How vote privacy works
Encrypted on your device
Everything you write into a session — option texts, votes, scores, numbers, chat messages, images, even the session's name — is encrypted on your own device before it is sent. The server receives and stores only the scrambled, unreadable form. The keys that unlock it exist only on participants' devices, carried by the session invite — which is why only the people in your session can read its content.
Results computed where the keys are
Adding up the result needs readable ballots, so it happens on participants' devices, not on our servers. When a session completes, the devices in the room also cross-check that they all computed the same combined result.
What the service does see
Running the service requires some operational data in readable form: that a session exists, when it was created and closed, how many participants and votes it has, account emails for registered users, and the technical request data any web service handles. What it never has is the content — what the options say, who voted for what, or what was written in chat.
The full picture — retention periods, your rights, the processors we use — is in the Privacy Policy.