Privacy Policy
This policy explains what personal data Isegora collects, why we use it, how long we keep it, and your rights. It is written for users in the United States, the United Kingdom, and the European Union / EEA, and covers only regimes that apply to this app.
By creating an account you acknowledge this policy. Optional uses (personalized ads, product analytics, push notifications, marketing-style email alerts) require a separate in-app choice under Privacy & ads. Technical and performance monitoring (crash/error diagnostics) runs under legitimate interests and is disclosed below — it is not the same as product analytics.
1. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account | Email, password hash (or OAuth id), username, avatar, short biography (≤280 characters) | You / chosen sign-in provider |
| Demographics | Gender, date of birth (private — not on public profile; age gate + anonymous age-bucket stats only; results never show which users are in which bucket) | You |
| Contact | Phone number (SMS verification) | You |
| Location signals | Latest IP and derived country/region/city; coarse geo on votes | Network |
| Content | Polls, options, comments, optional video clips, likes, follows, private poll visit history for Home → Visited (public profiles can show your published polls, polls you liked or followed, and your comments — each tab is on by default; you can turn any off) | You |
| Votes | Your choice + demographic/geo facts used for aggregate results. While a poll is open we hold a per-poll code linking your vote to your account, so you can change your vote, cannot vote twice, and can be told when results are in. The code is random, different in every poll, and never shown to anyone. When the poll closes we destroy that link — from then on nobody, including us, can tell how you voted. Consequences: after a poll closes your votes are no longer part of a data export (they are no longer personal data), and your region/city sharing choice applies to votes you cast after you change it | You |
| Device / notifications | Push token, app language, basic diagnostics | Device |
| Preferences | Consent records (ads, analytics, push, email, vote region/city share, terms) | You |
| Safety | Reports you file or that concern your content; Take It Down Act / NCII removal requests (name, contact, content locators, signature, good-faith statement); limited audit/security logs | You / us |
We do not sell personal information for money. We do not knowingly collect data from children under 13 (COPPA; UK/EU child-protection expectations).
2. Why we use data (lawful bases & US notice)
EU / UK (GDPR & UK GDPR)
| Purpose | Basis | Notes |
|---|---|---|
| Account, polls, votes, results, follows, comments | Contract | Needed to provide the service you request |
| In-app feed personalisation using your follows/likes/activity | Contract / Legitimate interests | Delivers the product experience — not advertising analytics |
| Age gate (13+), SMS verification, abuse/fraud/VPN blocking, rate limits, security | Legitimate interests and/or Legal obligation | Keep the platform safe and usable |
| Geographic & demographic aggregate results | Legitimate interests and/or Contract | Core product; coarse vote facts with no account reference on the vote row. Region and city are on by default; turn either off in Privacy & ads and votes you cast from then on count under “Unknown” for that filter (country is unchanged). Published breakdowns are also generalised so no area shown represents fewer than 10 voters — smaller areas are grouped under “Unknown”. |
| Soft-delete residual retention, legal holds, resolved-report / audit archives | Legitimate interests and/or Legal obligation | Investigate abuse, defend claims, comply with law (see §3) |
| Latest profile IP + derived geo (not exposed in the normal in-app profile; staff access restricted and logged; 12-month purge) | Legitimate interests and/or Legal obligation | Trust & safety — investigate illegal or policy-violating activity and support lawful reporting / requests |
| Technical & performance monitoring (crashes, errors, limited diagnostics) | Legitimate interests | Service integrity — see §2.1 |
| Coarse first-party operational counts from normal server logs | Legitimate interests | Capacity/reliability — minimized, not marketing profiles |
| Personalized ads; product / advertising / experimentation analytics; push; follow emails | Consent | Withdraw in Privacy & ads (ePrivacy / PECR) |
Legitimate interests (balanced). We use legitimate interests only where processing is reasonably expected for a social polling app and does not override your rights: (a) trustworthy aggregate results; (b) bots/fraud/anonymizer resistance; (c) investigating illegal or policy-violating content (including retaining latest profile IP + geo for up to 12 months to support trust & safety and lawful reporting); (d) securing and stabilizing the service (including crash/performance monitoring); (e) coarse operational measurement from server logs. You may object (see §6). We then stop unless we demonstrate compelling grounds or need the data for legal claims.
Special-category data is not sought. Gender and age-bucket statistics are used for aggregate results with minimization (no voter id on the public vote row).
2.1 Measurement and analytics (what needs consent)
| Category | Basis for Isegora | What we do |
|---|---|---|
| Technical & performance analytics | Legitimate interests | Crash/error/performance monitoring. Minimized diagnostics; not used for ads or marketing profiles. Always on while the app runs; disclosed here and in Privacy & ads. |
| Basic usage measurement (first-party ops) | Legitimate interests when limited to aggregate/server-side operational metrics from requests we already process | Reliability and capacity — not user profiling for marketing. |
| Product development & experimentation (A/B tests, behavioral product analytics) | Consent | Off unless you enable Product analytics. |
| Personalisation & recommendation analytics (marketing-style profiling) | Consent | Distinct from in-app feed ranking, which uses your account activity to provide the service (contract/LI above). |
| Advertising analytics | Consent | Ad measurement/attribution when ads ship — CMP/ATT where required. |
| Creator & business analytics | Split | A creator viewing their own poll aggregates = contract. Packaging cross-user audience insights for ads/third parties = consent. |
Forwarding of product/share funnel events to analytics tools is gated on the Product analytics toggle (privacy consent).
United States (notice at collection)
We collect the categories in §1 to operate Isegora, secure it, show aggregate results, moderate content, and run technical monitoring. We may review content you submit (including with automated checks and human review) to help keep the service safe. We process Take It Down Act non-consensual intimate imagery (NCII) removal requests (including from people without an account) under legitimate interests and/or legal obligation so we can locate and remove qualifying content within 48 hours when the request is valid — see Terms and https://isegora.com/legal/take-it-down. Only if you opt in, we personalize ads, run product/advertising analytics, or send push/email alerts. California and other state privacy laws may treat certain ad/analytics disclosures as “sharing” or targeted advertising; use the in-app toggles to opt out. We do not use sensitive personal information to infer characteristics beyond what is needed for the age gate, verification, and aggregate poll statistics described here.
3. Retention
| Data | How long |
|---|---|
| Active account profile & content (including username, avatar, short biography, demographics, phone) | While your account exists |
| Latest profile IP + geo | Up to 12 months, then purged. Stored for trust & safety only; not shown in the normal account UI. You may receive it in a data export. Authorized staff may access it only for investigations, with access logged. |
| After you delete your account | Hidden immediately; public “deleted” notice up to 7 days; profile fields (including biography) and content retained in the database then purged after 90 days, unless a legal hold applies |
| Legal hold (report on your content/profile) | Until the moderation case is closed |
| Resolved moderation reports | Up to 12 months |
| Security / audit logs | Up to 24 months |
| Push tokens (inactive) | 90 days |
| Notification queue | 30 days |
| Creator video clips | 30 days after the poll ends |
| Vote records | Kept as statistics. The per-poll link to your account is destroyed when the poll closes, after which the vote is anonymous and cannot be traced to you |
| Rate-limit keys | Short-lived; client IP stored hashed |
Residual retention after deletion supports trust & safety and legal duties (GDPR Art. 17(3)-style exceptions; US investigation / legal-process needs) and is limited to what is necessary.
4. Sharing & processors
We use service providers acting on our instructions for hosting, authentication, SMS verification, push delivery, IP-based location signals, optional email delivery, crash/performance monitoring (legitimate interests — §2.1), and — only if you enable Product analytics under Privacy & ads — product/share-funnel analytics (poll/share identifiers and a user UUID, not email/phone). If you sign in with a third-party account provider, that provider processes your sign-in. When ads ship, an advertising network (plus a consent platform and iOS ATT where required) may receive device/ad identifiers only if you allow personalized ads.
We may disclose data if required by law (including EU DSA / UK Online Safety information requests where applicable) or to protect rights, safety, or integrity of the service.
5. Electronic communications (SMS, email, push)
| Channel | Use | Rule |
|---|---|---|
| SMS | Account / phone verification | Transactional after you submit your number (TCPA / PECR transactional context) — not marketing |
| Alerts when someone you follow starts a poll | Only with email_notifications consent; opt out anytime (CAN-SPAM / PECR) | |
| Push | Poll ended, results, follow activity, @username tags in poll questions/captions/comments | Only with push_notifications consent; revoke in-app / OS settings |
6. Your rights
EU GDPR / UK GDPR: access, rectification, erasure, restriction, portability, objection (including to legitimate interests), withdraw consent. Complain to your EU supervisory authority or the ICO (UK).
California CCPA/CPRA (and similar US state laws where applicable): know/access, delete, correct, and opt out of “sale” or “sharing” / targeted advertising (use personalized-ads and analytics toggles; we do not sell data for money). Non-discrimination for exercising rights. Complain to the California Attorney General / Privacy Protection Agency or your state AG as applicable.
How: Privacy & ads → Export my data or Delete my account, or email privacy@isegora.com. We aim to respond within one month (GDPR/UK GDPR) or 45 days (CCPA; similar state timelines may apply).
7. International transfers
Data may be processed in the United States and other countries where our providers operate. Where GDPR or UK GDPR applies, we use appropriate safeguards (e.g. Standard Contractual Clauses and UK addenda where required).
8. Children and teens
Isegora is for users 13 and older. Under-13 registrations are blocked. Optional tracking/ads personalization is consent-gated on web only until native AdMob ships with App Tracking Transparency.
9. Changes
We will update this policy when practices change and revise the effective date. Material changes will be highlighted in the app or by email when appropriate.