Privacy Notice
Last updated August 8, 2026
Important status notice: The Machine Assurance Institute ("MAI," "we," "us," "our") is a newly formed nonprofit corporation. Our application for recognition of exemption under Section 501(c)(3) of the Internal Revenue Code (IRS Form 1023) is being drafted and has not yet been filed or determined. Until we receive an IRS determination letter, contributions to MAI may not be tax deductible as charitable contributions. Do not rely on deductibility until we publish confirmation that a favorable determination letter has been issued. We intend to seek retroactive reinstatement of deductibility to the effective date of incorporation if eligible, but no assurance of that outcome can be given.
1.1 Overview
This Privacy Notice describes how the Machine Assurance Institute ("MAI," "we," "us," "our") collects, uses, discloses, and protects personal information submitted through our public web intake form, currently published in connection with DEF CON and the "Open Source the Vote Initiative." MAI is a nonpartisan nonprofit organization conducting election voting-system security research.
1.2 What We Collect
We collect the following information when you submit our intake form:
- Name — to identify and address you.
- Email address — to send a one-time verification code and to communicate with you. Verified by a one-time code sent to the address you provide.
- Mobile phone number (optional) — to send a one-time SMS verification code. Verified by a one-time code sent to the number you provide.
- Organization — the organization you are with, which the form asks for under that name. Used to identify potential conflicts of interest and to understand your professional context. It need not be an employer.
- Role — to match you to suitable volunteer, donor, or vendor-participation opportunities.
- Skills — to match you to research or contribution opportunities.
- Free-text background — any additional information you choose to share about your experience, interests, or availability.
- Consent records — which of the six consents you gave, and the time you gave them: the Terms of Use, this Privacy Notice, email about your application, optional program updates, SMS verification, and public acknowledgment. They are recorded separately, because you may give some and withhold others. Every consent is recorded at the moment you submit, so there is one timestamp covering all of them rather than a separate time per consent.
- Professional profile — sector, years of experience, certifications, publications, prior relevant work, a public profile or code-hosting handle if you supply one, and the areas of the initiative you wish to be involved in.
- Availability and engagement — how much time you can offer, whether you work remotely or on site, and your willingness to travel.
- Security clearance level (optional) — collected only because some assurance work is performed under access restrictions. Supply it only if you wish to be considered for that work; the form functions without it.
- Willingness to sign a non-disclosure agreement — some vendor and pre-certification work cannot be discussed otherwise.
- Declared conflicts of interest — so findings can be assessed independently. This is the reason we ask about your employer.
- Contribution and pledge details (optional) — the kinds of support you may be able to offer, such as equipment, compute, expertise or funding, together with capacity, timing and the organization offering it, where you provide them.
- How you heard about the initiative — to understand which outreach reaches the people we need.
- Technical data recorded with your submission — a one-way salted hash derived from your IP address, and a one-way salted hash of your browser's user-agent string. We also record the two-letter country your connection is reported from, and that one is stored as-is rather than hashed, since a country on its own does not identify anyone. We deliberately do not store your IP address or user agent themselves. These values let us correlate abuse of the form without being able to identify or re-derive who you are, and they are sealed alongside the rest of your submission.
- Nothing is kept in your browser. We set no cookies, and we store nothing in local storage or session storage. Your answers live only in the page until you submit them, so closing the tab discards them and leaves nothing behind on a shared or borrowed computer. The consequence worth knowing is that there is no draft to come back to.
1.3 Why We Collect It (Purposes and Lawful Bases)
| Purpose | Lawful basis (GDPR) | Legal basis (CCPA/CPRA) |
|---|---|---|
| Verify your identity and contact details | Contract (taking steps at your request) | Necessary to perform a contract you request |
| Match you to volunteer, donor, or vendor opportunities | Consent and legitimate interests | Consent and business purpose |
| Assess conflicts of interest, so that findings about a vendor's systems can be shown to be independent | Legitimate interests | Business purpose |
| Determine eligibility for work performed under access restrictions or non-disclosure | Consent | Consent |
| Communicate with you about your submission and our programs | Consent and legitimate interests | Consent and business purpose |
| Maintain records for governance, audit, and legal compliance | Legal obligation and legitimate interests | Legal obligation and business purpose |
| Prevent fraud, abuse, and unauthorized testing | Legitimate interests | Business purpose |
1.4 Who Can See It
Access is restricted to authorized MAI personnel with a need to know. We do not sell your personal information. We may share information with:
- Our sub-processors (listed in Section 1.7), solely to provide hosting, email, and SMS services.
- Professional advisors (legal, accounting) under confidentiality obligations.
- Regulators or law enforcement if required by law or court order.
1.5 Retention
We retain submission data for two (2) years from the date you submit it. The expiry is set on the record at the moment it is stored and it is deleted automatically when that expiry is reached. The clock does not restart if you contact us later, and nothing we do afterwards extends it.
If we were ever required by law, audit, or an active litigation hold to preserve a record beyond that period, we would have to copy it out of the store before it expired; the stored copy still expires on schedule. You may request earlier deletion (see Section 1.9).
1.6 Encryption at Rest
All form submissions are encrypted at rest. The decryption key is held offline and is not accessible to our hosting provider or any sub-processor. Only a small number of authorized MAI personnel can access decrypted data, and only for the purposes described above.
Two emails are sent when you submit, and it matters what is in them:
- To you — a confirmation containing your reference number. It does not repeat what you told us.
- To our reviewers — a notice that an application arrived, containing only the reference, the time, and a hash of the sealed record. It deliberately contains no part of your application. Reading your application requires the offline key; it cannot be read by anyone with access to a mailbox.
Two limits on that, stated here rather than only in the specification, because someone reading this page should not have to go and find them:
- The sealing happens on our server, so our server handles your submission in the clear for the moment it takes to encrypt it. It is not decrypted again by anything online afterwards. No encryption-at-rest scheme protects a submission from an attacker who already controls the server at the moment you send it; what it protects is everything already stored.
- Some metadata is stored unencrypted. Each stored record carries the time it was submitted, its reference number, and a hash of the sealed record that links it to the previous one, so that the set of records can be audited for tampering or deletion. Your answers are never part of that metadata.
- We keep operational logs, separately from your application, so that a failure can be diagnosed. They record what happened rather than who it happened to: an event name such as "a code was sent" or "a code did not match", the first few characters of a session identifier, a country code, a failure reason, your reference number, how many areas of the initiative you selected as a count, and whether you verified a mobile number as a yes or no. The count and the yes-or-no are the shapes of your answers rather than the answers themselves: how many boxes you ticked, not which ones. The first few characters of the salted IP hash described above are written only when a request is rate limited, so that repeated abuse from one source can be recognized; ordinary use does not put it in a log at all. None of these logs contain a name, an email address, a phone number, a raw IP address, or any part of your application.
- Two different things hold those logs, with two different lifetimes. Error diagnostics we write to our own storage carry a 24-hour expiry and are deleted automatically when it passes. The event lines above are emitted to our hosting provider's logging, and how long Cloudflare keeps them is governed by their retention rather than ours; we do not control or extend it.
The technical specification for the encryption, including the algorithm, the wire format, and the public key, is published at /crypto.html so that this claim can be checked rather than taken on trust.
1.7 Sub-Processors
We use the following third-party service providers. Each is a sub-processor under GDPR and a service provider under CCPA/CPRA:
| Provider | Service | Purpose |
|---|---|---|
| Cloudflare, Inc. | Web hosting, bot mitigation, DDoS protection | Serves the intake form and protects it from abuse |
| Resend, Inc. | Email delivery | Delivers verification codes, your confirmation, and the reviewer notice described in Section 1.6. This is the transport we use in normal operation |
| Amazon Web Services, Inc. | Email infrastructure | Resend delivers through Amazon SES, so mail we send passes through AWS |
| Microsoft Corporation (Microsoft 365) | Email (fallback) | Used only if the Resend transport is unavailable, and for the mailbox that receives the reviewer notice |
| Twilio, Inc. | SMS one-time codes | Sends SMS verification codes to verify mobile numbers |
No application content is sent by email through any of these, as described in Section 1.6. What passes through the email providers is your address, your reference number, and a one-time code.
Each provider processes data under its own privacy policy and applicable data-processing agreements. We have not authorized them to use your personal information for their own commercial purposes.
1.8 International Transfers
MAI and its primary infrastructure are based in the United States. The providers listed in Section 1.7 — Cloudflare, Resend, Amazon Web Services, Microsoft, and Twilio — may process data in the United States and other countries. If you are located outside the United States, your information will be transferred to and processed in the United States. By submitting the form, you consent to that transfer. We rely on Standard Contractual Clauses or other appropriate safeguards where required for transfers from the European Economic Area, the United Kingdom, or Switzerland.
1.9 Your Rights — GDPR
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Erase your data ("right to be forgotten"), subject to legal retention obligations.
- Restrict or object to processing.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time (without affecting processing already carried out).
- Lodge a complaint with your supervisory authority.
To exercise any right, email vote@machineassurance.org. We will respond within one month, extendable by two months where necessary.
1.10 Your Rights — CCPA/CPRA
If you are a California resident, you have the right to:
- Know what personal information we collect and how it is used.
- Access and delete your personal information.
- Correct inaccurate personal information.
- Opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information as defined by CCPA/CPRA.
- Limit use of sensitive personal information — we do not collect sensitive personal information as defined by CCPA/CPRA beyond what you voluntarily provide in free-text fields.
- Not receive discriminatory treatment for exercising these rights.
To exercise any right, email vote@machineassurance.org. We will verify your identity before responding. Authorized agents may submit requests with written authorization.
1.11 Children
The form is not directed to children under 18. We do not knowingly collect data from minors. If you believe a minor has submitted data, contact us for prompt deletion.
1.12 Contact
Machine Assurance Institute Email: vote@machineassurance.org
1.13 Changes
We may update this Privacy Notice. Material changes will be posted on this page with an updated "Last updated" date.