Privacy Policy
Privacy Policy
Version 2026-09-01
We collect the minimum needed to review a submission and make a contribution. Submissions are made by adults; we do not ask for a child’s name, age, or other identity details.
What we never collect
The form does not request, and we do not want, any of the following. If a submission contains them we may reject it.
- A child’s name, date of birth, or age.
- Any Social Security number or taxpayer identification number.
- Tax returns or tax forms of any kind.
- Brokerage usernames, passwords, or one-time codes for a TrumpAccount.
- Bank account or card numbers.
- Identity documents, private keys, or recovery phrases.
We do not knowingly collect personal information from anyone under 18. The form is directed at adults acting for a child. The account link identifies a TrumpAccount; we collect that link from the adult submitter so a contribution can be directed correctly.
What we collect and why
- Guardian name and email address — to send a receipt, look up status, and contact you if the entry is selected.
- A password you choose — stored as a one-way scrypt hash so you can sign in on another device. We cannot read the password back.
- State or territory — to apply eligibility rules and to report aggregate reach.
- Relationship to the child — to confirm the submitter is authorized.
- The public account share link — so a contribution can be directed to the right account.
- At least one other contact channel — X handle, Facebook profile, WhatsApp number, and/or phone number.
- An optional note, attestations, and timestamps.
- A keyed fingerprint of your IP address — used only to slow repeated form abuse. We do not store the raw IP with your submission.
Where it is stored
Submission and contact records are written on this server, in encrypted files kept outside the public website folder. They are not written to your browser as the system of record. Published contribution and draw pages never include your name, email, or account link.
How it is protected
- Name, email, phone and other contact channels, account link, and notes are encrypted with AES-256-GCM before they are written to disk.
- Duplicate detection uses a keyed HMAC-SHA-256 fingerprint of the account link, not the plaintext URL.
- The operator desk shows masked fields by default. Revealing a contact record is a separate action and is written to an append-only audit log.
- Submit, sign-in, contact, and recovery routes are rate-limited in memory on this server.
- The site process does not hold the treasury wallet key and cannot move funds.
Receipt, recovery, contact, and winner notices are queued on this server. They are sent over SMTP or Resend only if those credentials are configured. Until then, the operator reads the same messages from the operator desk. The on-screen receipt after submit is still the code you should save.
What is public
Published contribution records show a contribution identifier, state, amount, funding date, status, and proof link. If we select an account from the current draw, we may publish that same kind of record — not the private receipt code. Form fields from your submission are not published.
How long we keep it
We keep submissions while the program is active and as needed to complete a contribution or respond to a dispute. There is no automatic 30-day wipe. Use the contact form from the address you submitted, or the status page, to ask for access, correction, or deletion.
Sharing
We do not sell personal information and we do not share it for advertising. If mail or hosting providers are configured later, they see only what is needed to deliver those services.
Changes
This policy is versioned. Material changes are published with a new version number.