// Legal

Privacy Policy

How SyncVotes handles your data on the Canton Network. Last updated 25 September 2026.

Overview

SyncVotes is an open-source governance platform built on the Canton Network. It collects the minimum it needs to run: there is no login, no e-mail, no tracking and no personal data harvesting. Your key is your identity, and it never leaves your browser.

What this validator sees

Every party in SyncVotes is hosted on the app's own validator, and the app's party co-signs every contract so that the ledger accepts it. This validator therefore sees every DAO run here — its name, members, proposals, ballots and comments — as Daml contracts, which it needs in order to count ballots and carry out decisions. It cannot act for you: the only key that can sign your transactions is yours. In particular, the app sees:

  • Your party id: the hint you chose and the fingerprint of your key
  • Your profile, if you keep one — a name, a picture by link, a few words — shown wherever your party appears in the app
  • The contracts of the DAOs you are in, and every ballot and comment in them
  • Canton Coin transfers to the validator's party (the app's address), read off the ledger to credit a balance
  • The address a request comes from, used to pace sign-ups

Other Canton validators receive none of this: Canton delivers a transaction only to the parties in it, and the synchronizer that orders it sees only encrypted views. What keeps a DAO to its members on the way to a browser is the app: a DAO is shown only to members who have proved they hold their key.

If you would rather no outside operator could read your DAOs, you do not have to use this site: SyncVotes is open source and runs on any Canton validator. See Self-Hosting.

What we don't collect

  • Personal identity information
  • E-mail addresses or passwords — there is no login
  • Private keys or recovery phrases — the key is generated and kept in your browser
  • Off-chain data or browsing history
  • Analytics, advertising identifiers or tracking cookies

Your key and your browser

The key comes from a twelve-word recovery phrase. Between visits it rests in your browser's storage encrypted with AES-GCM, unlocked by a passkey or a password, and locks itself after fifteen minutes idle. It is never sent to the server: the server prepares each transaction, the browser checks and signs the hash, and the server submits the signature. Your theme choice is also kept in your browser.

Sessions and cookies

SyncVotes sets one cookie, sv_session. Once per unlock the browser signs a challenge with your key, and the server keeps a session in memory behind that HttpOnly cookie for up to twelve hours, so that a DAO is shown only to its members. A restart of the server forgets every session. There are no other cookies.

On-chain data

All governance actions — creating a DAO, proposing, voting, commenting — are recorded on the Canton Network ledger as Daml contracts. Unlike public blockchains, Canton does not expose transaction data globally: only the parties on a contract — you, the other parties in it and this validator as the host of your party — can see its contents. Comments are on the record and cannot be edited or deleted. Ledger retention and visibility are governed by the Canton Network protocol, not by SyncVotes.

Third-party services

SyncVotes relies on Canton Network infrastructure for ledger operations and reads Canton Coin prices from the network's public Scan. The site is served through Cloudflare, which terminates connections at its edge and sees the requests it forwards, and its fonts are loaded from Google Fonts; each handles the requests it serves under its own privacy policy. We do not integrate third-party analytics trackers, advertising networks or external data processors.

Pictures that users add to DAOs, profiles and descriptions are links: your browser loads each one from wherever its author put it. That server sees your address and when the picture was loaded, though not the page it was shown on. Anyone who adds a picture can therefore learn when it was viewed.

Data retention

On-chain data persists on the Canton Network ledger according to the network's own rules. The server keeps an in-memory copy of the contracts the app's party sees, rebuilt from the ledger on every start; there is no separate database of users. Sessions live in memory for at most twelve hours.

Contact

SyncVotes is an open-source project. For questions or concerns about this policy, open an issue or reach out through the repository.

github.com/SYNCVOTES/syncvotes