Privacy Policy
Politihub Navigators — Privacy Policy
Last updated: 2026-05-15
This Privacy Policy describes how AO Cybersystems Inc. ("we," "us," "AO Cybersystems," "Politihub") collects, uses, shares, and protects information when you use the Politihub Navigators mobile application ("the App," "Navigators"). The App is the volunteer-facing field tool for campaigns running on the Politihub platform.
If you are an organizer or staff member rather than a volunteer, please refer to the Politihub Staff Console privacy policy at politihub.com.
1. Who this policy covers
Politihub Navigators is distributed to volunteers (the "you" of this policy) by political campaign committees that run on the Politihub platform. Volunteers do not self-register through the App; the campaign committee invites you. The committee that invited you, together with AO Cybersystems, is responsible for the data described below.
2. Data we collect
We collect the following categories of information when you use the App. Each category exists for a specific operational purpose described below; we do not collect data we do not need.
2.1 Authentication and profile data
When you sign in:
- Email address — your account identifier, used for authentication and for transactional emails (password reset, security alerts).
- Name — the display name shown to staff in the campaign's organizer console.
- Optional phone number — if you opt to receive SMS alerts from the campaign; you can opt out in the Me screen at any time.
- A non-personal volunteer user ID — a randomly generated UUID used internally to associate your activity with your account; not derivable from your name or email.
2.2 Voter data captured through canvass activities
When you knock doors, call voters, text voters, or collect petition signatures, you record information about other people (the voters your campaign is contacting). This is third-party data the campaign collects for legitimate political fieldwork purposes. The voter data you have access to is scoped to the walk lists, call lists, and turf assignments your committee has given you. Typical voter fields:
- Voter name and address
- Party affiliation and voting history (public-record data in most U.S. jurisdictions)
- Conversation outcomes you record (supportive / undecided / refused / not home, follow-up notes)
- Petition signatures you collect (drawn signature, signer match against the voter file, photos of physical petition pages)
This voter data does NOT belong to you and is not yours to retain independently. It is the campaign committee's property; it flows back into the campaign's voter file when you submit / sync.
2.3 GPS location data (opt-in only; foreground only)
The App supports an OPTIONAL GPS breadcrumb feature used by campaigns to visualize knocked turf. This feature requires two separate consents:
- Committee setting — the campaign organizer must explicitly enable GPS breadcrumb collection for your committee.
- Your consent — you must explicitly turn on the GPS toggle on the Me screen.
When both consents are in place, the App collects your latitude and longitude only while you are actively canvassing in the App (in an in-progress canvass session). GPS sampling stops the moment you leave the canvass screen or close the App.
The App does NOT collect location when backgrounded. It does NOT use
"always" mode. iOS uses NSLocationWhenInUseUsageDescription (in-app
only). Android does NOT request ACCESS_BACKGROUND_LOCATION or
FOREGROUND_SERVICE_LOCATION permissions.
You can revoke GPS consent from the Me screen at any time. Revocation takes effect immediately; previously collected breadcrumbs remain in your campaign's records (subject to retention rules below) unless you also request data deletion.
2.4 Photos
When you collect petition signatures via photo capture of a physical page, when you photograph a canvass result, or when you upload an image as part of any feature, the App stores those photos and uploads them to your campaign's organizer console. Photos are scoped to your committee.
2.5 Device identifiers and push tokens
- APNs token (iOS) or FCM token (Android) — used to deliver push notifications (canvass turf assigned to you, signature requests, training reminders, opportunity board updates). You can disable push notifications in the Me screen or in your device's system Settings.
- Operating system version, device model, app version — collected as part of diagnostic events to help us debug platform-specific issues.
2.6 Crash diagnostics
We use Sentry to receive crash reports from the App. Crash reports include the crash stack trace, the OS version, the device model, the App version, and the build number.
Crash reports are PII-scrubbed before transmission to Sentry:
- Your email, phone, and IP address are removed.
- Voter PII fields (voter name, address, phone, email, voter UUID) are removed.
- Location data (latitude, longitude) is removed.
- Push tokens are removed.
- HTTP request bodies are dropped entirely.
- HTTP cookies are dropped.
The Sentry scrubber is enforced by a load-bearing test
(test/core/observability/sentry_pii_scrubber_test.dart). The
volunteer's non-personal user UUID is kept so we can correlate multiple
crash reports from the same install.
2.7 Internet logs and operational metadata
Our backend logs (server-side) record API requests for security and debugging. These logs include source IP, request path, and response code, retained for 30 days. Logs do not include request bodies.
3. How we use your data
- To authenticate you and authorize your access to campaign data.
- To enable you to record canvass / phone bank / text bank / petition / training activity and synchronize that activity to the campaign.
- To deliver push notifications you have opted in to receive.
- To help your campaign visualize fieldwork (the optional GPS breadcrumb feature).
- To monitor the App for crashes and improve quality.
- To respond to your support requests.
- To comply with applicable law and protect against fraud or abuse.
We do NOT use your data to sell to third parties. We do NOT use voter data for any purpose other than the campaign work you contribute to.
4. How we share your data
- With your campaign committee. Your activity (knocks, calls, texts, signatures, training progress) is shared with the campaign organizers in your committee's organizer console. This is the primary purpose of the App.
- With service providers we contract with.
- Twilio for SMS delivery (if your campaign uses text bank).
- Apple Push Notification service (iOS) and Firebase Cloud Messaging (Android) for push delivery.
- Sentry for PII-scrubbed crash diagnostics.
- Cloudflare R2 (or equivalent) for petition page photo storage. All service providers operate under contractual data-handling obligations to AO Cybersystems.
- For legal reasons — to comply with subpoenas, court orders, or applicable law; to protect rights, safety, or property; or to investigate violations of our Terms.
We do NOT sell your personal data to third parties. We do NOT use voter data to target you personally for advertising.
5. Data retention
- Authentication and profile data — retained while your account is active; deleted within 30 days of account deletion request.
- Voter activity records — retained per the campaign committee's retention policy (typically the election cycle plus FEC compliance window).
- GPS breadcrumb data — retained for up to 12 months per the Obj 13 retention design, then aggregated and the raw points discarded.
- Photos — retained per campaign committee policy.
- Crash diagnostics — retained for 90 days in Sentry.
- Server-side request logs — retained for 30 days.
6. Your rights
Depending on your jurisdiction, you may have rights to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Request deletion of your personal data.
- Object to or restrict certain processing.
- Receive a copy of your personal data in a portable format.
- Withdraw consent for processing based on consent (such as the GPS breadcrumb feature, which you can revoke at any time from the Me screen).
To exercise any of these rights, email [email protected] with the subject line "Privacy Rights Request — Politihub Navigators." See also docs/navigators-store/data-deletion.md for the deletion-specific process.
For California residents: this policy also serves as your CCPA notice. We do not sell personal information.
7. Children
Politihub Navigators is intended for use by adult volunteers (18+). The App does not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, please email [email protected] and we will delete that information.
8. Security
- The on-device App database is encrypted with SQLite3MultipleCiphers (sqlite3mc) using a per-install key stored in the device Keychain (iOS) or Encrypted SharedPreferences (Android).
- All API traffic uses TLS.
- Authentication credentials use industry-standard password hashing on the backend.
- Crash reports are PII-scrubbed before transmission (see §2.6).
9. International data transfers
AO Cybersystems is based in the United States. By using the App, you acknowledge that your data may be processed in the United States. We take reasonable steps to ensure data is handled in compliance with applicable cross-border transfer requirements.
10. Changes to this policy
If we materially change this policy, we will notify you via the App (banner on the sign-in or Today screen) at least 30 days before the change takes effect. The "Last updated" date at the top of this document records the most recent revision.
11. Contact us
For privacy questions, data requests, or to report a privacy concern:
- Email: [email protected]
- Mail: AO Cybersystems Inc., Privacy Team, [address TBD — populate before first public release].
- Support: https://politihub.com/support
For general App support unrelated to privacy, contact your campaign organizer or use the support link in the Me screen.