Trust

Security & Trust

Last updated: July 12, 2026

We keep PollsLive simple, private, and safe by design. Production runs on EU infrastructure with layered defenses - edge bot protection, hardened auth, workspace RBAC, and scrubbed staging. We run regular internal security reviews; enterprise teams can request a written summary under NDA.

EU-hosted

Application, database, and cache run on EU infrastructure behind Cloudflare.

Argon2id passwords

Credentials are hashed with Argon2id. Reset and verify tokens are stored hashed.

Defense in depth

Turnstile, Redis rate limits, RBAC, SSRF guards, and poll access controls.

Isolated staging

test.pollslive.com uses a scrubbed snapshot - never shares production data.

Security-reviewed

We run regular internal security reviews and dependency scans. Enterprise teams can request a summary under NDA.

Your data, your control

Self-serve export and account deletion from Studio. GDPR-ready by design.

1. Hosted in the European Union

Our application, database, and cache run on infrastructure in the European Union, behind Cloudflare for DNS, TLS, and DDoS protection. The database and cache are not exposed to the public internet. A full list of providers is on our Sub-processors page.

2. Encryption & access

All traffic is encrypted in transit with TLS and HSTS. Passwords are stored as Argon2id hashes (with automatic migration from legacy bcrypt on next login). Password-reset and email-verification tokens are stored hashed - the raw value exists only in the emailed link. IP addresses used for anti-abuse are hashed. Access to production systems is restricted to what's needed to operate the service.

3. Your data, your control (GDPR)

PollsLive is built to be GDPR-ready. You can export a full copy of your data or permanently delete your account yourself from Studio → Account & privacy - no emails or waiting. Voters never need an account, and creators choose whether voter names are collected at all (off by default).

See our Privacy Policy and Cookie Policy for the full detail, including legal bases, retention, and international transfer safeguards.

4. Privacy-friendly by design

  • Minimal collection. We ask for as little as possible and don't sell personal data.
  • Consent-gated analytics. Privacy-friendly, cookie-less analytics load only after you opt in via the cookie banner.
  • No AI data bill. Live open-text insights use a deterministic, rule-based engine by default - your audience's answers aren't shipped off to a third-party AI to be processed.
  • No voter logins. Participants join with a code or link; we use privacy-preserving fingerprints to keep results fair.

5. Payments

Billing is handled by Whop as our Merchant of Record. Card details are processed by Whop's PCI-compliant systems - PollsLive never sees or stores your card number.

6. Abuse & spam prevention

Public actions are protected by Cloudflare Turnstile (a privacy-first CAPTCHA), Redis-backed per-IP rate limits, login throttling, and bot heuristics. Outbound webhooks and lead destinations are restricted to HTTPS URLs with SSRF guards. Polls stay fair and the service stays available - without putting friction on genuine voters.

7. Enterprise security documentation

We do not publish detailed security audit reports on the public internet. If your procurement or security team needs a written overview of our controls, data residency, and review practices, contact [email protected] or use our contact form (choose Enterprise sales or Privacy / GDPR). We can share a security summary under NDA for qualified enterprise evaluations.

8. Reporting a vulnerability

Found a security issue? We appreciate responsible disclosure. Email [email protected] (or use our contact form) with details and steps to reproduce, and we'll respond promptly. Please don't publicly disclose until we've had a chance to fix it.

Still have questions?

Our team is happy to help with anything on this page.

Contact us
Security & Trust | PollsLive