Skip to page content
VTE FILESUnited States edition
Independent · nonpartisan
Privacy

Useful measurement without visitor profiles

The site counts which broad features are used so they can be improved. It does not need to know who a reader is to do that.

Last updated September 10, 2026

What the site counts

The Vote Files keeps daily totals for broad page categories and a short list of product actions: searches submitted, area lookups, files added to or removed from a watchlist, browser watchlists copied into an account, interest in creating an account or enabling alerts, official-source links opened, briefing records opened, Morning Record links or graphics shared, topic-history filters used, daily check-ins enabled, and interest in supporting the project.

Each total can be separated by phone, tablet, or desktop and by whether the visit began directly, from another Vote Files page, or from another site. These are aggregate counters. They do not identify a person or claim to count unique visitors.

What is never put in product analytics

Product analytics do not store a name, email address, IP address, user agent, precise location, raw search phrase, ZIP code, public-record identifier, full page address, referrer address, cookie, session identifier, advertising identifier, or browser fingerprint.

The site does not build a visitor profile from these counters. It does not use an outside analytics or advertising company, and it does not sell these product analytics or use them to target advertising.

Information kept in your browser

An anonymous watchlist, a saved ZIP-based area, the date of your last briefing, and whether you enabled the Morning Record check-in can be stored in your browser so those features work without an account. They remain on that device unless a feature needs to ask the server for the current public record.

When you request a ZIP-based area, the ZIP code is sent to the server for that lookup. It is not included in product analytics. Removing the saved area or clearing site storage removes the browser copy.

When you check a recorded-vote claim

The recorded-vote pilot sends five structured fields to Vote Files: member identifier, Congress, chamber, roll-call number, and asserted cast. It does not accept article text, a quotation, a headline, or a link, and it does not fetch another website.

Those five fields are used to render the response and are not written to the Vote Files database, a cookie, browser storage, or product analytics. Results are not given a public result identifier and the pilot has no sharing endpoint. Ordinary hosting and security logs remain subject to the technical-logs disclosure below.

When another site loads a Vote Files record card

The public embed accepts only an allow-listed Vote Files record identifier. Its application starts no account session, reads or sets no account cookie, and loads no analytics or advertising code.

The official publisher loader tells the browser to send no referrer, requests credentialless loading where supported, and sandboxes the card without same-origin access, forms, or scripts. A publisher that bypasses that install pattern controls its own request behavior. An embed request can still appear in ordinary hosting and security logs under the technical-logs disclosure below; no embed, publisher, or visitor row is created in the Vote Files database.

When you choose to create an account

An account stores your email address, a one-way protected version of your passphrase, followed public files, optional saved area, briefing preferences, and active-session records. A browser-only watchlist is copied into an account only after you approve the transfer.

Verification and recovery links are random, single-use, and time limited. Session cookies are protected from JavaScript and are never stored in product analytics. Account settings let you sign out every device, download your private account data, or delete the account and its saved files.

Email briefings are sent through Postmark only on the schedule you choose and only when a dated public record behind a followed file changes. Postmark receives the email address and message needed to deliver, suppress, and diagnose that briefing under its own privacy terms. Every message links to the exact record and includes a direct way to turn off email alerts.

For account security, Vote Files stores a keyed one-way hash of the request address with authentication events. The hash is used to rate-limit abuse and investigate account access; it is not product analytics and is not used to identify or profile readers.

Public payments (currently closed)

Public PayPal checkout is currently closed. The public support page does not send payment or account information to PayPal and presents no active payment button. If checkout opens, PayPal will be the only payment processor.

Protected payment tables and identifiers can exist for authorized private readiness tests. Vote Files never receives or stores a card number, bank account number, or PayPal password. A private-test payment or dispute record may be retained for reconciliation, fraud-prevention, tax, and legal obligations.

Use the payment category on the tracked request desk for a private-test payment, refund, cancellation, duplicate-charge, or receipt question. Do not enter card, bank, or PayPal credentials in that form.

When you contact the tracked request desk

The request desk stores the category, short summary, message, affected Vote Files page, supporting source link, and any name or reply email you choose to provide. It assigns a random reference code and makes the request available only in the authenticated private review desk.

A short-lived, HttpOnly browser cookie protects the form from cross-site submission and binds the success receipt to the browser that submitted it. To limit automated abuse, the request desk temporarily counts submissions using separate keyed, one-way hashes for the browser token, request address, and coarse network range. The raw address and network range are not stored in the support-request database, the hashes are not used for product analytics or profiling, and expired rate-limit buckets are removed. The support-request database does not store a user agent. Ordinary hosting and security logs remain subject to the technical-logs disclosure below.

Submitted material is used to investigate, respond to, document, and resolve the request. It is not published automatically and is never treated as proof without independent source verification. Resolved requests may be retained when needed to document corrections, publisher instructions, payment disputes, privacy responses, abuse, or legal obligations.

Do not submit passwords, payment-card or bank details, government ID numbers, medical information, or sealed or victim-identifying material.

Retention and hosting logs

Aggregate daily product counters are kept for up to 400 days and then removed automatically.

Expired verification, recovery, and unsubscribe tokens and expired sessions are removed after a seven-day cleanup buffer. Authentication audit events and resolved email-delivery history are kept for up to 365 days. A delivery with an uncertain provider outcome is retained until it is reconciled.

Deleting an account removes its email, passphrase, sessions, tokens, followed files, saved area, account-linked audit history, and delivery history. A one-way suppression hash may remain when an address hard-bounced, complained, or was manually deactivated so Vote Files does not send to that address again.

Like most websites, the hosting and security systems may create technical access or error logs when a request reaches the server. Those infrastructure logs are separate from product analytics and may contain technical request information needed to operate and protect the site.

Questions and changes

Questions about this page can be sent through the privacy category on the tracked request desk. If the measurement design changes, this page and its update date will change with it.