Skip to main content

We the Citizens — Privacy Policy

Controller: ACT 3 AI, Inc., a Washington corporation, doing business as We the Citizens. General contact: ContactUs@ACT3ai.com. Privacy and data-rights contact: ContactUs@ACT3ai.com (subject line: "privacy request").


The Short Version

This is a summary. It is not the policy. Everything below it controls, and where the two differ the detail below wins. Nothing in this summary is true in a way the body contradicts — if you find a place where it is, that is a defect and we want to hear about it.

Your political positions stay on your own computer. We the Citizens is a local-first application. Your positions, values, evidence, and reasoning are flat files on your machine. We do not receive them, we cannot read them, we cannot restore them, and we cannot produce them to a government, because we never had them.

Recording your political opinions is what this product is for. That makes them special category data under Article 9 of the GDPR and the UK GDPR — the most protected class of personal data there is. We treat political opinion as sensitive everywhere in the world, by our own choice, and not because every jurisdiction makes us.

WE USE YOUR DATA TO TRAIN AI — ours, and other companies'. This is the most consequential thing on this page and we are not going to put it on page nine. Content that reaches us is used to train our own AI models, and it is also used to train AI outside our company. Training is irreversible: withdrawing consent stops future training, but nothing can be removed from a model already trained on it. Data that stays on your own machine is never trained on by anyone, because we never receive it — that is the one part of this product where training is impossible by construction, and it is the most important sentence in this policy. §11.

We do not share anything with campaigns, parties, political committees, PACs, or political data brokers. That promise is unaffected by the paragraph above and it is absolute. We do not sell your data as a mailing list to anyone. (Whether providing data to an outside party for AI training is legally a "sale" or "share" under California law is a question we have put to counsel and have not yet answered — so we are not making a flat "we never sell" claim on this page. §8.1.)

We show no advertising and run no analytics. As of 2026-08-19, an audit of every file in the application source — and a scan of all 559 packages it depends on — found no analytics service, no advertising pixel, no crash-reporting service, no session replay, no update check, and no telemetry of any kind.

The software contacts exactly two places, and you choose both. Your own machine, always. And Google, when you sign in — because you asked it to sign you in. That is the whole list. §3.5.

We keep no access log. There is no record of your network address, your browser, the pages you requested, or when. Not kept briefly, not kept anonymised — not written down at all. §9.2a.

AI is off unless you turn it on. The reasoning feature runs a local, offline, deterministic engine by default. Reaching an outside AI provider takes two deliberate acts by whoever installed the application, and out of the box neither has happened. §11.

When you ask what a government can get, here is the answer. Almost nothing — see §9. What we hold about a hosted account is an email address, a display name, a profile picture, and a session record. Your positions are not in that list, and no legal process can make them appear in it.

What you publish, you cannot fully un-publish. Publishing to a federated network sends copies to computers we do not run. We can delete our copy and ask others to delete theirs. We cannot promise it is gone. §10.

Getting your data out is easy, because most of it was never in. Your files are already on your disk, in a readable format, and you can delete them yourself without asking us. §17, §18.


Table of Contents

  1. The Short Version · 2. Who We Are and What This Policy Covers ·
  2. The Local-First Split · 4. The Data Map ·
  3. How We Use Data · 6. Legal Bases ·
  4. Political Opinions as Sensitive Data · 8. Sharing and Disclosure ·
  5. Law Enforcement and Government Requests ·
  6. Federation and Irreversibility · 11. AI Processing ·
  7. Payments · 13. Cookies, Tracking, and Analytics ·
  8. Children · 15. Security · 16. WeTheCitizens.tv and the VPPA ·
  9. Retention and Deletion · 18. Your Rights ·
  10. International Transfers · 20. Communications ·
  11. Community Mode and Publishing · 22. Governance and Accountability ·
  12. Changes to This Policy · 24. Contact

Appendices A–E follow the policy and are not part of it.


2. Who We Are and What This Policy Covers

2.1 The controller. ACT 3 AI, Inc., a corporation organized under the laws of the State of Washington, United States of America, doing business as We the Citizens, is the controller of the personal data described in this policy. In this document, "we", "us" and "We the Citizens" mean that company. Our general contact address is ContactUs@ACT3ai.com; our registered postal address is 16430 NE 50th Street, Redmond, WA 98052, United States of America.

2.1a THE SAME COMPANY OPERATES JFK SOCIAL, AND WE WOULD RATHER TELL YOU THAN LET YOU ASSUME OTHERWISE. ACT 3 AI, Inc. is the same legal entity behind JFK Social. "We the Citizens" is a brand and assumed name of that one company, not a second or separate corporation. Two brands does not mean two companies, and it does not mean two separate sets of records held by two separate controllers — one company is accountable to you for both, under this policy for this product and under JFK Social's own policy for that one. We say this because you are entitled to know which legal person holds your data, and because a reader who worked it out later would be right to wonder why we did not say it here.

2.2 What this policy covers. WeTheCitizens.io, the local application you run on your own computer, and — when it exists — WeTheCitizens.tv. It does not cover our sibling social network, which runs under its own privacy policy (§2.1a) and its own Terms of Service (Terms §3.1a).

2.3 WHAT EXISTS TODAY, STATED PLAINLY. This policy describes a product that is still being built, and we would rather say so than describe surfaces we do not operate. As of the last-modified date of this document, the following are not built and we operate none of them:

  • Surfaces — payments and subscriptions (§12), WeTheCitizens.tv and any video service (§16), publishing to a federated network (§10), and host-based party front doors (§7.4).
  • AI training — no training of any kind has taken place, ours or anyone else's (§11.6).
  • Your controls — the three Article 9 consents (§6.1), the switch that stops future training (§11.7), "Do Not Sell or Share" (§18.2), Global Privacy Control handling (§13.5), in-product rights-request buttons (§18.6), account deletion and retraction (§10.4), the publish-time irreversibility warning (§10.5), and self-service export (§18.8).
  • Things we owe you that need a person, not code — the queue behind the response deadlines at §18.5, the appeal reviewer at §18.7, the incident process behind §15.7, the sub-processor list at §8.5, and the transparency report at §9.9.

Each of those sections describes how the thing will work, written now so that the disclosure exists before the feature does. We will update this policy and give notice before any of them launches. Where a section describes something not yet built, it says so in its first line — and if you find one that does not, that is a mistake in this document and we want to hear about it at ContactUs@ACT3ai.com (subject line: "privacy request").

2.4 What this policy does NOT cover — other people's instances. We the Citizens is open source. Anyone can run their own copy, and many people do. If you are using an instance someone else runs, they are the controller of your data, not us, and this policy does not apply to you. Their practices are theirs. If you are not certain whose instance you are on, assume it is not ours and ask them.

2.5 Also not covered. Third-party services you connect, relays and media servers operated by others, other federated instances, and your identity provider's own handling of your account.

2.6 One policy, all front doors. If and when WeTheCitizens.io, WeCitizensR.com, WeCitizensD.com, WeCitizensL.com and WeCitizensSocialism.com operate as different front pages of one application, they are one product under one policy with identical data handling. A different door is a different page, never different treatment. See §7.4.

2.7 The local-client notice. For the application on your own machine, the honest answer to most questions in this policy is "this never reaches us." §3 is that notice, and it is the section to read first if you never create an account.

2.8 Processing on our own behalf, and on someone else's. Where we process data for our own purposes we are the controller and this policy governs. Where we process data on behalf of a community steward, they are the controller and their notice governs, not this one. §21.

2.9 Contacting us about privacy — and which address to use. The privacy and data-rights channel is ContactUs@ACT3ai.com (subject line: "privacy request") — see §24. It is the same mailbox as our general address, routed by subject line, and getting the subject line wrong forfeits nothing: a message that reaches us has reached us. What we cannot yet tell you is who reads it. No person has been named as responsible for answering inside the statutory deadlines at §18.5, and we would rather say that than let you assume otherwise.


3. The Local-First Split — What Never Reaches Us

3.1 Where your positions live. Your positions, values, evidence, reasoning chains, drafts, generated laws, and private notes are flat files in a directory on your own computer. They are created there, edited there, and stay there. There is no central server you must trust in order to use this product. The application is complete without an account and without us.

3.2 We do not have the technical means to read them. This is not a policy choice we could quietly reverse in a revision. The application does not transmit those files, and we operate no system that receives them. We cannot read them, search them, back them up, restore them, analyse them, or produce them to anyone.

3.3 What we will never say, and why we are saying that too. We will not tell you "we never collect your data" or "we cannot see anything," because both would be false the moment you create an account, contact support, publish something, or use an AI feature. The precise claim is the one in §3.1 and §3.2, and it is bounded by §3.4.

3.4 THE CROSSOVER MOMENTS — every point where data leaves your machine, named individually.

#MomentWhat leavesWhere it goes
1You sign inyour email, name and profile picture from your identity providerour hosted service, and your identity provider — §3.5a names the exact addresses
2You use an AI feature (only if it has been switched on — §11.1)the text of the position or reasoning being checkedthe AI provider
3You contact supportwhatever you write to usour hosted service
4You publish (not yet built — §10)what you chose to publishour hosted service, then the federated network
5You join a community (§21)your membership and what you contribute to itour hosted service and the community steward
6You pay us (not yet built — §12)billing detailsthe payment processor

If you do none of these six things, nothing about you reaches us at all. That is not a marketing sentence; it is a description of the architecture, and §3.5 is the evidence for it.

3.5 THE APPLICATION DOES NOT PHONE HOME. Audited 2026-08-19, and here is exactly what was audited. We examined every one of the 137 source files in the application and extracted every outbound address and every network call. The complete set of non-local addresses in the application source is one, and it is a comment in a code-generation file. Every network call the application itself makes goes to /api — the backend running on your own computer.

Specifically, and each of these is a thing many applications do and this one does not:

  • No analytics. No analytics product of any kind is present. (§13.2)
  • No crash-reporting or error-tracking service. Nothing is sent to a third party when the application fails. (§3.6)
  • No update check, no version ping, no feature-flag service, no licence check.
  • *No advertising or social pixel, no session replay, no keystroke or mouse-movement recording.
  • No access log. (§9.2a — this one is worth its own section.)

3.5a THE ONE EXCEPTION, AND IT IS SIGNING IN. We are naming it rather than letting §3.5 cover it. Sign-in is handled by a separate authentication component, and that component is not one of the 137 files above. It does contact the internet, and here is every address it uses:

AddressWhyWhen
accounts.google.com/o/oauth2/v2/authwhere your browser goes to sign you inonly when you choose to sign in
oauth2.googleapis.com/tokenexchanges the one-time code Google gives us for your identityonly when you choose to sign in
www.googleapis.com/oauth2/v3/certsfetches Google's public signing keys so we can verify that the identity really came from Googleonly on the sign-in path

None of these is telemetry, none carries anything you wrote, and all three happen only because you asked to sign in with Google — which is crossover moment #1 in the table above. We are separating this out because "the only address it contacts is your own machine" is a true sentence about the application, and a misleading one if you carry it across the sign-in boundary. We would rather give you the bounded version and the endpoint list.

3.5b WHAT THE AUDIT COVERED, AND WHAT IT DID NOT. We also scanned every one of the 559 software packages the application depends on and found no analytics, telemetry, crash-reporting, or session-replay product among them, and none among the components either half of the application declares directly. That scan matched package names, not behaviour — a component could in principle contact a server without a name that says so — and the audit was a reading of the code, not a recording of a running system. Both of those are on our own list to close, and we would rather tell you the shape of the evidence than let a strong sentence stand on more than it holds. This claim is dated and scoped to a version. We re-verify it at each release and we will say so if it ever changes — in advance, under §23.2, not in a quietly revised policy.

3.6 The one thing that looks like telemetry, and what it actually is. When the application hits an unexpected error in your browser, it sends the error message, the stack trace, and a short context label to the backend on your own machine, which writes it to a log file in your own state directory. A stack trace can contain fragments of what you were working on, so we disclose it — but understand what it is: the application writing a file to your own disk. Nothing is transmitted anywhere. The file is yours; you can read it and delete it. Its size is capped (§17.6).

3.7 What we cannot produce, and what that protects you from. There is no backup of your local files, no recovery, and no possibility of production under subpoena (§9.1). If you lose those files, we cannot help you get them back. The same fact that makes that true is what makes §9 true. It is a limitation and a protection at once, and you should understand both halves.

3.8 THE LAYER BENEATH US SEES THINGS WE DO NOT LOG. If you use a hosted service of ours, your connection passes through your internet service provider, our hosting provider, and any content delivery network or firewall in between. Those parties can see that a connection happened, from what network address, and to which hostname — including which front door you used — even where our own application never records it. We cannot prevent that; it is how the internet works. A no-logging claim that ignores the layer beneath it would be false, so we are not making one. See §7.4 and §9.2a.

3.9 If the boundary ever moves, you hear about it first. If we ever change what stays local and what reaches us, we will tell you in advance and, where the change affects special-category data, we will ask for fresh consent rather than relying on notice (§23.3).


4. The Data Map

4.1 The table. Verified against the application source on 2026-08-19. Rows marked UNVERIFIED describe a surface that is not yet built or a fact we have not yet confirmed, and the row says which.

CategoryExample fieldsWhere it livesPurposeLegal basisRetentionRecipients
Positions, values, evidence, reasoning, drafts, generated lawsyour own text and YAML filesLOCAL — your machine onlythe product itselfno basis needed — we are not the controller of data we never receivenever transmitted — stays on your device; you delete it yourselfnobody
Your local ledger / block recordsledger blocks, anchorsLOCALintegrity of your own recordas abovenever transmittednobody
Account identityemail address, display name, profile picture, Google subject id, whether your email is verified, your Workspace domain if you have one, rolesLOCAL in individual mode; HOSTED if you sign in to a hosted serviceto sign you in and know it is youcontract, Art. 6(1)(b)for the life of the session record — see the next rowyour identity provider (Google)
Session recordone file per session: session id, user id, email, name, roles, permissions, organisation, and four timestampsLOCAL / HOSTED — a file, permissions 0600so you stay signed in across restarts, and so a session can be revokedcontract, Art. 6(1)(b)retained as revoked after you sign out, not deleted — §4.4, §17.6nobody
Session cookiea short-lived signed tokenLOCAL / HOSTEDto keep you signed incontract, Art. 6(1)(b)until it expires and is refreshednobody
Application logstimestamps, log level, component, error messages and stack tracesLOCAL — files on your diskso the application can be fixed when it breakslegitimate interests, Art. 6(1)(f)5 MB per file, 5 rotations — then overwritten (§17.6)nobody
Network address (IP)your IP addresstransient — never written downto check a request came from your own machine, and to rate-limit error reportslegitimate interests, Art. 6(1)(f)not stored at allnobody
Hostname / front doorthe Host headertransient — never written down (and no front-door feature exists yet — §7.4)to check a request is locallegitimate interests, Art. 6(1)(f)not stored at allnobody
Access lognothingDOES NOT EXIST — §9.2ano record is creatednobody
AI request and responsethe position or reasoning text you asked to be checked, and the model's answerPROCESSOR — the AI provider, and only where the AI feature has been switched onto check your reasoning when you ask it toexplicit consent, Art. 9(2)(a) — consent 1we retain only the model name in your own record; the provider's own periods are in §11.5the AI provider
AI TRAINING DATA — our own modelspublished content only — see §11.6(c)HOSTED, then inside a trained modelto develop, train, fine-tune and improve our own AI modelsexplicit consent, Art. 9(2)(a)consent 2, separateirreversible once trained — §11.7. Withdrawal stops future training onlyus
AI TRAINING DATA — outside our companypublished content only — see §11.6(c)HOSTED → THIRD PARTIESso parties outside our company can train their AIexplicit consent, Art. 9(2)(a)consent 3, separate againirreversible once trained, and beyond our reach — §11.7No one yet - no party outside our company has received any of it, and none is named
Community membership and contributionswhich communities you joined, what you contributedLOCAL / HOSTEDto run community modecontract, Art. 6(1)(b), and Art. 9(2)(a) for the opinion contentfor the life of the membershipthe community steward, other members per §21
Support correspondenceyour email and what you wroteHOSTEDto answer youlegitimate interests, Art. 6(1)(f)UNVERIFIEDnobody
Published content (not yet built)whatever you publishHOSTED → FEDERATEDto publish it as you askedArt. 9(2)(e), manifestly made publicirreversible once propagated — §10the network, permanently
Billing (not yet built)plan, status, amounts, last four digits, brand, expiry, billing addressHOSTED / PROCESSORto charge youcontract, Art. 6(1)(b); legal obligation for taxtax period — UNVERIFIEDthe payment processor
Viewing data (not yet built)what you watchedUNBUILT — §16intended: never transmittedintended: nobody
Moderation records (not yet built)reports, enforcement actions, appealsHOSTEDabuse preventionlegitimate interests, Art. 6(1)(f)UNVERIFIEDnobody

4.2 What we deliberately do NOT collect. Verified against the source on 2026-08-19:

  • No date of birth. * No biometrics of any kind, including facial geometry — we do not collect, receive, possess, or have access to it. * No precise location. * No advertising identifiers. * No behavioural profile. * No session replay, and no recording of scrolling, clicks, mouse movement, or keystrokes. * No stored IP addresses. * No access log at all.
    • No purchased or enriched data about you from any third party, ever. * No political data broker file on you — see §8.4.

Every "no" in that list was checked against what the code actually does before it was written here, and each is re-checked before each release. None of it is a statement about training — see §11.6, which says plainly that we do train on data that reaches us.

4.3 What your identity provider actually sends us, and what it does not. When you sign in with Google we ask Google for exactly three things — openid, email, and profile — and nothing else. No access to your contacts, your calendar, your files, your mail, or anything else in your Google account is requested, and none could be granted by that scope. You can read the same three words on Google's own consent screen before you approve it, which is the point: it is a claim you can check against us rather than take from us. What comes back is your Google subject identifier, your email address and whether Google has verified it, your name and given/family name, your profile picture, and — if you sign in with a Google Workspace account — your organisation's domain.

4.4 YOUR SESSION RECORD IS A FILE, AND SIGNING OUT DOES NOT DELETE IT. Signing in writes one small file recording that session: its identifier, a user id derived from your Google subject, your email, your name, your roles and permissions, and the times the session was created, last used, last verified, and will expire. It is stored with permissions that allow only your own operating-system account to read it.

When you sign out, that file is not removed. It is rewritten with a "revoked" marker and kept. That is deliberate — a revoked session must not be re-creatable by a browser that still holds an old cookie — but it means the honest word is retained, not deleted. We have found no routine that removes expired or revoked session files, so they may accumulate. In the local application they are files on your own disk and you can delete them yourself (§17.6, §17.7). (An earlier version of this policy said session records were kept "until the session ends." That was wrong, and this is the correction.)

4.5 Metadata versus content, for anything we ever hold on your behalf. Where a hosted service holds an item for you, it may know that the item exists, when it was created and modified, and how large it is. That is different from being able to read it, and we state both halves rather than only the flattering one.

4.6 Data about people who never signed up. Your evidence and your reasoning will name real people — officials, politicians, public figures. That is personal data about them, and they have rights in it even though they never used this product. §11.4 and §18.9 say what those rights are and how they are exercised.

4.7 Combination and re-identification. If information that is not personal data on its own is combined so that it identifies someone, we treat the combination as personal data. We do not attempt to re-identify anything we have de-identified, and we do not permit anyone we share de-identified data with to do so either (§8.7).

4.8 A public/private list, itemised. When publishing exists (§10), this section will carry a binary, itemised list of exactly what publishing exposes and exactly what is never shown. It is not written yet because the feature is not built, and we will not describe the behaviour of something we have not implemented.


5. How We Use Data

5.1 To run your account and let you sign in. 5.2 To run the hosted service where you use one. 5.3 To publish what you asked us to publish, when publishing exists (§10). 5.4 To run the AI reasoning feature over the text you submit to it, when it is enabled (§11). 5.5 To keep the service secure and prevent abuse — including detecting inauthentic accounts and coordinated attempts to control a narrative, which the Terms of Service address at its §9. 5.6 To answer you when you contact us. 5.7 To meet legal obligations, including tax records and any mandatory reporting. 5.8 To fix the product when it breaks, using the local log files described at §3.6. 5.9 To train AI — ours, and other companies'. §11.6, and it is not buried in this list.

5.10 WHAT WE NEVER USE YOUR DATA FOR. Each of these was verified against the product before it was written:

  • We never sell it as a mailing list, a contact list, or a voter file, to anyone. §8.1 states the one open question about the legal meaning of "sale" and does not paper over it.
  • We never target advertising at you — we run no advertising at all. §13.4.
  • We never target anything on your political opinion, and there is no profiling engine in this product.
  • We never share it with a campaign, a party, a political committee, a PAC, or a political data broker. §8.4.
  • We never run behavioural analytics or session replay over your positions. There is no analytics of any kind. §13.
  • (Training is NOT on this list, and §5.9 above is where it is instead. We do train on data that reaches us, and it is also used to train AI outside our company. See §11.6 — we are not going to hide that inside a list of things we never do.)

5.11 Product improvement. We improve the product from the local error logs at §3.6 and from what you tell us directly. We run no A/B testing, no experiments, and no usage measurement, so there is no anonymous-analytics section here to read. If that ever changes, §23.2 applies and the product used will be named in §13.2.


6.1 EXPLICIT CONSENT FOR YOUR POLITICAL OPINIONS — Article 9(2)(a). (The consent mechanism described in this section is not built yet — see §2.3. Nothing you write reaches a hosted service or an outside AI provider today: your positions are files on your own computer (§3.1–§3.2), and the live AI engine is off unless someone supplies an API key and installs a component we do not ship (§11.1). This section states the basis we will rely on, and the controls you will have, before either of those changes — not after.)

Where we process your political opinions — which is what happens the moment any of it reaches a hosted service or an AI feature — we will rely on your explicit consent.

That consent will be separate from accepting the Terms of Service. It will not be bundled with signup, it will not be a pre-ticked box, and accepting the Terms will not give it. It will be asked for on its own, in its own words, at the moment it is needed, and it will name what it covers. You will be able to withdraw it at any time, and withdrawing it will be as easy as giving it — one control, in the same place. If you withdraw it we stop the processing it covered; §6.7 says honestly what withdrawal cannot undo. The Terms say the same thing from their side, at their §7.2C: the licence you grant is not the consent, and this policy controls on that question.

AND THERE WILL BE THREE OF THESE CONSENTS, NOT ONE. Recording your political opinions, training AI on them, and sending them outside our company so other parties can train on them are three genuinely different things, so we will ask you three separate times:

ConsentCovers
1. To recordholding your political positions on a hosted service at all
2. To trainusing them to train our own AI models (§11.6)
3. To train outsideproviding them to parties outside our company for their AI training (§11.6)

Consent to record is not consent to train, and consent to train is not consent to train outside our company. Each will be asked separately, each will be refusable on its own, and each will be withdrawable on its own without affecting the others. None of the three exists today, and no political opinion of yours reaches us until they do.

6.2 Manifestly made public — Article 9(2)(e). For content you deliberately publish, we also rely on the condition for data a person has manifestly made public. This covers only what you chose to publish. It does not cover a position sitting in a file on your own machine, it does not cover anything you drafted and did not publish, and it does not cover an inference about your leaning. §7.10 explains where the line falls and when you cross it.

6.3 Contract — Article 6(1)(b). Your account, your session, and (when built) your subscription and billing.

6.4 Legitimate interests — Article 6(1)(f). Security, abuse prevention, service integrity, and fixing faults. We carry out and record a balancing test for each of these rather than asserting the basis; you may ask us for the assessment (§18.1).

6.5 Legal obligation — Article 6(1)(c). Tax and accounting records, mandatory reporting where it applies, and responding to valid legal process.

6.6 Consent — Article 6(1)(a). Anything optional: non-essential cookies (we currently set none — §13.1) and any marketing email.

6.7 Withdrawing consent, and what it cannot undo. Withdrawal stops future processing. It does not reach: content already published and propagated to a federated network, which we cannot recall (§10.2); records we must keep by law (§12.4); or anything a model was trained on, which cannot be untrained (§11.7). We tell you this before you consent, not after you withdraw.

6.8 Where the basis is stated. Each basis is named in the section describing the processing it covers, and again in the table at §4.1, so you can see which basis covers which use without holding two sections in your head at once.


7. Political Opinions as Sensitive Data

7.1 This is the product, not a side effect. We the Citizens exists so that a citizen can record what they believe about how their society is governed, reason it through, and act on it. Your political opinions are the content of this product. We are not going to bury that in a data-categories list.

7.2 That makes them special category data. Under Article 9 of the GDPR and the UK GDPR, "political opinions" are special category data — processing is prohibited unless a specific condition applies. §6.1 and §6.2 say which conditions we rely on and for what.

7.3 An inference is treated exactly like a statement. If anything about how you use this product would let us infer a political leaning, that inference is special-category data just as much as a position you typed, and it gets identical treatment. We do not treat "we only inferred it" as a lesser category.

7.4 THE FRONT DOOR IS ITSELF A POLITICAL DISCLOSURE — and here is exactly where we stand today. The plan for this product includes four party front doors — WeCitizensR.com, WeCitizensD.com, WeCitizensL.com and WeCitizensSocialism.com — as different front pages of one application. A citizen who arrives at one rather than another has disclosed a political affiliation by hostname alone, before doing anything at all. No comparable platform has this problem, and we are not going to pretend it is not there.

What is true today, as audited on 2026-08-19: this feature does not exist. There is no edition concept, no host-based routing, and no party page in the application. The Host header is read in exactly one way — to check whether a request came from your own machine — and the value is compared and discarded, never written to any log or record. There is no access log for it to be written to (§9.2a).

What we commit to, rather than what we hope. We will not promise never to build it. We commit that if host-based editions ship, this policy is updated and notice is given before they go live, because that is the moment we would begin processing inferred special-category data at first request. And §3.8 already applies regardless: our host and any CDN see the hostname you connected to even where our application never records it, and no policy of ours changes that.

7.5 Extra safeguards for this category. Access is restricted to the people who need it for a named purpose (§15.6). It is never used for advertising (we have none), never enriched from a third-party source, and never used to profile you for targeting.

7.6 We treat political opinion as sensitive everywhere, by choice. GDPR and UK GDPR compel it. Most US state statutes do not — see §18.3. We apply the same protection worldwide anyway, as a matter of our own policy. We say "by choice" rather than claiming every jurisdiction requires it, because the first is true and the second is not.

7.7 We do not say "we do not process sensitive information." Several political publishers write exactly that sentence while collecting reading history and selling inferences. For us it would be false on the first screen of the product, and we would rather tell you what we do with sensitive data than deny holding any.

7.8 The narrower claim we do make. We do not use or disclose your political opinions for any purpose other than those in §5 — which is a purpose-limited statement we can stand behind, rather than a denial that we hold them.

7.9 Never filed under a friendlier heading. We do not classify political opinion as "demographic data" or any similar marketing category, and we do not process it on legitimate interests. It is named for what it is and it runs on Article 9.

7.10 Crossing from private to published. The moment you publish, the basis changes from your explicit consent (§6.1) to data you have manifestly made public (§6.2), and the consequences become irreversible (§10). We surface that at the moment you publish, in the product — not afterwards, and not only in this document.

7.11 The DPIA. None has been carried out yet, and one is in preparation — §22.6.


8. Sharing and Disclosure

8.1 SELLING — WHAT WE PROMISE, AND THE ONE QUESTION WE HAVE NOT ANSWERED.

What we promise flatly, with no exception: we do not sell, rent, licence, or trade your personal information as a mailing list, a contact list, a voter file, or a marketing audience, to anyone, ever. We take no money for access to you.

The question we are not going to pretend is settled. We provide data to parties outside our company for AI training (§11.6). The CCPA and CPRA define "sell" and "share" broadly — they reach disclosure for valuable consideration and for cross-context use, and money need not change hands. Whether that arrangement is a "sale" or a "share" in that technical sense is a question we have referred to counsel and have not yet resolved. Until it is resolved we are not making the flat "we do not sell your personal information" claim that this section used to carry, because we would rather leave a visible open question than make a statement we cannot yet stand behind. The Terms of Service say the same at their §7.11, and point at this section as the controlling one.

What that means for you in the meantime, and it is the safer outcome for you: we are treating it as though it were a sale and a share. You may opt out — see §18.2 and the "Do Not Sell or Share My Personal Information" control — and opting out costs you nothing, under §18.2's non-discrimination rule. If counsel concludes it is a sale, this section is rewritten and the opt-out becomes a formal legal right rather than a voluntary one. If counsel concludes it is not, the opt-out stays anyway.

8.2 Service providers, by category. Where we use one, it is: hosting, payments, email, media/CDN, and the AI provider. We list no vendor we do not use, which is why this list is short — most of those categories are empty today because the surfaces that would need them are not built (§2.3).

8.3 Who we actually share with today. As of the last-modified date: your identity provider (Google, if you sign in — §3.5a, §4.3) and the AI provider (only where the AI feature has been switched on — §11). That is the complete list.

8.4 NO SHARING WITH CAMPAIGNS, PARTIES, COMMITTEES, PACs, OR POLITICAL DATA BROKERS. Ever. There is an industry — NationBuilder, NGP VAN, i360, Aristotle, L2, Catalist and others — whose business is building files on voters' political affiliations and selling access to them. We are not in that business, we do not buy from it, we do not sell into it, and we do not enrich anything we hold from it. For this product that promise is worth more than any feature, and it is written as an absolute rather than as a default with exceptions.

8.5 The sub-processor list. (Not published yet — see §2.3.) We will publish the sub-processors we use, with purpose, processing location, and transfer safeguard for each, and keep it current. No list exists today, and until one does the only processor we rely on is the AI provider named at §11.2. Where our AI provider is listed, note that it has sub-processors of its own — the chain runs two levels deep, and we say so rather than stopping at a vendor name (§11.9).

8.6 Publication at your direction. When publishing exists, what you publish goes where you told it to go, and §10 governs.

8.7 Aggregated and de-identified data. Where we ever aggregate or de-identify, we say so, we do not attempt re-identification, and we contractually bind anyone we give it to not to attempt it either. We also tell you the limit honestly: de-identification is not a guarantee, and a small enough population can be re-identified from data that looks anonymous.

8.8 Corporate transactions. In a merger, acquisition, or insolvency, data may transfer to a successor. The successor is bound by this policy as it stood, and a change to how special-category data is used requires fresh explicit consent under §23.3 — it is not something an acquirer can simply announce.

8.9 Researchers and academics. We intend to offer a deliberate, on-terms access channel for independent research using aggregated, de-identified data only, published on our terms rather than conceded later under pressure. It does not exist yet.

8.10 Every limit is written as a carve-out, not a slogan. Where this section says we do not share something, it names the exceptions in the same sentence — because a bare denial reads as marketing and a denial with its exceptions reads as a commitment.


9. Law Enforcement, Government Requests, and Transparency

This section will be read closely by exactly the people we most want to trust us. It is written for them.

9.1 START HERE: WHAT WE CANNOT HAND OVER, BECAUSE WE NEVER HAD IT. It is not possible for us to produce your positions, your values, your evidence, your reasoning chains, or your drafts in response to any legal request, because we do not have them. They are files on your computer. No warrant, subpoena, court order, national security process, or foreign request can compel us to produce data we never received. This is not a policy we could be persuaded to change; it is a consequence of how the product is built (§3.2).

9.2 The short list of what we could actually produce. Under valid legal process, for a hosted account, the complete set is: your email address, your display name, your profile picture, the identifier your login provider gave us, your session records, and any support correspondence you sent us. When billing exists it adds subscription records (§12). That is the whole list, and its shortness is the point.

9.2a AND THERE IS NO ACCESS LOG — WE DO NOT HOLD ONE AT ALL. Most services can be asked for a history of when an account connected, from which network address, with which browser, and which pages it requested. We cannot, because we do not create that record in the first place. Audited 2026-08-19: the application has no request-logging component of any kind — no IP address, no browser or device string, no requested path, no referring page, no hostname, no timestamp is written per request. The only thing a request can produce in a log is a failure, recorded as the error and the status code, on your own machine.

This is not a retention promise that could be quietly shortened, and it is not anonymisation. The record does not exist, so there is nothing to hand over, nothing to subpoena, and nothing to breach. Read it together with §3.8: the layer beneath us — your internet provider, our host, any CDN — does see connections, and they are not bound by this policy.

9.3 What we require. Valid legal process, properly served, from an authority with jurisdiction. We object to overbroad, vague, or improperly issued requests, and we narrow them where we can. We use legal means to resist disclosure where there are grounds to, and we continue until the available remedies are exhausted.

9.4 We tell you. We notify you before disclosing anything about you, so that you have the opportunity to object — unless we are legally forbidden from doing so, or there is an emergency under §9.5. Where a gag order prevents notice, we notify you as soon as it lapses. There is no "with or without notice to you" escape hatch in this commitment.

9.5 Emergencies. We may disclose without prior notice only where we believe in good faith that there is a genuine risk of death or imminent serious bodily harm to a person, and only the information relevant to preventing it.

9.6 Mandatory reporting we cannot refuse. Child sexual abuse material must be reported to the National Center for Missing and Exploited Children under 18 U.S.C. §2258A. We comply and we do not notify the account.

9.7 Foreign and cross-border requests. We require a recognised route — a mutual legal assistance treaty, letters rogatory, or an equivalent — and do not treat a foreign request as self-executing.

9.8 National security process. We say what we are lawfully permitted to say, and no more. Where we are permitted to publish only a range rather than a number, we publish the range.

9.9 Transparency report. We intend to publish, on a stated cadence, the number of requests received, the number complied with in whole or in part, and the number refused. It does not exist yet.


10. Federation and Irreversibility

10.0 Not yet built. Publishing to a federated network is not implemented as of the last-modified date. Today, "publishing" inside the application sets a flag on your own record and sends nothing anywhere. This section is written before the feature ships, because the one thing a citizen must understand about federated publishing is something they need to know before they use it.

10.1 What publishing will do. Content published to a federated network is copied to relays, media servers, and instances operated by other people, not by us. It propagates automatically and quickly.

10.2 WE CANNOT DELETE IT. Once content has propagated, deleting our copy does not remove the copies held by anyone else. Other operators may honour a deletion request, may ignore it, may be offline, or may have already been archived by a third party. We will not describe a downstream deletion request as a deletion, because it is not one.

10.3 What a deletion request actually does. We delete our copy, and we send a deletion request downstream where the protocol supports one. That is the whole of what we can do, and we would rather tell you that plainly than let the word "delete" imply more.

10.4 Two separate controls, not one ambiguous button. You will have "delete my account" and "retract my published position" as distinct actions with distinct wording, because they do different things and one does not accomplish the other. Deleting your account does not retract what you published.

10.5 The warning will come at posting time. (Not built yet — see §2.3; publishing does not exist either.) The fact that a published position becomes part of a permanent public record will be shown to you at the moment you publish — not left to be discovered later in a deactivation screen.

10.6 Public keys, relay lists, and media URLs are data, and they are public. They can be used to link your activity across services. Publishing under a key associates everything published under that key.

10.7 Other instances are separate controllers. Operators of relays, media servers, and other instances decide for themselves what they keep and for how long. They have their own policies, and we have no authority over them.

10.8 Information you make public loses protections. Personal data you deliberately make public is not subject to the same legal protections as data you keep private. That is a consequence of publishing, not a policy of ours.


11. AI Processing

11.1 THE AI IS OFF UNLESS SOMEONE TURNS IT ON — AND OUT OF THE BOX IT IS OFF TWICE OVER. Verified against the source on 2026-08-19. The reasoning feature has two engines: a deterministic, offline engine that runs entirely on your own machine, and a live engine that calls an outside provider.

Reaching the outside provider requires two separate deliberate acts by whoever installed the application: an API key must be supplied, and the provider's software component must be installed, because it is not part of the application as distributed. Neither has happened in a standard installation. With either one missing, no AI call is ever made and your text never leaves your computer. Every failure of the live engine — no key, no component, no network, an error, an unusable answer — falls back to the local engine.

11.2 Which provider, and what is sent. Where the live engine is enabled, the provider is Anthropic and the model is a Claude model. What is sent is the text of the position or reasoning you asked to have checked — which means your political opinions are the payload. A single request is sent; nothing else about you accompanies it.

11.3 What WE keep of it. We record the name of the model that answered in your own decision record, on your own machine. We do not store the request or the response anywhere else.

11.4 AI output about other people. A reasoning chain may conclude something about a named official or public figure. That output is personal data about that person, and they have rights in it even though they never signed up. §18.9 says how they exercise them. Nearly every AI product's policy ignores this; ours does not.

11.5 What the PROVIDER keeps, and this is not ours to promise away. Everything we can truthfully say about the provider is bounded by the provider's own contract, and here is what it says today:

  • The PROVIDER does not train on inputs — but WE DO. Read those two facts together. The commercial terms we would operate under state that the provider may not train models on customer content. That is a contract term, not a policy statement, which is why we are willing to repeat it — and it is a fact about the provider, not about us. We train. See §11.6. Neither sentence is complete without the other.
  • This depends on being on the commercial surface. The same provider's consumer service trains on inputs unless the user opts out. An opt-out default is not valid consent for special-category data. This is the single most important fact for you to be able to rely on, and the one we must verify per deployment.
  • Retention: 30 days by default. Inputs and outputs are deleted from the provider's systems within 30 days.
  • THE LONGER TAIL, WHICH YOU SHOULD KNOW ABOUT. If the provider's automated safety systems flag a request, the provider retains the inputs and outputs for up to 2 years and a safety classification score for up to 7 years. Political content is exactly the sort of content most likely to trip such a classifier. That classification is an inference about your political speech, held by a third party, triggered by a system neither you nor we can see, and it survives any deletion we perform. We are telling you because you cannot find it out any other way.
  • We cannot guarantee deletion at the provider. We can ask. We cannot promise.

11.6 WE TRAIN AI ON YOUR DATA — OURS, AND OTHER COMPANIES'. Read this section twice.

This is the most consequential disclosure in this policy, and it is also in the summary at the top (§The Short Version) because it is too important to be found only here.

(Not yet in operation — see §2.3. No training has taken place, because nothing you write reaches us today (§3.2, §11.1). We are publishing this before the practice starts rather than after, so that you can decide with it in front of you. Everything below is what we will do.)

(a) We will train our own models. Data that reaches us will be used to develop, train, fine-tune, and improve our own AI and machine-learning models.

(b) It will also be used to train AI OUTSIDE our company. We intend to provide data to parties outside our company for their own AI training. This is a separate fact from (a), it carries more weight than (a), and we are stating it on its own line so it cannot be missed inside the first one. None of it has happened: no data has left our company for this purpose, no such party is named, and no such agreement exists. Before any of that changes we will name the recipients here, give the notice at §23.2, and ask you for consent 3 (§6.1).

(c) WHAT IS AND IS NOT INCLUDED — published content only. Nothing else. Not the text you type into an AI feature, not positions held privately on a hosted service, not community contributions, and not support correspondence. If we ever widen this list we will name the new category here and give the notice at §23.2 first — we will not describe it as "your data" and leave you to guess.

(d) WHAT IS NEVER TRAINED ON, BY ANYONE — and this is the part to hold on to. Data that never leaves your computer cannot be trained on by us or by anybody else, because we never receive it. Your local positions, values, evidence, reasoning chains, drafts, and private notes are outside all of this by construction, not by promise (§3.1–§3.2). It is not a policy we could reverse. If you want certainty that something is never used to train an AI, do not publish it and do not submit it to an AI feature — and then nothing else you do matters. The local-first split was always this product's best privacy feature. It is now its most important one.

(e) It will be consented, separately, and you can refuse. Training will require consent 2 under §6.1, and training outside our company will require consent 3. Each will be asked on its own, each refusable without losing the other, and each withdrawable on its own. Until those consents exist and are given, no training happens at all. The Terms of Service grant us the licence to do this at their §7.2A, and say expressly at their §7.2C that the licence is not the consent and that where the consent is absent or withdrawn the licence is not exercised.

(f) Do not confuse our AI vendor's promise with ours. §11.5 says our AI vendor's commercial terms state that the vendor may not train on what we send it. That is a fact about them. It is not a fact about us. We do train. Both sentences are true at the same time and we are putting them next to each other so that neither can be read alone.

11.7 TRAINING IS IRREVERSIBLE — THE SAME ONE-WAY DOOR AS PUBLISHING. Once data has been used to train a model, it cannot reliably be removed from that model. This is not a limitation of our diligence; it is a property of the technology, and AI providers say so themselves — correction is a reasonable-effort obligation that "may not always be possible," and rights over training data "have technical limitations."

So be clear about what withdrawing consent will do. Withdrawing consent 2 or consent 3 will stop future training. It does not remove anything from a model already trained, and it does not reach a model an outside party has already trained. We will never describe a training-data deletion request as a deletion, exactly as we will never describe a federated deletion request as one (§10.2–§10.3). The Terms of Service say the same at their §18.6A.

This product now has three one-way doors, and you should know all three before you use it: publishing to a federated network (§10.2), anything already inside an AI vendor's systems (§11.5), and training (this section). Everything you keep local passes through none of them.

11.8 No provider protects the sensitivity — only we do, and now the same applies to whoever we train with. We read the published terms of five major AI providers. Not one of them mentions Article 9, special-category data, or political opinions at all. Their commitments cover training, retention, access, and location — none covers the fact that what is being processed is a citizen's political belief. Choosing a careful vendor does not discharge that obligation, and neither does choosing a careful training partner. Any party outside our company that receives data for training is bound by contract to training only, may not re-share it, and may not use it to identify or contact you — the Terms of Service impose that at their §7.2B. That is a contractual protection, and we are telling you plainly that it is a weaker guarantee than the architectural one at §11.6(d).

11.9 The chain runs two levels deep. Our AI provider has its own sub-processors — cloud and network infrastructure across many countries. We name them in the sub-processor list (§8.5) and subscribe to the provider's change notifications so that list stays true.

11.10 Human review at the provider. Where a provider's safety systems flag content, a reviewer may see it. We disclose the controls the provider publishes — flagged-content-only access, per-request queries, hardened workstations, and approval by a manager — and, where available, which jurisdiction those reviewers sit in.

11.11 The AI can be wrong, and the correction route is a rights route. AI output may be incorrect, incomplete, or fabricated. Your right to rectification applies to inferences, not just to facts — you can challenge a conclusion the AI reached, and so can a person the AI wrote about. It is the same channel as reporting a mistake (§24.6), on purpose.

11.12 No automated decisions about you. No decision producing legal effects or similarly significant effects is made about you by automated means. The AI advises you; it does not decide anything about you, and it does not gate access, price, moderate, or rank you. If automated moderation is ever introduced, this section changes before it launches.


12. Payments

12.0 Not yet built. There is no payment processing in the product as of the last-modified date — no processor is integrated and no billing data exists. This section is written in advance and takes effect when payments launch.

12.1 What the processor gets and what we get. Your full card number goes to the payment processor and never to us. We receive and store: a processor token, the last four digits, the card brand, the expiry date, and your billing address. We say exactly that rather than "we do not store payment information," which is usually not quite true. That is the same list, field for field, as the Terms of Service §15.14 — deliberately, because a card-field list that differs between two of our own documents is the tell that one of them was not checked.

12.2 The processor is its own controller. It processes your payment data for its own purposes under its own privacy policy, and those purposes are not ours to control.

12.3 One record per subscription. Where you hold several concurrent subscriptions, each has its own billing record. Cancelling one does not cancel the others, and deleting your account does not cancel any of them — each is cancelled separately. That means a billing record can outlive an account-deletion request; the Terms of Service says the same thing at its §15.

12.4 TAX RECORDS OVERRIDE YOUR DELETION REQUEST, AND YOU SHOULD KNOW THAT UP FRONT. We are required to retain invoices and accounting records after you delete your account, and we set our retention period at seven years — long enough to cover every ordinary statutory window that can apply to us, rather than the shortest one. This is a genuine conflict between your erasure right and a legal obligation, and the obligation wins. What it means in practice: those records are locked away and are not accessed or used by anyone during that period, except to meet the legal obligation itself or in a dispute — and when the period expires they are permanently deleted.

12.5 Chargebacks. A dispute creates a record shared with your card network and the processor.

12.6 Donations. We do not currently take donations. If we ever do, and if any donation is politically reportable, disclosure of your identity may be legally mandatory — that is a privacy consequence you must be told about before donating, not after, and we will surface it at that point. We claim no nonprofit or tax-exempt status, so a donation record is a commercial record retained on the basis at §12.4 and never presented as a charitable-giving record.

12.7 We remove payment details we no longer need. Where a stored card is no longer valid or no longer needed, we delete it rather than holding it until someone asks.


13. Cookies, Tracking, and Analytics

13.1 What we set. A session cookie, so that you stay signed in. On a hosted service it is marked Secure. That is the only cookie the application sets, and it is strictly necessary. There are no non-essential cookies, so there is no consent banner to click through — because there is nothing to consent to.

13.2 Analytics: NONE. We run no analytics product of any kind. Verified against the source on 2026-08-19, and against all 559 software packages the application depends on — no analytics library of any kind is present in either. If we ever adopt one it will be a self-hosted, IP-anonymising installation, we will name the product here, and §23.2 notice applies first.

13.3 No third-party or social pixels. None. No advertising pixel, no social widget, no tracking beacon, no third-party script that reports on you.

13.4 No advertising. We do not show advertising anywhere in this product, which is why most of the machinery a privacy policy usually needs — ad identifiers, targeting opt-outs, interest categories, cross-context behavioural advertising disclosures — has nothing to describe.

13.5 Global Privacy Control and Do Not Track. (Not built yet — see §2.3. No handler for either signal exists in the application today.) We will honour the Global Privacy Control signal as an opt-out. We run no advertising and no analytics, so there is nothing there for it to switch off today — but it will not be a decorative commitment. Because we treat providing data to outside parties for AI training as a "share" pending counsel (§8.1), a GPC signal will be honoured as an opt-out of consent 3 (§6.1, §11.6) from the moment consent 3 exists. We state our Do Not Track position rather than dismissing it: we will honour it the same way.

13.6 No pixel anywhere near video. When WeTheCitizens.tv exists, no advertising or analytics pixel goes on any page where video plays. This is a legal landmine, not a preference — §16.

13.7 Local storage on your device. The application stores your session and interface preferences locally in your browser. It is on your machine, it is not transmitted, and clearing your browser storage removes it.

13.8 Email tracking. We do not use open tracking or click tracking in email.


14. Children

14.1 Minimum age. You must be at least 18 years old to create an account. This is the same number as the Terms of Service §4.1, and it is stated identically in both documents.

14.2 The absolute floor. No accounts for anyone under 13, and we do not knowingly collect personal information from anyone under 13, regardless of the minimum age stated above.

14.3 If we learn of one. We delete the account and the associated data. A parent or guardian can contact us at ContactUs@ACT3ai.com (subject line: "privacy request") to ask about, correct, or delete a child's data.

14.4 COPPA and the children's codes. We comply with the Children's Online Privacy Protection Act. Where we serve minors at all, the UK Age Appropriate Design Code and equivalent EU requirements apply.

14.5 What age assurance we actually do. We currently do no age verification beyond asking. We say what we do rather than what we wish we did.


15. Security

15.1 What we actually do. Data in transit to a hosted service is encrypted with TLS, and Secure cookies and strict transport security are enforced in hosted mode. The session signing secret is generated per installation from cryptographically random bytes and written with owner-only file permissions, as is every session record. Access to any production system is limited to people who need it. Application input that reaches a log is sanitised against injection, length-capped, and rate-limited.

15.2 The strongest security control in this product is that we do not hold your data. Data we never receive cannot be breached at our end. The second strongest is that we keep no access log (§9.2a): a record that does not exist cannot leak. Local-first is a privacy design, but it is a security one too.

15.3 We claim no certification. We do not hold SOC 2, ISO 27001, or any other security certification, and we will not imply one. If we ever obtain one we will name the auditor and the scope.

15.4 We do not promise your data is safe. No system is perfectly secure and we will not tell you otherwise. We use reasonable technical and organisational measures. That is a real commitment and it is not a guarantee.

15.5 Your side of it. Your account is only as secure as your login. Use multi-factor authentication with your identity provider. And note the local-first consequence: the security of your positions is the security of your own computer — its disk encryption, its screen lock, its backups, and the permissions on your own files. We cannot protect files we never receive.

15.6 Who can see special-category data. Access to any system holding political opinions is restricted to named people for a named purpose, and reviewed. Where a third party can ever see such content — the AI provider's safety review is the only case today — §11.10 says under what controls.

15.7 Breach notification, with real deadlines. If a breach affects your personal data we will notify the relevant supervisory authority within 72 hours of becoming aware of it, where GDPR requires, and notify you without undue delay where the breach is likely to result in a high risk to your rights. (These deadlines bind us now. The written incident process behind them is still being put in place, and we would rather say so than imply a drill has been run.) State-law deadlines apply where they are shorter — including Washington State's, since that is where the controller is incorporated (§2.1). We will not promise "immediate" notice, because that is a word nobody can keep and it tells you nothing.

15.8 Reporting a vulnerability. Report security issues to ContactUs@ACT3ai.com (subject line: "privacy request"). We will not pursue legal action against good-faith security research conducted within a reasonable disclosure process.

15.9 Data pending deletion. Where data is awaiting deletion in a backup, it is isolated from any further processing until the backup rotates. It is not used for anything in the meantime.


16. WeTheCitizens.tv and the Video Privacy Protection Act

16.0 Not yet built. There is no video service, no viewing data, and no .tv surface in the product as of the last-modified date — verified against the source on 2026-08-19. This section states the rules that will govern it before it is built, deliberately, because the statute below makes retrofitting expensive.

16.1 What we intend to keep: nothing that leaves your machine. Designed local-first, your viewing history need never reach us at all. Where that holds, the honest answer to "who gets your viewing data" is nobody, and the disclosure trigger of the statute below is never pulled.

16.2 THE VIDEO PRIVACY PROTECTION ACT — 18 U.S.C. §2710. The VPPA restricts disclosing a consumer's video-viewing history. It carries statutory damages of $2,500 per violation and a private right of action, and it is one of the most actively litigated privacy statutes in the United States. The typical defendant is a site that placed a third-party pixel on a page where video plays. The operational rule that follows is absolute: no advertising or analytics pixel, tag, or beacon goes anywhere near viewing data.

16.3 For us it is doubled. A viewing history on a political video service is both VPPA-protected and a revealed political opinion. Two statutes over one data set, which is why this section is stricter than a normal streaming service's.

16.4 If viewing data ever leaves us, it goes only under separate, standalone, revocable, VPPA-form written consent — not under this policy, not under the Terms of Service, and not bundled with anything else.

16.5 No "because you watched," anywhere. No viewing-derived recommendation, title suggestion, or interest signal is surfaced to any third party, partner interface, or recommendation exchange.

16.6 Purchases and rentals. Where pay-per-view exists, a purchase record is a billing record under §12 and is retained on that basis — separately from viewing behaviour, which is not retained at all.


17. Retention and Deletion

17.1 The table. Organised by where the data lives, because for this product that is the fact that matters most.

WhereDataHow long
Your machinepositions, values, evidence, reasoning, drafts, laws, ledgerNever transmitted. Yours indefinitely, and yours to delete. We hold nothing and can delete nothing.
Your machineapplication and error logs5 MB per file, 5 rotations kept, then overwritten automatically. Delete them yourself at any time. §17.6.
Your machine / hostedsession recordsRetained after sign-out, marked revoked — not deleted. No automatic cleanup exists. §4.4, §17.6.
Hostedaccount identitylife of the account, then §17.3
Hostedaccess lognone is created — §9.2a
Hostedsupport correspondencenot yet established
Hostedmoderation and abuse records (not built)not yet established
Hostedbilling and tax records (not built)7 years — overrides deletion (§12.4)
ProcessorAI request and response30 days; 2 years if flagged; 7 years for a safety classification score (§11.5)
Federatedpublished content (not built)permanent and beyond our reach (§10.2)
Inside a trained modelwhatever was trained onpermanent — cannot be untrained (§11.7)

We would rather show you an UNVERIFIED row than invent a number. A retention period we made up because it sounded reasonable would be a false statement about our own practices, and those rows are exactly the rows we are working to close.

17.2 The outer bound. No purpose described in this policy requires us to keep personal information about you for longer than you have an account, except the specific survivals listed at §17.3.

17.3 What account deletion removes, and what survives it. Deleting your account removes your account identity, your sessions, and your hosted content. It does not remove:

  • content already published and propagated to a federated network — we cannot recall it (§10.2);
  • records we must keep for tax and accounting — locked and unused until they expire (§12.4);
  • moderation and abuse-prevention records, including identifiers kept to prevent ban evasion, which we disclose here before we do it rather than afterwards;
  • backups, until they rotate — with the data isolated from further processing in the meantime (§15.9);
  • a safety classification score held by our AI provider for up to 7 years, if one of your requests was flagged (§11.5). This is not ours to delete.
  • anything a model was trained on, which cannot be untrained — ours or an outside party's. Deleting your account stops future training; it does not reach a model already trained on your data, and we cannot recall data an outside party has already used (§11.6, §11.7).

The Terms of Service list the same survivals at their §20.5, and say the same thing about retention obligations overriding a deletion request.

17.4 What "deleted" means, named store by store. When we say we delete something, we mean it is removed from the live database, from any cache, and from the working stores that serve it — and from backups when they next rotate. We name the stores rather than leaving "deleted" as an unqualified verb. Where something is kept rather than deleted, we say "retained", and §4.4 is the case where that distinction actually bites.

17.5 Post-closure deletion timing. (Not yet established.) Where a number is published it will be in days, not "promptly."

17.6 Your local files, and the three of them that are ours to explain.

  • The application's own two log files — everything, and the fault trail — are capped by the application at 5 megabytes each with 5 rotations kept, then the oldest is overwritten.
  • The launcher's console log is capped the same way, at the same numbers — but by the start-up script rather than by the application, and its limits can be changed by whoever starts it. If you launch the application some other way, you get the application's two caps and not this third one. We are separating them because "all logs are capped at 5 MB" would be one sentence covering two different mechanisms.
  • Your session files are not capped and not cleaned up (§4.4).

All of these are files on your disk. We never see any of them, and you can delete any of them at any time without affecting anything but your own sign-in state.

17.7 Local data is not ours to retain or delete. We do not retain your local files because we do not have them, and we cannot delete them for you — you delete them yourself, with your own file manager, without asking us and without us knowing.

17.8 Inactive accounts. (No policy set. Where one is set it will be a stated period after which an unused account is deleted automatically.)

17.9 Another citizen's speech is not yours to erase. Your erasure right cannot be used to delete a debate other citizens contributed to. Where a deletion would remove another person's contribution, we remove your personal data and leave theirs. California law expressly recognises this for "the exercise by another consumer of his or her right to free speech."

17.10 Anonymisation instead of deletion. Where we anonymise rather than delete, we say so, and we state the limit honestly (§8.7).


18. Your Rights

18.1 Your rights, in full. Access · rectification · erasure · restriction of processing · data portability · objection · withdrawal of consent at any time · and the right to complain to a supervisory authority, which we name at §24.4.

18.2 California (CCPA/CPRA). Notice at collection; the categories we collect, use, and disclose; the right to know, delete, and correct; the right to limit the use of sensitive personal information; and non-discrimination — using a right never costs you service, price, or quality.

On "Do Not Sell or Share My Personal Information": we will offer the control, and we are not resting on an argument that we do not need to. (The control is not built yet — see §2.3. Nothing is being sold or shared today, because nothing reaches us; §3.2.) As §8.1 explains, whether providing data to an outside party for AI training is a "sale" or a "share" in the statute's technical sense is an open question we have referred to counsel. Rather than assume the favourable answer, we behave as though the answer were yes — the opt-out will be available, it will be honoured, a Global Privacy Control signal will trigger it (§13.5), and it will cost you nothing. (An earlier version of this policy said there was "nothing to opt out of." That was written before the training decision and it is no longer accurate.)

18.3 THE US POSITION IS NOT WHAT YOU MIGHT ASSUME, AND WE ARE NOT GOING TO OVERSTATE IT. Under GDPR and UK GDPR, "political opinions" are expressly special category data. That is settled and we state it confidently. US state privacy statutes are not uniform, and most of their sensitive-data lists do not name political opinions. California's CPRA lists "religious or philosophical beliefs," which may or may not be read to reach political belief. We are not going to tell you US law settles this, because it does not. What we do instead is §7.6: treat political opinion as sensitive everywhere as a matter of our own policy.

18.4 Other US states. Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Tennessee, Minnesota and the rest of the state wave: consent for sensitive data where required, opt-outs for targeted advertising, sale, and profiling, and data protection assessments. We run no targeted advertising and no profiling at all; the sale-and-share opt-out is at §18.2. We maintain the list of states whose laws we honour rather than arguing later about which regime applies.

18.5 Our response times, as real numbers. 30 days under GDPR and UK GDPR, extendable by two further months for complex requests, and we will tell you if we extend. 45 days under US state laws, extendable once by a further 45 days. These are the statutory deadlines and we are bound by them from the day the Service accepts a request. We would rather tell you plainly that the queue and the named owner behind them are still being put in place than let you assume a rota exists that does not.

18.6 How to make a request. (In-product request buttons are not built yet — see §2.3.) Today a rights request is made by writing to ContactUs@ACT3ai.com (subject line: "privacy request"), and that route works now and will keep working. Request buttons will be added in the application, so that no right ever depends on knowing an email address. We verify that a request is really yours proportionately to its sensitivity, and we accept authorised agent requests with proof of authority.

18.7 Appeals. If we refuse a request you may appeal, and the appeal will be reviewed by someone who was not involved in the original decision. (We are a very small company. Where no second reviewer is available in-house we will obtain one — an adviser or outside counsel — rather than have the original decision-maker review their own refusal.) Virginia, Colorado, Connecticut, Minnesota, Montana, Oregon, Tennessee and Texas require this route; to use it, send us your full name and a copy of the denial. If we deny the appeal, you may contact your state Attorney General, and we will tell you how.

18.8 Export, and what it contains. Most of your data is already an export: your positions and evidence are readable files on your own disk, in an open format, right now. For hosted data we provide a self-service export of your account information and your published content. (The self-service endpoint is not built yet — see §2.3. Until it is, ask at ContactUs@ACT3ai.com (subject line: "privacy request") and we will produce the export by hand.)

18.9 If you are not a user but you appear in someone's evidence. Public figures, officials, and anyone named in a citizen's reasoning have the same rights as everyone else, including rectification of an inference the AI drew (§11.4, §11.11). Contact us at ContactUs@ACT3ai.com (subject line: "privacy request"). A public figure who holds an account is a data subject like any other, and nothing in the Terms of Service — including its covenant not to sue at §23.2 — waives a statutory privacy right.

18.10 Article 11 — where we genuinely cannot identify you. For data that never left your machine, we cannot link it to you, because we do not have it. Where we cannot identify a data subject from the information we hold, Article 11 of the GDPR applies: we are not required to acquire additional information purely to enable identification, and we will tell you so rather than asking you to prove an identity we have no way to check.

18.11 When we may refuse. A legal retention obligation; an open security or abuse investigation; another person's privacy or free-speech rights (§17.9); or a request that is manifestly unfounded, excessive, repetitive, or technically impossible. We always tell you which one, and you can always appeal (§18.7).

18.12 YOUR RIGHT TO COMPLAIN TO A REGULATOR IS NEVER CONDITIONED. The Terms of Service asks you to use our internal complaint process, then to send a notice, then to mediate, before other proceedings. That does not apply to a privacy complaint and could not. You may complain to a supervisory authority, a data protection authority, or a state Attorney General at any time, without contacting us first, without mediating, and without waiting for anything. The Terms carve this out by name at their §25.13"You never have to talk to us first" — and we state it affirmatively here so the two documents cannot be read as conflicting.


19. International Transfers and Regional Terms

19.1 Where data is hosted. For the local application, on your own computer, in your own country. For hosted services, Amazon Web Services, region us-east-2, located in Ohio, United States.

19.2 Transfer mechanism. Where personal data is transferred out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, as amended by the UK Addendum for UK data, or on an adequacy decision where one covers the destination.

19.3 Signing in involves a transfer, and we would rather name it. Authenticating you with Google means a request to Google's servers (§3.5a). Google is a separate controller for its own purposes under its own policy, and it operates internationally.

19.4 Our AI provider transfers data internationally. Where the AI feature is enabled, the provider processes data on servers that may be outside the EEA and the UK. The provider's deployment configuration — not merely its identity — determines where processing happens, and we state the configuration we actually use rather than the one that is theoretically available.

19.5 EU and UK representatives. Not applicable - we do not offer the Service to people in the European Economic Area or the United Kingdom, and we do not monitor their behaviour, so Article 27 does not require us to appoint a representative. If we ever do offer the Service there, we will appoint both an EU and a UK Article 27 representative, each with a postal address and a request route, name them here, and say so before the offering begins.

19.6 Regional supplements. Where a jurisdiction requires its own notice, we publish a supplement that expressly supersedes the main body on any conflict for readers in that jurisdiction, rather than pretending one document fits every country.

19.7 Swiss, Brazilian, and Canadian users. Where we serve them, the Swiss FADP, the Brazilian LGPD, and Canadian PIPEDA apply and are addressed in the supplements at §19.6.

19.8 EU Digital Services Act. Where the hosted service is in scope, DSA transparency obligations overlap this policy. We keep them coordinated with the Terms of Service rather than stating them twice and differently.

19.9 Language. The English version of this policy controls. Translations are provided for convenience.


20. Communications and Marketing

20.1 Two kinds of email, and only one is optional. Transactional email — security alerts, account and billing notices, legally required notifications — you cannot opt out of while you have an account. Marketing email you can opt out of at any time.

20.2 Marketing is opt-in. We do not send marketing email unless you asked for it, and every one carries one-click unsubscribe. Unsubscribing takes effect immediately.

20.3 CAN-SPAM and ePrivacy. We comply with CAN-SPAM, and with the ePrivacy consent requirement where it applies.

20.4 Push and in-app notifications. Controlled in settings and in your operating system.

20.5 WE NEVER SHARE YOUR EMAIL ADDRESS WITH A CAMPAIGN, A PARTY, OR A COMMITTEE. For a political product this promise matters more than most, and there is no exception to it. See §8.4.

20.6 What opting out does and does not change. Opting out of marketing stops marketing email. It does not stop transactional email, and it does not change anything about how your data is handled — those are separate things and we would rather say so than let you assume otherwise. The training opt-outs are separate again, and they are at §6.1.


21. Community Mode and Publishing

21.1 What becomes visible, and when. In individual mode, nothing is visible to anyone — that is the default and it needs no action from you. In community mode, what you contribute to a community is visible to that community, and you are told what will be shared before you share it.

21.2 What a community steward can see. A steward can see the membership of their community and what members contribute to it. They cannot see your local files, your unpublished positions, or anything you did not contribute.

21.3 The steward is a controller in their own right. Where a community steward collects data about their members, they are the controller of it and we are their processor, bound by a data processing agreement. Their handling is governed by their notice, not this policy.

21.4 Which means rights requests go to the right place. If your request concerns data a community steward holds, please contact that steward — we cannot answer for their processing. If you ask us and we cannot answer, we will tell you who to ask rather than leaving you stuck.

21.5 Stated in both documents. Our dual role — controller for some data, processor for other data — is stated in the Terms of Service as well as here, so neither document can be read alone and give the wrong answer.

21.6 Public profiles. What is public by default and what is public only by your choice will be itemised here when community publishing ships (§4.8).

21.7 Search engines and archives. Anything public can be indexed, cached, archived, and scraped by third parties we do not control and cannot compel. Removal from our service does not remove it from their copies.

21.8 Blocks and mutes. Blocking someone is stored so we can enforce it. Be aware a blocked party can often infer that they were blocked from the behaviour of the service.


22. Governance and Accountability

22.1 Records of processing. We maintain the Article 30 record of processing activities.

22.2 Agreements with processors. Every processor is under a written data processing agreement with obligations at least equivalent to ours.

22.3 Training and access review. Staff with access to personal data are trained on handling special-category data, and access is reviewed.

22.4 Privacy by design — and the strongest evidence for it is the architecture itself. The best proof that a product minimises data is that it never receives it. Local-first is our Article 25 answer, and it is a stronger one than any process document. The second-best proof is that the parts which could have collected data — an access log, an analytics package, a crash-reporting service — are simply not there (§9.2a, §13.2).

22.5 Data Protection Officer. Not applicable - we have not appointed a Data Protection Officer, because we do not offer the Service in the EEA or the UK and Article 37 therefore does not require one. We record the reasoning and not only the conclusion, because the reasoning is the part that changes: our core activity is large-scale processing of special-category data, which is exactly the trigger in Article 37(1)(c). The moment we offer the Service in the EEA or the UK, a DPO becomes a real obligation and not a formality.

22.6 Data Protection Impact Assessment. None has been carried out yet, and one is in preparation. A DPIA is required for large-scale processing of special-category data, which is exactly what this product is.

22.7 Vendor due diligence. Especially for the AI provider, where — as §11.5 shows — the privacy-relevant facts are configuration settings, not the vendor's name. We record which configuration we run, dated, and re-check it.

22.8 Verifiable artefacts, not adjectives. The source code of this product is public. Every claim in §3.5, §3.5a, §3.5b, §4.2, §9.2a, §13.2 and §13.3 is checkable by anyone who wants to read it, and we would rather be checked than believed. We also intend to publish the sub-processor list with a change history and the transparency counters at §9.9.

22.9 The advisory group. The product refers to a "board of directors," which is a guide and advisor group, not a corporate board. Its members are not staff and not a processor. They do not have access to personal data, and if that ever changes it will be stated here with the access controls that apply.

22.10 Third-party components and forks. Community-contributed components and anything a self-hosted fork ships are bound by a published developer policy: client-side telemetry is prohibited, and any network use must be disclosed. This is how the §3.5 guarantee survives contact with an extension ecosystem — and it is also the answer to §3.5b's honest limit, that a dependency scan matches names rather than behaviour.


23. Changes to This Policy

23.1 How we notify. We post the updated policy with a new version number and last-modified date, and notify account holders by email or in-product notice.

23.2 Material changes get advance notice, before they take effect — not after.

23.3 A CHANGE TO HOW WE USE SPECIAL-CATEGORY DATA REQUIRES FRESH EXPLICIT CONSENT, NOT NOTICE. If we change how we process political opinions, we ask you again. We do not treat continued use as agreement, and we do not roll a new purpose in under a notice banner. This is the distinction most privacy policies get wrong, and it is the one that matters most here.

23.4 Version history. Every version is published with its date and a summary of what changed, and previous versions stay available. Where a later version corrects an earlier one, we say so rather than editing quietly — §4.4 and §18.2 in this version are corrections of statements in version 0.3, and they are marked as such.

23.5 No retroactive application. A new basis or purpose applies to data collected after it takes effect. Data collected under a narrower basis stays under that basis.

23.6 Dated with equal care to the Terms. This policy and the Terms of Service both carry a visible last-modified date and version, maintained together.

23.7 The summary and the body are the same document. The Short Version at the top is checked against the body, and the body is checked against the product, before each release. A truthful summary sitting over inaccurate detail is worse than no summary — a regulator reads the body.


24. Contact

24.1 How to reach us. The company's general address is ContactUs@ACT3ai.com. The dedicated privacy and data-rights channel is ContactUs@ACT3ai.com (subject line: "privacy request") — the same mailbox, routed by subject line (§2.9). Our registered postal address is 16430 NE 50th Street, Redmond, WA 98052, United States of America. 24.2 Data Protection Officer. Not applicable - we have not appointed a Data Protection Officer, because we do not offer the Service in the EEA or the UK and Article 37 therefore does not require one. 24.3 EU and UK representatives. Not applicable - we do not offer the Service to people in the European Economic Area or the United Kingdom, and we do not monitor their behaviour, so Article 27 does not require us to appoint a representative. 24.4 Your supervisory authority. You may complain to your national data protection authority — your own national supervisory authority for EEA users, the Information Commissioner's Office (ICO) for UK users — or to your state Attorney General. You may do this at any time and you never have to come to us first (§18.12). 24.5 Rights requests. In the application, or at ContactUs@ACT3ai.com (subject line: "privacy request") (§18.6). 24.6 Reporting a mistake. The same channel named in the Terms of Service for reporting inaccurate content is also the rectification channel under this policy — for you, and for anyone the AI wrote about (§11.11).

Related documents: the Terms of Service (the contract; this policy controls on any question of what we do with personal data) · the Cookie Policy · the DMCA policy · the sub-processor list (§8.5) · the transparency report (§9.9, when it exists).


Last modified: 2026-08-19 · Version: 0.4 · Change log and previous versions: Version history