Skip to content

Legal

Privacy Policy

Last updated: April 12, 2026

1. What We Collect

When you sign the petition, we collect the following information depending on your sign-in method:

  • OAuth (Google, Apple, X): Your name, email address, and profile photo as provided by the OAuth provider.
  • Magic link: Your email address only. Your display name is derived from your email prefix.
  • Automatically: A unique user ID and timestamp of when you signed.

2. How We Use Your Data

  • Name & avatar: Stored privately for authentication only. Never displayed publicly on the site.
  • Email: Used solely for authentication. Never displayed publicly. Never shared with third parties.
  • Signature count: Aggregated and displayed as an anonymous total count on the site. Individual signatures are not publicly listed.

3. What We Do NOT Do

  • We do not sell your data to anyone.
  • We do not send marketing emails.
  • We do not post on your social media accounts.
  • We do not access your contacts or social graph.
  • We do not use advertising or tracking cookies. Analytics cookies are only set with your consent (see Section 5).

4. OAuth & Third-Party Authentication

We use Google, Apple, and X (Twitter) OAuth solely to verify your identity and prevent duplicate signatures. We request the minimum permissions needed (basic profile info). We do not request write access to your accounts.

5. Cookies

We use Supabase authentication cookies to maintain your sign-in session. These are strictly functional.

We also use Vercel Analytics to collect anonymous, aggregated page-view data (page path, referrer, browser type). This data is not tied to your identity. Analytics cookies are only set if you accept the cookie banner. If you decline, no analytics data is collected.

6. Data Storage

Your data is stored in a Supabase-hosted PostgreSQL database with row-level security enabled. Data is retained indefinitely to maintain the integrity of the petition count.

7. Data Deletion

You may request deletion of your signature and all associated data at any time by emailing info@retire91.com. We will process deletion requests within 30 days.

8. Children's Privacy

The Site is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has signed, contact us and we will remove the data.

9. Changes to This Policy

We may update this Privacy Policy at any time. Changes take effect when posted. Continued use of the Site after changes constitutes acceptance.

10. Contact

Questions or deletion requests? Email us at info@retire91.com.