Privacy Policy
Effective Date: September 19, 2026 | Version 1.1
1. Introduction
TownSphere ("we", "our", or "us"), available at townsphere.org and through our mobile applications, provides a privacy-first public opinion intelligence and sentiment tracking platform. This Privacy Policy explains what information we collect, how it is processed, and our strict safeguards to protect your personal identity and voting anonymity.
2. Architectural Separation of Identity & Votes
Unlike traditional social networks or comment sections, TownSphere enforces a strict cryptographic firewall between your account identity and your voting records:
- Authentication Boundary: When you log in with your email (via passwordless One-Time Passcode) or OAuth provider, credentials are handled securely by our authentication infrastructure.
- Pseudonymous Voter ID: Your authentication ID is hashed using HMAC-SHA256 with a private
server salt. This one-way cryptographic derivation produces an un-linkable
voter_id. - Unlinkability: Cast votes, opinion shifts, and poll tallies reference only the pseudonymous
voter_id. There is no foreign key or database link connecting cast votes back to your email address or real identity.
3. Data We Collect
We believe in strict data minimization. We only collect the minimal information necessary to deliver the service:
- Account Credentials: Your email address, used solely to send authentication One-Time Passcodes (OTP) and maintain your session.
- Voluntary Demographic Information: Age bracket (e.g. 18–24, 25–34), general occupation sector, education level, and country. Providing this information is strictly optional and can be skipped or updated anytime in Settings.
- Public Sentiment Activity: Voting choices and opinion change history associated only with
your pseudonymous
voter_id. - Aggregated Technical Usage: Anonymized view counts and click events batched locally to prevent real-time device profiling.
4. Data We NEVER Collect
To preserve complete privacy, TownSphere strictly does NOT collect:
- Precise GPS location data.
- Biometric data or device hardware fingerprints.
- Financial, payment, or credit card information.
- Address books, contacts, camera feeds, or microphone audio.
- Cross-site tracking identifiers for third-party advertising.
5. Demographic Privacy & k-Anonymity
To prevent individual re-identification in demographic sentiment breakdowns, TownSphere enforces statistical k-anonymity (k ≥ 5). If a demographic cohort (e.g., specific age and occupation in a region) has fewer than the privacy threshold of voters, its statistics are automatically redacted and suppressed until sufficient sample size is reached.
6. Account Deletion & Right to be Forgotten
In full compliance with Apple App Store Guidelines (Guideline 5.1.1(v)), Google Play Data Safety requirements, and GDPR/CCPA regulations, you have the right to permanently delete your account at any time:
- In-App Deletion: Navigate to
Settings → Delete Account. Confirming this action immediately and permanently removes your email, authentication profile, and demographic attributes from our servers. - Web Request: You may also request complete account deletion by emailing our Data Protection team at townsphere.org@gmail.com.
7. Data Security & Encryption
All data in transit is protected using industry-standard TLS 1.3 encryption (HTTPS). Databases are hosted in secure, ISO-27001 and SOC-2 compliant data centers with encrypted storage volumes and automatic security patching.
8. Age Eligibility
TownSphere is intended for users who are at least 16 years of age (or the legal age of digital consent in your jurisdiction). We do not knowingly collect or solicit personal data from children under 16.
9. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or your data rights, please contact our team at:
TownSphere Privacy Team
Email: townsphere.org@gmail.com
Website: https://townsphere.org