Privacy policy
Effective September 15, 2026 · Last updated September 15, 2026
This policy explains how Vote.to handles personal information when you browse questions, sign in, vote, share an explanation, or contact us.
Who we are
ProHelp Inc, based in the United States, operates Vote.to and is responsible for its handling of personal information. Contact us at how@vote.to about this policy or your information.
Information we collect
- Accounts. We receive your sign-in provider’s account identifier and display name, plus your username for X when enabled. We store these with your Vote.to account identifier and creation date.
- Google sign-in. We request basic profile and email permissions and use your account identifier and display name. We do not save your Google email or profile photo as account fields or request Gmail messages, Drive files, or contacts.
- Connected accounts. We store encrypted authorization tokens, their expiry, and permissions to support connected features. We do not receive your Google, X, or Facebook password.
- Facebook sign-in. When enabled, we request public-profile access to verify your app-specific Facebook account identifier and display name. We do not request your email, friends list, posts, or publishing permissions. Connecting Facebook while signed in links it to your existing Vote.to account.
- Creator explanations. You can separately submit a short explanation for the poll creator’s summary. We save it only when you explicitly choose to share it with the creator. The creator and authorized administrators can see its text and vote position without an attached account name or identifier. Your words may identify you. Summaries group these explanations by vote position and show illustrative quotes; no external AI provider processes them. You can replace or remove your explanation. Changing your vote removes the prior explanation until you choose to submit one again.
- Questions and votes. We store questions, descriptions, creator details, eligibility lists, closing times, and each account’s score and update time. Sharing previews include text, reasons, result snapshots, scores, and disclosure choices; publishing adds X post details and status.
- Previous X posts. When you choose this feature, we retrieve previews of your public X posts. Linking a post saves its identifier, X account, your score at the time, and your public-listing choice. We do not save the linked post’s text in our database or publish a new X post when you link it. You can remove the link in the voting page.
- Technical information. We process session and verification data, IP addresses, and request information to deliver and protect the service. Infrastructure and verification providers also process browser, device, and network information.
- Support. If you email us, we receive your email address, message, attachments, and any account or question details you include.
Questions, votes, and explanations may reveal sensitive opinions or information, including political views, religion, or health. Participation and explanations are optional. Consider what your contribution reveals and avoid including unnecessary sensitive information about yourself or others.
How we use information
We use information to recognize accounts, link providers, check eligibility, save votes, calculate results, create requested images and creator summaries, publish explicitly confirmed posts when enabled, and check public X listings. We also use it for support, security, abuse prevention, enforcing our terms, and handling legal obligations or claims.
Google data is used for sign-in and visible account and voting features. We do not sell personal information or use it for advertising or AI model training. Vote.to has no advertising or analytics trackers.
What is public
Questions, descriptions, creator display names and internal Vote.to identifiers, and aggregate results are public. The app shows individual eligibility lists only to their creator.
Votes are linked to accounts in our database and are not displayed as named public votes by default. Votes are not anonymous to authorized operators, who can access records, and small tallies or changes may reveal an individual score.
Showing your score in a shared image and listing your X post beside your score are separate choices. Anyone with a result-image link can view it, including a preview. Choosing Share on X or Share on Facebook activates an unlisted snapshot page containing your selected image and optional reason. Anyone with that link can view or reshare it, even if you cancel the external composer. Your position is included only when you choose to show it. Creating a preview alone does not activate this page. Public listings associate your X account with your score when shared. Removing a listing does not delete its X post. Public-post checks are not instantaneous, and copies or screenshots may remain elsewhere.
Providers and processing location
Our hosting is on Amazon Web Services in Oregon, United States. Hosting, backup, security, and email providers process information to supply their services. Authorized operators may access it for operation and support. Your information may be processed outside your country, where privacy laws may differ.
Google provides sign-in. Facebook sign-in is available when enabled and is separate from manual Facebook sharing. X sign-in and direct publishing are available only when enabled. Authorized direct publishing sends your reviewed text and image to X. Manual sharing opens X or Facebook with your activated snapshot link; you review and finish posting on that service. The link makes your selected image and optional reason available to that service and anyone who receives the link. Facebook sharing does not connect a Facebook account to Vote.to or give Vote.to access to your Facebook password or posts. Their policies apply to their processing: Google privacy policy, X privacy policy, and Meta privacy policy.
Cloudflare Turnstile receives verification information, including your IP address, and processes browser and device signals to help detect automated requests. See the Turnstile privacy policy.
We may disclose relevant information when legally required or necessary to investigate abuse, protect people or the service, or establish or defend legal claims.
Cookies and security
We use an essential session cookie for sign-in and request protection, including anonymous browsing sessions. Sessions expire after seven days; signing out ends the current session. Blocking cookies may prevent sign-in or voting.
To limit automated activity, we keep verification request details and short-lived request counters. Counter identifiers are keyed hashes derived from accounts and network addresses; the counter table does not store raw IP addresses. Network limits are abuse signals, not proof that everyone using a network is one person.
HTTPS, restricted infrastructure access, and encrypted provider tokens help protect information. No security measure guarantees protection against every loss or unauthorized access.
How long information is kept
Account, question, vote, activated snapshot-link, and published-share records have no automatic expiry. Explanations shared with the creator remain until you remove them, change your vote, or the related account or poll is deleted. Records of publishing attempts with an unconfirmed outcome also have no automatic expiry. We retain these to operate the service, preserve results, investigate problems, and address requests or legal obligations.
Temporary sign-in verification expires after ten minutes. We periodically remove expired sessions and sign-in records. Unshared drafts are automatically eligible for cleanup after seven days. Activated snapshot links remain available so shared links keep working; the draft cleanup rule does not cover these links, published records, or unconfirmed publishing records.
Voting verification requests expire after five minutes. Abuse-counter windows last up to one hour under the current settings. Expired requests and counters become eligible for periodic cleanup in bounded batches; expiry blocks further use even before cleanup runs.
Support records are kept as needed to address the matter. Backup copies can remain after active records change or are removed. There is no single automatic deletion deadline for all backups.
Your choices and rights
You can update your vote while voting is open, choose sharing disclosures, and sign out. Revoke connected access in Google account settings or X’s connected-app settings, or remove Vote.to in Facebook’s Apps and Websites settings. Revocation does not automatically delete Vote.to records. For account or Facebook-data removal, follow our data-deletion instructions or contact how@vote.to.
Depending on applicable law, you may have rights to access, correct, delete, or obtain a portable copy of information; restrict or object to processing; and withdraw consent where processing relies on consent. Withdrawal does not affect earlier lawful processing. These rights may have exceptions. You may also complain to the relevant privacy authority.
Describe your request and how to identify your account. We may reasonably verify your identity before acting. We will respond within applicable legal deadlines and explain any applicable limits on fulfilling a request.
Children
Vote.to is not directed to children under 13, or a higher minimum age required locally. We do not knowingly collect their personal information. If you believe a child has provided information, contact us to request its removal.
Changes and contact
We will publish updates here with the revised date and provide additional notice when required. New uses of Google data requiring consent will be presented for consent before that use begins.
Privacy questions and requests: how@vote.to. Vote.to is operated by ProHelp Inc in the United States.