Privacy Policy
Last updated: September 2026
1. Who We Are
World Republic ("World Republic," "we," "us," or "our") operates the World Republic application and website at https://www.worldrepublic.org (the "Service"). World Republic is a Swiss association (Verein) under Art. 60 et seq. of the Swiss Civil Code with its seat in Zug, Switzerland. It has legal personality under Art. 60(1) of the Civil Code and is not entered in the commercial register. The Service is administered from Hungary by our board, so for the purposes of the EU General Data Protection Regulation (GDPR) World Republic is established in the European Union, and our lead supervisory authority there is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).
For most processing described below we are the data controller. For identity verification, we are the controller and Amazon Web Services acts as our processor / service provider. A second provider, Didit, is named below for an escalation route that is not currently offered — see Section 4.2.
- Privacy contact: privacy@worldrepublic.org
- Contact in the European Union: Balázs Kónya, board member, 3626 Hangony, Dózsa György út 5., Hungary (privacy@worldrepublic.org)
2. Scope
This policy applies to everyone who uses the Service, worldwide. Where local law gives you additional rights — including the EU and UK GDPR, the revised Swiss Federal Act on Data Protection (revFADP), the California Consumer Privacy Act as amended by the CPRA, and U.S. state biometric laws (Illinois BIPA, Texas CUBI, Washington) — those rights are described in Section 10.
World Republic currently runs non-binding test elections. We are not yet enrolling members; participation is experimental.
3. Information We Collect
3.1 Information you provide
- Account information: if you sign in with Google, we receive an authentication token and your Google account identifier. We keep the identifier, which is what links your account to your Google sign-in; the token is dropped and never stored. We deliberately do not store your Google name, email, or photo.
- Passkey credentials: if you use a passkey (WebAuthn), we store the public key credential, an identifier, and the device metadata needed to authenticate you.
- Profile information: an automatically generated username and referral code.
- Content you create: political party names, descriptions, and links.
- Age confirmation: that you confirmed you are 18 or older, and when. We ask this once, before identity verification. We do not ask for your date of birth and do not store one — only that the confirmation was given, the age it was given against, and the time.
- Review outcome for your party: whether the automated review in Section 5.1 listed your party by default or set it aside as spam, the ground it gave, which of its two checks (or which person) decided, and when.
- Voting record: that you voted in a given test election, and when. Not which party you voted for. The ballot is secret: your choice is added to the party's total and no record links it to you (see Section 5).
- Transaction details: when you withdraw WDD, the destination wallet address, amount, and selected chain.
3.2 Identity verification and biometric data
To keep test elections fair (one verified person, one vote) and to prevent fraud and duplicate accounts, we verify that you are a unique, live, real person. See Section 4 for the full, separate explanation of biometric data — please read it carefully.
3.3 Information collected automatically
- Device and log information: device and browser type, operating system, and similar technical data.
- IP address: we process your IP address to enforce rate limits and prevent abuse (stored short-term in our rate-limit records). We also store your IP address and browser user-agent as part of a consent record when you accept our Terms and Privacy Policy or give biometric consent, as proof of that consent.
- Usage information: features used and actions taken within the Service.
- Copies of your data: when you download the machine-readable file described in Section 10.1 we record that a copy was made, when, that it was the file, and which parts of the record it carried. We keep it so that every device you are signed in on reads the same list — it is the only way we have of telling you that somebody with your session took a copy of everything, since we hold no address to tell you at. Reading the copy on screen is not recorded; what the list catches is the copy that leaves the device.
- Performance measurement: we measure how quickly pages load and respond on your device (Core Web Vitals) and send those timings to our hosting provider, along with the page's route and coarse device, connection and country information derived from the request. This is cookieless, stores nothing on your device, and is not linked to your account. The address reported is reduced to the page path before it leaves your device, so query strings — including referral links — are not sent.
3.4 Cookies and local storage
We use only strictly necessary and functional cookies and local storage:
- Authentication and security (session and account-linking cookies).
- Preferences (e.g. your selected language).
- Functional state (e.g. referral capture, return-to-page after verification).
We do not use advertising cookies, and we run no advertising or cross-site tracking SDKs. We do run one cookieless performance-measurement SDK (Vercel Speed Insights) to measure page-loading speed: it sets no cookies, stores nothing on your device, and does not identify you — see §3.3.
4. Biometric Data (Face Liveness) — Please Read
To vote in test elections you must complete a face liveness check. This involves processing biometric data, which is sensitive / special-category personal data. We want to be fully transparent about it.
4.1 What happens
- Your device captures a short live facial video, which is processed by Amazon Web Services (AWS) Amazon Rekognition Face Liveness to confirm a real, live person is present (anti-spoofing).
- On a successful check, AWS stores a reference facial image for the session, and we create a facial vector (template) that is added to a secure AWS Rekognition collection.
- We use that collection to run a one-to-many comparison against other users' facial vectors to check whether the same face is already verified on another account.
The refusal is automatic. If the comparison finds a match, verification for that account is refused at that moment, by the comparison itself, and no person takes part in the decision. The only thing weighed is how closely the facial vector made from your scan resembles a vector already in the collection, measured against a single fixed similarity threshold; nothing else about you enters it. A refused account cannot vote in test elections or register a party, and the refusal stands for that account unless a person reverses it.
You can ask a person to look at it. Write to privacy@worldrepublic.org, or ask in our Help Community, and we will answer within one month. A person compares the reference image from your check with the one held for the account it matched, where both still exist — the other image may already have been destroyed under Section 4.5 — and can reverse the refusal and verify you. So that this is possible, we keep the record of the match with the refused check: which account was matched, and how close the comparison was (Section 8).
4.2 Escalation to Didit
This route is not currently offered, and no check can be started. It is described here because it is designed, and because it was briefly available in mid-2026.
The idea is an escalation to Didit, an identity-verification provider, for someone the face check refuses in error — a false duplicate match between people who look alike. It would ask for your explicit consent and have Didit check a document and a selfie on our behalf.
Today none of that runs: the Service has no screen that offers it, and the route that would start a check refuses every request. Didit holds no verification data of ours — every check made during that earlier period was deleted from Didit in September 2026. If you were declined by the face check, the route open to you is the one in Section 4.1: ask in our help community, and a person can look at both records and reopen verification.
If the escalation is ever offered again, this Section will say what it collects and what we receive before it does.
4.3 Service-provider notice (AWS and Didit)
World Republic uses service providers for identity-verification services. Biometric identifiers and biometric information ("biometric data"), specifically scans of your facial geometry and the related facial images and templates, may be collected, stored, and used by these service providers (AWS; and Didit, if the escalation in Section 4.2 is ever offered again) on World Republic's behalf for the purpose of verifying that you are a unique, live, real person and preventing duplicate or fraudulent accounts. World Republic destroys the biometric data AWS stores on its behalf when the initial purpose for collecting it has been satisfied, when you request deletion, or earlier if required by law. Didit holds no biometric or identity data of ours: the escalation is not offered, and the checks made while it briefly was were deleted from Didit in September 2026. Should it ever be offered again, the terms on which Didit may hold and must delete that data will be settled and stated here first. Biometric data may be transmitted between World Republic and its service providers as necessary to provide this service.
4.4 Your consent and choice
We process your biometric data only with your explicit, opt-in consent, which we request at the start of the face liveness step. You can decline, but you will not be able to vote in test elections without completing verification.
You can withdraw that consent at any time, and you do not have to delete your account to do it. In the app, open Account → Verification → Delete my face data. Withdrawing takes effect immediately and destroys both the reference image and the facial template we compare it against. Your account, your WDD balance, any party you lead and any vote you have already cast are unaffected. You will not be able to vote again until you complete a new face check, which you are free to do at any time — unless your check has already been refused as a duplicate of another account (the automatic refusal described in Section 4.1). Withdrawing destroys the data but does not change that decision; contact privacy@worldrepublic.org to contest it.
One exception, and it is the same one Section 4.5 describes for account deletion: if a test election you have voted in is still open when you withdraw, your consent ends at once but the biometric data itself is destroyed when that election closes — unless you complete a new face check before then, in which case that new consent stands and nothing is destroyed. You can also delete your whole account instead (Section 9), or contact us to exercise any of the rights in Section 10.
4.5 Retention and destruction
We retain biometric data only as long as needed for verification and anti-duplication, and we destroy it when the purpose is satisfied, on your deletion request, or within the period set in our written biometric retention and destruction policy — whichever occurs first. Destruction includes deleting the AWS reference image (Amazon S3) and the facial vector (Rekognition collection).
One exception, bounded and stated here because you should know it before you act: if you delete your account — or withdraw your biometric consent under Section 4.4 — while a test election you have voted in is still open, we keep your biometric data until that election closes and destroy it then. If you withdrew and then verify again before the election closes, the pending destruction is cancelled, because the new face check is a new consent; deletion is never cancelled this way. Because the ballot is secret, a cast vote cannot be withdrawn, and the face check is the only thing that stops the same person from verifying a new account and voting a second time in the same election. The delay never exceeds the election's remaining window and never exceeds fourteen days: an election that closes more than fourteen days after you act does not hold the destruction at all. Nothing else about the deletion waits.
4.6 Where biometric data is processed
Your facial templates and reference images are processed and stored by AWS in the European Union (Ireland). Associated verification metadata (for example, confidence scores and storage references) is held in our primary database (see Section 7).
5. How We Use Information and Our Legal Bases
| Purpose | Examples | Legal basis (GDPR / revFADP) |
|---|---|---|
| Provide the Service | Accounts, parties, wallet, voting | Contract |
| Run test elections | A record that you voted, and when; your ballot added to the party's total | Contract, for the record that you voted. The ballot itself is secret — no record links your choice to you, and party totals are counts, not records about any person |
| Verify unique, live identity | Face liveness and deduplication (the Didit escalation in Section 4.2 is not currently offered) | Explicit consent (special-category) |
| Authenticate and secure | Sign-in, passkeys, sessions | Contract / legitimate interest |
| Prevent fraud and abuse | Rate limiting (IP); the automated duplicate-face refusal in Section 4.1 | Legitimate interest / legal obligation; for the refusal, contract and your explicit consent (Section 4.1) |
| Review party registrations | An automated check of a party's name, description, link and leader username for advertising, impersonation, paying for votes, incitement to violence and obscenity — never for its politics (Section 5.1) | Legitimate interest (an honest ballot registry); for the political opinions a registration expresses, they are ones you have manifestly made public by registering the party |
| Process WDD withdrawals | On-chain transfers | Contract |
| Keep proof of consent | Consent records (Terms/Privacy acceptance, biometric consent) with timestamp, IP, and user-agent | Legal obligation / legitimate interest (accountability) |
| Improve the Service | Fix bugs, basic usage analysis | Legitimate interest |
| Comply with law | Respond to lawful requests | Legal obligation |
5.1 Automated review of party registrations
When you register a party or edit it, a program reviews it before it is listed in the default registry. No person takes part in that step.
- What it reads: the party's name, description, website link and the leader's username — nothing else about you.
- What it decides: whether the party appears in the default lists, search and ballot, or is set aside as spam. A party set aside is not removed: it stays at its own address, can be found by choosing to show all parties, and can be voted for.
- The grounds: advertising for something outside the Service (including impersonating the Service or an established party), offering individual payment for votes, incitement to violence, and obscenity. Political views are never a ground, and the review must quote what it flags.
- How it decides: a large language model, GLM-5.3 Flash by Z.ai, applies those rules to the text. It runs on Baseten in the United States (Sections 6 and 7), which keeps nothing of the request once it is answered and does not train on it. A second, fixed rule compares the party's name with established parties' names. The outcome, its ground and which check decided are kept with the party (Section 8).
- Your options: the party's leader sees the outcome and the ground on the party's page. Editing the party resubmits it for review. You can ask a person to review the outcome through the Help Community linked from that notice, or by writing to privacy@worldrepublic.org.
6. How We Share Information
We do not sell your personal information. We share it only with processors acting on our behalf, and as required by law:
- Google — authentication (policies.google.com/privacy).
- Amazon Web Services (AWS) — Amazon Rekognition Face Liveness, Amazon S3 (reference images), and Amazon Cognito (temporary guest credentials), as our service provider for biometric verification (EU region).
- Didit — identity verification on escalation. Not currently offered and holding no data of ours (Section 4.2). See Didit's Verification Privacy Notice and End User Terms for Identity Verification.
- Coinbase — executes WDD blockchain withdrawals; receives the destination address, amount, and chain only.
- Thirdweb — executed WDD blockchain withdrawals until August 2026, and still completes withdrawals started before then; receives the same data.
- Neon — database hosting for Service data (Singapore region).
- Vercel — application hosting, infrastructure logs, and cookieless performance measurement (Singapore region); its AI Gateway also carries the party-review request in Section 5.1 to Baseten and nowhere else.
- Baseten — runs the language model that reviews party registrations (Section 5.1); receives the party's name, description, link and leader username, keeps none of it once the request is answered, and does not train on it (United States).
A current list of sub-processors is available on request. We may also disclose information to comply with law or valid requests by public authorities, and in a merger, acquisition, or asset transfer (subject to lawful safeguards).
7. International Data Transfers
We are established in Switzerland, which benefits from an EU adequacy decision. Your data is processed in more than one country:
- Biometric data (facial templates and reference images) is processed and stored by AWS in the European Union (Ireland).
- Account and application data is hosted with Neon (database) and Vercel (hosting) in Singapore.
- Party registrations under review (name, description, link, leader username) are sent to Baseten in the United States for the automated review in Section 5.1, and are not stored there.
Singapore is not covered by an EU or Swiss adequacy decision, and the United States only for recipients certified under the Data Privacy Framework. For transfers to Singapore, to the United States and to any other country without adequacy, we rely on the European Commission's Standard Contractual Clauses, the Swiss complement, and appropriate supplementary measures. Where adequacy decisions apply (for example, EU–Switzerland), we rely on those.
8. Data Retention
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account (biometric data has its own three-year inactivity ceiling — see the biometric row and the retention policy) |
| Biometric data (image + vector) | Until purpose satisfied, deletion request, or the period in our biometric policy — whichever is first |
| Identity-verification records | Minimal result data: the outcome of the duplicate-face check and, on a refusal, which account was matched and the similarity score; deleted with your account. A refusal record on another account that matched your face is kept with that account while it exists. For checks made before September 2026, when the human review that then applied opened and closed, and what it decided, are kept with your verification record and deleted with it |
| Identity-verification sessions from our first verification route, retired June 2026 | We keep only the sessions that recorded a completed check — they are your evidence that you verified through that route, and there is no other. Sessions that were abandoned, expired or failed are not kept: they record no outcome about anyone, and had no purpose left once the route was retired. Cleared September 2026 on storage-limitation grounds |
| Voting record (that you voted, and when) | With your account; kept, anonymized, after deletion to preserve the integrity of test elections |
| Party vote totals | Indefinitely — they are counts, not records about any person |
| Party review request (what Section 5.1 sends to the review model) | Not stored by the review host — it exists there only while the request is answered |
| Party review outcome (verdict, ground, which check, when) | With the party, and reset each time you edit it |
| Transaction records | As required by applicable law. Where a payout could not be sent, we also keep a record of the refused attempt — when it happened, the network, and the status the payment provider returned — for as long as we keep the withdrawal it belongs to |
| Consent records | The fact, date, document version, language and screen of each consent and any withdrawal are kept with your anonymized account as evidence that consent was given and withdrawn; the IP address and device details recorded with them are removed when the account is deleted |
| Record of copies of your data you asked for | The date, the format and which parts each copy carried — never the copy itself. Kept with your account and deleted with it. It is not aged out: the list is short because there is a limit on how often a copy can be built (Section 10.5), and a record that expired would be one an attacker could outwait |
| IP / rate-limit records | Short-term (cleared automatically) |
9. Account Deletion
You can delete your account in the Service. On deletion we destroy the biometric data AWS holds on our behalf, delete our record of any Didit check, remove your verification records, and delete or irreversibly anonymize your personal data, except where we must retain limited information to meet legal obligations or to preserve the integrity of test elections.
You can save a copy of your data before you do (Section 10.1). Once the account is deleted we cannot produce one, because there is nothing left to build it from.
Votes you have cast stay counted. The ballot is secret, so there is no record of your choice to remove; the anonymized record that you voted is kept so that each election's turnout stays true. If a test election you voted in is still open when you delete, your biometric data is destroyed when that election closes rather than immediately (see Section 4.5).
10. Your Rights
Depending on where you live, you may have the rights below. Exercising them normally costs you nothing (Section 10.5), and you will not be treated differently for exercising them.
- EU/EEA and UK (GDPR / UK GDPR): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Where a decision about you was reached by automated means alone and has a significant effect on you — the refusal described in Section 4.1, and the listing decision in Section 5.1 — you also have the right to obtain human intervention on our part, to express your point of view, and to contest the decision; write to privacy@worldrepublic.org. You may complain to your local supervisory authority; for EU GDPR purposes our lead supervisory authority is the Hungarian NAIH (Section 14).
- Switzerland (revFADP): access, rectification, deletion, data portability (Art. 28 revFADP), objection, and the right to complain to the Federal Data Protection and Information Commissioner (FDPIC). For the automated refusal described in Section 4.1, you can also state your position and ask for the decision to be reviewed by a person.
- Brazil (LGPD): confirmation that we process your data, access, correction, anonymisation or deletion, portability, information about who we have shared your data with, and withdrawal of consent.
- California (CCPA/CPRA): know, delete, correct, opt out of sale/sharing (we do not sell or share), and limit the use of sensitive personal information (which includes biometric data).
- Biometric laws (Illinois BIPA, Texas CUBI, Washington): we obtain your consent before collecting biometric data, do not sell it, and follow a written retention and destruction schedule.
10.1 How to exercise them
There are two routes. The first answers access and portability on the spot, without asking anybody.
- In the app. Open your account settings; under Account there is a row called Your data. It builds a copy of everything we hold about you that we can reach from your account — a page you can read, and a machine-readable file you can hand to another service. It is built at the moment you ask, for the account that is asking, and it is stored nowhere: we keep no copy of it and there is no link anyone else could be sent. That is our answer to access and to portability, and you do not have to ask us for it. Deleting your account is on the same screen.
- In writing. Everything else — rectification, restriction, objection, a question about data held by our providers (Sections 4.3 and 6), or a complaint about a decision — goes to privacy@worldrepublic.org.
We hold no email address for you (Section 3.1), so we can only reply to an address you write to us from. There is no other channel: we cannot email you, message you or notify you about anything you did not start.
10.2 How long we take
Balázs Kónya, board member, is accountable for answering requests sent to privacy@worldrepublic.org, within the periods set out below. We do not promise a shorter internal deadline than the law requires: a target nobody operates is worse than the statutory one met, and the periods below are what we work to.
Time runs from the day your request reaches us — not from the day we finish identifying you, and not from the day we find what you asked for. Under the GDPR and the UK GDPR we answer without undue delay and in any event within one month of receipt. Where a request is complex, or where you have made several, we may take up to two further months; we will tell you within the first month that we are doing so, and why.
Where the law where you live sets something different, that is what we do:
- United Kingdom. If we reasonably need more information to identify you or to find what you have asked for, the clock pauses from the day we ask until the day you answer. We will ask only where we genuinely cannot proceed without it.
- Brazil. We confirm whether we process your data and give you access to it in a simplified form immediately, and in full within 15 days of your request.
- Switzerland. We answer within 30 days as a rule. The answer carries what Art. 25(2) revFADP requires it to carry, including the recipients or categories of recipient your data goes to and, where it goes abroad, which country and the safeguards we rely on — Sections 6 and 7 set both out in advance.
- California. We confirm receipt within 10 business days and answer within 45 days, which we may extend once by a further 45 days if we tell you why.
10.3 How we know it is you
We hold no identity document for you and no address on file, so the ladder below is what we have. We work down it and stop at the first rung that answers.
- Your signed-in account. The copy in the app is built for the account that asks for it, in the moment it asks. Nothing identifies you better, which is why it is the first route in Section 10.1 rather than a convenience.
- A passkey registered to that account. If you cannot reach the app, we may ask you to complete a passkey sign-in against a credential the account already holds.
- The Google account linked to it. If you signed in with Google, we may ask you to show control of that account by signing in with it.
- More information. If none of those is possible, we may ask you for further information we reasonably need to be satisfied the request is yours, and for no more than that.
- A written refusal. If we still cannot be satisfied, we will tell you so in writing, within the time in Section 10.2, with our reasons and with the complaint route in Section 10.4. We would rather refuse a request we cannot place than answer it to the wrong person.
We will never accept a wallet address as proof of who you are. Withdrawals are made on public blockchains, so an address you have used is something anyone reading the chain can name; knowing it proves nothing, and signing a message from it would prove control of a key rather than of this account.
We will also not ask you for an identity document in order to answer a request. We hold none to compare it against (Section 4.2), so it would tell us nothing and would cost you more than the request is worth.
10.4 If we refuse
If we do not act on your request we will tell you why, within the time in Section 10.2, and we will tell you what to do next. You can complain to the data protection authority where you live — for EU purposes the Hungarian NAIH, in Switzerland the FDPIC, in the United Kingdom the ICO (Section 14) — and you can go to court. Neither depends on our agreement.
In the United Kingdom you also have the right to complain to us directly. We will acknowledge a complaint within 30 days and tell you the outcome without undue delay. Complaining to us is not a condition of complaining to the ICO.
10.5 What it costs
Nothing. Where a request is manifestly unfounded or excessive — in particular where it repeats one we have already answered — the law allows us to charge a reasonable fee or to decline, and if we ever do either we will say which and why. We would rather decline one request with reasons than put a price on the rest.
The machine-readable file has a small limit on how many times a day it can be built. That is not a fee and it is not about capacity: it is there so that somebody who gets hold of your session cannot quietly take your whole record away again and again. It never stops you reading the copy on screen, and it never stops you writing to us.
10.6 Two rights we do by hand
Access, portability and deletion are in the app and need no request. Restriction and objection are not. We hold no switch that suspends processing of one part of your record while leaving the rest working, so a request to restrict or to object is carried out by us, by hand, case by case, within the times in Section 10.2. Write to us, say what you want stopped and what it is about your situation that makes it matter, and we will weigh it and tell you what we did. We would rather tell you this is manual than let you infer it from how long it takes.
11. Security
We use TLS in transit, access-controlled storage, and least-privilege access. No system is perfectly secure, but we work to protect your data.
12. Children
The Service is for adults 18 or older. Before we verify your identity we ask you to confirm you are 18 or older, and we do not verify anyone who does not. We record only that the confirmation was given and when; we do not ask for your date of birth.
We do not knowingly collect data from anyone under 18. If we learn that we hold data about a person under 18, we close their account and destroy their biometric data as described in our Biometric Data Retention and Destruction Policy. If you believe someone under 18 has an account, contact privacy@worldrepublic.org.
13. Changes
We may update this policy and will revise the "Last updated" date and, for material changes, notify you in the Service.
This policy is written in English. Where we publish a translation, it is provided for convenience; if a translation and the English text differ, the English text prevails.
14. Contact
- Privacy: privacy@worldrepublic.org
- Contact in the European Union: Balázs Kónya, board member, 3626 Hangony, Dózsa György út 5., Hungary (privacy@worldrepublic.org)
- EU lead supervisory authority: Hungarian National Authority for Data Protection and Freedom of Information (NAIH), Budapest — naih.hu
- Swiss supervisory authority: Federal Data Protection and Information Commissioner (FDPIC), Bern
- UK supervisory authority: Information Commissioner's Office (ICO), Wilmslow — ico.org.uk