CAMILLE CHASTAIN FOR U.S. SENATE

Privacy Policy

We collect the information a political campaign actually needs, protect it according to the sensitivity of the record, and do not treat “quantum-secured” as a substitute for ordinary privacy engineering.

Collect less.We limit collection to campaign, volunteer, security, and legal purposes.
Protect the endpoints.Quantum key agreement cannot compensate for a compromised phone, wallet, browser, or campaign system.
Separate secrecy from anonymity.Encryption protects content. Metadata protection requires additional network and retention controls.

1. Information We Collect

When you choose to interact with the campaign, we may collect information you provide directly, including your name, email address, mobile number, ZIP code, county, volunteer interests, event participation, message content, communication preferences, and other information you choose to send us.

For field organizing, we may associate campaign contact history with public voter-registration information, publicly available records, geographic turf assignments, event attendance, and campaign-generated notes such as whether a voter asked for follow-up. We do not need or want passwords, banking credentials, Q-Wallet private keys, biometric templates, medical records, or government identification numbers through ordinary campaign web forms.

2. How We Use Information

We use campaign information to organize volunteers, respond to inquiries, provide campaign news and event notices, conduct lawful voter contact, prevent abuse, maintain site and network security, comply with campaign-finance and election law, reconcile contributions, and preserve records that the campaign is legally required to keep.

Software may help route messages, identify duplicate records, flag apparent abuse, or prioritize routine follow-up. The campaign does not delegate final decisions about contribution eligibility, volunteer access, sensitive constituent matters, or law-enforcement referrals to an autonomous system without accountable human review.

3. Website, Device & Network Data

Like most public websites, campaign infrastructure may receive technical information necessary to deliver and secure a request, such as the requested page, timestamp, browser or client family, coarse network region, protocol version, security-event indicators, and a network address or privacy-relay identifier. Security logs are separated from supporter profiles wherever practical and are retained for a shorter period unless an incident requires investigation.

This site does not use third-party advertising pixels to build cross-site behavioral profiles. Essential first-party storage may be used for security, accessibility, language, or session preferences. Opening an external social network, mailing-list provider, Q-Wallet, or other third-party service subjects that interaction to the provider’s own privacy practices.

A secure connection is not the same thing as an anonymous connection. Encryption can hide the contents of a request while network operators may still be able to observe some combination of timing, traffic volume, or endpoint information. Where Q-Net privacy relays are available, the campaign supports them rather than requiring a directly identifying network path.

Q-NET PRIVACY PROFILE

4. How Quantum-Secured Privacy Actually Works

The Q-Net is designed so that quantum mechanisms contribute fresh key material and intrusion evidence; they do not carry ordinary campaign messages as qubits and they do not make endpoint data disappear. Most campaign content remains classical data encrypted over classical optical links.

4.1 Entanglement-Based Key Agreement

On supported high-assurance routes, certified endpoints establish end-to-end quantum correlations using an entanglement-based protocol derived from BBM92. Quantum repeaters extend those correlations through entanglement swapping. The endpoints choose measurement bases independently, disclose only the basis and parameter-estimation information required by the protocol, estimate the quantum bit error rate, reconcile disagreements over an authenticated classical channel, and apply privacy amplification before any resulting bits are accepted as secret key material.

The security property is statistical. An adversary attempting to obtain information about the quantum states can disturb the correlations and raise the observed error rate. That does not mean the network can magically identify every intruder or prove that every endpoint is trustworthy. Side channels, defective hardware, compromised software, and dishonest endpoints remain ordinary security problems.

4.2 Authentication and a Second, Independent Secret

Quantum key distribution cannot authenticate a stranger by itself. Q-Net endpoints therefore authenticate the classical control channel with hardware-protected post-quantum credentials. The current compatibility suite uses ML-DSA-87 for active endpoint signatures and establishes an independent ML-KEM-1024 shared secret in parallel with the quantum-derived secret.

The QKD output, ML-KEM output, authenticated session transcript, and fresh session nonce are combined through a domain-separated SHA-3-family key-derivation function. The resulting traffic key therefore does not depend on a single cryptographic assumption. Approved successor algorithms may replace these compatibility algorithms as federal profiles evolve.

4.3 The Data Is Still Encrypted Classically

Campaign messages, volunteer records, contribution records, and identity claims remain classical bits. Session payloads are protected with AES-256-GCM authenticated encryption using fresh per-session keys and nonces. Associated data cryptographically binds each protected record to its intended service, authenticated endpoint, session transcript, and sequence number so that an attacker cannot silently substitute those fields without detection.

For stored campaign records, quantum links are not used to “encrypt a database.” Sensitive records use envelope encryption: a fresh data-encryption key protects the record, that key is wrapped under a hardware-protected campaign key, and access is limited by role. Hardware security modules enforce key use, rotation, and destruction. Backups are separately encrypted and integrity-checked.

4.4 Metadata Requires Different Protections

QKD protects key establishment; it does not inherently hide who contacted whom, when, or how much traffic moved. Q-Net privacy mode therefore uses rotating pseudonymous session identifiers and, where available, two non-colluding privacy relays: the ingress relay can see the user-side connection but not the final campaign destination, while the egress relay can see the campaign destination but not the originating user identity. Neither relay is intended to possess the complete mapping.

Relay separation reduces ordinary metadata exposure but is not represented as perfect anonymity against a global observer capable of correlating traffic across the entire network. Timing correlation, endpoint compromise, malicious clients, or information a user voluntarily includes in a message can still identify the sender.

4.5 Keys Are Ephemeral; Records Are Not Necessarily

Raw quantum measurement results, rejected key material, reconciliation work data, session traffic keys, and wallet signing keys are not campaign records and are not retained by the campaign website. Session keys are destroyed after their defined cryptographic lifetime. By contrast, a decrypted volunteer request, campaign message, or legally required contribution record may need to be retained after transport encryption ends. Quantum security protects the path; the campaign remains responsible for the record at the endpoint.

In plain English: the quantum layer helps the two ends agree on secret material and detect suspicious disturbance; post-quantum cryptography authenticates the ends and contributes a second secret; ordinary authenticated encryption protects the actual data; separate privacy relays and retention rules address metadata and stored records.

5. Q-Net Contributions

This website does not collect or process banking credentials. Selecting qnet://chastain2056 transfers control to the contributor’s registered Q-Wallet or other authorized financial client. The wallet and regulated financial network perform identity, eligibility, contribution-limit, source-of-funds, and payment authorization checks.

The campaign receives the contribution information it needs for deposit, reconciliation, supporter records, and legally required campaign-finance reporting. It does not receive the donor’s wallet private key, QKD raw measurements, session traffic key, or online-banking password. Information that campaign-finance law requires to be publicly disclosed cannot be made private by Q-Net encryption.

For the detailed transfer-security profile, see the Q-Net Security Architecture in our Terms of Use.

6. Volunteers, Q-Net Outreach & GLASS

Volunteer information is used to place people with appropriate field teams, events, Q-Net outreach, GLASS outreach, canvassing routes, and campaign-office work. Field volunteers should receive only the voter-contact information needed for their assigned task rather than unrestricted access to the campaign’s full supporter database.

Q-Net outreach may provide transport confidentiality, but a message becomes readable at the recipient endpoint. GLASS conversations are treated as live human contact; the campaign may retain call disposition, consent, follow-up notes, and other operational records, but does not treat the fact that a channel is “analog” as permission to collect more information than necessary. Where a conversation is recorded or transcribed, notice and applicable law govern that recording.

7. Retention, Separation & Deletion

We retain information according to purpose. Routine security telemetry is kept for a short operational period; volunteer and supporter records may be retained through the campaign and a reasonable post-election transition period; campaign-finance, accounting, legal, and incident records are retained for the periods required by law or necessary to resolve an active matter.

Where records no longer need to be retained, they are deleted or de-identified under campaign retention schedules. For encrypted stores, retirement can include cryptographic erasure by destroying the wrapping keys that make retired ciphertext recoverable. Legal holds, campaign-finance reporting obligations, completed contribution records, and records already lawfully disclosed to public authorities may not be erasable on request.

8. When We Share Information

We may share information with campaign staff, authorized volunteers with a need to know, professional service providers acting for the campaign, regulated payment and Q-Net operators, election and campaign-finance authorities, law enforcement when legally required, and other parties when necessary to protect the campaign, its systems, or another person from a credible threat.

We do not sell personal information to commercial data brokers. Service providers are expected to use campaign information only for the contracted purpose, apply appropriate security controls, and return, delete, or lawfully retain data at the end of the service.

9. Your Choices

You may opt out of campaign marketing and volunteer messages using the method provided in the communication or by contacting the campaign. You may ask us to correct campaign contact information, stop non-required outreach, or explain what campaign record categories we maintain about you, subject to identity verification and legal retention requirements.

You can also disable Q-Net language rendering or privacy-relay features in your own client. Doing so changes presentation or network routing; it does not alter the signed source content published by the campaign.

10. Privacy Questions

Questions about this policy, campaign data practices, correction requests, or suspected privacy issues may be sent to privacy@camilleforsenate.com.

Please do not send passwords, banking credentials, Q-Wallet private keys, seed material, government identification numbers, or raw quantum-network diagnostic data by email.