How the votes are protected

How the service is designed, what you can check yourself, and what is not claimed.
What this page is
This page describes how Popverdict is designed. It does not add to or change the Terms of Use.
Your choice is sealed
The record of your choice holds no reference to your identity. No screen, export or interface shows who voted for what — not the person who asked, not the administrator of a Parliament, not another member, not our moderators. You can see your own choice; nobody else can.
A record that is only ever added to
The service is built so that a cast choice cannot be edited or deleted through any function of the app, the website or our administration tools. Changing your vote before the close adds a new entry and marks the earlier one as replaced. Each entry carries a fingerprint of the entry before it, so any later alteration, removal or reordering — even by someone with direct database access — would break the chain and show up when the result is checked.
No count before the close
The server refuses to give out a count before the closing time, and the result is calculated once, on the server, at the close. The app can only display a result; it cannot calculate one.
Checking the record
The check on any result verifies the chain of entries in front of you. It proves that the published record has not been altered; it does not show who cast each entry.
Who could reach the raw data
A person with direct administrative access to the database could technically connect a choice to the account that cast it. We do not do this, and that access is restricted to the people who operate the service and to our hosting provider, which is bound by a data processing agreement. Popverdict is not built for anyone whose safety depends on a vote never being traced.
How we protect the service
Every connection is encrypted in transit, the rules of each vote are enforced by the database rather than by the app, write actions are rate-limited, and two-step sign-in is available for accounts.
Reporting a security problem
Write to team@popverdict.com with "SECURITY" in the subject line and enough detail for us to reproduce the problem. Please test only against your own account; do not access, change or keep other people's data; do not disrupt the service; and give us reasonable time — normally 90 days — to fix the problem before you publish it. We confirm your report within 5 working days, keep you informed, and credit you if you wish. If you follow these rules in good faith, we will not take legal action against you over your research.
If something goes wrong
If a security incident affects personal data, we notify the competent authority where the law requires it and tell the people affected without undue delay where there is a high risk to them.
Last changed September 28, 2026.