Skip to main content

Politicians make promises on their stump — we watch and hold them accountable.

Help keep the record honest →Create an account

Privacy Policy

Effective June 20, 2026 · Operated by StumpWatch

This Policy explains what StumpWatch (“we”) collects when you use StumpWatch, why, and your choices. It is part of our Terms of Service.

1. Our privacy principles

  • We do not sell your personal data — ever.
  • We collect only what we need to run the Platform and what you choose to share.
  • Sensitive information (demographics, voting preferences) is strictly optional and used only in aggregate.
  • Your real name, if provided, is used for accountability and is never shown publicly.

2. Information you provide

When you create an account, we collect:

  • Required: first name, last name, email address, a username, a password (stored only as a salted hash — we never see your actual password), and your city, state, and ZIP code (used to localize the voter information we show you).
  • Optional: street address and phone number.
  • Optional & sensitive — your choice: self-reported demographic information and voting-preference information. Providing these is entirely voluntary; they are never required, never sold, never displayed publicly, and are used only in aggregate (for example, to understand our audience as a whole). You can leave them blank or remove them at any time from your account.

Your legal name is private: public contributions you make (votes, comments, proposed edits) show only your chosen display name or username, not your real name.

3. Content you contribute

Votes, comments, flags, disputes, and proposed edits you submit are stored with your account. Because the Platform keeps a tamper-evident, append-only record, contributions that are later hidden or removed are retained in our audit history rather than permanently deleted — see “Data retention” below and Terms §11.

4. Donations

Donations are processed by Stripe. We receive a record of your donation (amount, date, frequency, and the name/email you provide at checkout) but we never receive or store your full card details — those go directly to Stripe under its own privacy policy.

Retention of donor identity. The donor name and email address you supply at checkout are retained on file for tax-receipt purposes, so that a receipt can be reissued and so we can meet the record-keeping requirements that apply to charitable contributions if and when StumpWatch obtains 501(c)(3) recognition. The amount, date, and ledger record of every donation are always preserved as part of our accountability record. If you wish to have your donor name and email removed from a specific donation, you may request anonymization at any time through our contact form; an administrator will sever your identity from the donation record while leaving the amount and ledger row intact.

5. Information collected automatically

To keep the Platform secure and working, we log limited technical data such as IP addresses and request metadata in our security and audit logs.

First-party analytics (always on, cookieless). We maintain our own first-party usage analytics that record page-level traffic only. This system sets no cookies, does not use browser fingerprinting, and stores no personal information — only aggregate counts of pages viewed.

Third-party analytics and advertising (only if the operator has enabled them). Site administrators may optionally configure third-party Google services — Google Analytics 4, Google Tag Manager, and/or Google Ads — through the site’s admin settings. When any of those IDs are configured, the corresponding Google scripts load on non-admin pages and may set their own cookies and collect data about your visit, governed by Google’s own policies: Google’s Privacy Policy and Google’s cookie policy. When none of those admin settings are populated, no third-party analytics or advertising scripts run and no such cookies are set.

We do not sell your data to advertisers.

6. How we use information

  • operate your account and let you contribute;
  • localize the officials and races we show you (city/state/ZIP);
  • send transactional email (verification, password reset, donation receipts);
  • maintain the integrity and security of the Platform; and
  • understand our audience in aggregate to improve the service.

7. How we share information

We do not sell personal data. We share information only with service providers that help us operate (for example, Stripe for payments and our email provider for transactional mail), and when required by law or to protect rights and safety. Public-record data about public figures is sourced from government databases and is public by law.

8. Data retention & your choices

You can view and update your profile, and remove optional fields, from your account. Note that the Platform’s append-only audit record means published contributions are retained in the audit history even after being hidden, so there is no guaranteed right to permanently erase content you have posted (Terms §11). For account or data requests, contact us through the contact form.

Contact-form submissions. Messages you send us through the contact form — including the name, email address, message body, and the IP address the submission came from — are retained for up to 180 days so we can reply and follow up, and are then automatically deleted. An administrator may also delete an individual message sooner on your request; contact us through the contact form to ask. Contact-form submissions are not part of the site’s public accountability record and, unlike published contributions above, are removed rather than soft-hidden when deleted.

Deleting your account. Signed-in users may delete their account at any time from /account/delete. Deleting the account removes your personal information — your name, email address, mailing address, phone number, date of birth, gender, and party affiliation — and permanently deletes every politician on your watchlist. Contributions you authored (promises, sources, assessments, votes, comments, and revisions) remain in the public accountability record with the byline “[deleted user],” so the tamper-evident audit chain that gives the record its credibility is preserved. Administrators may perform the same action on your behalf if you request it.

9. Security

Passwords are stored using salted PBKDF2 hashing; we use encryption in transit (HTTPS) and restrict access to personal data. No system is perfectly secure, but we work to protect your information and to limit what we collect in the first place.

10. Children

The Platform is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it where required.

11. Changes & contact

We may update this Policy; we will revise the effective date and, for material changes, give reasonable notice. Questions or requests may be submitted through our contact form. We do not publish a direct email address.

StumpWatch is live, and the record is still growing. Many promises and positions aren’t tracked yet, and some features are still in beta. Add a sourced promise and help keep the record honest.

Help keep the record honest →