Skip to main content

Last updated August 9, 2026

Privacy

Capital Ark collects only the information needed to connect a supporter’s action with a coalition’s crowdsourced progress. We never receive card numbers, bank details, or campaign-processor credentials.

Information collected

When you only read a public page, Capital Ark does not ask for a name or account. When you choose to contribute, the site creates an opaque visitor identifier in a secure cookie and records the candidate, intended amount, tracking code, time, and a salted one-way hash of the network address used for recent abuse investigation. That hash is cleared after 30 days.

Capital Ark does not save the generated processor URL, request referrer, or full browser user agent. Outbound attribution keeps only the target, processor, tracking code, optional intended amount, and time, without separate visitor or pledge fields. A non-flat tracking code contains a short opaque visitor fragment for committee reconciliation, never a name or email address.

When you create a drive, Capital Ark stores the drive description, candidate and committee details, goals, official processor links, and an opaque organizer identifier so the submission can be attributed and moderated. Community-created drives are labeled separately from information independently reviewed by Capital Ark.

If you return and verify a contribution, Capital Ark stores the receipt-backed amount, required attestation version, review result, and time. The recipient committee’s processor—not Capital Ark—collects and processes your payment information.

Receipts and accounts

To add a contribution to public progress, you must upload one PNG, JPEG, or WebP image of the completed contribution receipt and consent to a one-time automated consistency check. Crop the image to the receipt and hide donor names, addresses, email addresses, and card digits, while leaving the recipient, processor, amount, completed status, and date visible.

Capital Ark sends the screenshot to OpenAI only after that consent. If the visible receipt details cannot be confidently matched, the contribution is not added; you can crop a clearer image or try another receipt. There is no receipt-free self-reporting path.

Capital Ark does not save the raw screenshot on the AI-checking path. It stores limited derived information: the model used, controlled review reasons, extracted amount and date, recipient and processor match flags, and a keyed image digest that prevents one screenshot from backing multiple contributions. The public site shows only a general evidence label, never those receipt details.

AI requests use the OpenAI Responses API with application-state storage disabled. OpenAI may still retain abuse-monitoring logs, including submitted content, for up to 30 days unless Capital Ark’s API organization has Zero Data Retention. An AI-checked match is not conclusive proof that a committee accepted a contribution.

If you later claim an account, the authentication provider may store your email address and session information. Account details are kept separate from public receipt activity.

How information is used and shared

Information is used to generate tagged processor links, maintain crowdsourced totals, let you finish an interrupted confirmation, protect the service from abuse, and preserve the attestation record. Capital Ark does not sell personal information.

Infrastructure providers may process limited data to host the application, database, authentication, or private storage. When you open a donation page, you leave Capital Ark and the campaign processor’s own privacy policy applies.

OpenAI acts as an infrastructure provider only when you submit a receipt for checking. Capital Ark does not use receipt images to generate political messaging, target supporters, or train its own models.

A WhatsApp share button opens WhatsApp with a draft containing public drive information. Capital Ark does not receive your chat list, choose a group, or send the message for you.

Embedded drives and organization signup forms

A Capital Ark drive can appear in a read-only frame on another organization’s website. The frame receives the same public coalition, candidate, aggregate progress, and anonymized activity information that appears on Capital Ark. It does not request a Capital Ark identity or expose receipt records, contributor identities, or private organizer information to the host site.

The widget builder can place a separate, organization-owned Google Form beside the drive. Form entries travel from the visitor’s browser to Google and the organization’s linked Sheet; Capital Ark does not proxy, store, or receive those form fields. The generated Capital Ark frame also uses a no-referrer policy, so the embedding page address is not sent with its request.

The organization controls its form, access permissions, consent language, retention, and use of submitted information. Its own privacy notice and Google’s terms apply to that separate form. Do not submit receipt images or contribution details through an organization signup form.

Retention and your choices

Unresolved contribution intents expire after 72 hours. Confirmed records are retained while needed to operate the public totals, prevent duplicate reporting, and maintain an audit trail. You can delete the Capital Ark visitor cookie in your browser. Salted network-address hashes on contribution records are cleared after 30 days. Deleting the cookie may prevent the site from reopening an unfinished pledge.