Votur ← Back to home

Privacy Policy

Last updated: July 5, 2026

Votur is built privacy-first. A poll is a question and two choices — nothing more sensitive than that. We only process what we need to run the Service, our servers are in the EU, and we never show third-party ads, never sell your data, never track you across other apps, and never use your content to train AI models.

1. Introduction

Votur ("Votur", "we", "us", or "our") operates the Votur application, the votur.app website, and related services (the "Service"). The Service is available as native apps for iOS and Android, and on the web at votur.app.

This Privacy Policy explains how we collect, use, store, and protect personal data when you use the Service — including when you only visit the website or vote through a shared link without the app.

Votur is operated from the Netherlands by its founders, who act as the data controller for the personal data processed through the Service. (A Dutch legal entity is being incorporated and will take over as controller; we will update this policy when that happens.) You can reach the controller at support@votur.app. We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). We are also committed to compliance with applicable app store guidelines, including Apple's App Review Guidelines and the Google Play Developer Program Policies.

2. Personal Data We Collect

A. Identity and sign-in

When you first open the Votur app, we automatically create a guest account: a random identifier stored on our servers, not linked to your name, email, or device serial numbers. It lets us save the polls you create, the votes you cast, and your preferences without asking who you are. Browsing and voting never require a real account.

If you choose to sign in (with Google, Apple, or an email address and password), we receive the basic identity information you authorize: your email address and a stable user identifier, plus the name on that account and — for Google — its profile photo. Your guest history (votes, preferences) is merged into your account where technically possible, so what you did before signing up is normally preserved. Apple's "Hide My Email" relay addresses work normally.

  • The name imported from Google or Apple is shown only to you (in your own settings). Publicly, you are your @username.
  • A profile photo imported from Google is copied once to our own storage, so other users' devices don't fetch it from Google.
  • If you sign in with Apple on iOS, we store the Apple token needed to revoke Votur's access to your Apple ID when you delete your account (an Apple requirement). It is used for nothing else and is deleted with your account.
  • We never receive your contacts, calendar, or other account data from Google or Apple.

B. Your profile

You can add a public @username (required to post), a short bio, a profile photo, and links to your Instagram, TikTok, Pinterest, X, or Snapchat. These are visible to other users and through our public interface.

Separately, you can share optional personalisation details: interests (picked from a fixed topic list), a coarse age range, and a gender option. These are always skippable, can also be set while using a guest account, are used only to tune your Discover feed, and are never shown to other users. Your content-language preferences (which include your device language) are stored for the same purpose.

C. Polls and content you create

When you create a poll ("Duo"), we store the question, the two options (text, emoji, and/or photos you upload), the style you picked, quiz fields if any, and whether the poll is public, private, or posted anonymously. If you add photos, we store those images, small preview versions, and the share-card images Votur renders from your poll.

For every new poll our systems also derive and store: the content's language, an English translation (so people who speak other languages can read it), topic tags, and a safety verdict — see Section 5 on automated moderation.

Photos are re-encoded on your device before upload, which in normal operation removes embedded photo metadata such as GPS location. Poll photos and share-card images are served from public web addresses so that polls and link previews work; anyone who has such an address can fetch the image. Photo addresses are keyed to the poll, not to your account.

D. Votes

When you vote, we record which option you chose, linked to your (guest or signed-in) identifier, so we can show live results and prevent duplicate votes. Be aware of who can see what:

  • Public results are always aggregate: percentages and counts, never a list of names.
  • The creator of a poll can see that you voted on their poll (so they know who they are still waiting on) — but not what you picked: which option anyone chose is never shown to any user, including the creator. Results are only ever counts.
  • If someone invited you with a personal invite link, that person can see that their link was used to vote. Votur never learns who the link was sent to — that stays on the inviter's phone.
  • Votes cast on the web (via a share link, without the app) are stored with a random browser identifier and no account at all.

We use your voting history to personalise your own Discover feed (Section 2.H) — never to build advertising or marketing profiles, and we never sell it.

E. Circles, invites, and your contacts

You can invite people to vote by @username, from your phone contacts, or via saved groups ("circles"). We designed this so that your contacts never leave your phone:

  • Picking a contact uses your phone's own picker — Votur has no contacts permission and cannot read your address book.
  • A contact's name and number are stored only on your device. Our servers hold an anonymous link token, and only learn "this link was used to vote".
  • Circles are private to you: server-side they contain only the circle's name and the app users in it. People are not notified that they are in your circle and cannot see it.
  • For app users you invite, we store who invited whom to which poll, so the invite can appear in their inbox and you can see who has voted.

F. Follows, reactions and blocks

You can follow other creators and bookmark polls. Follower and following lists are public, like on most social platforms. Bookmarked polls are private to you. You can also react to a poll with one emoji from a fixed positive set of six; we store your one reaction per poll (which emoji, and when) so the poll can show its totals. Only aggregate counts are ever shown — nobody, including the poll’s creator, sees who reacted. If you block someone, that is stored privately — the blocked person is not told — and their content stops appearing in your feeds, while your content stops appearing in theirs.

G. Reports

If you report a poll, we store the poll, your identifier, the reason, and any note you add, so our moderation can review it. Reports are confidential: the poll's creator never sees who reported. These records are part of our safety audit trail.

H. Usage data and feed personalisation

We collect two kinds of first-party usage data (we use no third-party analytics or advertising SDKs):

  • Product events — e.g. "app opened", "poll created", "share sheet used", with the app build number. These contain no content, names, or free text and help us understand which features work.
  • Feed signals — which polls you see, how long a poll card stays on your screen, and what you vote. Our servers combine these with the polls' topic tags into a per-topic taste score for your account, refreshed continuously over a rolling 30-day window. This is what makes your Discover feed feel like yours (see Section 5 for the automated-processing details).

These signals are used only for ranking your own feed and improving Votur — never for advertising, and they are never shared or sold. Usage events older than 12 months are deleted automatically; on account deletion they are immediately anonymised. You can influence personalisation directly by editing your interests, and you can object to it entirely (Section 12).

I. Technical and crash data

To keep the Service stable and secure we process:

  • Crash and error reports — when something breaks, our error-monitoring service (Sentry, EU servers) receives the error, device model, OS version, app version, the screens navigated before the error, and your IP address (processed transiently at ingest, not stored in the report). From a small random sample of sessions it also receives anonymous performance measurements (such as screen-load timings) so we can spot slowdowns — with the same device details and no personal content. Reports are deleted after 90 days.
  • IP addresses — inherent to any internet request. We use them transiently at our hosting edge (Cloudflare) for abuse prevention such as vote rate-limiting; we do not store them in our database or build profiles from them.
  • Web voting identifiers — if you vote via a share link in a browser, we store a random identifier in your browser's local storage to prevent duplicate votes. It is a random number, not a fingerprint of your device, and it is used for nothing else. The votur.app website sets no cookies and runs no tracking or analytics scripts.
  • On-device translation — the in-app translation feature runs entirely on your device (Google ML Kit): the text you translate never leaves your phone. The ML Kit software itself may send its own technical usage diagnostics to Google as an SDK; this contains no poll content.
  • Test-phase feedback reports — during test phases the app shows an optional feedback button. If you choose to send a report, we receive your message, an optional screenshot of the app (you can remove it before sending), your device model, OS version, screen properties, language settings, and a short log of the screens used just before — used only to fix the problem you reported, readable only by the team, and removed when the test phase ends.

J. Website launch list

If you join the launch list on votur.app or votur.app/business, we store your email address, when you signed up, and which page you signed up on. We use it to tell you when Votur launches — and if you signed up on the business page, also to reply personally about the launch-partner program. No newsletter, no marketing drip. We delete the list shortly after the launch announcement, and you can ask us to remove your address at any time via support@votur.app.

3. How We Use Personal Data

  • Provide the Service — create polls, cast votes, show live results, and sync across your devices.
  • Sign you in (as a guest by default, or with Google, Apple, or email if you choose).
  • Render and host share-cards and link previews so your polls look right when shared.
  • Personalise your Discover feed based on your interests, languages, and feed signals.
  • Translate polls across languages (an English version is prepared per poll; further translation happens on your device).
  • Moderate content automatically and manually to keep Votur safe (Section 5).
  • Operate the report-and-block system.
  • Send account emails (confirmation, password reset). We send no marketing email — the only exception is the single launch announcement you can sign up for on our website (Section 2.J).
  • Detect and prevent misuse (such as vote manipulation or spam).
  • Comply with legal obligations.

We do not use personal data for advertising profiles, behavioural ad targeting, cross-app tracking, or to train AI models. We do not sell personal data.

4. AI Processing and Automated Moderation

Votur is designed to stay warm and helpful: no comments, no direct messages, no public negative feedback. To keep the shared spaces safe, every new poll is automatically analysed shortly after posting:

  • The question, option texts, and any photos are sent to Google's Gemini model on Vertex AI (EU servers, Netherlands) which returns a safety assessment, topic tags, the content's language, and an English translation. Only the content is sent — never your name, email, or account identifier.
  • Photos are additionally screened by AWS Rekognition (EU servers, Ireland) for explicit or harmful imagery. As part of protecting minors, this includes automated face detection with an estimated age of people visible in the photo. These estimates exist to catch unsafe images of minors; they are stored with the poll's confidential moderation record and are not used for anything else. Please remember that uploading photos of other people requires their permission (see our Terms).
  • Neither provider uses your content to train models (we use the paid, no-training tiers and have opted out of AI-improvement programs). Your content is processed transiently to produce the assessment and is not kept by the providers beyond short-term operational processing (such as abuse monitoring).

Automated decisions: clearly unsafe content (for example, sexual content involving minors, or content that objectifies real people) is rejected automatically, without human review. Borderline cases are held for review by our human moderation team. If your poll is held or rejected and you believe that is wrong, you can contest the decision — contact support@votur.app and a person will review it.

Two honesty notes: our moderators can see the actual creator of polls posted "anonymously" (anonymity applies to other users, not to our safety team), and moderation decisions are kept in a permanent audit log — see Section 6.

5. Legal Bases for Processing (GDPR)

  • Performance of a contract — running the Service: accounts, polls, votes, invites, sharing, translation.
  • Consent — optional personalisation details (interests, age range, gender), uploading photos, making a poll public, and joining the launch list. You can withdraw consent by removing the data or content.
  • Legitimate interest — our legitimate interests in keeping the Service safe, stable, and relevant: security and abuse prevention, content moderation (including the automated screening in Section 4), crash monitoring, first-party usage measurement, and feed personalisation. You can object to processing based on legitimate interest (Section 12).
  • Legal obligation — when we must retain or disclose data by law.

6. Data Retention

  • Polls, photos, and share-cards — until you delete them or your account. (Publicly cached pages and previews at our edge network expire within minutes; cached copies of image files can take somewhat longer to expire.)
  • Votes — as long as the related poll exists. When you delete your account, your votes on other people's polls are anonymised, not deleted: the count remains correct, but the link to you is removed permanently.
  • Guest accounts — automatically purged in a monthly clean-up once they have gone about 90 days without voting.
  • Feed-personalisation scores — rolling 30-day window; scores fade out and are deleted as the window moves.
  • Usage events — anonymised on account deletion and deleted automatically after 12 months.
  • Crash reports — 90 days.
  • Moderation records — a poll's AI safety scores live and die with the poll. The audit log of moderation decisions is kept permanently as our safety trail, also after content or account deletion.
  • Report and block records — reports you filed are deleted when you delete your account, and when a reported poll is re-approved or deleted; blocks are deleted when either account is deleted.
  • Launch-list emails — until shortly after the launch announcement, or until you ask us to remove yours.

You can delete individual polls at any time, and delete your account in the app (Settings → Account) or via votur.app/delete-account. Deletion removes your profile (including personalisation details), your polls, photos, share-cards, circles, follows, reactions, and sign-in identity from our servers.

7. Data Storage & Security

Our database, storage, and server functions run on Supabase in the EU (Frankfurt). We protect personal data with encryption in transit (HTTPS), encryption at rest, and server-side row-level security, so that each account can only read what it is entitled to. Optional personalisation details (interests, age range, gender) are readable only by your own account. Access to moderation data is restricted to our moderation team.

Private polls follow the share-link model (like sharing a Google Docs link): the unguessable link is what grants access. Anyone you give the link to can open and vote on the poll; private polls are kept out of the Discover feed and out of search engines.

8. International Transfers

Our core processing happens in the European Economic Area: database and storage in Frankfurt, AI moderation in the Netherlands and Ireland, error monitoring in Germany. Some providers operate globally: Cloudflare serves votur.app from a worldwide edge network (processing request metadata such as IP addresses transiently), Apple processes sign-in and token revocation globally, Meta receives share URLs for link previews, and email delivery may be routed outside the EEA by our email provider. Where a provider processes personal data outside the EEA, we rely on appropriate safeguards under GDPR — typically the EU Standard Contractual Clauses or an adequacy decision. You can request a summary or copy of the safeguards that apply to a specific provider via support@votur.app.

9. Sub-processors

We use the following services to provide Votur. Each acts on our instructions and may process data only for the purposes described. This list is kept up to date as our infrastructure changes.

Service Purpose Region Data involved
Supabase Database, authentication, photo & share-card storage, server functions EU — Frankfurt Identifiers, profiles, polls, photos, votes, reports, usage events
Cloudflare Website + vote-share pages (votur.app), share-card delivery, vote rate-limiting Global edge network Request metadata (IP, user-agent) processed transiently; cached public pages
Google Cloud (Vertex AI / Gemini) Automated safety moderation, topic tagging, language detection & translation of new polls EU — Netherlands A poll's question, option texts, and photos; no account identifiers; never used to train models, processed transiently
Amazon Web Services (Rekognition) Automated image-safety screening of poll photos (explicit content & child-safety, incl. estimated ages of visible faces) EU — Ireland Poll photos only; never used to train models, processed transiently
Sentry Crash and error monitoring of the app EU — Germany (ingest) Error details, device/OS/app version, navigation breadcrumbs; configured to exclude personal content; 90-day retention
Google Firebase Cloud Messaging Delivering push notifications (strictly opt-in) Global (Google infrastructure) A device push token and the notification text; the token is deleted when you sign out or delete your account
Pexels Optional free stock-photo search inside the create flow Global CDN Your search term only, relayed through our server without any account identifier or IP; photo thumbnails load from Pexels' CDN after an explicit search; a chosen photo is stored by us, not linked from Pexels
Zoho ZeptoMail One-off transactional email: the launch-list signup confirmation and, at launch, the single download-link email Global (Zoho infrastructure) Your email address and the message itself; nothing else is shared
Wikimedia Foundation (Wikipedia) Short article summaries under quiz explanations ("read more") Global The article title only, requested by our server — your IP never reaches Wikimedia; tapping "read more" opens wikipedia.org in your in-app browser, where Wikimedia's own privacy policy applies
Zoho Sending account emails (confirmation, password reset) from noreply@votur.app Global (Zoho mail infrastructure) Your email address and the account email's content
Google (content delivery) Delivery of app components: translation models to your device (translation itself runs on-device), and occasional font components for the votur.app web pages where a glyph isn't bundled Global CDN A standard download request (IP); the text you translate never leaves your device
Meta (Facebook) Link-preview pre-fetch and share-to-Stories hand-off Global The public share-link URL and our app identifier; when you share to Stories, the card image is handed to the Instagram/Facebook app on your device
Apple App Store / Google Play App distribution and optional sign-in Per the platform's own terms Sign-in handshake; for Apple sign-in, the token used to revoke access on account deletion

When you choose to share a poll to another app (WhatsApp, Instagram, TikTok, Pinterest, or via your device's share sheet), the share-card image and link leave Votur and are handled under that app's own privacy policy.

10. Sharing & Public Visibility

  • Discover feed — if you make a poll public, it can appear in Votur's Discover feed and on your public profile after passing moderation.
  • Share links — every poll has a share link. Knowing the unguessable link is what grants access: anyone you send it to can open and vote on the poll, whether it is public or private.
  • Post anonymously — an anonymously-posted poll shows no creator name or profile to other users. The creator is still known to us (and visible to our moderation team); it is "not shown publicly" rather than "unknown to Votur".
  • Public profile — your @username, photo, bio, social links, follower/following lists, and your non-anonymous public polls are visible to others. Your real name (if imported from Google/Apple), email, votes, bookmarks, reactions, interests, age range, and gender are not.
  • Sharing to other apps — once shared externally, content can be copied or redistributed beyond our control.

11. What We Never Do

  • No third-party advertising, and no advertising SDKs in the app.
  • No selling or renting of personal data. Ever.
  • No training of AI models on your content — ours or anyone else's.
  • No cross-app or cross-site tracking, and no advertising identifiers.
  • No reading your contacts, location, camera roll, or messages. The app's only system permissions are internet access and — solely if you enable them — notifications.
  • No cookies and no analytics trackers on votur.app.
  • Push notifications are strictly opt-in and individually switchable per type. We bundle them into at most one warm daily summary, plus a handful of someone-is-waiting moments (an invitation, everyone voted, your poll closing). Quiet at night, and an empty day sends nothing. Signing out deletes your device's token.
  • If we ever show sponsored polls, they will be clearly labelled, capped, and matched only on a poll's context and the interests, age range, or gender you chose to share — never on your voting history, your feed signals, or data bought elsewhere. We will update this policy first. Aggregated results shown to a sponsor are exactly that: aggregated, never individual votes with identities.

12. Your Rights Under GDPR

If you are in the European Union (and in many other places), you have the right to:

  • Access, rectify, or erase your personal data.
  • Restrict processing, and object to processing based on legitimate interest — including feed personalisation from usage signals.
  • Receive your data in a portable format.
  • Withdraw consent at any time (for example, by removing your interests/age/gender in the app, deleting a photo or poll, or deleting your account).
  • Not be subject to solely automated decisions with significant effects: for content moderation you can always request human review of an automated rejection (Section 4).

Most of this you can do directly in the app; for everything else contact support@votur.app. You also have the right to lodge a complaint with your data protection authority (in the Netherlands: the Autoriteit Persoonsgegevens).

You are never legally obliged to give us personal data. Some features simply need certain data to work — a @username to post, an email address to create a sign-in — and without it that feature is unavailable while everything else keeps working.

13. Minimum Age

Votur is intended for users who meet the minimum age that applies in their jurisdiction — 13 in most countries, and higher where local law requires (for example, 16 in the Netherlands and other EEA countries that set the age of digital consent at 16).

If you are below the age of digital consent in your country, a parent or guardian must give or approve the consent required under data-protection law. We encourage parents and guardians to be involved in their children's use of Votur.

We do not knowingly collect personal data from anyone below the minimum age that applies to them without the required parental consent. If we become aware of such data, we will delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated within the Service before they take effect. Where a change relies on your consent, we will ask for it — continuing to use Votur is never treated as consent.

15. Contact

If you have any questions about this Privacy Policy or how Votur handles data, contact the controller (Votur, operated from the Netherlands) at support@votur.app.

  • About
  • FAQ
  • Community Guidelines
  • Privacy Policy
  • Terms of Service
  • Delete account
  • Contact
© 2026 Votur