PolitiMind — Your Political Intelligence Engine

    Privacy Policy

    Last updated:

    1.Scope & Controller

    This Privacy Policy describes how PolitiMind, Inc. ("PolitiMind", "we", "us") collects, uses, discloses, and protects information when you access politimind.com, the PolitiMind application, $PMIND wallet integrations, and any related services (collectively, the "Services").

    For the purposes of the EU/UK GDPR, PolitiMind acts as the data controller. For California residents, this Policy serves as our CCPA/CPRA notice at collection.

    2.Information We Collect

    We collect the following categories of information:

    • Account data: name, email, password hash, authentication metadata.
    • Identity-verification data: government-issued ID images, biometric facial-match vectors, and liveness signals used to confirm one verified human per account. Biometric templates are processed by our verification sub-processor and not retained in raw form by PolitiMind.
    • Identity details you enter during verification: your legal first and last name, date of birth, mobile phone, and residential address. These are held in a temporary, consent-gated verification draft and transmitted to our identity-verification sub-processor solely to prefill and cross-check your inquiry against your government ID. If the name or date of birth does not match your ID, verification is blocked — we record only the reason for the mismatch, never the values read from your document. The draft is deleted when verification finalizes and automatically purged within 14 days if you do not finish. Your name and date of birth are never added to your public or research profile.
    • Wallet & on-chain data: public wallet addresses, $PMIND balances, NFT ballot ownership, and on-chain transaction hashes anchored to Base (Coinbase L2).
    • Civic activity: poll responses, voting records within the platform, sentiment inputs, and related timestamps.
    • Technical & device data: IP address, user-agent, device fingerprint hash (SHA-256), session cookies, and the pmind_voter_id identifier used for guest deduplication.
    • Geolocation: coarse and (where authorized) precise location used to enforce U.S.-only access and detect VPN/proxy circumvention.
    • Communications: emails, support tickets, and form submissions.
    • Protected email aliases: the randomly generated alias addresses you create on m.politimind.com, the mapping between each alias and your account inbox, and per-alias delivery counters (forwarded, blocked, bounced, complained).

    3.Email Anonymization (Account Aliases)

    Every PolitiMind account is issued one permanent alias on m.politimind.com at signup. That alias — not your real email address — is the address of record for your account everywhere in the platform. Aliases are opaque random strings; they encode nothing about your identity.

    • No readable copy of your email: your real address is held by our authentication system for sign-in and as an encrypted copy in our protected vault, alongside a one-way fingerprint used only for account matching. No application table stores it in readable form, so exports, internal queries, and a database compromise do not reveal it.
    • Staff visibility: staff and administrators see only the alias. Revealing a real address requires a vault administrator, a written justification, and produces a permanent, append-only audit record.
    • Mapping confidentiality: the alias-to-inbox mapping is readable only by our mail-processing plane through restricted server-side routines. It is never exposed to your browser, to other participants, or to your correspondents.
    • Reply rewriting: when you reply through an alias, our outbound processor verifies a signed reply token, confirms you own the alias, and strips your real address and identifying headers before delivery.
    • Minimized logging: we retain per-message delivery outcomes (forwarded, blocked, capped, bounced, complained) and timestamps for abuse handling and deliverability. We do not retain message bodies, and delivery records are not used to build correspondent profiles.
    • Abuse controls: aliases carry a daily forwarding cap. Trust & Safety staff can review aggregate per-alias counters and suspend an alias; they cannot read your mail.
    • Retention: inbound message objects are deleted from staging storage within 7 days; suppression records for bounced or complaining destinations are retained as long as needed to protect deliverability.

    4.Lawful Bases (GDPR Art. 6 & 9)

    • Contract: to provide the Services you request.
    • Legitimate interests: fraud prevention, manipulation detection, security, and product improvement.
    • Legal obligation: KYC/AML, election-integrity, and regulatory compliance.
    • Consent: for biometric processing (Art. 9), marketing emails, and optional analytics.

    5.How We Use Information

    • Operate identity verification, polling, and $PMIND token issuance.
    • Anchor poll outcomes to public blockchains for tamper-evidence.
    • Detect sybil attacks, vote manipulation, and coordinated inauthentic activity.
    • Generate aggregated civic-intelligence reports (no individual identification).
    • Provide AI-assisted features through our neutrality-audited AI layer.
    • Comply with law and respond to lawful process.

    6.Sub-Processors & Sharing

    We share data only with vetted sub-processors under written data-processing terms:

    • Supabase (hosting, database, auth, storage)
    • Base / Coinbase L2 (public blockchain anchoring & $PMIND token)
    • HubSpot (CRM & email)
    • Contentful (resource CMS)
    • Sentry (error monitoring)
    • Lovable AI Gateway and underlying LLM providers (Grok, OpenAI, Gemini) for the neutrality-audited AI layer
    • Slack (internal staff alerting only)

    We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

    7.International Transfers

    Data is processed primarily in the United States. Where data is transferred from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (2021/914) and supplementary technical measures including encryption in transit and at rest.

    8.Retention

    • Account data: for the life of the account, plus 24 months for fraud and dispute resolution.
    • Identity-verification artifacts: 12 months after verification, or until deletion is requested where legally permissible.
    • On-chain data: by design, immutable and not deletable from public ledgers.
    • Audit and AI-inference logs: 24 months in append-only form.
    • Marketing data: until you unsubscribe, then suppression-list only.

    9.Your Rights

    Depending on your jurisdiction, you may have rights to access, correct, delete, port, restrict, or object to processing of your data, and to withdraw consent.

    California residents have rights under the CCPA/CPRA. Virginia, Colorado, Connecticut, Utah, and other state residents have analogous rights — see the State & Regional Privacy Rights Notice for the jurisdiction-by-jurisdiction breakdown. EU/UK/Swiss residents have rights under the GDPR/UK GDPR/FADP.

    Submit a verified request through our Privacy Rights Request form, or email chris@politimind.com. We acknowledge every request, verify identity before acting, and respond within 45 days (extendable once where the law permits). You may lodge a complaint with your supervisory authority.

    10.Security

    We employ defense-in-depth controls including row-level security, security-definer RPCs, JWT validation, strict Content-Security-Policy headers, encryption in transit (TLS 1.2+) and at rest (AES-256), zero-trust PII handling, and continuous monitoring. No system is perfectly secure; you assume residual risk by using the Services.

    11.Children

    The Services are intended for individuals 18 years or older. We do not knowingly collect data from children under 13. Identity verification will reject minors.

    12.Do Not Track & Global Privacy Control

    We honor recognized Global Privacy Control (GPC) signals as a valid opt-out of sale/sharing under U.S. state privacy laws. When a GPC signal is present, analytics and advertising categories stay off and cannot be re-enabled from the consent banner. We do not respond to legacy "Do Not Track" headers because no common standard exists.

    You can review or change your cookie choices at any time from the "Cookie preferences" and "Do Not Sell or Share My Personal Information" links in the site footer. See the Cookie Policy for the full category list.

    14.Changes

    We may update this Policy. Material changes will be notified by email and via in-product notice no less than 14 days before effect.

    15.Contact

    PolitiMind, Inc., 1209 Orange Street, Wilmington, DE 19801, USA.
    Privacy: chris@politimind.com · DPO: chris@politimind.com

    This document is provided as initial v1 policy language and does not constitute legal advice. For questions, contact chris@politimind.com.