Privacy policy
Last updated: 29 July 2026
1. About this policy
This Privacy Policy explains how How2Vote handles information when you use the website, compare your views with historical parliamentary records, create a voting plan, choose to contribute to research, or contact us.
How2Vote is operated by General Consulting Services Pty Ltd as trustee for the Australian Business Trust, trading as National Digital (ABN 13 744 838 758, ACN 658 447 280) (National Digital, we, us or our).
We apply privacy-by-design principles and handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles to the extent they apply to us.
2. The privacy design in summary
The core comparison and voting-plan functions are designed to run in your browser:
- there is no account or login;
- your quiz answers and preference order are processed on your device;
- your current progress and saved plans are stored in your browser unless you clear them;
- we do not automatically upload your answers or preference order for research;
- research contribution is a separate, optional opt-in; and
- usage analytics is aggregate and cookieless, and sets nothing on your device.
Some technical information must still be processed when your device connects to the website, and information is sent when you choose to contribute to research or submit a form. Those activities are described below.
3. Information stored on your device
The Service may store the following in your browser's local storage or similar device storage:
- your selected electorate and state or territory;
- your quiz answers and issue weights;
- the preference order you choose;
- saved voting plans;
- the data and methodology version used;
- your selected election and display preferences, such as light or dark theme;
- your acknowledgement of the Terms of Use; and
- your privacy choices.
This information stays on your device unless you choose an action that sends it, such as research contribution or a form submission. You can remove it using the Service's start-again and delete controls, or by clearing site data in your browser.
One qualification for the app versions, so that "stays on your device" is not read as more than it is. We never transmit this information, but on iOS the operating system's own device backup may include an app's stored data, so if you have iCloud Backup or an encrypted computer backup switched on, a copy can be held by that backup service under your own account and restored to a replacement device. That is a function of the platform's backup, not of the Service, and we cannot read it. The Android app switches this off: it declares itself out of Android's automatic cloud backup. Using the delete control in section 11 clears the data on the device; it does not reach into a backup already taken, which you manage through your device or backup provider's settings.
4. Shared links and plans
A share link may encode your answers or results in the part of the address after the # symbol, known as the URL fragment. The Service is designed so that
its servers and analytics do not receive or record that fragment; the recipient's browser uses it
to reconstruct the shared result on their device.
Anyone who receives the link can see the information encoded in it. A link may also be exposed through screenshots, copied messages, browser synchronisation, browser extensions or the actions of a recipient. Only share with people you choose.
A share link does not expire and cannot be recalled or deactivated. Because the answers live inside the link rather than on our servers, there is nothing for us to switch off: once you send a link, it keeps working for anyone who has it, and clearing your own device does not affect a copy someone else already holds. You are shown this before you copy a link.
5. Optional research contribution
Our research privacy commitments
Each commitment below is backed by an automated test in our source code, and is shown here only while that test is passing and the commitment is current; the detail follows in this section.
- Contributions are stored only as additions to aggregate group counts; no individual research record is created or stored.
- Your individual quiz answers and importance weights never leave your device — only a party match and a per-proposition agree/neutral/disagree stance, worked out on your device, are sent.
- Your electorate is sent as its own separate request and kept only as a running count, never paired with any result or survey answer.
- Published research suppresses any group with fewer than 10 contributions.
- A contribution carries no name, email address, phone number, IP address, cookie or device identifier.
- The research endpoints never read your IP address or user agent, and never log the request body or full address of your contribution.
- Research contributions are sent only over an encrypted (HTTPS) connection with caching disabled, and only a fixed allowlisted set of fields is ever transmitted.
No automatic research upload
We do not send a research record merely because you complete the quiz or create a voting plan. After your result is available, you may be invited to contribute a research record. Participation is optional, is not required to use the Service and does not change your result or voting plan.
Before a record is sent, you must actively select a separate consent control confirming that:
- you are at least 18 years old;
- you have read the short collection notice and this policy; and
- you consent to the specified device-derived results and optional survey information being collected for the described research purposes.
The consent control is off by default.
What is collected if you opt in
Your device does the analysis before anything is sent: it works out your closest party match and reduces each proposition you answered to agree, neutral or disagree. Your individual quiz answers and the weights you selected never leave your device. A contribution then contains only:
- the closest party match calculated on your device;
- whether you agreed, were neutral or disagreed with each proposition you answered;
- your state or territory, but not your electorate;
- the election being compared, together with that election's public AEC timetable dates, which the server uses to classify the period in which you contributed;
- the version of the consent notice you agreed to, which is kept only as an aggregate count of how many contributors accepted each version, never against your other answers;
- the dataset and app versions, which are sent so the server can check your contribution against the current research wave but are not kept in the dataset; and
- optional survey answers you choose to provide.
Everything received is stored only as additions to aggregate counts — running group tallies such as “one more contributor in this age group whose closest match was this party”. No individual research record is created or stored, and counts that pair a result with a sensitive survey answer are kept at national level only, never by state.
The optional survey may ask about age range, gender, education, employment, union membership, household circumstances, income range, country of birth, language, Aboriginal or Torres Strait Islander origin, religion, sexual orientation, political identification, previous vote and intended vote. Some of these categories may be sensitive information under Australian privacy law, including political opinions or associations, union membership, racial or ethnic origin, religious beliefs and sexual orientation. Every survey question is optional and includes a prefer-not-to-say option.
What is never collected
A contribution is designed not to contain your:
- individual quiz answers or importance weights (analysed on your device only);
- name, email address or phone number;
- street address;
- precise date of birth;
- IP address;
- advertising identifier;
- cookie identifier;
- device fingerprint;
- electorate (kept only as the separate running count below); or
- selected preference order.
Your IP address and other technical data may nevertheless be processed briefly by hosting, network and security providers to transmit and protect the request. We configure the research system so that those technical details are not copied into the research dataset.
How electorate is handled separately
So that we can describe the geographic spread of contributions without holding your electorate near any result, electorate is kept only as a running count — a tally of how many contributions come from each electorate, with no results, survey answers, dates or anything else attached — sent by your browser as its own separate request that is not joined to your contribution in our storage. No count ever pairs an electorate with a result or a survey answer. (Because two requests from the same device travel the same network path, we describe this as separated by design rather than as an absolute guarantee of unlinkability.)
Research purposes
We use contributed records to:
- study how participants' stated views compare with selected historical parliamentary voting records;
- examine aggregate patterns across sufficiently large groups;
- test and improve the methodology and data quality;
- detect errors and unusual data patterns; and
- publish aggregate research, explanations or dashboards.
We do not use research records to target political advertising, build individual voter profiles, contact participants, determine eligibility for a service, or make decisions about an individual.
Aggregate-only storage and residual risk
The research dataset is aggregate-only by construction: it holds group counts, not individual records, and the set of counts it may hold is fixed in advance by a published analysis plan. We do not collect a name, email address or account identifier with a contribution. However, no de-identification technique can eliminate every possible re-identification risk: while contributions are being gathered a group count can be small, and a very small count in a rare category could say something about a person known to have contributed, particularly if combined with information held elsewhere.
We reduce that risk by keeping any count that pairs a result with a sensitive survey answer at national level only, restricting access to the counters themselves, separating research data from operational logs, limiting retention and publishing only aggregated results that meet disclosure thresholds. We do not attempt to re-identify participants and contractually prohibit service providers and authorised researchers from attempting to do so.
Deletion of a contribution
Because we do not issue or retain a record identifier linked to you, we will generally be unable to locate a particular contribution for access, correction or deletion. A contribution is stored only as additions to group tallies and holds no name, contact detail, account, cookie or per-record code, so there is no individual record that could tie a stored count back to you. You control whether a contribution is ever made at all through the opt-in described above; nothing is sent unless you actively consent.
Research retention and publication
Research contributions are stored only as additions to aggregate group counts — there is no individual record. Because those counts are genuinely aggregated statistics that do not relate to an identifiable individual, we may retain them indefinitely to support long-run repeated cross-sectional analysis, comparison across federal election datasets and collection periods, methodological validation and historical research. Participants are not identified or linked between elections, so this supports repeated cross-sectional and cross-election comparison rather than following the same individuals over time.
We still review the aggregates after each federal election and delete any that are no longer reasonably required for a research purpose. Retention is not limited by a fixed maximum period, because the group counts we hold are not personal information; the protections that matter for those counts are the disclosure controls below, not a deletion clock.
Public research results:
- contain aggregate counts, percentages or summaries only;
- do not publish raw individual records;
- do not publish electorate-level results;
- suppress groups with fewer than 10 records; and
- are reviewed for re-identification risk before release.
A threshold of 10 is a minimum control, not a guarantee. We may use a higher threshold, combine categories or withhold a result where the circumstances create additional risk. You can see the current results on the insights page.
6. Analytics
We measure how the Service is used with Cloudflare Web Analytics, which counts page views and general usage in aggregate, at our hosting provider's edge network. It is cookieless: it sets no cookie, stores nothing on your device and assigns you no identifier, so it cannot be used to recognise or track you across visits or across sites. Because it collects no personal information and needs no cookie, there is nothing to switch on and no consent banner to dismiss.
Analytics never receives:
- quiz answer values;
- issue weights;
- electorate;
- party or candidate alignment results;
- preference order;
- shared-link fragments; or
- research survey answers.
We do not use analytics for advertising or political targeting. Cloudflare processes this aggregate measurement as our hosting provider; see the provider table below and the Cloudflare privacy policy for details.
7. Contact and feedback forms
If you submit a contact or feedback form, we collect the information you enter, such as your name, email address and message. We use it to respond, investigate reports, maintain the Service and protect our legal rights. Form messages are normally retained for up to 24 months, unless they are needed for a continuing complaint, legal matter, security incident or recordkeeping obligation.
The forms post to our own service, which sends your message to us by email through our hosting provider's email service; there is no third-party form provider, and this site stores no copy of the message. Spam and abuse prevention is a self-hosted, cookieless check that is non-interactive — there is no puzzle to solve — and is computed on your device when you submit one of those forms; it loads no third-party CAPTCHA or tracker. You can contact us by email or telephone instead of using a form.
8. Hosting, security and technical logs
When you visit the Service, hosting, content-delivery and security systems necessarily process technical information such as your IP address, request time, browser, requested page and security signals. We use this information to deliver the website, prevent abuse, diagnose faults and investigate security incidents. We do not intentionally combine routine technical logs with research records, and technical-log retention is limited to what is reasonably required for security and operations.
9. Service providers and overseas processing
We use service providers to host, secure and operate the Service. They process information for us under their terms and contractual privacy and security commitments. This list is generated from our internal vendor register, so it reflects every service recorded in that register. Current providers are:
- Cloudflare (Cloudflare, Inc.): Website hosting and CDN (Cloudflare Pages), edge compute (Pages Functions), the consented research counter database (Cloudflare D1), cookieless aggregate usage measurement (Cloudflare Web Analytics, measured at the edge with no client tag or cookie), the transactional email relay for the contact/feedback forms (Cloudflare Email Sending, called server-side at api.cloudflare.com), edge security (per-IP rate limiting on the API routes), and release-binary hosting (R2). The anti-abuse challenge is self-hosted (an in-app proof-of-work issued and verified by our own Pages Functions) — no Cloudflare or other third-party code loads in the browser for it, so this infrastructure entry adds no Content-Security-Policy source. Data location: Global — Cloudflare edge network; may be processed outside Australia.
- GitHub (GitHub, Inc.): Source-code hosting, pull-request review and continuous integration via GitHub Actions. The deployed site does not contact GitHub at runtime. Data location: United States and global — Microsoft/GitHub infrastructure.
- Google (Google LLC): Application distribution through Google Play: hosts the store listing and delivers the Android store build (apps/mobile). The deployed site and the app do not contact Google at runtime; the app's only Play touchpoint is a user-initiated store deep link handed to the operating system. Data location: United States and global — Google infrastructure.
- They Vote For You (OpenAustralia Foundation): Source of parliamentary voting-record data (party positions) via the They Vote For You API, retrieved at data-build time and compiled into the dataset. The deployed site does not contact this service at runtime. Data location: Australia — OpenAustralia Foundation.
Before sending personal information to an overseas recipient, we take reasonable steps appropriate to the circumstances to ensure it is handled consistently with applicable Australian privacy requirements. We do not sell personal information or research records.
The list below is generated automatically from our internal service registry, so it always reflects exactly what this site can load, the category each service falls under, and the cookies it may set. Fonts and everything else the app needs are served from our own domain, so they are not third parties.
None — no third-party service loads in your browser. The anti-spam check is self-hosted and usage is measured by cookieless edge analytics; infrastructure providers we rely on (hosting, source control, data sources) are listed in the providers table below.
10. Security
We use reasonable technical and organisational measures appropriate to the nature of the information, including encrypted network connections, access controls, separation of research and operational systems, least-privilege access, dependency and vulnerability management, backups and incident-response procedures. No internet service or storage system can be guaranteed completely secure. If an eligible data breach occurs, we will assess and notify affected individuals and the Office of the Australian Information Commissioner where required by law.
11. Access, correction and deletion
You can view, change or delete locally stored answers and plans through the Service, or through your browser settings on the web. In the iOS and Android apps there are no browser settings to use, so the control below is the way to clear that data: it clears both the app's own storage and the durable copy the app keeps so the operating system cannot quietly evict your saved plans. The control below clears everything stored on this device in one step — your in-progress quiz, saved comparisons, selected election, theme, Terms acknowledgement, privacy choices and age-eligibility confirmation, together with the offline copy of the app — and it is also available on the Saved cards page. It clears this device only: it cannot recall a link you have already shared, because a share link carries its answers inside the link itself and stays with whoever received it (see section 4).
Clear all your data on this device
How2Vote keeps everything in this browser — there is no account and nothing is uploaded. This removes all of it from this device in one step:
- your in-progress quiz answers and selected electorate;
- every comparison you saved on this device;
- your selected election and light/dark theme;
- your Terms acknowledgement and privacy choices;
- your age-eligibility confirmation; and
- the offline copy of the app and dataset stored for use without a connection.
This clears this device only. It cannot take back a link you have already shared: a share link carries its answers inside the link itself, so once you send it, it stays with whoever received it.
You may ask us to access or correct personal information we hold about you, or to delete it where applicable, by contacting contact@how2vote.au. We may need to verify your identity before acting. As explained above, a de-identified research record holds nothing that could locate it, so we are unable to retrieve or delete an individual research record.
12. Complaints
Privacy questions or complaints can be sent to:
National Digital Privacy Contact
Email: contact@how2vote.au
Telephone: 1300 800 855
Gold Coast, Queensland, Australia
We aim to acknowledge a privacy complaint within five business days and provide a substantive response within 30 days. If you are not satisfied, you may contact the Office of the Australian Information Commissioner.
13. Children and young people
The core information tool may be viewed by younger people, but we do not knowingly accept research contributions from anyone under 18. A person must confirm that they are at least 18 before submitting a research record. Because a contributed record is de-identified, we may be unable to locate a specific record later; we will delete a record contributed by a person under 18 where we can identify it.
14. Changes to this policy
We may update this policy when the Service, providers, research or law changes. The current version and effective date will be published on this page. Material changes to research collection or use will not be applied to a new research submission without a new or updated collection notice and consent.
15. Contact
National Digital
ABN 13 744 838 758
ACN 658 447 280
Email: contact@how2vote.au
Telephone: 1300 800 855
Gold Coast, Queensland, Australia