Privacy Policy
Last updated: September 2026
1. Who We Are
World Republic ("World Republic," "we," "us," or "our") operates the World Republic application and website at https://www.worldrepublic.org (the "Service"). World Republic is a Swiss association (Verein) under Art. 60 et seq. of the Swiss Civil Code with its seat in Zug, Switzerland. It has legal personality under Art. 60(1) of the Civil Code and is not entered in the commercial register. The Service is administered from Hungary by our board, so for the purposes of the EU General Data Protection Regulation (GDPR) World Republic is established in the European Union, and our lead supervisory authority there is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).
For most processing described below we are the data controller. For identity verification, we are the controller and our verification providers (Amazon Web Services and Didit) act as our processors / service providers.
- Privacy contact: privacy@worldrepublic.org
- Contact in the European Union: Balázs Kónya, board member, 3626 Hangony, Dózsa György út 5., Hungary (privacy@worldrepublic.org)
2. Scope
This policy applies to everyone who uses the Service, worldwide. Where local law gives you additional rights — including the EU and UK GDPR, the revised Swiss Federal Act on Data Protection (revFADP), the California Consumer Privacy Act as amended by the CPRA, and U.S. state biometric laws (Illinois BIPA, Texas CUBI, Washington) — those rights are described in Section 10.
World Republic currently runs non-binding test elections. We are not yet enrolling members; participation is experimental.
3. Information We Collect
3.1 Information you provide
- Account information: if you sign in with Google, we receive an authentication token and your Google account identifier. We deliberately do not store your Google name, email, or photo in our user records.
- Passkey credentials: if you use a passkey (WebAuthn), we store the public key credential, an identifier, and the device metadata needed to authenticate you.
- Profile information: an automatically generated username and referral code.
- Content you create: political party names, descriptions, and links.
- Age confirmation: that you confirmed you are 18 or older, and when. We ask this once, before identity verification. We do not ask for your date of birth and do not store one — only that the confirmation was given, the age it was given against, and the time.
- Review outcome for your party: whether the automated review in Section 5.1 listed your party by default or set it aside as spam, the ground it gave, which of its two checks (or which person) decided, and when.
- Voting record: that you voted in a given test election, and when. Not which party you voted for. The ballot is secret: your choice is added to the party's total and no record links it to you (see Section 5).
- Transaction details: when you withdraw WDD, the destination wallet address, amount, and selected chain.
3.2 Identity verification and biometric data
To keep test elections fair (one verified person, one vote) and to prevent fraud and duplicate accounts, we verify that you are a unique, live, real person. See Section 4 for the full, separate explanation of biometric data — please read it carefully.
3.3 Information collected automatically
- Device and log information: device and browser type, operating system, and similar technical data.
- IP address: we process your IP address to enforce rate limits and prevent abuse (stored short-term in our rate-limit records). We also store your IP address and browser user-agent as part of a consent record when you accept our Terms and Privacy Policy or give biometric consent, as proof of that consent.
- Usage information: features used and actions taken within the Service.
- Performance measurement: we measure how quickly pages load and respond on your device (Core Web Vitals) and send those timings to our hosting provider, along with the page's route and coarse device, connection and country information derived from the request. This is cookieless, stores nothing on your device, and is not linked to your account. The address reported is reduced to the page path before it leaves your device, so query strings — including referral links — are not sent.
3.4 Cookies and local storage
We use only strictly necessary and functional cookies and local storage:
- Authentication and security (session and account-linking cookies).
- Preferences (e.g. your selected language).
- Functional state (e.g. referral capture, return-to-page after verification).
We do not use advertising cookies, and we run no advertising or cross-site tracking SDKs. We do run one cookieless performance-measurement SDK (Vercel Speed Insights) to measure page-loading speed: it sets no cookies, stores nothing on your device, and does not identify you — see §3.3.
4. Biometric Data (Face Liveness) — Please Read
To vote in test elections you must complete a face liveness check. This involves processing biometric data, which is sensitive / special-category personal data. We want to be fully transparent about it.
4.1 What happens
- Your device captures a short live facial video, which is processed by Amazon Web Services (AWS) Amazon Rekognition Face Liveness to confirm a real, live person is present (anti-spoofing).
- On a successful check, AWS stores a reference facial image for the session, and we create a facial vector (template) that is added to a secure AWS Rekognition collection.
- We use that collection to run a one-to-many comparison against other users' facial vectors to check whether the same face is already verified on another account.
The refusal is automatic. If the comparison finds a match, verification for that account is refused at that moment, by the comparison itself, and no person takes part in the decision. The only thing weighed is how closely the facial vector made from your scan resembles a vector already in the collection, measured against a single fixed similarity threshold; nothing else about you enters it. A refused account cannot vote in test elections or register a party, and the refusal stands for that account unless a person reverses it.
You can ask a person to look at it. Write to privacy@worldrepublic.org, or ask in our Help Community, and we will answer within one month. A person compares the reference image from your check with the one held for the account it matched, where both still exist — the other image may already have been destroyed under Section 4.5 — and can reverse the refusal and verify you. So that this is possible, we keep the record of the match with the refused check: which account was matched, and how close the comparison was (Section 8).
4.2 Escalation to Didit
If you cannot complete the AWS face liveness check (for example, a false duplicate match for look-alikes), we offer an escalation to Didit, an identity-verification provider, to confirm your identity. In that flow we ask for your explicit consent, and document, selfie, and liveness data are processed by Didit on our behalf. We receive only the verification result and a minimal record (such as a document expiry date and an internal reference) — not your document images, full name, date of birth, or document number.
4.3 Service-provider notice (AWS and Didit)
World Republic uses service providers for identity-verification services. Biometric identifiers and biometric information ("biometric data"), specifically scans of your facial geometry and the related facial images and templates, may be collected, stored, and used by these service providers (AWS and, on escalation, Didit) on World Republic's behalf for the purpose of verifying that you are a unique, live, real person and preventing duplicate or fraudulent accounts. World Republic destroys the biometric data AWS stores on its behalf when the initial purpose for collecting it has been satisfied, when you request deletion, or earlier if required by law. Data processed by Didit during an escalated check is held by Didit under its own retention terms (Section 8); deleting your account does not currently send a deletion instruction to Didit, and requests about that data go to privacy@worldrepublic.org. Biometric data may be transmitted between World Republic and its service providers as necessary to provide this service.
4.4 Your consent and choice
We process your biometric data only with your explicit, opt-in consent, which we request at the start of the face liveness step. You can decline, but you will not be able to vote in test elections without completing verification.
You can withdraw that consent at any time, and you do not have to delete your account to do it. In the app, open Account → Verification → Delete my face data. Withdrawing takes effect immediately and destroys both the reference image and the facial template we compare it against. Your account, your WDD balance, any party you lead and any vote you have already cast are unaffected. You will not be able to vote again until you complete a new face check, which you are free to do at any time — unless your check has already been refused as a duplicate of another account (the automatic refusal described in Section 4.1). Withdrawing destroys the data but does not change that decision; contact privacy@worldrepublic.org to contest it.
One exception, and it is the same one Section 4.5 describes for account deletion: if a test election you have voted in is still open when you withdraw, your consent ends at once but the biometric data itself is destroyed when that election closes — unless you complete a new face check before then, in which case that new consent stands and nothing is destroyed. You can also delete your whole account instead (Section 9), or contact us to exercise any of the rights in Section 10.
4.5 Retention and destruction
We retain biometric data only as long as needed for verification and anti-duplication, and we destroy it when the purpose is satisfied, on your deletion request, or within the period set in our written biometric retention and destruction policy — whichever occurs first. Destruction includes deleting the AWS reference image (Amazon S3) and the facial vector (Rekognition collection).
One exception, bounded and stated here because you should know it before you act: if you delete your account — or withdraw your biometric consent under Section 4.4 — while a test election you have voted in is still open, we keep your biometric data until that election closes and destroy it then. If you withdrew and then verify again before the election closes, the pending destruction is cancelled, because the new face check is a new consent; deletion is never cancelled this way. Because the ballot is secret, a cast vote cannot be withdrawn, and the face check is the only thing that stops the same person from verifying a new account and voting a second time in the same election. The delay never exceeds the election's remaining window and never exceeds fourteen days: an election that closes more than fourteen days after you act does not hold the destruction at all. Nothing else about the deletion waits.
4.6 Where biometric data is processed
Your facial templates and reference images are processed and stored by AWS in the European Union (Ireland). Associated verification metadata (for example, confidence scores and storage references) is held in our primary database (see Section 7).
5. How We Use Information and Our Legal Bases
| Purpose | Examples | Legal basis (GDPR / revFADP) |
|---|---|---|
| Provide the Service | Accounts, parties, wallet, voting | Contract |
| Run test elections | A record that you voted, and when; your ballot added to the party's total | Contract, for the record that you voted. The ballot itself is secret — no record links your choice to you, and party totals are counts, not records about any person |
| Verify unique, live identity | Face liveness, deduplication, Didit escalation | Explicit consent (special-category) |
| Authenticate and secure | Sign-in, passkeys, sessions | Contract / legitimate interest |
| Prevent fraud and abuse | Rate limiting (IP); the automated duplicate-face refusal in Section 4.1 | Legitimate interest / legal obligation; for the refusal, contract and your explicit consent (Section 4.1) |
| Review party registrations | An automated check of a party's name, description, link and leader username for advertising, impersonation, paying for votes, incitement to violence and obscenity — never for its politics (Section 5.1) | Legitimate interest (an honest ballot registry); for the political opinions a registration expresses, they are ones you have manifestly made public by registering the party |
| Process WDD withdrawals | On-chain transfers | Contract |
| Keep proof of consent | Consent records (Terms/Privacy acceptance, biometric consent) with timestamp, IP, and user-agent | Legal obligation / legitimate interest (accountability) |
| Improve the Service | Fix bugs, basic usage analysis | Legitimate interest |
| Comply with law | Respond to lawful requests | Legal obligation |
5.1 Automated review of party registrations
When you register a party or edit it, a program reviews it before it is listed in the default registry. No person takes part in that step.
- What it reads: the party's name, description, website link and the leader's username — nothing else about you.
- What it decides: whether the party appears in the default lists, search and ballot, or is set aside as spam. A party set aside is not removed: it stays at its own address, can be found by choosing to show all parties, and can be voted for.
- The grounds: advertising for something outside the Service (including impersonating the Service or an established party), offering individual payment for votes, incitement to violence, and obscenity. Political views are never a ground, and the review must quote what it flags.
- How it decides: a large language model, GLM-5.3 Flash by Z.ai, applies those rules to the text. It runs on Baseten in the United States (Sections 6 and 7), which keeps nothing of the request once it is answered and does not train on it. A second, fixed rule compares the party's name with established parties' names. The outcome, its ground and which check decided are kept with the party (Section 8).
- Your options: the party's leader sees the outcome and the ground on the party's page. Editing the party resubmits it for review. You can ask a person to review the outcome through the Help Community linked from that notice, or by writing to privacy@worldrepublic.org.
6. How We Share Information
We do not sell your personal information. We share it only with processors acting on our behalf, and as required by law:
- Google — authentication (policies.google.com/privacy).
- Amazon Web Services (AWS) — Amazon Rekognition Face Liveness, Amazon S3 (reference images), and Amazon Cognito (temporary guest credentials), as our service provider for biometric verification (EU region).
- Didit — identity verification on escalation. See Didit's Verification Privacy Notice and End User Terms for Identity Verification.
- Coinbase — executes WDD blockchain withdrawals; receives the destination address, amount, and chain only.
- Thirdweb — executed WDD blockchain withdrawals until August 2026, and still completes withdrawals started before then; receives the same data.
- Neon — database hosting for Service data (Singapore region).
- Vercel — application hosting, infrastructure logs, and cookieless performance measurement (Singapore region); its AI Gateway also carries the party-review request in Section 5.1 to Baseten and nowhere else.
- Baseten — runs the language model that reviews party registrations (Section 5.1); receives the party's name, description, link and leader username, keeps none of it once the request is answered, and does not train on it (United States).
A current list of sub-processors is available on request. We may also disclose information to comply with law or valid requests by public authorities, and in a merger, acquisition, or asset transfer (subject to lawful safeguards).
7. International Data Transfers
We are established in Switzerland, which benefits from an EU adequacy decision. Your data is processed in more than one country:
- Biometric data (facial templates and reference images) is processed and stored by AWS in the European Union (Ireland).
- Account and application data is hosted with Neon (database) and Vercel (hosting) in Singapore.
- Party registrations under review (name, description, link, leader username) are sent to Baseten in the United States for the automated review in Section 5.1, and are not stored there.
Singapore is not covered by an EU or Swiss adequacy decision, and the United States only for recipients certified under the Data Privacy Framework. For transfers to Singapore, to the United States and to any other country without adequacy, we rely on the European Commission's Standard Contractual Clauses, the Swiss complement, and appropriate supplementary measures. Where adequacy decisions apply (for example, EU–Switzerland), we rely on those.
8. Data Retention
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account (biometric data has its own three-year inactivity ceiling — see the biometric row and the retention policy) |
| Biometric data (image + vector) | Until purpose satisfied, deletion request, or the period in our biometric policy — whichever is first |
| Identity-verification records | Minimal result data: the outcome of the duplicate-face check and, on a refusal, which account was matched and the similarity score; deleted with your account. A refusal record on another account that matched your face is kept with that account while it exists. For checks made before September 2026, when the human review that then applied opened and closed, and what it decided, are kept with your verification record and deleted with it |
| Voting record (that you voted, and when) | With your account; kept, anonymized, after deletion to preserve the integrity of test elections |
| Party vote totals | Indefinitely — they are counts, not records about any person |
| Party review request (what Section 5.1 sends to the review model) | Not stored by the review host — it exists there only while the request is answered |
| Party review outcome (verdict, ground, which check, when) | With the party, and reset each time you edit it |
| Transaction records | As required by applicable law. Where a payout could not be sent, we also keep a record of the refused attempt — when it happened, the network, and the status the payment provider returned — for as long as we keep the withdrawal it belongs to |
| Consent records | The fact, date, document version, language and screen of each consent and any withdrawal are kept with your anonymized account as evidence that consent was given and withdrawn; the IP address and device details recorded with them are removed when the account is deleted |
| IP / rate-limit records | Short-term (cleared automatically) |
9. Account Deletion
You can delete your account in the Service. On deletion we destroy the biometric data AWS holds on our behalf, delete our record of any Didit check, remove your verification records, and delete or irreversibly anonymize your personal data, except where we must retain limited information to meet legal obligations or to preserve the integrity of test elections.
Votes you have cast stay counted. The ballot is secret, so there is no record of your choice to remove; the anonymized record that you voted is kept so that each election's turnout stays true. If a test election you voted in is still open when you delete, your biometric data is destroyed when that election closes rather than immediately (see Section 4.5).
10. Your Rights
Depending on where you live, you may have the rights below. To exercise any right, contact privacy@worldrepublic.org. You will not be discriminated against for exercising them.
- EU/EEA and UK (GDPR / UK GDPR): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. For the automated refusal described in Section 4.1, you also have the right to obtain human intervention on our part, to express your point of view, and to contest the decision — write to privacy@worldrepublic.org and we will answer within one month. You may complain to your local supervisory authority; for EU GDPR purposes our lead supervisory authority is the Hungarian NAIH (Section 14).
- Switzerland (revFADP): access, rectification, deletion, objection, and the right to complain to the Federal Data Protection and Information Commissioner (FDPIC). For the automated refusal described in Section 4.1, you can also state your position and ask for the decision to be reviewed by a person.
- California (CCPA/CPRA): know, delete, correct, opt out of sale/sharing (we do not sell or share), and limit the use of sensitive personal information (which includes biometric data).
- Biometric laws (Illinois BIPA, Texas CUBI, Washington): we obtain your consent before collecting biometric data, do not sell it, and follow a written retention and destruction schedule.
11. Security
We use TLS in transit, access-controlled storage, and least-privilege access. No system is perfectly secure, but we work to protect your data.
12. Children
The Service is for adults 18 or older. Before we verify your identity we ask you to confirm you are 18 or older, and we do not verify anyone who does not. We record only that the confirmation was given and when; we do not ask for your date of birth.
We do not knowingly collect data from anyone under 18. If we learn that we hold data about a person under 18, we close their account and destroy their biometric data as described in our Biometric Data Retention and Destruction Policy. If you believe someone under 18 has an account, contact privacy@worldrepublic.org.
13. Changes
We may update this policy and will revise the "Last updated" date and, for material changes, notify you in the Service.
This policy is written in English. Where we publish a translation, it is provided for convenience; if a translation and the English text differ, the English text prevails.
14. Contact
- Privacy: privacy@worldrepublic.org
- Contact in the European Union: Balázs Kónya, board member, 3626 Hangony, Dózsa György út 5., Hungary (privacy@worldrepublic.org)
- EU lead supervisory authority: Hungarian National Authority for Data Protection and Freedom of Information (NAIH), Budapest — naih.hu
- Swiss supervisory authority: Federal Data Protection and Information Commissioner (FDPIC), Bern