BallotBar
PRIVACY BOUNDARY

Your private ballot record stays with you.

BallotBar’s voter tools do not require an account, phone number, email address, or voter profile. Your full legal name, voter-registration address and date of birth are required inside each new encrypted ballot backup. These details are not sent to BallotBar.

Effective 2026-09-17

Who operates BallotBar

BallotBar is a nonpartisan voter-education and civic public-service initiative of InVision Church Los Angeles, Inc. BallotBar is not a separately incorporated nonprofit and is not an election authority.

Accountless voter tools

You can use ballot-photo guidance, exact-ballot lookup, Private Ballot Copy, encrypted backup, official tracking resources, and the missing-ballot case file without creating or signing in to a voter account. BallotBar does not create a hidden or anonymous voter profile when you use those tools.

Editable case template

The downloadable Word/Pages case template is not encrypted by BallotBar. You edit and save it yourself. Its contents are not sent to BallotBar; your document application may sync them to a cloud account depending on your settings. Keep the document in a private folder and share only what you intend. The optional encrypted browser case workspace and encrypted ballot backup are separate.

Private records in this browser

Ballot images, marked Private Ballot Copies, selections, record-specific attestations, local record identifiers, case notes, case numbers, and screenshots are encrypted before persistent storage in this browser. Decrypted working data can exist in memory while you actively view or edit it. These local records do not automatically appear in another browser or device, can be erased by browser cleanup or device loss, and can be removed with the controls in the product.

Portable encrypted files

The durable portable formats are the encrypted .bbbackup ballot record and .bbcase case file. BallotBar does not receive those files or their passphrases. You choose where an exported file is saved; a destination such as iCloud Drive, Google Drive, or another cloud-backed folder is governed by that provider and is not exclusively local hardware storage. Keep the file and its passphrase separate and verify that you can reopen it. BallotBar is the reader for these encrypted formats. The Offline Reader can be saved to your device while online. After setup, it reads your saved files without internet. It caches only the public reader software; opened files and passwords stay in memory and are not uploaded or saved by the reader. Clearing website data can remove the reader, requiring setup again.

Record attestations and timestamps

For a new finalized ballot record, your self-reported full legal name, birth date and registration address, the statement you accept, acceptance, record type, covered content and integrity references, applicable ballot source details, and device-reported time information remain inside the encrypted record. These details identify whose private record it is. BallotBar does not receive them or the attestation, and does not verify your identity or voter registration. You control whom you show your opened backup to; anyone with its file and password can read the included personal details and ballot choices. Older unnamed and name-only backups remain readable. Device-reported time is not a trusted third-party timestamp, and file creation time is not treated as the date you voted. A voting date is included only if you choose to report one and is labeled voter-reported.

Finding your ballot

You can create a replica of federal and statewide races by choosing your state and congressional district. No street address is required. If you don’t know your district, the optional district finder uses your address. Taking a ballot photo does not require an address lookup. If address suggestions are available, the text you type in the district finder is sent to Geoapify to fill in the address fields. For supported district matching, the address without an apartment or suite may be sent to the official U.S. Census Geocoder. If Census finds no address match, that address may be sent to Geoapify for an exact building-location check. Only one fully matching building result is accepted; its coordinates are then sent to Census to check the reviewed election district. Approximate or conflicting locations are not used. Coordinates and provider responses are not retained in the ballot backup. A selected address may otherwise be sent to Google Civic Information or another named election-information source. The lookup address and geocoder response are not automatically retained in the backup or intentionally stored on BallotBar’s servers. Before saving, you must separately enter or confirm a voter-registration address for your encrypted private record. That field stays on your device, is not sent for a lookup, and is not shared with optional email signup or support. Official sites you open have their own privacy practices and may require identifying information.

Optional email updates

After a record task, you may separately choose to provide an email address for BallotBar updates, election deadlines, voter resources, and important midterm information. This is optional and is not required to use any voter tool. The subscriber system receives only the email and communications consent data, plus ordinary operational and delivery metadata needed for security, confirmation, suppression, and unsubscribe. It must not receive ballot content, record or backup identifiers, attestation, exact location, voting method, tracker result, or case-file data. Existing account addresses and support correspondents are not automatically enrolled.

Support and information you deliberately send

Your local case file is not uploaded. If you use your email application to contact support@ballotbar.com, BallotBar and the email providers involved receive the information you deliberately include. Review the message before sending. Never email a ballot image, selection, backup, passphrase, full address, signature, or voter identifier. Sending a support message does not enroll you in optional communications.

If you submit the website support form, BallotBar receives and stores the issue category, summary, optional source link, and optional reply email you provide. These submissions are separate from your encrypted ballot and case files. An on-screen reference confirms receipt; an email acknowledgement is sent only when email delivery is available.

Public site and operational data

Like ordinary websites, BallotBar’s hosting and security infrastructure may process network information such as IP address, request time, browser headers, requested path, security signals, and error information. BallotBar limits application payloads and logs so private ballot records, selections, attestations, passphrases, and local case files are not intentionally sent. No claim of perfect anonymity or zero third-party processing is made.

Site visit counter

The homepage shows a shared total of visits. Each new page load adds one; moving between screens does not. Repeat visits and reloads can count again, so this is not a count of individual people or completed backups. The counter stores only a total, with no visitor identifiers, cookies, IP addresses, ballot content, or usage history. Test-site visits are kept separate from public visits. Hosting providers may still process ordinary network information as described above.

Public election data

Official blank-ballot definitions, source citations, photo-rule decisions, publication checks, and operational status records are public election information and may be stored on BallotBar’s backend. They are not a voter’s completed ballot record.

External donation transaction

Donation links leave BallotBar for InVision Church Los Angeles, Inc.’s external giving provider. Payment credentials, bank details, receipts, and related transaction data are handled by that provider—not a private ballot record or optional subscriber record. BallotBar does not use donor status to change access or support.

Preserved account-enabled service

Accounts created under BallotBar’s separately preserved account-enabled service are not converted into subscribers and are not deleted by this accountless version. Its authentication provider, profile and security records, and necessary account communications remain governed by the policy shown with that preserved service. Existing users may contact support to request help with those records.

Security and retention limits

Local encryption reduces central exposure but cannot protect an unlocked or compromised device, a disclosed passphrase, or a file saved to an insecure destination. No software can guarantee absolute security. Subscriber and support records are retained only as needed for the stated service, security, legal, suppression, and recordkeeping purposes; unsubscribe and applicable privacy requests remain available.

Questions and corrections

Use the BallotBar support and source-correction form or email support@ballotbar.com.