Draft policy — legal and privacy review pending.
This draft summarizes the intended privacy posture for HushVoting! and HushNetwork public website and pilot-access workflows. It is written for Switzerland-first launch planning and is not a finalized legal privacy notice, data-processing agreement, or jurisdiction-specific compliance statement.
The public website is designed to collect only the information needed to explain HushVoting! and respond to pilot requests. When a visitor requests pilot access, the form asks for an email address and a short message; the destination address is not published on the page to reduce spam harvesting. Standard server, browser, and security logs may also be processed to keep the site available, diagnose issues, and protect against abuse.
HushVoting is built around Protocol Omega's election-mode separation between eligibility/checkoff records and ballot-choice records. The product direction is the digital equivalent of a named checkoff in the electoral roll and an anonymous ballot in the ballot box: an organization may need to know that a voting right was used, while the ballot transaction and vote choice must not become attributable to the named voter.
The Protocol Omega privacy model requires plaintext vote choices, trustee share material, tally private material, ballot-decrypting keys, and voter-to-choice joins to stay out of durable blockchain payloads, server storage, Redis, report packages, ordinary runtime logs, metrics, traces, backups, and support artifacts.
Organizations using HushVoting! remain responsible for their own lawful authority to run an election, voter notices, roster sources, member eligibility rules, retention obligations, and jurisdiction-specific privacy requirements. Switzerland is the first target jurisdiction for review. HushVoting! can provide privacy-preserving voting and evidence mechanics, but it does not replace a customer's legal, governance, or compliance review.
The current website does not use analytics or marketing cookies. If analytics are introduced later, the privacy notice and consent behavior should be updated before those tools are enabled, especially for Switzerland-first and later EU/EEA review.
HushVoting! should not be described as providing total anonymity against all observers. Current documentation distinguishes validated implementation evidence from formal certification, and it does not claim protection against compromised user devices, colluding threshold trustees, live process-memory inspection, timing/metadata correlation, or jurisdiction-specific public-election requirements.