Effective date: August 16, 2026
Siyasa Privacy Policy
1. Introduction
Siyasa is a civic engagement platform for American Muslim communities. Siyasa provides a public website, mobile app, voter participation dashboards, candidate and official scorecards, election guides, voter registration and polling-place resources, mail-in and absentee ballot resources, news, events, and civic notifications.
This Privacy Policy explains how Siyasa, including its owners, operators, employees, contractors, administrators, and authorized organizational partners, collects, uses, discloses, stores, protects, and deletes information when a person uses Siyasa websites, mobile applications, APIs, dashboards, communications, forms, or related services.
By using Siyasa, creating an account, submitting information, signing up for notifications, or contacting Siyasa, you acknowledge this Policy. If you do not agree, do not use the Services.
2. Scope
- Website: siyasausa.com and related public pages, including voter participation dashboards.
- Mobile app: Siyasa iOS and Android applications.
- Backend services: account, profile, civic data, scorecards, notifications, contact, event, news, polling-place, ballot, and administrative services.
- Communications: email, SMS, push notifications, in-app messages, contact forms, support messages, and administrative notices.
- Organizational tools: staff/admin functions for publishing events, news, notifications, scorecards, and election information.
This Policy does not control privacy practices of third-party websites or services that Siyasa links to or relies on. Those services have their own privacy policies.
3. Information We Collect
A. Account and profile information
- Name, including first and last name.
- Email address and username.
- Password credentials. Passwords should be stored in hashed form by the authentication system, not as readable plaintext.
- Phone number.
- Residential address, including street address, apartment, city, state, and ZIP code.
- Date of birth, if provided.
- Self-reported voter-registration status, such as registered, not registered, or not sure.
- Communication preferences, including SMS opt-in, email opt-in, push opt-in, privacy consent, and onboarding display preferences.
- Authentication token used to keep a user signed in to the app.
- User roles and organization membership roles for staff, organization administrators, members, or viewers.
B. Contact and support information
- First name, last name, subject, and message submitted through contact forms.
- Account association if a logged-in user sends the message.
- Resolution status and administrative notes, if staff use them to respond or manage support.
C. Device, app, and notification information
- Expo push notification token or similar device token.
- Device platform, such as iOS, Android, web, or unknown.
- Device name or model name, if provided by the device.
- Push permission status and whether push notifications are enabled.
- Notification read receipts and unread counts.
- App storage values, such as an auth token and auth email stored locally on the device to keep the user signed in.
D. Civic, election, and location-related information
- State, city, ZIP code, and address fields used to show elections, deadlines, ballot information, polling places, representatives, districts, events, news, and notifications relevant to the user.
- Address or state query parameters submitted for voter information, polling-place, election authority, Democracy Works, Google Civic, or Cicero lookups.
- Election, candidate, contest, representative, district, deadline, authority, and ballot data returned by civic data providers.
- State-level cached civic datasets and source payloads used to improve speed and reliability.
E. Scorecard and public civic information
- Public congressional member records, service terms, bill data, roll-call vote records, sponsorship and cosponsorship records, and source snapshots from official government sources.
- Candidate score snapshots, candidate names, candidate external IDs, member Bioguide IDs, scorecard results, grades, policy categories, score line items, and public methodology.
- Administrator-created scorecard information, such as scorecard owner, organization, positions, rationales, categories, weights, and publishing status.
F. Event, news, and content information
- Events, event dates, event type, locations, addresses, regions, descriptions, source URLs, attachments, and target audience fields.
- News items, headlines, body text, summaries, authors, regions, attachments, source URLs, and target audience fields.
- Notifications, notification type, title, message, source URL, attachments, publish time, targeting fields, and push sent time.
- Uploaded image or PDF attachments for events, news, notifications, or ballot instructions.
G. Website, technical, and audit information
- IP address.
- Browser or app user agent.
- HTTP method, request path, query string, status code, and timestamp.
- System activity logs and data change logs.
- Cookies, session identifiers, local storage, cache data, or similar technologies, where used by the website, app, backend, hosting provider, or analytics provider.
- Diagnostic information, error details, and crash reports if crash reporting or monitoring tools are enabled in production.
H. Aggregate voter participation and analytics information
Siyasa’s public website describes live voter participation and Muslim voter analytics as aggregate-only. Siyasa should not expose individual voter records in public dashboards. Aggregate dashboards may include counts, trends, turnout summaries, and breakdowns by geography or other categories, such as state, district, city, ZIP, party, vote method, ballot type, or similar dimensions, only when presented in a privacy-safe aggregate form.
4. Sensitive Information
Some information used by Siyasa can be sensitive. Examples include precise home address, date of birth, phone number, self-reported voter status, civic participation interests, community affiliation inferences, political content preferences, and location-related election queries.
Siyasa should not intentionally collect more sensitive information than is needed to operate the Services. Siyasa should not ask for Social Security numbers, driver’s license numbers, passport numbers, financial account numbers, payment card numbers, government ID scans, health records, or exact GPS location unless a future feature requires it and the privacy policy is updated first.
5. How We Collect Information
- Directly from users when they create an account, update a profile, opt into communications, contact Siyasa, or submit a request.
- Automatically when users access the website, app, or backend, including logs, device data, request data, and notification read status.
- From the user’s device when push notification permission is granted and the app registers a push token.
- From civic data providers and public sources when the app requests election, polling-place, candidate, district, representative, scorecard, or legislative information.
- From administrators and organizations when they create events, news, notifications, scorecards, attachments, and targeting criteria.
- From public government records, including Congress.gov, House and Senate roll-call sources, election authority records, and other official civic sources.
- From hosting, storage, database, security, email, SMS, push, analytics, or monitoring providers that process technical information on Siyasa’s behalf.
6. How We Use Information
| Purpose | Examples of use |
|---|---|
| Account operation | Create accounts, authenticate users, keep users signed in, manage profile data, support deletion requests, and prevent duplicate accounts. |
| Civic personalization | Show elections, candidates, ballot data, voter deadlines, polling locations, absentee ballot instructions, representatives, events, news, and notifications relevant to a user’s state, city, ZIP code, or address. |
| Communications | Send email, SMS, push, in-app, administrative, support, election reminder, legislative alert, event, news, or mobilization messages based on user preferences and targeting rules. |
| Scorecards | Publish candidate and official scorecards, calculate grades, show bill-by-bill explanations, and link candidates to congressional records where appropriate. |
| Voter participation dashboards | Display aggregate-only turnout or participation information and analytics without exposing individual voter records publicly. |
| Safety and security | Detect abuse, investigate errors, audit administrative actions, secure accounts, protect the platform, and enforce policies. |
| Operations and improvement | Debug, test, maintain, analyze performance, improve features, manage content, respond to users, and plan civic engagement services. |
| Legal compliance | Comply with applicable law, legal process, tax, corporate, nonprofit, campaign finance, election, app-store, or regulatory requirements where they apply. |
7. How We Use Location And Address Information
Siyasa uses address and location-related information to provide civic features, not to expose a person’s individual voting behavior. The app may use a user’s state, city, ZIP code, or full address to find relevant elections, ballot items, voter registration resources, polling places, election authorities, districts, representatives, absentee ballot instructions, targeted events, targeted news, and targeted notifications.
The current mobile app and backend use typed address/profile fields. The reviewed code does not show collection of continuous GPS location. If future versions collect precise GPS location, Siyasa should update this Policy and ask for permission before doing so.
8. Voter Records And Voter Participation Data
Siyasa’s public website states that voter participation data is aggregate-only and that individual voter records are not exposed. Siyasa should maintain that standard. Public dashboards should show only aggregate counts, trends, and breakdowns that are privacy-safe and should avoid displaying individual voter files, individual turnout records, or individually identifiable voting participation records.
Siyasa may use public, licensed, purchased, partner-provided, or internally prepared datasets to produce aggregate voter participation analytics. If such datasets include personal information, Siyasa should restrict access to authorized personnel, use them only for lawful civic engagement purposes, and avoid publishing individual-level records.
9. Communications And Choices
- Email: Users may opt in or out of non-essential email communications through profile settings where available or by following unsubscribe instructions when provided.
- SMS: Users may opt in or out of SMS communications. Standard carrier message and data rates may apply. SMS consent should not be treated as consent to receive unrelated communications.
- Push notifications: Users may enable or disable push notifications in the app profile where available and through device settings.
- Transactional messages: Siyasa may still send necessary service, security, account, legal, or administrative messages even if a user opts out of promotional or mobilization messages.
- Targeted civic messages: Events, news, and notifications may be targeted by ZIP code, city, or state, using profile data supplied by the user.
10. How We Disclose Information
Siyasa may disclose information in the following circumstances:
- Service providers: Hosting, database, storage, email, SMS, push notification, analytics, security, monitoring, support, and infrastructure vendors that process data for Siyasa.
- Civic data providers: Democracy Works, Google Civic Information API, Cicero, Congress.gov, official House/Senate sources, election authorities, and other civic data sources when needed to retrieve civic information.
- Push notification provider: Expo or operating-system push notification services to deliver push messages to devices.
- Organizational partners: Authorized organizations or administrators that manage events, news, notifications, scorecards, or civic content, subject to role permissions and need-to-know access.
- Legal and safety: Courts, regulators, law enforcement, government authorities, or third parties when required by law or when Siyasa believes disclosure is necessary to protect rights, safety, users, the platform, or the public.
- Business or organizational transfers: A successor, affiliate, merger partner, purchaser, fiscal sponsor, reorganized entity, or similar party if Siyasa changes structure, transfers assets, or combines operations.
- With consent: Any other disclosure directed or authorized by the user.
Siyasa does not sell individual voter records through public dashboards.
11. Third-Party Services And Sources
| Provider / source | Role |
|---|---|
| Democracy Works | Election, authority, ballot, deadline, and voting-location data where configured. |
| Google Civic Information API | Voter information, polling-place, election, and civic data lookups where configured. |
| Cicero | Representative and district lookup data where configured. |
| Congress.gov and official congressional sources | Bill, member, sponsor, cosponsor, roll-call, and legislative source data. |
| Expo push service and platform push services | Delivery of push notifications to iOS/Android devices. |
| Hosting / database / storage providers | Operation of the backend, database, static files, media files, and public website. |
| Google Cloud Storage or DigitalOcean Spaces, if enabled | Remote media storage for uploaded attachments or files. |
| Crash reporting / monitoring providers, if enabled | Error diagnosis and app stability monitoring. |
When users click links to third-party sites, such as official election offices, candidate websites, social media, Ballotpedia, mapping tools, or source URLs, those third parties may collect information under their own policies.
12. Legal Bases For Processing
Where privacy laws require a legal basis, Siyasa may process personal information based on one or more of the following: user consent, performance of a requested service, legitimate interests in operating and securing a civic engagement platform, compliance with legal obligations, protection of vital interests, or public-interest civic activity where recognized by applicable law.
13. Cookies, Local Storage, And Similar Technologies
- The website and backend may use cookies or sessions for security, admin access, authentication, preferences, and basic operation.
- The mobile app stores certain values locally, including authentication token and email, to keep a user signed in.
- The app or website may use cache storage to improve performance and reduce repeated network requests.
- Users can clear app data, use logout features, adjust browser settings, or uninstall the app to remove some local data. Server-side account data may remain until deleted or otherwise handled under this Policy.
14. Data Retention
Siyasa keeps information for as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law. Retention periods may vary by data type.
| Data type | Typical retention approach |
|---|---|
| Account and profile data | Kept while the account is active, then deleted or deidentified after account deletion unless retention is legally required. |
| Authentication tokens | Kept while needed for login/session operation; invalidated or removed when the account is deleted. |
| Contact messages | Kept as long as needed to respond, support the user, maintain records, and improve services. |
| Push device tokens | Kept while enabled and associated with an account; removed when the account is deleted or token is replaced/disabled. |
| Notification read receipts | Kept to provide unread counts and user experience, unless deleted with the account or under a retention schedule. |
| Audit logs | The code includes an AUDIT_LOG_RETENTION_DAYS setting with a default of 30 days, but operational retention may depend on deployment procedures. |
| Civic source payloads and scorecard records | May be retained for auditability, public transparency, historical scorecards, and source verification. |
| Aggregate analytics | May be retained in aggregate or deidentified form for trend analysis and reporting. |
15. Account Deletion And User Requests
The mobile app/backend supports deletion of the current authenticated user account. Deleting an account should remove the user and associated profile-dependent records according to database relationships and operational backups. Some information may remain where required for security, legal compliance, backups, public-interest records, aggregate statistics, or records that are not linked to the deleted account.
Users may request the following, subject to verification and applicable law:
- Access to personal information.
- Correction of inaccurate profile information.
- Deletion of account or personal information.
- Opt-out of non-essential communications.
- Restriction or objection to certain processing where applicable.
- A copy of personal information in a portable format where required by law.
- Information about categories of personal information collected, used, or disclosed.
To make a request, use in-app account controls where available or contact Siyasa through the contact method listed on siyasausa.com. Siyasa may need to verify identity before acting on a request.
16. Security
Siyasa uses administrative, technical, and organizational measures intended to protect information. Examples may include account authentication, password validation and hashing, HTTPS/TLS in production, role-based administrative access, audit logging, limited staff access, hosted database protections, secure API keys, and controlled access to media and source datasets.
No online system can be guaranteed to be perfectly secure. Users should choose strong passwords, keep devices updated, protect email accounts, and promptly report suspected unauthorized access.
17. Children And Minors
Siyasa is intended for civic engagement by users who are old enough to use election and voter information responsibly. Siyasa does not knowingly seek to collect personal information from children under 13. If Siyasa learns that it has collected personal information from a child under 13 without required parental consent, Siyasa should delete it as required by law.
Because some users may be younger voters, first-time voters, students, or preregistration-eligible individuals, Siyasa should avoid collecting more information from minors than necessary and should treat date of birth and address information carefully.
18. Political And Civic Data Notice
Siyasa is a civic and political engagement platform. Use of the Services may reveal or suggest interests in elections, candidates, organizations, policies, communities, geography, voting resources, or civic participation. Siyasa should handle such information carefully and should not use sensitive civic engagement information for unrelated commercial profiling.
Siyasa may publish organization-created scorecards, endorsements, election guides, public candidate information, public legislative records, aggregate voter participation analytics, and civic resources. These materials may reflect editorial, organizational, or community perspectives and are separate from a user’s private account profile.
19. Public Content And User-Submitted Messages
Most users do not publish public content directly through the current mobile app. If Siyasa later allows users to submit public comments, forum posts, endorsements, testimonials, event RSVPs, volunteer signups, or other public content, Siyasa should update this Policy before or when those features launch.
Contact messages and support requests are not intended to be public, but they may be reviewed by authorized staff or service providers to respond to the request and operate the Services.
20. Automated Decision-Making And Profiling
Siyasa may use profile fields such as state, city, and ZIP code to decide which events, news items, notifications, election information, and reminders to show. Siyasa may calculate candidate or member scorecard grades using published methodology and official legislative data. Siyasa does not currently appear to use automated decisions to determine a user’s legal eligibility to vote, register, receive government services, obtain credit, employment, housing, insurance, or similar high-impact outcomes.
21. Do Not Track And Preference Signals
Some browsers send Do Not Track or global privacy control signals. Siyasa should honor legally required opt-out preference signals where applicable. Because standards vary, the Services may not respond to all browser signals in the same way.
22. State Privacy Rights
Depending on where a user lives, state privacy laws may provide rights to know, access, correct, delete, obtain a copy of, or opt out of certain uses or disclosures of personal information. These laws may include, without limitation, privacy laws in California, Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, Virginia, and other states as they become effective.
Siyasa should not discriminate against users for exercising privacy rights. Siyasa may deny or limit a request where permitted by law, such as when identity cannot be verified, the request conflicts with legal obligations, or an exception applies.
California notice
If California law applies, California residents may have rights to know categories of personal information collected, sources, purposes, disclosures, and retention; access specific pieces of information; correct inaccurate information; delete information; opt out of sale or sharing; limit use of sensitive personal information; and avoid discrimination. Siyasa does not intend to sell individual personal information for money. If Siyasa ever uses advertising or analytics practices that constitute sale or sharing under California law, it should provide required opt-out mechanisms.
23. International Users
Siyasa is focused on United States civic engagement. If a user accesses Siyasa from outside the United States, information may be processed in the United States or other locations where Siyasa or its providers operate. Those locations may have privacy laws different from the user’s location.
24. Data Integrity And Source Accuracy
Civic data may come from public agencies, official election offices, Congress.gov, legislative sources, Democracy Works, Google Civic, Cicero, and other providers. Siyasa aims to present useful information, but source data may be incomplete, delayed, or incorrect. Users should verify critical voting details with official election authorities before acting.
25. Changes To This Policy
Siyasa may update this Policy from time to time. The updated version should show a new effective date. If changes are material, Siyasa may provide additional notice through the website, app, email, push notification, or other reasonable means. Continued use after an update means the user acknowledges the updated Policy.
26. Contact
For privacy questions, account requests, deletion requests, or concerns, contact Siyasa at contactus@siyasausa.com or through in-app support/contact features when available.
27. Plain-English Summary
- Siyasa collects account and profile information so it can show civic tools relevant to the user.
- Siyasa uses address, city, state, and ZIP code to provide elections, polling-place, ballot, representative, event, news, and notification features.
- Siyasa’s public voter participation dashboards should remain aggregate-only and should not expose individual voter records.
- Users can update profile information, opt in or out of communications where available, disable push notifications, and delete their account.
- Siyasa uses third-party civic data providers and infrastructure providers to operate the Services.
- Siyasa keeps information only as long as needed for service, security, legal, audit, historical, or aggregate purposes.
Appendix A: Data Category Matrix
| Category | Examples | Primary purposes |
|---|---|---|
| Identifiers | Name, email, phone, auth token, user ID. | Account access, support, communications, security. |
| Profile and civic context | Address, apartment, city, state, ZIP, DOB, voter status. | Personalized civic resources, targeting, reminders. |
| Device and notification | Expo token, platform, device name, read receipts. | Push delivery, notification preferences, unread counts. |
| Technical logs | IP, user agent, path, status, query string, timestamps. | Security, debugging, audit, abuse prevention. |
| Public civic records | Candidates, officials, bills, votes, sponsorships, scorecards. | Public information, transparency, scorecard calculations. |
| Content/admin records | Events, news, attachments, organizations, targeting fields. | Publishing, organizing, notifications, community updates. |
| Aggregate analytics | Turnout summaries, trends, location breakdowns. | Public dashboards, organizing, advocacy, reporting. |
Appendix B: Operational Commitments To Preserve The Public Privacy Promise
- Do not publish individual voter records in public dashboards.
- Review small-count aggregate breakdowns before publication to reduce reidentification risk.
- Limit staff access to detailed datasets by role and need.
- Use aggregate, deidentified, or summarized data where individual-level data is not necessary.
- Keep API keys and provider credentials out of public repositories and client-side code.
- Document any new data categories before launching new features.
- Update this Policy before launching GPS location, donations, volunteer canvassing, public comments, ad tracking, or other new data-intensive features.
Questions about this document? Get in touch. See also our Privacy Policy and Terms of Service.