Privacy Notice
Last updated: —
Overview
[DRAFT — counsel to confirm] PeopleVoice operates under Thailand's Personal Data Protection Act (PDPA, B.E. 2562). This notice explains what personal data we collect, why, how long we keep it, and your rights.
What data we collect
[DRAFT — counsel to confirm] We collect the minimum needed to keep the public record authentic. The table below covers the data most people expect us to hold. We also store your email address; the country and region derived from your IP address; characteristics of the device you post from; and how you typed each message — how long you took, the interval between keystrokes, and whether text was pasted. We use the device and typing records to detect automation and duplicate accounts.
| Data | Classification | How it is stored |
|---|---|---|
| Username | Personal data (if linkable) | Stored as entered; users are advised not to use real names. |
| Phone number | Directly identifiable | Hashed (one-way) after OTP verification; plaintext is never stored. |
| IP address | Personal data under PDPA | Logged for trust signals; purged after 90 days. |
| Account–message link | Internal association | Kept internally for abuse/legal; never public unless detached. |
| Message content | Public record | Stored permanently; shown anonymously if ownership is detached or the account is banned. |
Why we process your data
[DRAFT — counsel to confirm] We rely on legitimate interest to retain the internal account–message association and IP logs: abuse prevention and trust scoring, legal compliance, and platform integrity. A Data Protection Impact Assessment has not yet been carried out. [NEEDS: who owns the Data Protection Impact Assessment and when it will be completed]
In legal terms, our bases for processing are as follows. For the data needed to open and use an account, we rely on performance of a contract with you. For abuse prevention, trust scoring, security and platform integrity, we rely on legitimate interest. For responding to lawful orders, we rely on compliance with a legal obligation. For the public record itself, and for publishing information about politicians, parties and government bodies, we rely on public interest and freedom of expression. Political opinions are sensitive personal data under section 26 of the Personal Data Protection Act B.E. 2562, and the messages citizens write on this platform are political opinions their authors have chosen to publish. [NEEDS: counsel to confirm the lawful basis for each category above, and in particular whether publishing citizens' political opinions requires explicit consent under PDPA section 26 rather than legitimate interest] [NEEDS: counsel to confirm the basis for processing personal data about politicians and other named subjects, who are not our users and have not given consent]
How we handle your phone number
[DRAFT — counsel to confirm] Your phone number is used only for one-time-password (OTP) verification and ban enforcement. After verification it is stored as a one-way keyed hash (HMAC-SHA256 under a secret key held only on our servers). The plaintext number is never written to our database. Hashes of banned accounts are kept for up to one year, then deleted.
IP address and logs
[DRAFT — counsel to confirm] We log IP addresses to compute trust signals. The IP stored against your messages and your sign-ins is kept for a maximum of 90 days: the IP on a message is erased in place, and sign-in IP records are deleted outright. Two things are not covered by that limit. Our application request logs also contain IP addresses, and today they have no retention limit. And the country and region we derive from your IP are stored with your message permanently, and are not removed when you erase your account. [NEEDS: a retention period for application request logs]
How long we keep data
[DRAFT — counsel to confirm] Retention summary: phone — a one-way keyed hash, kept for the life of the account; IP — 90 days in the database; banned-account phone hash — up to one year; message content — retained permanently as a public record, including rejected and removed messages, and displayed without a name if the account is detached or banned. Some records are kept permanently and are not removed when you erase your account: our append-only audit log, the history of every handle your account has held, the votes you cast, device and typing records, trust signals, and reports you filed. [NEEDS: whether any of these permanently retained records should carry a retention limit]
Your rights
Under the Personal Data Protection Act B.E. 2562 you have the right to access and obtain a copy of your personal data, to have inaccurate data corrected, to have data erased, to have processing restricted, to object to processing, to have your data transferred in a machine-readable form, to withdraw consent where we rely on consent, and to lodge a complaint with the Personal Data Protection Committee. Two of these you can exercise yourself today: changing your handle from your settings, and erasing your account from your settings. Please read the note below on what erasure removes and what it does not. For the other rights there is no automated route yet. We have no data-export feature, so a request for a copy of your data has to be handled by hand. [NEEDS: an email address for privacy and data-subject requests] [NEEDS: how long we take to answer a data-subject request] [NEEDS: how we verify that a request comes from the account holder]
[DRAFT — counsel to confirm] You can erase your account from your settings. This clears your email address, your phone hash, your legacy username, your province, and your password and one-time-password fields; deletes your sign-in IP records and the politicians and topics you follow; removes the IP address from your messages; and detaches every message from your account so that it is displayed without a name. It does not delete the account record itself. Because of that, records keyed to your account survive: your generated handle and its full history, the votes you cast, device and typing records, trust signals, reports you filed, and our append-only audit log — which includes a record, for each vote, of how your account voted on a specific message. Message content remains in the public archive under the PDPA's archival and public-interest exception, and cannot be withdrawn once published. Anything self-identifying that you typed into the body of a message is not removed by erasure. [NEEDS: counsel to confirm which of the surviving records may lawfully be retained, and which must be deleted or de-identified]
Sharing with authorities
[DRAFT — counsel to confirm] We do not voluntarily disclose your phone number, your email address, or the link between your account and your messages. We respond only to a valid court-issued warrant reviewed by our legal counsel. We do not currently keep a log of government requests for data, and our monthly transparency report covers content-moderation decisions only — it contains nothing about government requests. [NEEDS: whether we commit to logging and publishing government data requests, and from when] Separately from the authorities, service providers process personal data on our behalf: Twilio receives your phone number in plaintext in order to send the one-time password; Sentry receives error reports that can include your account identifier; PostHog, hosted in the EU, receives page views and interaction events, which necessarily exposes your IP address to it; ip-api.com receives your IP address; and Anthropic receives citizen message text and politicians' quote text in order to generate summaries. [NEEDS: the country and cross-border-transfer basis for each of these processors, and whether sending citizens' political speech to a foreign AI provider requires separate treatment]
Contact and Data Protection Officer
There is no contact address published anywhere on this site today. That is an unfixed gap, not a policy. The consequence is that a citizen with a privacy question, and a politician who considers information we publish about them inaccurate, have no way to reach us at all, other than by creating a user account and reporting an individual message. [NEEDS: legal entity name and registered address of the data controller] [NEEDS: an email address for privacy and data-subject requests] [NEEDS: whether a Data Protection Officer must be appointed for this processing and, if so, the DPO's name and contact details] You may also complain directly to the Office of the Personal Data Protection Committee (PDPC). This notice is published in both Thai and English. The Thai version is the operative version. If the two versions differ in meaning, the Thai version prevails.
See also our Terms of Service

