rcv-lab Privacy Policy
Last updated: May 18, 2026
Plain-language summary
rcv-lab is a free, public-benefit ranked-choice voting platform operated by Kaphan Foundation. We collect the minimum information needed to run the Service: an email address (and name from Google, if you sign in with Google) for accounts, the contents of ballots you create, and the votes cast on those ballots. We never sell your data. We don't currently use cookies. Voters access ballots via single-use tokens delivered by email or SMS. Ballot creators can see who used their invitations, but no one — not even rcv-lab — can link a voter's identity to the rankings on their ballot. You can ask us to delete your data at any time.
If you have questions about this Privacy Policy, contact us at privacy@rcv-lab.org.
1. Who we are
This Privacy Policy describes how the Kaphan Foundation ("we," "us," "Kaphan Foundation," or "rcv-lab"), a Washington nonstock corporation and IRS §501(c)(3) private foundation, collects and uses information in connection with the rcv-lab Service.
The Service includes the rcv-lab website, applications, APIs, MCP server, and integrations such as Discord. This Policy applies to information collected through the Service. It does not cover information collected by third parties (such as Discord, Google, or any AI agent you authorize) according to their own policies.
2. Information we collect
Information you provide
- Account information. If you create an account using email and password, we collect your email address. If you create an account using Google sign-in, we receive your email address and, depending on your Google account settings, your name from Google.
- Ballot content. When you create a ballot, we store the ballot's title, candidates, configuration, and other content you provide. Ballot titles and content are visible to anyone with access to the ballot; you should not include personally identifying or sensitive information in ballot content unless you intend it to be visible to voters.
- Voter invitation data. When you invite voters to a ballot, we store the email address or phone number of each invited voter, depending on which channel you chose for that invitation. Each invitation uses one channel; if you want to reach the same person by both email and SMS, you create two separate invitations.
- Write-in candidates. Voters may submit write-in candidate names during voting. These names become visible to other voters of the same ballot and may appear in published results.
- Votes. When voters cast ballots, we store their ranked choices. Ballot creators can see who voted (i.e., which invitations were used), but they cannot see how anyone voted — the system is designed so that there is no stored link between a voter's identity and the specific rankings on their ballot. See Section 7.
- Communications. If you email us, we retain those messages and our responses.
Information collected automatically
- Technical data. When you interact with the Service, our servers receive standard technical information including IP address, browser type, operating system, request timestamps, and pages or endpoints accessed. We use this for security, debugging, and aggregate analytics.
- Anti-duplicate-voting data. rcv-lab prevents duplicate voting using single-use voter tokens. Each invitation to a ballot contains a unique UUID; when the token is redeemed, it is marked as used. We do not use device fingerprinting, IP-based heuristics, or third-party fraud-detection services to detect repeat voting.
- Voter receipts and verification data. When a voter casts a ballot, the Service generates a cryptographic receipt — a hash of the canonicalized rankings combined with a random salt. The server retains the inputs needed to reproduce the receipt, but as a matter of policy will not do so (see Section 4 and the Terms of Service §5).
Information from integrations
If you connect rcv-lab to a third-party service (such as Discord), we receive identifiers and other information from that service as needed to provide the integration — for example, a Discord user ID, server membership, or display name. We do not receive your password or credentials for those services.
Information from AI agents and API clients
If you authorize an AI agent or other software to access rcv-lab on your behalf via the API or MCP server, that agent acts under your account. The MCP authorization flow uses a localhost-redirect OAuth-style handoff: your agent receives a refresh token at a localhost endpoint and uses it to obtain access tokens for subsequent requests. We log API and MCP activity for security and debugging on the same basis as ordinary Service use.
3. Sub-processors and where we store data
rcv-lab uses the following sub-processors to operate the Service:
- Google Cloud Platform — hosting, authentication (Firebase Auth), database (Firestore), serverless compute (Cloud Run), and scheduled jobs (Cloud Tasks). Subject to Google's privacy policy.
- Postmark — transactional email delivery (invitations, reminders, results notifications).
- SendGrid — alternate transactional email provider, configured for failover or switching.
- Twilio — SMS delivery for notification of voters by text message.
- Sentry — server-side error tracking. We configure Sentry with
sendDefaultPii: false, which excludes IP addresses and other default fields that could identify users. Sentry receives stack traces and technical context (URLs, request methods, breadcrumbs); it does not receive voter contact information or ballot contents. - RCVis — third-party visualization rendering for tabulation results. Only post-tabulation aggregate election summaries are uploaded; no per-voter data is ever sent to RCVis.
We do not use advertising networks or third-party marketing trackers.
Data is processed and stored in the United States. If you are accessing the Service from outside the United States, see Section 11.
4. Voter receipts and verification — privacy notes
rcv-lab's voter-receipt system lets a voter confirm that their ballot was correctly recorded. The system has these privacy properties:
- A receipt is a cryptographic hash derived from the voter's canonicalized rankings plus a random salt. The receipt alone does not, by itself, reveal the rankings on the corresponding ballot.
- However, the public verification table for an election lists receipts alongside their associated rankings. Anyone holding a receipt can look it up in that table and see the rankings on that ballot. Voters should treat their receipts as private if ballot secrecy matters for their use case.
- The server retains the salt and canonicalized ranking that would allow it to reproduce a voter's receipt, but as a matter of design and policy, the Service does not expose any operation that would reproduce a receipt. This preserves the verification property: only the voter holds their receipt.
- Verification data (the public table of receipts and rankings) is retained for as long as the ballot creator's account is active, unless the creator deletes the ballot. See Section 8 for our overall retention practice.
5. Cookies and similar technologies
rcv-lab does not currently use cookies. We use the following mechanisms instead:
- Authentication. Admin and account-holder sessions use Firebase ID tokens stored in your browser's IndexedDB. When you make requests to the Service, your token is sent in an
Authorization: Bearerheader. No authentication cookies are set. - Voter access. Voters access ballots through unique single-use URL tokens delivered by email or SMS. There are no voter-side cookies; vote deduplication is handled entirely server-side by marking each token as used after redemption.
- Functional preferences. Some browser-side state is stored in your browser's LocalStorage and never transmitted to our servers as part of normal use. This includes UI widget preferences, a per-browser candidate-shuffle seed (so a voter sees candidates in a stable random order across reloads), and general component state such as collapsed sections.
Because rcv-lab does not use cookies, there is no cookie banner to dismiss and no third-party tracking cookies set by our site.
6. How we use information
We use the information we collect to:
- Operate and maintain the Service, including hosting ballots, delivering invitations, recording votes, and tabulating results;
- Send service-related communications (e.g., account confirmations, ballot invitations, reminders, results notifications, security notices);
- Detect, investigate, and prevent abuse, fraud, and security incidents;
- Improve the Service through aggregate analysis of usage patterns;
- Respond to support requests;
- Comply with legal obligations.
We do not use your information to send marketing or fundraising emails. We do not use rcv-lab data to train AI models, and we do not permit programmatic users to scrape rcv-lab data for the purpose of training competing AI systems.
7. Sharing of information
We do not sell or rent your personal information. We share information only as follows:
- With service providers (sub-processors listed in Section 3) that help us operate the Service, under appropriate confidentiality and data-processing terms.
- With the ballot creator, in a limited way: the creator can see which invitations they sent, which of those invitations have been used (so they know who has voted), and the aggregate tally results. The ballot creator cannot see which voter cast which ranked ballot. There is no stored linkage between a voter's identity and the rankings on their ballot that is accessible to ballot creators — this is an intentional design property of the platform.
- With third-party integrations you authorize (e.g., Discord), to provide the integration.
- As required by law, in response to a valid legal process. We will challenge requests we believe are overbroad or improper, where reasonable to do so.
- In connection with a transfer of the Service to a successor organization that agrees to continue operating rcv-lab consistently with this Privacy Policy and its public-benefit mission. We do not anticipate any such transfer.
8. Data retention
The current Service does not automatically delete data on a fixed schedule. Our retention practice is:
- While your account is active, we retain your account information, the ballots you have created, your voter invitation lists, voting results, voter receipts and verification data, and related records.
- On request, we delete your account and associated personal information. We will complete deletion requests within 30 days of receiving them, except where we are required to retain certain records by law or where deletion would compromise the integrity of an ongoing election that other voters are relying on (in which case we will anonymize rather than fully delete affected records).
- Server logs and technical data used for security and debugging are retained on the underlying infrastructure for the periods configured by our hosting and error-monitoring sub-processors.
- Email correspondence with us is retained for ordinary support and recordkeeping purposes.
We may introduce automated retention limits in the future. If we do, we will update this Policy and provide notice as described in Section 14.
You may request deletion at any time (see Section 9).
9. Your rights
You may exercise the following rights by emailing privacy@rcv-lab.org:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct inaccurate information.
- Deletion — ask us to delete your account and associated personal information. Note that ballots you created may be deleted as part of this process; if other voters relied on those ballots, we may anonymize rather than fully delete certain records.
- Export / portability — request your account information and ballot data in a portable format.
- Objection or restriction — object to or restrict certain processing, where applicable law gives you that right.
- Opt out of non-essential email — you can opt out of any non-essential email by replying to ask us to stop or by using an unsubscribe link if present. You cannot opt out of essential service notices (e.g., security alerts) while you have an active account.
We will respond to verifiable requests within a reasonable time, generally within 30 days.
For California residents
Under the California Consumer Privacy Act (CCPA), as amended by the CPRA, California residents have the rights described above plus the right to know what categories of personal information we collect and the right to non-discrimination for exercising privacy rights. We do not "sell" or "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA.
For residents of the European Economic Area, United Kingdom, and Switzerland
If you are in the EEA, UK, or Switzerland, the legal bases on which we process your personal information are:
- Performance of a contract — to provide the Service you've requested (operating your account, delivering invitations, recording your votes).
- Legitimate interests — to secure the Service, prevent abuse, and improve the platform, where these interests are not overridden by your rights.
- Consent — where we ask for it (e.g., optional integrations).
- Legal obligation — where required by law.
You have the rights described above, plus the right to lodge a complaint with a supervisory authority in your country of residence. Our processing involves transfer of personal information to the United States; we rely on appropriate safeguards for these transfers, including adequacy frameworks (where applicable) and standard contractual clauses where relevant.
10. Security
We use reasonable technical and organizational measures to protect personal information, including encryption in transit, access controls, and security monitoring. No service can guarantee complete security; transmission over the internet always carries some risk.
If we become aware of a security incident affecting your personal information, we will notify affected users without undue delay where required by law and where we have a means of contacting you.
11. Children
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us and we will take reasonable steps to delete it.
The Service may be used by educational institutions for student elections and learning activities. Schools using the Service for students under 13 are responsible for obtaining any consents required under the Children's Online Privacy Protection Act (COPPA) or other applicable law.
12. International users
The Service is operated from the United States. If you are using rcv-lab from outside the United States, you understand that your information will be transferred to, processed, and stored in the United States, which may have different data-protection laws than your country of residence. By using the Service you consent to this transfer, subject to the safeguards described in Section 9.
13. Automated decision-making
rcv-lab uses deterministic algorithms (Meek's method, WIGM, IRV, and similar) to tabulate ballots. These are not "artificial intelligence" or machine-learning systems, and tabulation does not involve profiling or automated decisions about individual users. The outcome of a ballot is determined by the votes cast and the tabulation method the ballot creator selected.
14. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If we make material changes, we will provide more prominent notice (such as a notification when you next sign in, or an email to account holders, depending on the change).
15. Contact
To exercise any of your rights or ask questions about this Privacy Policy:
Kaphan Foundation
P. O. Box 18801
Seattle, WA 98118
privacy@rcv-lab.org