Privacy Policy

Last updated: July 29, 2026. This policy explains what information Nanovote handles and how we protect it.

Who we are

"Nanovote" — and "we", "us", and "our" in this policy — is the service at nanovote.com, operated by Stanislav Yefimenko, PE (ФОП) in Ukraine. For any privacy question, or to exercise your rights, contact us at [email protected].

Your privacy, in short

Nanovote is built so that your votes stay yours. When you take part in a session, the things you create and submit — the options, your votes, your scores, rankings, numbers, messages, and any images — are encrypted on your own device before they ever reach us. Your device never sends us this content in a readable form; we only ever receive and store the scrambled, unreadable result.

So we can't see what you voted for, nor how you voted — not the scores, rankings, or values themselves. We also don't add up the result; that happens on participants' devices, not on ours. Whatever reaches our servers stays encrypted with keys we don't have, so the content can be unlocked only by the people in your session.

What we can see

To run the Service, we handle some information that is not part of your encrypted content:

  • Your email address, if you register an account — for sign-in, account recovery, verification, and occasional service messages. You can also use Nanovote as a guest, without giving an email.
  • Your password only in a protected, one-way form. We never store it in a way we can read, and we cannot recover it for you.
  • Basic account and session facts: that an account or session exists, when it was created, how many people joined, a session's status, and how many votes were submitted — but never their contents.
  • Your IP address and basic device information (such as browser type and operating system) with each request, to keep the Service running, prevent abuse, and troubleshoot problems.

What we never see or keep

  • The contents of your votes, options, session settings, messages, or images in any readable form.
  • Your password in readable form, or your recovery phrase — we never receive it.
  • Any advertising, tracking, or profiling identifiers.

A note on invite links

An invite link is like a key to a session: anyone who has it can join and see that session. Share invite links only with the people you want to include, and treat them like passwords.

How long we keep things

  • Sessions: removed 60 days after they finish. Sessions that never finish are removed 60 days after their last activity. This includes everything a session holds — options, votes, and chat messages. It's how Nanovote is designed: decide together, then move on.
  • Active accounts: kept until you delete them.
  • Deleted accounts: removed immediately when you ask — your account is erased from our live systems right away. Encrypted session data you created may remain for the other participants (we can't read it either way).
  • Backups: we keep encrypted backups of our database for disaster recovery. They expire on a rolling schedule — the oldest copies are removed within about six months — so deleted data also disappears from backups as they rotate.
  • Sign-in and verification tokens: expire automatically and are cleaned up on a schedule.
  • Server logs: kept for up to 30 days and then deleted. They never contain your vote or option contents; they may include IP addresses and request times.

Who else processes data for us

We rely on a small number of trusted providers, and your encrypted content stays unreadable to them:

  • OVHcloud (France) — hosting for our servers and database.
  • Cloudflare — network security, traffic routing, and content delivery.
  • Amazon Web Services (SES) (EU region) — sending account emails such as verification and password reset. No vote contents are ever in our emails.
  • Backblaze (EU) — off-site storage of our database backups. Backups are encrypted on our own servers before upload, so Backblaze stores only encrypted data.

We do not use analytics suites, advertising networks, email-marketing platforms, or session-replay / heatmap tools.

Cookies and local storage

Nanovote uses no cookies, so there is no cookie banner. To keep you signed in, hold the keys that protect your content, and remember basic in-app preferences, the app stores a small amount of data in your browser's local storage, on your own device — this is essential to how the Service works, is never used for advertising, tracking, or profiling, and is never shared. Our analytics are cookieless and place no tracking identifier on your device.

Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or object to the processing of your personal data, and to complain to your local data-protection authority.

Because we can't read your content, some of this works differently than with most services: the readable version of your votes, options, messages, and images lives only in the app, decrypted on your own device with keys we don't have. We can't hand you a readable copy of that content, because we can't unlock it — to us it is always opaque data. So you can:

  • access and delete your account yourself from your profile page (deletion takes effect immediately);
  • view your content in the app, on your own device, where it is decrypted;
  • request a copy of the personal data we can actually read — such as your account details and session metadata — plus your encrypted content as the opaque data we store; a self-serve export is planned, and in the meantime you can email us;

To exercise any of these, or to ask a privacy question, email [email protected].

Children

Nanovote is not directed to children. You must be at least 18 to use the Service, and we do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has provided us with personal data, email [email protected] and we will delete it.

Where your data is handled

Our servers and database are hosted in the European Union (France). Some of the providers above may process limited data — such as network traffic or email delivery — in other countries, under appropriate safeguards.

Reporting a concern

To report a security or privacy concern, email [email protected].

Changes to this policy

We'll let registered users know by email about material changes — for example, a new provider that handles personal data, a change in how long we keep data, or any change that weakens how your content is protected. Minor changes, like fixing a typo, may be made without notice.

bgcsdeelenesetfifrhuiditjaltlvnbnlplptrosksvtruk