Privacy Notice
Last updated: September 8, 2026
This Privacy Notice explains how Agreeish collects, uses, stores, shares, and otherwise processes information when you use the Agreeish website, services, and features (the "Service").
Agreeish is designed so that you can use the core voting experience without creating an account. Guest use is pseudonymous, not necessarily anonymous: a browser or session identifier may still be treated as personal data because it can distinguish one visitor from another.
Agreeish distinguishes between information needed to operate, secure, troubleshoot, and measure the basic reliability of the Service and optional third-party product analytics. Those categories are described separately below.
1. Information We Collect
Guest voting and use
When you use Agreeish without an account, we may collect or generate:
- a random or pseudonymous browser/device identifier
- a browser-session identifier
- a broad country code inferred from network information or selected by you
- poll choices, voting activity, and result interactions
- XP, level, streak, and other progress information
- page, route, navigation, session, performance, error, and diagnostic information
- timestamps and basic technical information needed to operate, secure, troubleshoot, and protect the Service
Agreeish does not require your name, email address, age, date of birth, precise GPS location, or physical address in order to vote as a guest.
Accounts
If you create an account, we may also process:
- your email address
- an authentication-provider identifier
- your generated nickname and account identifier
- saved voting history and progress
- XP, level, streaks, and related progress
- account settings and preferences
If you use a third-party sign-in provider such as Google, that provider may send us information needed to authenticate you, including an email address, provider-specific identifier, and basic profile metadata made available by that provider. Agreeish does not deliberately send Google profile names or avatars to PostHog.
We do not require your date of birth as part of account creation.
Country and network information
Agreeish uses broad country-level information for features such as Country Comparison and for high-level product and security analysis. We do not request device GPS permission for this purpose and do not intentionally store precise location in your voting profile.
Infrastructure, authentication, network, security, and hosting providers may process IP addresses and related network information as necessary to deliver and protect the Service and to infer a broad country. Agreeish vote records and user profiles do not intentionally store IP addresses as profile fields.
2. Information Stored in Your Browser
Agreeish uses a secure visitor cookie, localStorage, sessionStorage, authentication cookies, and similar browser technologies. Depending on the feature and your settings or region, these may support:
- remembering a pseudonymous guest identifier
- maintaining authentication and security
- preserving progress and preventing duplicate voting
- remembering appearance, sound, country, and analytics-preference settings
- maintaining a browser-session identifier and one-time event markers
- storing optional PostHog analytics state only when PostHog analytics is enabled under the applicable rule or by your choice
Some browser storage is needed to provide requested functionality, security, vote integrity, or settings. Other storage may be optional. Where applicable law requires consent or another choice, Agreeish will provide that choice.
You can remove browser-stored information through your browser settings. Doing so may reset guest identification, preferences, progress, authentication, or session state.
Clearing browser storage does not necessarily delete information already stored on Agreeish servers or by service providers.
3. How We Use Information
We may use information to:
- provide the voting experience and record votes
- show Global and Country Comparison results
- prevent duplicate, automated, fraudulent, or abusive voting
- maintain accounts, authentication, voting history, XP, levels, streaks, and progress
- remember settings and preferences
- understand aggregate product usage and engagement
- measure reliability, page performance, and technical quality
- diagnose failed or slow loads, errors, and other technical issues
- protect the Service, users, data, and infrastructure
- troubleshoot, test, and improve Agreeish
- respond to support, privacy, security, or legal requests
- comply with legal obligations where applicable
We do not use your vote history to make decisions about your eligibility for employment, credit, insurance, housing, healthcare, education, or similar high-impact services.
4. Poll Responses and Sensitive Topics
Poll responses are used to operate Agreeish and calculate aggregated results. Other users may see aggregate information such as overall percentages, response counts, country-level percentages, and other comparison results.
Other users do not receive your private individual voting history through those aggregate results. Country results may only be displayed after a minimum number of responses has been reached.
Agreeish results reflect Agreeish respondents only and are not representative population statistics. We do not sell individual voting histories and do not publicly identify you with an individual vote unless a feature clearly tells you otherwise and you choose to use that feature.
Depending on the subject of a poll, a response may reveal or imply a sensitive opinion or characteristic in context. Agreeish is not intended to require highly sensitive personal information as an account profile field. Do not place passwords, authentication credentials, government identifiers, financial account numbers, medical records, or sensitive information about another identifiable person in URLs, support messages, or other inputs to the Service.
5. Essential and Operational Telemetry
Agreeish may collect limited first-party operational telemetry that is separate from optional PostHog analytics. This telemetry is used to operate, secure, troubleshoot, measure, and improve the Service and may be collected even when optional PostHog analytics is disabled, to the extent permitted by applicable law.
Operational telemetry may include:
- page and route views
- pseudonymous visitor and session identifiers
- navigation timing and first-load versus repeat-load performance
- page usability, timeout, failure, and error signals
- browser, device category, release/build identifier, and broad country
- referrer, previous page, landing page, and relevant URL/query information
Incident diagnostics
When the Service hits a technical error, Agreeish may store a diagnostic incident record so operators can fix the failure. These records are available to Agreeish operators in an admin incident inbox. They are not shown to other visitors and are not a public profile.
Incident records may include:
- the page or API route where the error happened, a grouped error message, stack trace, release/build identifier, and timestamps for each retained occurrence
- the same pseudonymous visitor identifier and browser-session identifier already used to operate voting
- a broad country code and whether that country came from a saved choice, network inference, or was unknown
- a truncated browser user-agent string
- your account identifier if you were signed in when the error happened
Agreeish does not store raw IP addresses in incident records. A short-lived keyed hash of network address information may be used only to rate-limit anonymous error reports and is deleted within minutes. Country-level inference for diagnostics uses the same infrastructure country signals described above.
Agreeish may treat meaningful query-string changes as separate page keys for product measurement. Framework-generated transport parameters that do not represent a meaningful user-visible page state, such as Next.js internal RSC parameters, may be normalized or excluded from reporting. Repeated visits to the same normalized page are still recorded as separate page-view events.
URLs and query parameters can contain information supplied by users, sites, or third parties. Do not place secrets or highly sensitive personal information in a URL used with Agreeish.
6. Optional Product Analytics
Agreeish currently uses PostHog for optional product analytics. In the UK and European Economic Area, optional analytics are off until you choose "Allow" in the analytics prompt or enable Analytics in Settings. Where a prior choice is not required, privacy-limited analytics may be enabled by default. If country-level inference needed to apply the regional rule is unavailable, Agreeish defaults to showing the prompt.
Optional analytics may include:
- explicit page, poll-view, vote-submission, result-view, Next Take, sharing, signup, login, and guest-to-account events
- pseudonymous visitor and session identifiers
- poll identifier, category, country code, session position, and guest/returning status where relevant
- landing-page, referrer, and UTM information
- technical browser, operating-system, screen, viewport, language, and timezone information supplied by the analytics library
Automatic interaction/content capture, screen recording, and console-log recording are disabled in Agreeish's PostHog setup. Agreeish also configures PostHog to discard the client network address and not add location enrichment to Agreeish custom events.
We do not deliberately send selected answer text or option labels, email addresses, Google profile names, avatars, or Agreeish nicknames to PostHog.
Where prior consent is required, PostHog does not initialize Agreeish analytics persistence before consent. Turning Analytics off stops future optional capture and resets or opts out the PostHog client.
7. Service Providers
Agreeish relies on third-party providers that may process information on our behalf, including:
- Vercel — hosting and application delivery
- Supabase — database, authentication, and backend infrastructure
- PostHog — optional product analytics
- Resend — email delivery for authentication messages
- third-party authentication providers such as Google when you choose to use them
Providers process information as necessary to provide their services and may also be subject to their own terms and privacy obligations. Agreeish does not authorize providers to use information for unrelated purposes merely because they provide infrastructure to the Service.
8. Legal Bases for Processing
Where data-protection law requires a legal basis, the basis depends on the activity and may include performance of a service you requested, legitimate interests in operating, securing, preventing abuse of, measuring, and improving Agreeish, consent where required, or compliance with legal obligations.
Where processing relies on consent, you may withdraw that consent as provided by applicable law. Withdrawal does not make earlier lawful processing unlawful.
9. Data Retention
Agreeish retains information only for as long as reasonably necessary for the purposes described in this Notice. The period depends on the type of information, whether an account remains active, vote-integrity and fraud-prevention needs, technical and security needs, legal obligations, dispute-resolution needs, and whether information can be aggregated or de-identified.
- account information may generally be retained while the account remains active
- voting records may be retained in pseudonymous, de-identified, or aggregated form where necessary to preserve aggregate poll results and vote integrity
- operational and analytics records may be retained for product, security, troubleshooting, abuse-prevention, and reporting needs and may later be aggregated or deleted
- incident diagnostic records may retain per-occurrence visitor, session, country, and timestamp details for a limited operator troubleshooting window and are pruned with the rest of the incident log
- security, fraud, legal, and backup records may persist for a limited period after deletion where reasonably necessary or required
- browser-stored identifiers remain on the device until they expire, are replaced, or you remove them
10. Account and Data Deletion
If you have an Agreeish account, you may submit a deletion request in Settings or by emailing support@agreeish.com. We may verify the requester before completing the request.
Deletion may include information associated with:
- Supabase Auth credentials and account records
- profile and nickname-regeneration history
- visitor/account associations, XP, level, streak, and progress data
- sessions and account-linked analytics or operational events where applicable
- PostHog person and event data where applicable and reasonably identifiable
Some information may be retained, reassigned, aggregated, or de-identified when reasonably necessary to preserve aggregate poll integrity, prevent fraud or duplicate voting, comply with law, establish or defend legal claims, maintain security records, or complete ordinary backup rotation.
Deleting an account does not necessarily require removing the user's contribution from aggregate statistics. Individual vote rows may be reassigned to a fresh non-account visitor identifier, with the deleted account and original visitor association removed, solely to preserve aggregate poll counts and integrity.
11. Your Privacy Rights
Depending on where you live and which law applies, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or other legally available choices, and to complain to an applicable data-protection authority.
You can submit a privacy request to contact@agreeish.com. We may need to verify that you are the person associated with the information before completing certain requests, and legal exceptions may apply.
Guest users
Guest information is intentionally pseudonymous. To locate a guest record, we may need the relevant browser/device identifier or other information that lets us identify the applicable records. If the local identifier has already been deleted, we may be unable to identify which pseudonymous records belong to you. We will not seek disproportionate additional personal information solely to identify a guest.
12. Sale, Sharing, and Advertising
Agreeish does not currently sell personal information or individual voting histories.
We do not currently share individual vote histories with advertisers for cross-site or cross-context behavioral advertising.
If Agreeish introduces advertising, sponsored content, or another data practice that materially changes how personal information is used or shared, this Notice will be updated and legally required notices, choices, or opt-outs will be provided where required.
Aggregated or de-identified statistics that do not reasonably identify an individual may be used for product, analytics, commercial, benchmarking, or research-related purposes, subject to applicable law.
13. International Data Processing and Transfers
Agreeish is available internationally, and service providers may process information in countries other than the country where you live, including countries whose privacy laws may differ from yours.
Where applicable law requires a transfer mechanism, Agreeish may rely on an adequacy decision, standard contractual clauses, a UK transfer mechanism, another approved contractual safeguard, or another lawful transfer basis appropriate to the provider and destination. You may contact contact@agreeish.com for additional information about applicable safeguards, subject to confidentiality and legal limitations.
14. Security
We use reasonable technical and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. Measures may include access controls, authentication, secure transport, restricted administrative access, logging, and service-provider security controls where appropriate.
No online service can guarantee absolute security. You are responsible for protecting access to your own email account, device, browser, and authentication credentials.
If a security incident requires notification under applicable law, we will provide the required notifications.
15. Users Under 18
Agreeish is intended only for users who are at least 18 years old.
We do not intentionally design the Service for children or knowingly seek to collect personal information from people under 18. We do not collect age or date of birth for analytics purposes.
If we reasonably believe that an account or identifiable user belongs to someone under 18, we may restrict access and, where appropriate, delete the account and associated personal information.
If you believe someone under 18 is using Agreeish, contact support@agreeish.com.
16. Automated Processing
Agreeish may automatically calculate voting results, percentages, progress, XP, levels, streaks, country comparisons, product and operational analytics, and fraud, abuse, integrity, or technical signals.
We do not use automated processing to make decisions about users that produce legal or similarly significant real-world effects.
17. Who Is Responsible for the Information
The operator of Agreeish determines the purposes and means of the processing described in this Notice where Agreeish acts as the data controller or equivalent responsible party. Some third-party providers may also have their own independent legal responsibilities.
Privacy and data-protection inquiries can be sent to contact@agreeish.com. Where applicable law requires additional controller or representative information, Agreeish will provide the information required by that law.
18. Changes to This Privacy Notice
We may update this Privacy Notice as Agreeish develops or as our legal, technical, or operational practices change. When we make changes, we will update the "Last updated" date. If a change materially affects how personal information is used, we may provide additional notice or obtain a new choice where appropriate or required by law.
19. Contact
For privacy questions, data requests, or general legal inquiries: contact@agreeish.com
For account support, saved progress, or reports involving potential underage use: support@agreeish.com