Privacy Policy
Effective September 7, 2026
This policy explains how PROMISEcause collects and handles personal information when you browse the service, sign in, or send feedback. It also explains the limited Google account data used for Google Sign-In.
Requested email reports
When you request a snapshot or assessment history, we send it only to your verified account email through our transactional email provider. We retain the report and delivery record for up to 30 days to handle delivery and repeated requests. A report request does not subscribe you to recurring emails.
Information we collect
We collect only the information needed to operate, secure, and improve the service:
- Google Sign-In data: your verified email address, Google account name, profile image URL, and the stable Google account identifier and issuer used to link future sign-ins to the same PROMISEcause account.
- Email sign-in data: your email address, a hashed one-time code, the requested return page, and sign-in timing and attempt information. Email challenges are removed after 24 hours.
- Account and session data: an internal account identifier, authentication provider, account status, account creation and update times, last sign-in time, and secure session identifiers.
- Technical and security data: IP address, request time, requested path, response status, referral information, pseudonymous public-session identifier, and information needed to detect abuse and enforce request limits.
- Following and comparisons: the politicians or promises you follow, saved comparison selections, publication-read position, and your email preferences remain private account data. You can remove follows and comparisons on the Following page.
- Assessment corrections: the explanation and optional source you submit are available to reviewers. Published decisions omit your account identity and private explanation.
- Optional feature counts: if you enable anonymous feature counts, we count follow and comparison actions by day. These aggregates contain no account identity, politician, search term or source URL and expire after 180 days.
- Feedback: the category, message, page address, and optional reply email that you choose to submit.
How Google user data is used
PROMISEcause requests only the openid, email, and profile scopes. We use that data to verify your identity, create or link your account, display your name or profile image in account controls, maintain your signed-in session, and protect the service from fraud or abuse.
We do not use Google user data for advertising, profiling, credit decisions, political targeting, or training artificial intelligence models. PROMISEcause does not receive your Google password and does not request access to Gmail, Google Drive, contacts, calendars, or other Google content. OAuth credentials involved in sign-in are used only for authentication and not to access other Google services.
Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
How we use information
- Provide authenticated access to detailed accountability records and preserve your return destination after sign-in.
- Operate, troubleshoot, secure, and prevent misuse of PROMISEcause.
- Deliver one-time sign-in codes and feedback messages when you request those features.
- Comply with legal obligations and enforce the Terms of Service.
Cookies
PROMISEcause uses strictly necessary cookies. pc_auth maintains an authenticated session and expires after 12 hours of inactivity or within 24 hours of authentication. pc_session is a signed pseudonymous identifier used to protect public endpoints and expires after 24 hours. These cookies are not used for advertising or cross-site tracking.
You can block or delete cookies in your browser, but sign-in and some security controls may stop working.
Sharing and service providers
We do not sell personal information or share it with advertisers or data brokers. Information may be processed by vendors that help operate the service, including Google for authentication, Cloudflare for network delivery and security, hosting and database infrastructure providers, and Resend for requested sign-in, feedback or opt-in weekly update email delivery. Each receives only the information needed for its function.
We may also disclose information when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or respond to valid legal process. If the service is reorganized or transferred, information may transfer subject to this policy or notice of materially different terms.
Retention and security
Account identifiers and profile details are kept while your account remains active and as reasonably necessary for security, legal compliance, and dispute resolution. Expired server-side sessions are cleaned up automatically. Feedback is delivered as email and retained under the mailbox and email provider settings used to administer the service. Security logs are retained only as reasonably necessary for operations and abuse prevention.
Weekly update email is off until you opt in. Its stored message body expires after 30 days; delivery-event identifiers expire after 90 days. Unsubscribe links stop future digests. Publication evidence and correction decisions remain part of the historical accountability record.
We use encrypted transport, restricted database access, HttpOnly secure session cookies, CSRF protection, bounded login attempts, and short session lifetimes. No internet service can guarantee absolute security.
Your choices and requests
You may sign out at any time. You can also remove PROMISEcause from your Google Account's third-party connections; doing so stops future Google authorization but does not by itself delete the PROMISEcause account record.
To request access, correction, deletion, or restriction of your account information, use Leave feedback in the site footer, choose General feedback, include the email address associated with your account, and state your request. We may need to verify that you control the account before acting. Local law may provide additional rights or permit us to retain limited information.
Children and international use
PROMISEcause is intended for a general audience and is not directed to children under 13. If you believe a child has provided personal information, use the footer feedback channel. Information may be processed in countries where PROMISEcause and its service providers operate, subject to applicable safeguards.
Changes and contact
We may update this policy when the service or its data practices change. Material changes will be reflected by a new effective date and, when appropriate, an additional notice.
PROMISEcause is responsible for the practices described here. For privacy questions or requests, use Leave feedback in the footer of any PROMISEcause page.