Privacy Policy

Exactly what we collect, why, who else sees it, and what you can do about it. No euphemisms.

Version 2026-09-11 · In effect from 11 September 2026

The short version

  • We record how you use the app in detail. Every tap, every swipe, which polls you look at and for how long. Not just the things you deliberately do.
  • We know roughly where you are: your country, your state and your city, worked out from your internet connection. We do not collect your GPS location, and we do not keep your IP address, only a salted one-way hash of it.
  • We never sell your data.
  • Your votes and polls are permanent. Closing your account removes your name from them, not the votes themselves.
  • Some of what you type leaves our servers. Search text and poll text go to OpenAI to power search and content checks, and a profile photo goes to OpenAI for an image check. Details below.
  • You can ask us what we hold on you, correct it, or ask us to delete it. You can close your account yourself, from Settings.

1. Who is responsible for your data

Sura Praveen, an individual based in Hyderabad, Telangana, India, is the data fiduciary for the personal data described here. Meaning the person who decides what is collected and why, and who is accountable for it.

Questions, requests and complaints: [email protected].

2. What we collect. Your account

Only if you sign in, on the website or in the Android app. You can browse and vote without an account.

  • Email address. Used to sign you in and to send notifications you have asked for.
  • Google account identifier, if you sign in with Google. We receive a stable ID and your email address from Google. We do not receive your Google password.
  • Handle, display name, bio and avatar colour. These are public. Anything you put in a bio is visible to anyone.
  • Profile photo, if you add one. Optional, and public: it appears next to your handle everywhere your handle appears. We receive only the photo you choose. We never read your photo library. We keep two copies, the circle that is shown and the picture it was cut from, so you can reposition it later without uploading it again. We re-encode the picture before storing it, which strips camera metadata such as where and when it was taken. Every photo goes to an automated image check at upload. A photo that fails the check is refused and not stored. If the check cannot be reached, the photo is stored and shown while we run the check again shortly afterwards, and a photo that fails then is removed without asking you. Both copies are deleted when you remove the photo or close your account.
  • Your settings, including whether you have allowed your handle to appear in public voter lists (off by default), which kinds of notification you want, and who you have blocked.
  • Date of birth. We ask for this when you create an account, and we use it for two things. First, to check you are 18 or over. See the Terms; if you tell us you are younger, we close the account and delete its personal details rather than keeping them. Second, to group results by age band. It is not shown on your profile, it is never shown to anyone else, and it is deleted if you close your account.
  • Gender, if you choose to give it. Optional, always. You can skip it, you can answer "prefer not to say", and you can change or clear it later. We ask for one reason: so a poll's result can be reported by group rather than only as one number. It is not shown on your profile, it is never shown to anyone else, and it is deleted if you close your account.

On reporting results by group. We collect these so that questions like "do younger and older readers answer this differently" can be answered at all. We will only ever publish such a breakdown where enough people in each group have voted that no individual can be picked out of it, and today, on almost every poll, that is not the case, so no breakdown is shown. We would rather hold the data and show nothing than publish a number that identifies somebody.

3. What we collect. Identifiers

  • A device identifier. When you first open OpinionSphere we generate a random ID and store it on your device: in your browser's storage on the website, and in the app's own private storage on Android. It is how we remember which polls you have already voted on when you are not signed in. It is a random number, not a fingerprint. We do not build a profile from your browser, fonts, screen size or hardware. On the website you can clear it by clearing your browser storage for this site; in the app, by clearing the app's storage or uninstalling it. Either way you will then be able to vote again on polls you have already answered.
  • A session identifier, stored for the current browsing session only, used to group your activity into one visit.
  • A salted hash of your IP address. We take your IP address, add a secret value, and run the result through a one-way hash. We store the hash, never the address. We use it to spot vote-stuffing and to rate-limit abusive traffic; the rate-limit counters keyed on it expire within a day. It is pseudonymous data rather than anonymous data, and we treat it that way.
  • A sign-in cookie (`os_session`) if you have an account and use the website. It is httpOnly, meaning JavaScript on the page cannot read it.
  • Sign-in tokens, if you use the Android app. Instead of a cookie, the app keeps a short-lived access token and a longer-lived refresh token in its own private storage, which other apps cannot read. The refresh token is replaced each time it is used and expires after 90 days; the list of signed-in devices in Settings comes from those tokens. Signing out invalidates them.

4. What we collect. Where you are

We record the country, state and city your connection appears to come from, on every vote and every recorded action. This is worked out at the network edge by Cloudflare from your IP address, before the request reaches us.

We use it to understand where the app is being used and to show how opinion differs between regions. Which is a core part of what the product is for.

We do not collect precise location. Latitude and longitude are available to us from the same source and we deliberately do not read them. A coordinate pair points at a person; a city points at a population. City is the most precise location we store, and we intend to keep it that way.

We also do not use GPS, Bluetooth, Wi-Fi scanning, or your device's location permission. The app never asks for it.

5. What we collect. How you use the app

This is the section most privacy policies are vague about, so here it is in full. We record:

  • Every tap and click, including which control you pressed, on which screen, and which poll it was inside.
  • Swipes.
  • Every page you open, and how you arrived (a shared link, a notification, the installed app icon, a search engine).
  • How long you spend on a poll, on a trend chart, on the comments, and on each card as you scroll the feed. This measures time the content is actually on your screen. It stops counting when you switch away.
  • Which polls scroll into view, how far down a feed you go, and whether you looked at results.
  • What you search for. We store the text you type into search, as typed. If you are signed in, that record carries your account ID. After 180 days we delete the record and keep only the phrase, how often it was searched, and whether it found anything, with no account, device or session attached. We keep those phrases to find out what people look for that we do not have. Do not type personal information into search: a phrase is kept as typed, and we cannot tell a name from a search term.
  • Actions you take: votes, polls created, comments, reactions, reposts, follows, shares, notification opens, sign-ups.
  • Errors the app hits while you are using it.
  • Which version of OpinionSphere you are using. Every request tells us whether it came from the website or the Android app, and for the app, which build you are on. We use it to tell a fault in one from a fault in the other, and to know which build a piece of feedback was written against.

Each of these records carries your device identifier, your session identifier, your account ID if you are signed in, the time, and your country, state and city.

We use all of this to work out which parts of the app are worth keeping and which are wasting your time.

6. What we collect. What you create

Polls, their options and context text, votes, comments and the people you mention in them, reactions, reposts, follows, blocks, pinned polls, options you suggest on other people's polls, reports you file, and feedback you send. Most of this is public by design; blocks, reports and feedback are not.

If you send feedback, we store your message, the page or screen you sent it from, your browser's user-agent string, which client and app version you sent it from, and your email if you typed one. We keep feedback until you ask us to remove it. Closing your account detaches your account and any email address from feedback you sent; the message itself stays.

To deliver notifications we store a delivery address. On the website that is the push subscription your browser gives us when you allow notifications: a delivery address, two encryption keys, and your user-agent string. The Android app registers a delivery token with Google's Firebase Cloud Messaging when it starts, whether or not you have allowed notifications, and sends us that token with the app version, your device language and your Android version. Until you allow notifications nothing is shown on your device, but the token exists and Google can see that the app is installed. We delete the registration when you close your account, and uninstalling the app invalidates the token.

If a vote cannot be sent from the Android app, the app keeps it on your device and tries again later. We hold nothing until it arrives.

7. What we do not collect

Stated plainly, because the absence is as important as the list above:

  • No GPS or precise location, ever.
  • No IP addresses in storage. Only the salted hash described in section 3.
  • No access to your contacts, your photo library, your files, your microphone or your camera. The one image we handle is the profile photo you choose to upload.
  • No third-party analytics services. No Google Analytics, and nothing like it. The usage records described in section 5 are our own, and they stay on our own servers.
  • No browser fingerprinting.
  • No passwords. We do not use them.
  • No payment information. The app is free and takes no payments.
  • No special-category data. Please do not put health, religious, caste, sexual-orientation or financial information about yourself or anyone else into a poll, a comment or a bio.

8. Who else sees your data

We do not sell your data. We do use these service providers to run the app:

  • Cloudflare (global). Sits in front of the app. Sees your IP address and the content of your requests, and works out your country, state and city for us.
  • Amazon Web Services (Mumbai, India). Hosts the app, the database, profile photos and the nightly database backups. Your data is stored in India.
  • OpenAI (United States). This one deserves your attention. Three things go to OpenAI's API. The text you type into search, and the questions and options of polls that are created, are converted into a mathematical representation that powers search and duplicate detection. Poll text is also sent for an automated content check and for topic grouping. And a profile photo, when you add one, is sent for an automated image check; if that check cannot be reached at upload, the photo is sent again when we retry. Text and photos can therefore leave India and be processed in the United States. We send only the text or the photo itself, never your email, account ID or device identifier.
  • Google (global), only if you choose to sign in with Google.
  • Push delivery services. On the website, Google (Firebase Cloud Messaging), Mozilla, Microsoft or Apple, depending on your browser, and only if you turn on notifications. In the Android app, always Google: it receives the delivery token whenever the app runs, and the content of a notification only when we send you one.

We will also disclose data where the law requires it, or to protect our rights or someone's safety.

9. How long we keep it

  • Polls, options and votes: permanently. This is the product's core promise. See section 6 of the Terms.
  • Search records: 180 days, then reduced to the phrase and its counts, kept without an attached account, device or session identifier. The phrase itself may contain identifying information (section 5).
  • Usage records (taps, page views, time spent): 180 days, then automatically deleted. Before they are deleted we keep a daily count of how many events of each kind happened in each country. Those counts carry no device identifier, no session identifier and no account, so they cannot be traced back to you, and we keep them to see whether the app is growing.
  • Account data: until you close your account, then handled as set out in section 11.
  • Comments, reactions, reposts, follows and blocks: as long as the account exists, then as set out in section 11.
  • Feedback you send: until you ask us to remove it. Closing your account detaches your account and email from it.
  • Reports you file, and the record of what we decided about them: kept. Moderation decisions go into a log that is never edited, so we can show what was done and why.
  • The record of which version of these documents you accepted, and when: kept, including after you close the account, because it is how we prove what you agreed to.
  • A closed account's handle: held back from new accounts for 90 days, so nobody can take over a name people knew you by. The row recording that hold contains the handle and a date and nothing else.
  • Push registrations: until you turn notifications off, close your account, or your browser or Google invalidates them.
  • Sign-in: a website session lasts 30 days; the app's refresh token expires 90 days after it was last used. Signing out or closing the account ends them at once.
  • Backups: we take a copy of the database every night, for recovery after an outage. Copies on our server are kept for seven days; copies in Amazon Web Services are kept for a limited period under a lifecycle rule and then deleted. A deletion reaches a backup only when that backup expires, and we restore from a backup only to recover from an outage, never to bring deleted data back.

10. Your rights

You can contact us to make the requests below. India's Digital Personal Data Protection Act, 2023 is taking effect in phases. Under the November 2025 commencement notification, its principal processing, children and individual-rights provisions take effect 18 months after publication. As of this policy's date, those provisions are not yet in force. We offer the requests below now; statutory rights and escalation routes apply as their provisions take effect.

  • Know what personal data we hold about you and who we have shared it with.
  • Correct data that is wrong, incomplete or out of date. You can edit most of it yourself in your profile and at opinionsphere.app/settings.
  • Erase personal data that we no longer need for the purpose it was collected for. Read the next section before relying on this one.
  • Nominate someone to exercise these rights on your behalf if you die or become incapacitated.
  • Complain to us. Where the applicable law provides a route to the Data Protection Board of India, you can use it if we do not resolve your complaint.

To exercise any of these, email [email protected]. We will respond within the timeframe the law requires.

Where we rely on your consent, you can withdraw it at any time. Withdrawing consent does not undo what was lawfully done while it was in force.

11. Deletion, and its limits. Read this one

We will not pretend this is simpler than it is.

You can close your account yourself: Settings, then Delete account, on the website or in the Android app; or the page at opinionsphere.app/delete-account; or by emailing us from the address on the account.

What goes. Your email address, your handle, your display name, your bio, your profile photo (both copies), your date of birth, your gender, your link to your Google account, and every session and sign-in token on every device. Your push registrations are deleted, so notifications stop. Your account and any email address are detached from feedback you sent.

What you choose. Your comments stay unless you tick the box to remove them when you close the account. A removed comment becomes a blank placeholder that keeps its place in the thread, so replies to it still make sense.

What stays. Your votes and the polls you created stay, without your name. Your account row stays labelled "Deleted account", because polls, votes and comments point at it. Its public profile details are removed, but retained activity still refers to its account ID. Vote records can retain device identifiers and salted IP hashes; this is not complete unlinking or a guarantee of anonymity. Reactions, reposts, follows and option suggestions you made stay attached to that account row. Usage records and search records that carry your account ID remain until their 180-day deletion runs; the daily counts that survive it carry no identifier. The record of which terms you accepted stays, because it is how we prove what you agreed to. Your handle is held back from new accounts for 90 days.

What you wrote may still identify you. A comment that names you, a bio copied into a poll, a poll question about yourself: closing your account does not rewrite text. Tell us and we will look at it.

We keep votes and polls because a public poll's result is a record that other people have relied on, quoted and built on, and because removing votes retrospectively would let anyone rewrite history by deleting an account. We believe this is a legitimate reason to retain that data in de-identified form. This position has not been tested. If you believe we are holding something we should have deleted, tell us and we will look at it properly rather than pointing you at this paragraph.

If we learn an account belongs to someone under 18, we close it the same way, and we remove its comments as well, without asking. A date of birth that fails the check is never stored.

If you want a poll you created taken down entirely, not just anonymised, email [email protected] and explain why. We will consider it, and we will always take down content that is unlawful or that violates someone's rights.

12. Cookies and on-device storage

What we use:

  • `os_session`• a cookie that keeps you signed in. Strictly necessary.
  • `os_device`• a random ID in local storage, so we know which polls you have voted on.
  • `os_session_id`• a random ID for the current visit, in session storage.
  • A few small preference values, such as your light/dark theme choice, which prompts you have dismissed, and which version of this policy the privacy notice was last shown for.

The Android app uses no cookies. It keeps the same short list of values, your sign-in tokens, the device ID, your preferences and any votes waiting to be sent, in its own private storage instead.

Clearing your browser storage for this site removes all of these, as does clearing the app's storage or uninstalling it. Either way you will be signed out and OpinionSphere will forget which polls you have already answered.

13. Children

OpinionSphere is not for anyone under 18. We do not knowingly collect personal data from children. If you believe a child is using the app, tell us and we will close the account, delete the data and remove the comments.

This is our product rule because the app tracks behaviour in detail. The DPDP provisions on children are subject to the phased commencement described in section 10; our 18+ rule applies now.

14. How we protect it

Traffic is encrypted in transit. Sign-in cookies are httpOnly. We hash IP addresses with a secret salt rather than storing them. Access to the production database is restricted.

We are a small team running beta software. We will not claim our security is perfect. If you find a vulnerability, please tell us at [email protected] before telling anyone else, and we will fix it and credit you if you want us to.

If a breach occurs that puts your data at risk, we will notify you and the Data Protection Board as the law requires.

15. Changes to this policy

We will update this policy as the app changes. When the change is material we assign it a new version and date, shown at the top of this page.

If you have an account, we ask you to read and accept the new version the next time you open the website or the Android app signed in, and we record which version you accepted and when.

If you use the app without an account, nothing asks you to accept anything. On the website, the notice at the bottom of the page appears again after a material change and links here. The current Android app does not repeat a dismissed anonymous notice after a version change; you can read this policy from its menu. The date at the top tells you whether it has changed since you last read it.

16. Complaints

Grievance Officer: Sura Praveen

Email: [email protected]

Address: Hyderabad, Telangana

We will acknowledge your complaint and respond within the period required by law. If you are not satisfied with our response, you can use the escalation routes available under the applicable law. The DPDP timetable is explained in section 10.