Privacy Policy

Last updated August 26, 2026

This Privacy Policy explains what information Podium (the "Service") collects when you use it, why, and what choices you have. It's written to describe what this software actually does, not generic boilerplate — if a section doesn't apply to how you're using the Service (for example, because a feature is turned off), it simply won't come up.

Who this policy covers

The Service is operated by Felix Kaechele ([email protected]). References to "we," "us," and "our" below mean the operator.

The public nature of this Service

Podium exists to make an election's questions and answers public. Before anything else, understand that most content you submit is designed to be seen by anyone, not just other logged-in users:

  • Questions you ask a candidate, once approved by a moderator, are public.
  • Candidate answers, comments, votes/reaction counts, and follow counts are public.
  • A candidate's profile — bio, platform statement, photo, contact info, and social links they choose to add — is public.
  • If you ask a question anonymously (without an account), your email address is used only to confirm you're a real person and is never shown publicly.

Don't include anything in a public field that you don't want attached to your name.

Information we collect

Account information

If you create an account, we collect:

  • Your name and email address.
  • A securely hashed password, if you sign up with email and password — we never store your password in plain text and can't retrieve it for you.
  • If you sign in with Google or Facebook, the name, email address, and profile photo that provider shares with us. We don't receive your password on that provider.
  • If you sign in with an emailed "magic link" instead of a password, we log that the link was requested and used.

Candidate profile information

If you're a candidate who has claimed a profile, the profile fields you choose to fill in — bio, platform statement, photo, public email, phone number, website, and social media links — are stored and shown on your public profile. A profile can also be created and partially filled in by an election administrator before you claim it (see "Unclaimed profiles" below).

Content you submit

Questions, answers, comments, votes, follows, and reports/flags you submit are stored, linked to your account (or, for an anonymous question, to the email address you verified it with), and — except for reports/flags, which only moderators see — shown publicly as described above.

Address lookups ("Find my ward")

If you use the address lookup to find your ward, the address you type is sent to a geocoding service to determine your location, and the address text is cached so the same address doesn't have to be looked up twice. That cache is not linked to your account or any other information about you.

Information collected automatically

  • Cookies. A session cookie keeps you signed in. It's required for the Service to work if you have an account; we don't use advertising or cross-site tracking cookies.
  • IP address. We briefly use your IP address to limit how many questions, comments, votes, or sign-up attempts can come from one place in a short period (to deter spam and abuse), and — if enabled — to run a CAPTCHA check via Cloudflare Turnstile. These uses are short-lived and not compiled into a profile about you.
  • Basic analytics. If enabled, we use a self-hosted analytics tool (Umami) that counts page views and general traffic sources without cross-site cookies or tracking you across other websites.
  • Error reports. If enabled, technical error details (like a stack trace and the page you were on) are sent to our error-tracking tool when something breaks, so we can fix it.

How we use your information

  • To operate the Service: creating accounts, showing content, sending you questions/answers you've asked for.
  • To send you email: confirming an anonymous question, notifying a candidate of a new question, notifying an asker their question was answered, notifying someone who follows a candidate of a new answer, and account-related email (magic links, candidate invitations). You can turn some of these notifications off from your account settings.
  • To moderate content and enforce the rules described in our Terms of Service.
  • To detect and limit spam, abuse, and automated misuse.
  • To fix bugs and keep the Service reliable and secure.

A question's topic may be automatically categorized by a third-party AI service after a moderator approves it (see "Third-party services" below); this only looks at the question text itself, not who asked it.

Unclaimed profiles

An administrator may create a candidate profile before the candidate registers, using publicly available information (such as a name and, where available, a public campaign contact email) so constituents can see who's running. This is clearly labeled "unclaimed" on the public profile. A candidate can claim their profile via a personalized invitation link sent to them, after which they control the profile directly. If you're a candidate and want an unclaimed profile corrected or removed before you claim it, contact us using the details below.

Third-party services

Depending on how this deployment is configured, some of your information may be processed by these third parties, each only for the purpose described:

  • Email delivery — sending the transactional emails described above.
  • Google / Facebook — if you choose to sign in with one of these, for authentication.
  • Cloudflare Turnstile — CAPTCHA verification on question submissions, if enabled.
  • An AI language model provider (via OpenRouter) — automatic topic tagging of approved questions, if enabled. Only the question text is sent, not your identity.
  • Self-hosted analytics and error tracking — as described above, if enabled.
  • Cloud object storage — candidate photos are stored with a storage provider so they can be served on the public site.

Some of these providers may process data on servers outside your country, including in the United States.

Data retention

We keep account and content data for as long as your account exists or the content remains part of the public record of the election. Because Podium is meant to serve as a durable, citable record of what candidates were asked and how they answered, published questions and answers are ordinarily kept as an archive after the election rather than deleted, even if the asking or answering account is later closed — a moderator-removed item still shows that it was removed, the same way a correction works elsewhere on the Service. If you'd like your account itself deleted, contact us using the details below.

Data security

We use industry-standard measures to protect your information, including encrypted connections (HTTPS), securely hashed passwords, and access controls limiting who can see non-public data (like report/flag details or an unclaimed profile's admin-only fields). No system is perfectly secure, and we can't guarantee absolute security.

Children's privacy

The Service isn't directed at children and isn't intended for use by anyone under 16. If you believe a child has provided us personal information, contact us and we'll remove it.

Your choices and rights

  • You can review and update most of your account and profile information yourself.
  • You can turn off "new question" and "daily digest" email notifications from your account settings.
  • You can ask us to access, correct, or delete personal information we hold about you, subject to the public-record retention described above for already-published Q&A content.

To exercise any of these, contact us at [email protected].

Changes to this policy

We may update this policy from time to time. If we make a material change, we'll update the "Last updated" date above.

Contact us

Questions about this policy or your information? Contact Felix Kaechele at [email protected].

See also our Terms of Service.