Privacy Policy
Version 2026-09-03 · Effective 2026-09-03
1. Who this covers
Voter Count is operated by IVC Media LLC (“we”, “us”). This policy explains what we collect about the people who use Voter Count, how we use it, who we share it with, and how long we keep it.
Voter Count is a conversational interface to voter-registration data licensed from L2 Inc. (“L2”). This policy covers information about you, our user. It is not a description of L2’s own privacy practices as the source of the underlying voter data — those are published by L2 separately.
Voter Count is a professional research tool intended for use in the United States by people aged 18 or over.
2. The short version
- We collect the information needed to run an account: your email, your password (stored only as a cryptographic hash) or your Google sign-in, and your subscription status.
- We store the questions you ask and the answers you receive, so your conversation history is there when you return.
- Your questions are sent to Snowflake, which runs the analysis that produces your answer. They are sent without your name, email, or account identifier attached.
- Voter Count answers in aggregate — counts, segments, and trends. It is not designed to return individual voters' names, phone numbers, or addresses, and the data it can query excludes those fields.
- We do not sell your personal information. We do not run advertising or third-party tracking on the product, and no analytics or advertising scripts are loaded today.
- If you ask us to see, correct, or delete your information, email us and we will handle it.
3. What we collect
Account information.Your email address, and your name and profile image if you sign in with Google. If you use a password, we store only an Argon2id hash of it — we never store the password itself and cannot recover it. We also record when your account was created and what role it holds. If you created your account using an invite link that another member shared with you, we record which link you redeemed, and the member who issued that link can see your account’s email address and when you redeemed it — nothing else about your account or activity is shown to them. Our administrators can see the same redemption record for every invite link, as part of the administrative access described under “Administrative records” below.
Your conversations.The questions you type, the answers returned to you, and the supporting output for those answers (the tables and charts, and the generated query behind them). A conversation’s title is taken from the opening words of your first question in it. This applies equally to questions sent through our API rather than the web interface — if you connect another tool to Voter Count with an API key, the questions it sends and the answers it receives are stored the same way.
Feedback you send us.If you rate an answer or flag it as wrong, we store that rating and any comment you write. Please don’t put personal or confidential details in a feedback comment: comments are passed on to the team that maintains the underlying data model exactly as you wrote them, and they cannot be edited or withdrawn once sent.
Billing information. If you subscribe, our payment processor Stripe handles your payment details. We never see or store your card number. We keep your Stripe customer and subscription identifiers and your current plan status.
Technical information. Your IP address, used to apply rate limits and to protect sign-in against automated abuse. In our database we store only a salted one-way hash of an IP address, never the address itself; the address is held briefly in a rate-limiting service keyed to short expiry windows. We also record your browser user-agent string when you record a consent choice, and we keep server logs of requests.
Administrative records. We keep an append-only audit log of privileged actions taken inside the product — including when a member of our staff views a conversation. These records exist so access to your data is accountable, and by design they cannot be altered or deleted.
If you request an invite.While Voter Count is invite-only, requesting access stores your email address, the time you asked, your answer to one required question about the kind of work you do (chosen from a fixed list), and — only if you arrived from a link for a specific plan, such as a full plan’s waitlist link on our pricing page — the name of that plan, which the form shows you before you submit; and nothing else. We delete the whole record from our own waiting list when your invite is issued, and any address still on that list is deleted no later than 90 days after we stop taking requests. Your email address, your answer about the kind of work you do, and the plan name if you gave one are also copied to a shared waiting-list spreadsheet that the Independent Voter Project maintains — see who receives your information for what that means, including that our deletion of our own copy does not reach theirs.
If you are on a team.A Premium subscriber can share their plan with other Voter Count accounts by inviting them to a team. When a team owner invites you, we store the email address they typed, when the invite was sent, and when it expires, and we send that address one email with an accept link; the link stops working after seven days, if the owner withdraws it, or once it has been used. If you accept, we record that your account belongs to that team and when you joined. The team owner can see the email address of each member and pending invitee and the date each member joined — nothing about your questions, conversations, or activity — and each member can see the owner’s email address. Inviting, revoking, joining, and removing are recorded in the audit log described under “Administrative records.” Removing you from a team deletes the membership record; the invite record is kept until the team is deleted. If you were invited but never accept, the record lapses with the invite and is removed when the team is deleted or when the owner sends you a new invite.
If a team invite creates your account.If the address a team owner invited has no Voter Count account, the invite link lets you create one on the spot — the invite itself is the authorization, so you do not need a separate beta invite and you are not added to the waiting list. At that moment we store the invited email address as your account email (it cannot be changed during sign-up), either a hash of the password you choose or the link to the Google account you signed in with (which must be the invited address) together with the name and profile image Google provides (the same fields “Account information” in this section describes), the time you accepted these terms and this policy, and your membership of the team. Two entries are written to the audit log described under “Administrative records”: one that your account was created from a team invite (naming the team, the invite, and whether you used a password or Google) and the same “joined” entry every member gets.
4. Voter data, and what this product does not do
This is the section most people are actually asking about, so it is worth being precise.
Voter Count answers questions in aggregate. It reports counts, segments, distributions, and trends across the voter file. It is not a lookup tool for individual people, and it is not a way to obtain a list.
That limit is enforced upstream of this application, not by filtering in your browser. The product queries a restricted view of L2’s data that excludes personally identifying fields, so the information needed to identify or contact a specific voter is not present in what the product can reach. The product also offers no bulk download or data-delivery function.
If you need licensed access to individual voter records, that is granted by L2 alone, under L2’s own approval, compliance, and fulfillment process. We cannot grant it.
When you ask for that access — or request a demo of L2’s full offering — we pass your contact details and what you asked for to L2 so their team can follow up with you. That is the point of the handoff, and it only happens when you ask for it. See section 6.
Availability of voter-registration records, and what may lawfully be done with them, varies by state. Our Terms place responsibility for following the rules that apply to you on you, and we make no claim here about the legal status of the underlying records.
5. How we use information
- To operate your account, authenticate you, and keep your conversation history available across your devices.
- To produce answers to your questions, which requires sending the text of your questions to our data-analysis provider.
- To apply your plan's usage limits and to bill you if you subscribe.
- To send transactional email: invites, password resets, and notices when your login credentials change. We do not send marketing email from the product.
- To keep the service secure and available — rate limiting, abuse prevention, debugging, and investigating incidents.
- To improve the product, including reviewing flagged answers to correct the underlying data model.
- To meet our legal obligations and to enforce our Terms.
We do not use your conversations to train artificial-intelligence models, and our agreement with L2 requires that query responses and user interaction data are not used to train external models.
8. How long we keep information
Your account information and conversation history are kept for as long as your account is open. We keep them because the product’s purpose is to let you return to earlier analysis; we do not currently delete conversation history on a fixed schedule.
When you close your account, we delete your account information and conversation history within 30 days. Deleting a single conversation in the product hides it from your history immediately; ask us and we will remove it permanently.
Server logs are kept for 30 days. If you request access to Voter Count and never take it up, we delete your email address from the waiting list no later than 90 days after we stop taking requests. That deletion covers our own records. A copy of your email address, your answer about the kind of work you do, and the plan name if you gave one also sit in the shared waiting-list spreadsheet maintained by the Independent Voter Project, which we do not control and which our deletion does not reach; ask us and we will pass a deletion request on, but we cannot promise a deadline for a record we do not hold.
Two categories are deliberately permanent and survive deletion of your account: the audit log of privileged actions, and consent records. Both exist to prove who did what, which is a purpose that a deletable record cannot serve. Neither contains the content of your conversations, and the audit log holds identifiers rather than your personal details.
We may keep information longer where we need it to meet a legal, tax, or accounting obligation, or to resolve a dispute.
9. Your choices and how to exercise them
You can update your password from your account page, and you can cancel a subscription at any time through the billing portal.
To see what we hold about you, correct it, obtain a copy, or delete your account and its data, email privacy@votercount.ai. We will verify that the request comes from you, and we will respond within the time the law allows — 45 days where a state statute sets that deadline. We will not treat you worse for exercising these rights.
We handle these requests by hand today rather than through a button in the product. Self-serve export and account deletion are being built; until they ship, email is the route, and it reaches a person.
Some information cannot be deleted on request. We keep records we need in order to meet legal, tax, and accounting obligations, to resolve disputes, and to enforce our Terms. As noted in section 8, audit and consent records are permanent by design.
10. State privacy rights
Depending on where you live, you may have specific rights over your personal information — to know what is collected and why, to obtain a copy, to correct it, to delete it, to opt out of its sale or of targeted advertising, and to appeal a decision we make about a request. Residents of California, Colorado, Connecticut, Texas, Virginia and a number of other states have these rights under their own statutes.
We do not sell personal information and we do not use it for targeted advertising or profiling, so those opt-outs have nothing to act on here. For everything else, use the contact route in section 9. If we decline a request, you may ask us to reconsider by replying to our decision, and you may complain to your state attorney general.
We are not a data broker. We do not hold, store, or sell voter data — it stays in L2’s own environment, and Voter Count queries it and returns aggregate results. The rights above concern your account information, which is the only personal information we keep.
11. How we protect information
Passwords are stored as Argon2id hashes. Invite links, password-reset links, and API keys are stored only as one-way hashes, so a copy of our database does not reveal a usable credential. Session cookies are restricted to our own domain and are not readable by scripts in your browser.
Connections to the product are encrypted in transit. Our database rejects unencrypted connections, is not reachable from the public internet, and its storage is encrypted with a key we control. Access to privileged functions is checked on the server on every request, and privileged actions are recorded in the audit log described in section 3.
Being straightforward about the limits: the contents of your conversations are stored in our database as ordinary text, protected by the encryption of the underlying storage and by access controls, rather than separately encrypted field by field. No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed.
12. Children
Voter Count is not directed to children and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.
13. Changes to this policy
If we make a material change we will update the version at the top of this page and, where the change affects how we use information you have already given us, ask you to review it the next time you sign in. Earlier versions are available on request.
14. Contact us
Privacy questions and data requests: privacy@votercount.ai. Our Terms of Service govern your use of the product.
IVC Media LLC, 2700 Adams Ave Suite 202, San Diego, CA 92116.