Privacy Policy
Effective: August 18, 2026 · Last updated: August 18, 2026
This platform funds political activity. That makes the data here more sensitive than a normal privacy policy has to deal with — who you fund reveals what you believe, and where you were reveals where you protested. This document is written to be accurate rather than reassuring. Where we hold something risky, we say so. Where we can't protect you, we say that too.
1. Who We Are
STAND/WITH/ME is operated by Zenith Content LLC, a Minnesota limited liability company, which is the controller responsible for your personal information.
Zenith Content LLC202 N Cedar Ave, Ste #1
Owatonna, MN 55060
United States
privacy@stand-with-me.com
2. What We Collect
- Account — email, and phone if you give it. Authentication is handled by Clerk.
- Profile — your alias, bio, links, photo, city and state. Activists are public under an alias, not a legal name.
- Identity verification — performed by Stripe Identity. See section 4.
- Payment — card details go to Stripe and are never held by us. We hold the transaction record: amount, date, campaign, and Stripe's identifiers.
- Campaign content and proof of action — text, budgets, photos and video you submit.
- Location — see section 3. This is the category most likely to hurt you, so it gets its own section.
- Messages — conversations between users on the platform.
- Safety records — SOS alerts, hazard reports, incident reports, and your trusted contacts.
- Device and usage — IP address and browser or device identifier, recorded with account activity for security.
3. Location — Read This One
Precise coordinates are sensitive information and we treat them that way. An earlier version of this policy said GPS is collected only during Safety Mode or Emergency SOS. That was wrong, and here is the accurate account:
- Emergency SOS — coordinates are required. The feature cannot work without them.
- Hazard reports — coordinates are required, and are broadcast to other users within a radius you set. That is the point of the feature: warning people nearby.
- Incident reports — coordinates are optional. You choose.
- Proof of action — we do not collect coordinates, deliberately. GPS plus a timestamp plus a named political campaign is a protest attendance record. We removed the field, and we strip location metadata from uploaded photos and video.
Location is never used for advertising, never sold, and never shared except as described in section 12. You can decline location permission and still use the platform; the features above will not work without it.
4. Identity Verification and Biometrics
Activists verify identity before they can receive funds. The check is a government ID plus a selfie, and comparing the two is a facial recognition measurement — a biometric process. We tell you that plainly because you deserve to decide knowingly.
Stripe performs the check and holds the documents. We receive a result — verified or not — and an identifier that lets us look the verification up with Stripe if we ever legally must. We do not store your government ID image, your selfie, any biometric identifier or template, your date of birth, your ID number, or your home address. We removed those fields from our database rather than leaving them empty.
Stripe's verification flow asks for your consent before it captures anything, and links to this policy while it does. If you decline, you can still use the platform as a supporter. You cannot receive funds as an activist without verifying, but contact us and we will tell you what non-biometric options exist for your situation.
What Stripe does with it. Stripe collects identity document images, facial images, ID numbers and addresses, along with fraud signals and information about the device you connect from. Stripe shares the result with us, and also uses this information to operate and improve its own services, including fraud detection. You may separately choose to let Stripe use your data to improve its biometric verification technology. Read Stripe's privacy policy for the detail.
Deleting it. Stripe keeps a copy of everything submitted during verification. Ask us and we will redact the verification session, which deletes the images and personal data Stripe holds for us. To remove data Stripe holds as its own controller, or to withdraw consent you gave Stripe directly, contact Stripe support. We cannot do that part for you.
5. Political Information
What you fund reveals what you believe. Campaign participation, funding history, causes and interests are political information, and we treat them as sensitive whether or not the law where you live classifies them that way.
- Never sold. Never shared for cross-context behavioural advertising.
- Never used to build advertising profiles or lookalike audiences.
- Never disclosed except as described in section 12.
- Supporter funding history is private by default. You choose whether your profile and contributions are visible.
Be clear about what this protection is: for most people in the United States it is a promise we are making, not a statutory floor, because most state privacy laws do not list political opinion as sensitive data. We are writing it down because the commitment is the thing that binds us.
6. Information About Other People
Some of what you submit is about people who never agreed to anything: bystanders and fellow protesters in proof photos, witnesses in an incident report, the emergency contacts you add.
- We strip location metadata from uploaded media by default, server side, on every upload.
- Witness details are optional. Do not add someone without asking them.
- Trusted contacts are told when you name them, so they know they are on your list.
- We never use identifiable third parties in advertising. No exceptions.
7. Who Else Processes Your Data
Named, with what they get and why. This list is also a map of where someone could serve legal process, which is exactly why you should have it.
| Processor | What they receive |
|---|---|
| Stripe | Payments, payouts, and identity verification — government ID, selfie, bank details |
| Clerk | Authentication — email, phone, session, IP |
| Convex | The database itself — everything in section 2 lives here |
| Anthropic | Campaign and proof text, for automated review |
| OpenAI | Campaign text, for the second independent review |
| Amazon SES · Sendy | Email address, to send you mail |
| Sevalla | Hosting |
| Sentry · PostHog | Error reports and product analytics in our mobile app. Not used on this website. |
Campaign content sent to Anthropic and OpenAI is used to score that submission and nothing else. It is not used to train their models.
What an alias cannot protect you from. Legal process served directly on Stripe or Clerk is not visible to us. We cannot resist it for you, we may never learn it happened, and no alias protects against it. Stripe knows who you are. That is the trade for being able to receive money.
8. How Long We Keep Things
| What | How long |
|---|---|
| SOS coordinates and recordings | Life of the alert plus 30 days, then purged |
| Hazard report coordinates | Until the hazard expires, plus 7 days |
| Incident coordinates and witnesses | 30 days, unless you ask us to preserve them |
| Proof media and campaign records | Life of the campaign plus the payment dispute window |
| IP address and device identifier | 30 days |
| Verification result | Life of the account, plus the limitations period |
| Transaction records | 7 years — tax and dispute obligations |
| Alias reservations | Permanent, by design — an alias signed campaigns and proofs, and handing it to a stranger would attribute one person's record to another |
Two exceptions, published rather than hidden. If we receive legal process or credible notice of a claim, we suspend deletion for the specific records involved and document that we did. And you can ask us to preserve your own incident or SOS records past their expiry — evidence of how you were treated is yours to keep if you want it.
9. Your Rights
You can ask us to:
- Tell you what we hold about you, and give you a copy
- Correct anything wrong
- Delete your data, subject to section 10
- Export it in a portable format
- Limit how we use sensitive information, including location
- Opt out of any sale or sharing — though we do neither
- Opt out of automated decision-making, described in section 11
We will never treat you worse for exercising any of this.
How to do it
Use your account. You are already signed in, which proves who you are better than any identity check we could invent, and it means we collect nothing new to verify you. Exports are delivered in your session or by an expiring link — never as an email attachment.
You can also email privacy@stand-with-me.com. We will confirm it in your account before releasing anything. We respond within 45 days, and tell you if we need longer. If we say no, we tell you why and how to appeal. We notify you about every request for your data, including ones we refuse.
Someone acting on your behalf needs written authorisation we can verify, and cannot obtain your precise location history or safety records at all.
10. What Deletion Actually Means
Most policies say “we delete your data” and quietly keep a lot. Here is what survives, and for how long:
- Your alias reservation — permanently. It is never reissued to anyone else.
- Transaction records — 7 years, for tax and dispute obligations.
- Published campaigns and proof that supporters funded — the record of what their money did outlives your account, though we disconnect it from your profile.
- Administrative logs of enforcement decisions — 2 years.
- Whatever Stripe holds. Stripe is its own controller. We can ask them to delete your verification data and we will, but their retention is theirs, not ours.
11. Automated Decisions
Campaigns are reviewed by two independent AI systems before they go live, checking for legality, peacefulness and policy compliance. Proof of action is scored the same way. Strong results may publish automatically, clearly bad ones are rejected, and anything in between goes to a human.
We do not publish the exact scoring thresholds, because doing so would tell anyone trying to game the system precisely where the line is. What we do commit to: you can always ask a human to review a decision about you, you will be told the reason, and no account is permanently terminated on an automated decision alone.
12. Government and Legal Process
This section matters more here than on most platforms, so it is specific.
- We require valid legal process. A subpoena, court order or warrant. We do not hand over data on an informal request from law enforcement, however urgently it is framed.
- We tell you. If we receive process for your data we notify you, so you have a chance to fight it — unless the law forbids us, or there is an imminent risk of death or serious injury.
- We push back on requests that are overbroad, improperly issued, or look retaliatory, and we produce only what the process actually compels.
- Payments are different. Identity, transaction, fraud and dispute information flows to Stripe, card networks, banks and sanctions screening because payments cannot work otherwise. That lane is narrow, and limited to those categories.
- Emergencies. If someone is in danger of death or serious harm we may share what is needed with emergency services. A named senior person approves it and we document it.
We intend to publish a regular transparency report covering the requests we receive and how we responded. Treat that as a statement of intent, not a contractual promise.
13. Security — Only What's True
An earlier version of this policy claimed end-to-end encryption, regular penetration testing, and that location data was accessible only to you. None of that was accurate and we have removed it. What is true:
- Data is encrypted in transit, and encrypted at rest by our infrastructure providers.
- Identity documents are held by Stripe, not by us.
- Access to production data is limited to the people who need it to operate the platform.
- Administrative access is role-based and logged.
Who can actually see your location
You. Trusted contacts you notified. Other users nearby, for hazard reports — that is the feature working as designed. Named staff, when investigating a safety report. And anyone with valid legal process. It is not encrypted in a way that hides it from us, and we are not going to claim otherwise.
14. Tracking and Advertising
As of August 18, 2026, this website carries no advertising pixels, no third-party trackers, and no analytics tags. It sets one cookie, to remember whether you prefer light or dark. We are stating the date because if that ever changes, it should be a documented decision rather than something you discover.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising — using those terms as the law defines them, not as marketing. If we ever run advertising, we will honour Global Privacy Control signals and publish a Do Not Sell or Share link from day one, and no advertising tag will ever be placed on a page showing campaign, funding, safety or messaging content.
15. Children
STAND/WITH/ME is for adults. You must be 18 or older, and the platform is not directed to or offered to anyone under 18. We do not knowingly collect information from minors. If you believe a minor has an account, email privacy@stand-with-me.com and we will remove the account and its data.
16. If There Is a Breach
If your personal information is exposed, we will tell you and the relevant regulators without unreasonable delay. The notice will say what happened, what data was involved, when it happened, what we have done, and what you should do. Given what is here, we would rather over-notify than under-notify.
Security contact: privacy@stand-with-me.com
17. Changes
If we change this policy in a way that materially affects your rights, we will tell you before it takes effect — not by quietly editing the page. The last-updated date at the top always reflects the current version.
Your data is not the product. It never will be.