Privacy notice

How your information is used

Effective 1 August 2026. This notice explains what Informed Opinion records, why it is needed, who receives it, and the choices available to participants.

Who is responsible

Data controller and contact

Andrew Thomas Blake is the data controller for information processed through this service. Privacy enquiries and rights requests should be sent to hello@informedopinion.info.

This notice applies to the public Informed Opinion service, including its Informed Opinion and What's Your View? website presentations. Both use the same accounts, questions, participation records and database. External sources linked from fact questions operate under their own privacy notices.

Data categories

Information collected

Account information consists of first and last name, email address, encrypted password credentials, account role, authentication tokens and relevant timestamps. Passwords are not stored in readable form.

Participation information consists of registered topic positions, fact-question answers and correctness, answer and review counts, knowledge weights, likes or dislikes and their reasons, fact reports, proposed opinion and fact questions, and moderation outcomes.

Operational records may include IP addresses, request times, browser information, delivery records and security events in short-lived application, hosting and email logs. Moderator API activity records the moderator account, the revocable access token used, the action, affected editorial record, request identifier and changed values. API secrets are stored only as one-way digests. The service does not ask for demographic profiles and does not use advertising or behavioural analytics.

Why it is processed

Purposes and lawful basis

Account and operational information is processed to provide the requested service, preserve progress, secure accounts, prevent abuse, answer support requests and maintain the integrity of public results. For moderators, this includes recording which moderation items have been displayed so that editorial notifications remain accurate across sessions. The intended Article 6 basis is legitimate interests in operating a transparent, secure public-interest participation service. Those interests are balanced against participants' privacy through data minimisation, private individual records, access controls and account deletion.

Topic positions can reveal political opinions or philosophical beliefs. These may be special-category data. The Article 9 condition used for recording and calculating with those responses is the participant's separate, explicit consent. Consent is recorded with the version of this notice and can be withdrawn by deleting the account or by contacting the privacy address.

The calculation is automated, but it does not make decisions about individuals and has no legal or similarly significant effect. It assigns topic-specific weight and contributes an unattributed value to a public aggregate according to the published methodology.

Publication

What is and is not public

The site publishes aggregate opinion results and aggregate participant counts. It does not publish a participant's name, email address, individual answer history, individual knowledge weight or individual topic position.

Approved question proposals may become public editorial questions, but the public question is not attributed to the proposer. Moderators see the material and action required; normal moderation interfaces do not identify contributors to moderators unless operational investigation makes access necessary.

Moderators may use an authorised AI assistant to analyse and edit editorial material through the moderator API. The API deliberately withholds contributor identity from moderation issue data. The assistant cannot publish or alter material without an authenticated moderator token, and its writes are audited.

Recipients

Service providers and transfers

Render hosts the application and PostgreSQL database. Resend delivers transactional account email. Gandi provides domain and related email services. These organisations process limited information as service providers under their own security and contractual arrangements.

Providers may process data outside the UK. Where required, transfers should be covered by applicable adequacy arrangements or contractual safeguards. The operator should retain current provider agreements and transfer information as part of the deployment record.

Personal information is not sold, supplied to advertisers or used for targeted political messaging. It may be disclosed where legally required or reasonably necessary to investigate security abuse.

Storage period

Retention and deletion

Account and participation records are retained while the account remains active because they are needed to preserve progress and calculate current aggregates. Participants can delete them from the Account page. Dormant accounts and associated participation should be reviewed after two years without a sign-in and deleted unless the participant is first offered a reasonable opportunity to retain them.

Ordinary application and security logs should be retained for no longer than 30 days unless a specific security incident requires a restricted copy for investigation. Transactional email delivery records follow the configured provider retention period and should be reviewed periodically.

Moderator API audit records are retained with the editorial history while needed for accountability, security and review. They contain the moderator actor but not the identity of the participant who submitted the underlying proposal or report.

Account deletion removes the live account and associated participation records immediately. Encrypted backup copies may remain temporarily within restricted disaster-recovery backups until those backups expire under the hosting provider's rotation. They are not used for ordinary processing and should not be restored without reapplying subsequent deletion records where practicable.

Published editorial questions produced from approved proposals may remain because they no longer retain public attribution to the proposer. Contact the privacy address if their text itself contains personal information.

Essential storage only

Cookies

The site uses an encrypted session cookie named _informed_opinion_session to keep a participant signed in, protect forms and retain the current session. If “Remember me” is selected, an additional authentication cookie can retain the sign-in for up to two weeks.

These cookies are strictly necessary to provide account and security functions. No advertising, cross-site tracking or analytics cookies are currently used, so there is no non-essential cookie consent banner. If non-essential technology is introduced, this notice and the consent mechanism must be changed before it is enabled.

Control

Your data-protection rights

Depending on the circumstances, participants may request access, correction, erasure, restriction, portability, or object to processing. Explicit consent for sensitive topic responses can be withdrawn at any time. The automated Account page provides immediate deletion; other requests should be sent to hello@informedopinion.info.

Right to objectYou may object to processing based on legitimate interests. Send the request to hello@informedopinion.info; it will be considered without undue delay.

Concerns should first be raised with the operator. Participants also have the right to complain to the UK Information Commissioner's Office through ico.org.uk/make-a-complaint.

This notice will be reviewed when the service, providers or purposes change. Material changes affecting consent will require participants to review and accept a new notice version.