Last updated: July 5, 2026
Votur is built privacy-first. A poll is a question and two choices — nothing more sensitive than that. We only process what we need to run the Service, our servers are in the EU, and we never show third-party ads, never sell your data, never track you across other apps, and never use your content to train AI models.
Votur ("Votur", "we", "us", or "our") operates the Votur application, the votur.app website, and related services (the "Service"). The Service is available as native apps for iOS and Android, and on the web at votur.app.
This Privacy Policy explains how we collect, use, store, and protect personal data when you use the Service — including when you only visit the website or vote through a shared link without the app.
Votur is operated from the Netherlands by its founders, who act as the data controller for the personal data processed through the Service. (A Dutch legal entity is being incorporated and will take over as controller; we will update this policy when that happens.) You can reach the controller at support@votur.app. We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). We are also committed to compliance with applicable app store guidelines, including Apple's App Review Guidelines and the Google Play Developer Program Policies.
When you first open the Votur app, we automatically create a guest account: a random identifier stored on our servers, not linked to your name, email, or device serial numbers. It lets us save the polls you create, the votes you cast, and your preferences without asking who you are. Browsing and voting never require a real account.
If you choose to sign in (with Google, Apple, or an email address and password), we receive the basic identity information you authorize: your email address and a stable user identifier, plus the name on that account and — for Google — its profile photo. Your guest history (votes, preferences) is merged into your account where technically possible, so what you did before signing up is normally preserved. Apple's "Hide My Email" relay addresses work normally.
You can add a public @username (required to post), a short bio, a profile photo, and links to your Instagram, TikTok, Pinterest, X, or Snapchat. These are visible to other users and through our public interface.
Separately, you can share optional personalisation details: interests (picked from a fixed topic list), a coarse age range, and a gender option. These are always skippable, can also be set while using a guest account, are used only to tune your Discover feed, and are never shown to other users. Your content-language preferences (which include your device language) are stored for the same purpose.
When you create a poll ("Duo"), we store the question, the two options (text, emoji, and/or photos you upload), the style you picked, quiz fields if any, and whether the poll is public, private, or posted anonymously. If you add photos, we store those images, small preview versions, and the share-card images Votur renders from your poll.
For every new poll our systems also derive and store: the content's language, an English translation (so people who speak other languages can read it), topic tags, and a safety verdict — see Section 5 on automated moderation.
Photos are re-encoded on your device before upload, which in normal operation removes embedded photo metadata such as GPS location. Poll photos and share-card images are served from public web addresses so that polls and link previews work; anyone who has such an address can fetch the image. Photo addresses are keyed to the poll, not to your account.
When you vote, we record which option you chose, linked to your (guest or signed-in) identifier, so we can show live results and prevent duplicate votes. Be aware of who can see what:
We use your voting history to personalise your own Discover feed (Section 2.H) — never to build advertising or marketing profiles, and we never sell it.
You can invite people to vote by @username, from your phone contacts, or via saved groups ("circles"). We designed this so that your contacts never leave your phone:
You can follow other creators and bookmark polls. Follower and following lists are public, like on most social platforms. Bookmarked polls are private to you. You can also react to a poll with one emoji from a fixed positive set of six; we store your one reaction per poll (which emoji, and when) so the poll can show its totals. Only aggregate counts are ever shown — nobody, including the poll’s creator, sees who reacted. If you block someone, that is stored privately — the blocked person is not told — and their content stops appearing in your feeds, while your content stops appearing in theirs.
If you report a poll, we store the poll, your identifier, the reason, and any note you add, so our moderation can review it. Reports are confidential: the poll's creator never sees who reported. These records are part of our safety audit trail.
We collect two kinds of first-party usage data (we use no third-party analytics or advertising SDKs):
These signals are used only for ranking your own feed and improving Votur — never for advertising, and they are never shared or sold. Usage events older than 12 months are deleted automatically; on account deletion they are immediately anonymised. You can influence personalisation directly by editing your interests, and you can object to it entirely (Section 12).
To keep the Service stable and secure we process:
If you join the launch list on votur.app or votur.app/business, we store your email address, when you signed up, and which page you signed up on. We use it to tell you when Votur launches — and if you signed up on the business page, also to reply personally about the launch-partner program. No newsletter, no marketing drip. We delete the list shortly after the launch announcement, and you can ask us to remove your address at any time via support@votur.app.
We do not use personal data for advertising profiles, behavioural ad targeting, cross-app tracking, or to train AI models. We do not sell personal data.
Votur is designed to stay warm and helpful: no comments, no direct messages, no public negative feedback. To keep the shared spaces safe, every new poll is automatically analysed shortly after posting:
Automated decisions: clearly unsafe content (for example, sexual content involving minors, or content that objectifies real people) is rejected automatically, without human review. Borderline cases are held for review by our human moderation team. If your poll is held or rejected and you believe that is wrong, you can contest the decision — contact support@votur.app and a person will review it.
Two honesty notes: our moderators can see the actual creator of polls posted "anonymously" (anonymity applies to other users, not to our safety team), and moderation decisions are kept in a permanent audit log — see Section 6.
You can delete individual polls at any time, and delete your account in the app (Settings → Account) or via votur.app/delete-account. Deletion removes your profile (including personalisation details), your polls, photos, share-cards, circles, follows, reactions, and sign-in identity from our servers.
Our database, storage, and server functions run on Supabase in the EU (Frankfurt). We protect personal data with encryption in transit (HTTPS), encryption at rest, and server-side row-level security, so that each account can only read what it is entitled to. Optional personalisation details (interests, age range, gender) are readable only by your own account. Access to moderation data is restricted to our moderation team.
Private polls follow the share-link model (like sharing a Google Docs link): the unguessable link is what grants access. Anyone you give the link to can open and vote on the poll; private polls are kept out of the Discover feed and out of search engines.
Our core processing happens in the European Economic Area: database and storage in Frankfurt, AI moderation in the Netherlands and Ireland, error monitoring in Germany. Some providers operate globally: Cloudflare serves votur.app from a worldwide edge network (processing request metadata such as IP addresses transiently), Apple processes sign-in and token revocation globally, Meta receives share URLs for link previews, and email delivery may be routed outside the EEA by our email provider. Where a provider processes personal data outside the EEA, we rely on appropriate safeguards under GDPR — typically the EU Standard Contractual Clauses or an adequacy decision. You can request a summary or copy of the safeguards that apply to a specific provider via support@votur.app.
We use the following services to provide Votur. Each acts on our instructions and may process data only for the purposes described. This list is kept up to date as our infrastructure changes.
| Service | Purpose | Region | Data involved |
|---|---|---|---|
| Supabase | Database, authentication, photo & share-card storage, server functions | EU — Frankfurt | Identifiers, profiles, polls, photos, votes, reports, usage events |
| Cloudflare | Website + vote-share pages (votur.app), share-card delivery, vote rate-limiting | Global edge network | Request metadata (IP, user-agent) processed transiently; cached public pages |
| Google Cloud (Vertex AI / Gemini) | Automated safety moderation, topic tagging, language detection & translation of new polls | EU — Netherlands | A poll's question, option texts, and photos; no account identifiers; never used to train models, processed transiently |
| Amazon Web Services (Rekognition) | Automated image-safety screening of poll photos (explicit content & child-safety, incl. estimated ages of visible faces) | EU — Ireland | Poll photos only; never used to train models, processed transiently |
| Sentry | Crash and error monitoring of the app | EU — Germany (ingest) | Error details, device/OS/app version, navigation breadcrumbs; configured to exclude personal content; 90-day retention |
| Google Firebase Cloud Messaging | Delivering push notifications (strictly opt-in) | Global (Google infrastructure) | A device push token and the notification text; the token is deleted when you sign out or delete your account |
| Pexels | Optional free stock-photo search inside the create flow | Global CDN | Your search term only, relayed through our server without any account identifier or IP; photo thumbnails load from Pexels' CDN after an explicit search; a chosen photo is stored by us, not linked from Pexels |
| Zoho ZeptoMail | One-off transactional email: the launch-list signup confirmation and, at launch, the single download-link email | Global (Zoho infrastructure) | Your email address and the message itself; nothing else is shared |
| Wikimedia Foundation (Wikipedia) | Short article summaries under quiz explanations ("read more") | Global | The article title only, requested by our server — your IP never reaches Wikimedia; tapping "read more" opens wikipedia.org in your in-app browser, where Wikimedia's own privacy policy applies |
| Zoho | Sending account emails (confirmation, password reset) from noreply@votur.app | Global (Zoho mail infrastructure) | Your email address and the account email's content |
| Google (content delivery) | Delivery of app components: translation models to your device (translation itself runs on-device), and occasional font components for the votur.app web pages where a glyph isn't bundled | Global CDN | A standard download request (IP); the text you translate never leaves your device |
| Meta (Facebook) | Link-preview pre-fetch and share-to-Stories hand-off | Global | The public share-link URL and our app identifier; when you share to Stories, the card image is handed to the Instagram/Facebook app on your device |
| Apple App Store / Google Play | App distribution and optional sign-in | Per the platform's own terms | Sign-in handshake; for Apple sign-in, the token used to revoke access on account deletion |
When you choose to share a poll to another app (WhatsApp, Instagram, TikTok, Pinterest, or via your device's share sheet), the share-card image and link leave Votur and are handled under that app's own privacy policy.
If you are in the European Union (and in many other places), you have the right to:
Most of this you can do directly in the app; for everything else contact support@votur.app. You also have the right to lodge a complaint with your data protection authority (in the Netherlands: the Autoriteit Persoonsgegevens).
You are never legally obliged to give us personal data. Some features simply need certain data to work — a @username to post, an email address to create a sign-in — and without it that feature is unavailable while everything else keeps working.
Votur is intended for users who meet the minimum age that applies in their jurisdiction — 13 in most countries, and higher where local law requires (for example, 16 in the Netherlands and other EEA countries that set the age of digital consent at 16).
If you are below the age of digital consent in your country, a parent or guardian must give or approve the consent required under data-protection law. We encourage parents and guardians to be involved in their children's use of Votur.
We do not knowingly collect personal data from anyone below the minimum age that applies to them without the required parental consent. If we become aware of such data, we will delete it.
We may update this Privacy Policy from time to time. Material changes will be communicated within the Service before they take effect. Where a change relies on your consent, we will ask for it — continuing to use Votur is never treated as consent.
If you have any questions about this Privacy Policy or how Votur handles data, contact the controller (Votur, operated from the Netherlands) at support@votur.app.