record.
  • Saved district. A five-digit ZIP you choose, stored in the av_zip cookie, in browser localStorage (av_district), and optionally on a signed-in profile.
  • Account profile if you join: email (stored so we can issue a login code and show the account), a hash of that email, display name, handle, optional bio, role (citizen / creator / candidate), optional ZIP and district label, optional candidate office / FEC committee / filing URL, subscriber flag, and verification timestamps.
  • Phone (optional, often unset). If Twilio is configured on this host, we may store a hash of the number and the last four digits. If Twilio is not configured, we do not mark a number verified and we do not pretend SMS was sent.
  • Anonymous voice cookie (av_voice): a random browser id used for anonymous comments and verdicts on the official record, watch-list items, notification preferences, and anti-bot rate limits. It is not a login.
  • Session cookie (av_session) after you verify an email code. The token is hashed at rest. Sessions last about 30 days.
  • User-generated speech: civic-feed / topic thoughts, anonymous comments and verdicts on the record, influencer posts and disclosure, marketplace placement drafts, waitlist sign-ups (desk / serve / alerts), and reports.
  • Integrity and rate-limit events: a hashed network identifier (not the raw IP), voice id, and a short reason (too many login codes, duplicate text, sanction). Used to slow bots. Not a dossier.
  • Last-seen cookie (av_last_seen) so the digest can show what changed since your last visit.
  • Notification prefs and optional Web Push keys (endpoint, p256dh, auth) only if you opt in and VAPID keys are set on this host. Without those keys we do not subscribe and we do not fake delivery.
  • Theme preference in localStorage (av-theme).

We do not collect government ID scans, precise GPS tracks, contact-book uploads, or payment-card numbers. Stripe is documented as optional later; this build stores marketplace intents and external checkout URLs only.

Why we use it

  • Show you the civic record for the seats you live in.
  • Issue a one-time email code and keep you signed in.
  • Host identified opinion on the civic feed and topic pages.
  • Let you watch an official or a roll call, and (when configured) send rare, sourced alerts.
  • Rate-limit bots, hold spam, and apply public sanctions.
  • Label marketplace placements so paid speech is not mistaken for the record.
  • Remember a ZIP and a theme so the installed app still feels like your district.

We notify rarely, and only with sources. Default notification categories are roll calls, safety follow-ups, and major executive orders — not influencer posts or topic chatter.

What we never sell

We do not sell the civic index. We do not sell personal data so that someone can rewrite, hide, or bury a recorded vote. Money never buys a score, a quieter sanction, or a verified politician badge. A subscriber flag can skip labeled feed ads and keep posting privilege after strikes. That is privilege, not a rewrite of the record.

We do not sell email lists. We do not sell ZIP lists. We do not broker “constituent files” to campaigns. Marketplace placements are labeled paid speech sitting beside the record — never on it.

Accounts and identity

Join is a hashed email one-time code, then a session cookie. Google / Apple OAuth is documented as a later add and is not required today. Production sends that code primarily through Microsoft Graph Mail.Send (Entra app) as [email protected]. Resend and SMTP are fallbacks in code. SMTP AUTH to Microsoft 365 is often blocked by Security Defaults (535), so this page does not describe mail as “SMTP or Resend” alone. Production without any sender refuses to pretend a code was emailed. Local development may echo the code in JSON; that flag is forbidden in production.

Roles are citizen, creator, or candidate — one primary. Candidate verification is checked against a public FEC committee when a key is present; otherwise the badge stays Self-attested — not verified against FEC. We do not invent verified politicians. Creator “verified” is a public checklist, not a paid blue check.

Phone verification and captcha (Turnstile / hCaptcha) are stubs behind env vars. A personhood challenge is a small proof-of-work issued to suspicious accounts. None of these are sold as identity products.

Anonymous comments and verdicts on the official record still follow the av_voice cookie (McIntyre-style anonymous speech). Topic thoughts and civic-feed posts are opted-in identified speech and require a verified email.

Cookies and local storage

This host sets a small, named set of first-party cookies. There is no third-party ad pixel.

NameWhatNotes
av_sessionSigned-in sessionHttpOnly, SameSite=Lax, Secure in production, ~30 days. Cleared on logout.
av_voiceAnonymous voice idHttpOnly, SameSite=Lax, Secure in production, ~1 year. Comments, verdicts, watch list, prefs.
av_zipSaved ZIPSameSite=Lax, ~1 year. Not HttpOnly so the installed app can mirror it. Clear it on /my-district.
av_last_seenLast digest visitSameSite=Lax, ~1 year. Powers “what changed,” not advertising.

Browser storage: av_district (ZIP + saved-at) and av-theme (light / dark). A service worker may cache the shell and the last digest so the home-screen app still opens offline. You can clear cookies and site data in the browser at any time.

Cloudflare, sitting in front of this host, may set its own cookies for bot or TLS management. This app does not write those names, and they are not an advertising pixel.

Public speech vs. private data

If you post a thought, an influencer item, or a marketplace draft, treat it as public. Handles live at /u/:handle. Civic-feed posts are district-first opinion. They are labeled opinion and are never scored as the record.

Email, phone hash, session tokens, and waitlist notes are not published on the feed. Strike counts and public sanction notes are visible on the integrity ladder — sanctions are not silent. Banned accounts keep old posts with an audit marker so the public can see what was said and what was done about it.

Reports (sockpuppet / bot / other) store a detail and the reporter’s voice id. Cases appear on /integrity. There is no shadowban of the civic record.

Marketplace, ads, and subscriptions

Monetization is a labeled marketplace next to the record. Outreach must name a payer. Cause rows say they are not the official record. Pending drafts show on the money trail even at $0. They do not enter scores.

The free civic feed may insert a labeled marketplace ad about every three items (cadence = 3). Subscribers skip those slots. The subscriber flag is an env stub or an account field today — not a live card-not-present checkout. When payments exist, they are expected to stay on an external processor; this app does not store card numbers.

Influencer shops are external (Shopify, Etsy, WooCommerce, Square, or similar). American Voices does not sell those items or take that payment. Checkout stays on the merchant.

Moderation and enforcement

Anti-bot is a public ladder: email verified → optional phone → rate limits → creator checklist → candidate FEC/filing review → personhood challenge. Writes that trip integrity rules are held, not silently erased. The hold reason is stored.

Profile enforcement is reprimand → mute → ban, with a required public note. Free accounts can lose posting privilege after strikes; subscribers keep the right to post after a mute. Enforcement writes profile_actions and integrity events. We keep those logs so a sanction can be audited. We do not use them to rewrite votes or scores.

Analytics

This codebase does not include Google Analytics, Mixpanel, Plausible, PostHog, Sentry, or a similar product-analytics SDK. We do not run a third-party advertising pixel.

First-party product signals are the last-seen cookie, watch-list rows, notification prefs, and hashed integrity events. Azure Container Apps and Cloudflare (the reverse proxy in front of it) may keep ordinary request logs — IP, user-agent, path — and Cloudflare may collect network-error reports. That is hosting telemetry under each vendor’s settings, not a growth dashboard we built.

Third parties

Depending on what is configured on this host, data may reach:

  • Microsoft Azure — Container Apps and Key Vault in East US (eastus). The live durable store is Azure Database for PostgreSQL Flexible Server psql-av-ilpcewax6poae in eastus2 (eastus was capacity-restricted; ACA stays in eastus), via DATABASE_URL. Secrets are referenced from Key Vault, not committed to git.
  • Cloudflare — public DNS is orange-cloud in front of ACA. TLS to the origin is Full (strict). A WAF / security baseline is on. The raw ACA origin is locked to Cloudflare IP ranges. Cloudflare sees the request (IP, user-agent, path, TLS metadata) and may set its own cookies. We do not claim we control Cloudflare’s retention.
  • Email — primarily Microsoft Graph Mail.Send (Entra app) as [email protected]. Microsoft sees the recipient address and the one-time code. Resend and SMTP are fallbacks in code when Graph is unset; SMTP AUTH to Microsoft 365 is often blocked by policy.
  • SMS — Twilio, only if all three Twilio env vars are set.
  • District lookup — Zippopotam.us and the U.S. Census Geocoder when a ZIP is not already cached. Optional Google Civic Information API if you look up a street address and that key is present.
  • Candidate check — OpenFEC, when a committee id is submitted and an FEC key is present.
  • Web Push — the browser’s push service (typically Apple, Google, or Mozilla) if you opt in and VAPID keys exist.
  • Optional captcha — Cloudflare Turnstile or hCaptcha, only if those secrets are set. Unset means proof-of-work only; we do not fake a captcha pass.
  • Fonts — Libre Caslon and IBM Plex Mono via next/font/google (usually self-hosted after build); Satoshi via a Fontshare stylesheet. Fontshare may see a page request when that stylesheet loads.
  • Public-record ingest — Congress.gov, GovInfo, OpenStates, FEC, CourtListener, Federal Register, and similar. Optional keys may also call NewsAPI, Quiver Quantitative, Financial Modeling Prep, or X for attributed context. Those calls fetch public items. They are not a user-tracking graph.

Each of those services has its own terms. We send them only what the feature needs. We do not claim we control their retention.

Hosting, security, and limits

Production is Azure Container Apps in eastus, resource group rg-american-voices, reached through Cloudflare as described above. Secrets belong in Key Vault. The live durable store is Azure Database for PostgreSQL Flexible Server psql-av-ilpcewax6poae in eastus2 (eastus was capacity-restricted; ACA stays in eastus), via DATABASE_URL. The live host (americanvoices.app) reports health driver pg.

Local development — and any host with DATABASE_URL unset — still uses SQLite (default ./data/american-voices.sqlite). The Phase 2 ACA demo used /tmp/american-voices.sqlite on ephemeral container disk; that file could vanish on a replica replace. It is not how live user data is stored today.

Session and voice cookies are HttpOnly and SameSite=Lax, and Secure when NODE_ENV=production. Auth codes and session tokens are hashed. Network identifiers used for rate limits are hashed with a server salt. Email is stored in the clear on the profile so we can reach you — that is a deliberate tradeoff, not an accident, and it is a reason to keep the host locked down.

We do not claim SOC 2, ISO 27001, “bank-grade encryption,” or that no one can ever breach a container. If you need a compliance attestation, this page is not it.

How long we keep data

  • Login codes expire in about 15 minutes and are marked used.
  • Sessions expire in about 30 days or when you log out.
  • ZIP, voice, and last-seen cookies last about a year unless you clear them.
  • Public posts, sanction notes, and the civic index are kept for audit as long as this host retains its Postgres database.
  • Azure Flexible Server has automated backups. This page does not promise a specific backup window, a restore SLA, or that a deleted row is immediately gone from backups.
  • Historically, the Phase 2 Azure demo used SQLite at /tmp/american-voices.sqlite, which vanished when the container was replaced. That is not the live store.

Your rights

You can read most of your account on /account. You can clear a saved ZIP on /my-district, log out, and wipe cookies and local storage in the browser. You can stop push by unsubscribing in the browser (when push is actually configured).

This build does not yet ship a self-serve “delete my account” button. If you want access beyond the account page, correction of a profile field we control, or deletion of an account, email the operator contact below. We will delete or anonymize account fields we reasonably control when we can. We may retain what we must keep to explain a public sanction or to prevent immediate re-abuse.

We cannot “delete” a recorded vote or an official’s public finance totals because you asked. That is government data on the civic index, not a consumer profile.

If you live somewhere with additional privacy laws — including California, the EEA, or the UK — you may have rights those statutes describe (access, deletion, correction, portability, objection). We will try to honor requests we can actually fulfill on this host. We do not claim CCPA certification, GDPR certification, a formal DSAR portal, or that this page makes the product “fully compliant.”

Children

American Voices is a civic product about public officials. The sunlight record is public government information. The identified features — accounts, civic-feed posts, waitlists — are not directed at children under 13.

Do not create an account, submit an email, or post if you are under 13. If we learn we have collected personal information from a child under 13, we will delete that account data we control. If you are 13–17, you may read the public record; identified posting should be done with a parent or guardian’s knowledge. We do not knowingly market marketplace placements to children.

Changes to this policy

If this policy changes, we will update the date at the top of this page. Material changes belong in plain English here — not buried in a changelog. Continued use after the new date is how this host treats acceptance, which is another reason counsel should review the language before anyone leans on it.

Contact

Privacy questions and deletion requests: [email protected]. That address comes from PRIVACY_CONTACT_EMAIL on this host.

Method and sources live on /method. Integrity cases live on /integrity. The civic record lives on /digest.

Privacy Policy · American Voices