Privacy Policy

Last updated: January 20, 2026

1. Introduction

Welcome to Said vs Done ("we," "our," or "us"). We are committed to protecting your privacy and being transparent about how we collect, use, and share your information. This Privacy Policy explains our practices regarding the data we collect when you use our pledge tracking platform.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Your name
  • Email address
  • Profile picture (if you sign in with Google or upload one)
  • Email verification status

2.2 Authentication Data

To keep your account secure and prevent abuse, we collect session information including:

  • IP address (stored with your session)
  • Browser user agent
  • Session tokens and expiration times

2.3 Location Information

We collect limited location information to provide regional context:

  • Country code only: We derive your country from hosting provider headers (e.g., Vercel, Cloudflare). We only store the two-letter country code (e.g., "GB", "US"), never your precise location or full IP address for this purpose.
  • Self-reported country: You may optionally tell us your country to enable filtered views of voting data by region.

We implement minimum threshold requirements to prevent deanonymization when displaying regional data.

2.4 Voting and Activity Data

When you interact with pledges, we collect:

  • Your votes on pledge questions (yes/no responses)
  • Timestamps of your voting activity
  • Vote history for audit purposes

2.5 Analytics Data

We use PostHog for product analytics to understand how users interact with our platform and improve the experience. PostHog may collect:

  • Pages visited and features used
  • Device type and browser information
  • Referral sources
  • Session recordings (anonymized)
  • Performance metrics

You can opt out of analytics tracking using the cookie preferences or browser settings.

3. How We Use Your Information

We use your information to:

  • Provide and maintain the Said vs Done platform
  • Authenticate your account and keep it secure
  • Process and display aggregated voting results
  • Send you magic link emails for passwordless authentication
  • Prevent abuse and enforce rate limits
  • Improve our services through analytics
  • Respond to your requests and provide support
  • Comply with legal obligations

4. Cookies and Tracking Technologies

We use the following types of cookies:

4.1 Essential Cookies

These cookies are necessary for the platform to function and cannot be disabled:

  • Session cookies: Used to keep you logged in and maintain your authentication state.

4.2 Analytics Cookies

These cookies help us understand how you use our platform:

  • PostHog cookies: Used for product analytics, feature usage tracking, and improving user experience. These cookies may track your browsing behavior across sessions.

4.3 Managing Cookies

You can control or delete cookies through your browser settings. Note that disabling essential cookies may prevent you from using certain features of the platform, such as staying logged in.

5. Third-Party Services

We use the following third-party services:

6. Data Sharing

We do not sell your personal information. We may share your data in the following circumstances:

  • Aggregated data: Voting results are displayed in aggregate form and never reveal individual votes.
  • Service providers: We share data with the third-party services listed above to operate our platform.
  • Legal requirements: We may disclose data if required by law or to protect our rights and safety.

7. Data Retention

We retain your data as follows:

  • Account data: Retained while your account is active and for a reasonable period afterward.
  • Session data: Sessions expire automatically and are cleaned up periodically.
  • Voting history: Retained for audit and integrity purposes.
  • Analytics data: Retained according to PostHog's data retention policies.

8. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Data portability
  • Withdraw consent for optional data processing

To exercise these rights, please contact us using the details below.

9. Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encrypted data transmission (HTTPS)
  • Secure password hashing
  • Rate limiting to prevent abuse
  • Regular security reviews

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

10. Children's Privacy

Our platform is not intended for children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our platform or sending you an email. Your continued use of the platform after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

Email: privacy@saidvsdone.com

Privacy Policy - Said vs Done