Skip to content

METHODOLOGY & TRUST

Results you can actually trust

A poll is only worth the reliability of its votes. Here is, in full transparency, how VoxPop guarantees that one vote = one real person, without ever sacrificing your privacy.

The 4 pillars of the chain of trust

One voter, one voice

Every vote is validated server-side and protected by several independent, cross-checked safeguards: account, device, network and identity. Voting twice in the same poll is blocked, even when switching devices or connections.

Certified identity

Beyond the account, VoxPop offers reinforced verification levels: device biometrics (Face ID, fingerprint) and identity certification by an independent private verifier (ID document + selfie). The higher the level, the more the vote weighs in the credibility of the result.

Verifiable anonymity

Your answers are decoupled from your identity. Each voter receives a cryptographic fingerprint (hash) of their ballot: you can verify YOUR vote was counted, and nobody can know what you voted.

Blockchain anchoring

rolling out

Votes will be anchored on the public Polygon blockchain: a tamper-proof, timestamped fingerprint of every poll, auditable by anyone, without revealing any personal data. The mechanism is currently being rolled out.

Three poll certification levels

Every poll displays the level of scrutiny applied to its voters — you always know what the numbers you read are worth.

Standard

Open to any VoxPop account. Ideal for a quick pulse check — anti-double-voting safeguards already apply.

Verified

Restricted to voters with reinforced proof (device biometrics). The recommended level for societal questions.

Officially certified

Restricted to identities certified by our independent private verifier. The level for high-stakes consultations: one vote = one unique physical person, verified without any state apparatus.

How we measure representativeness

VoxPop compares the structure of its French panel with that of the French adult population. That comparison produces a single index, computed with a published and reproducible method. Here is the method, where the reference figures come from, and what the index is actually worth.

The index, in one sentence

We use Duncan's index of dissimilarity (Duncan & Duncan, 1955). It answers a single question: what share of Voxers would have to be moved from one bracket to another for the panel to match the real structure of the population exactly? If 12 % would have to move, the index is 0.12 and we display 88 % correspondence. If nobody has to move, the match is perfect. The calculation covers two variables: age, in five brackets (18-24, 25-34, 35-44, 45-54, 55 and over), and gender.

The reference we compare against

INSEE — Population at 1 January 2026 by sex and single year of age (2025 demographic report, provisional estimates), restricted to the population aged 18 and over, then renormalised across our five brackets. Scope: France. It is the only population reference embedded in the product.

Why Duncan rather than another index

Three serious candidates existed. Kullback-Leibler divergence goes to infinity as soon as a reference category is empty in the panel — guaranteed to happen on a young or sparse panel, which would make the index undisplayable exactly when it is needed. Hellinger distance runs through a square root whose result means nothing to a non-statistician. Duncan is bounded between 0 and 1, reads directly as a share of the population that would have to move, tolerates empty categories, and is citable: the method has been published since 1955 and does not belong to VoxPop.

How age and gender are weighted

Each dimension counts for half, and the displayed score is the plain average of the two. This is not a scientific weighting and we do not present it as one: it is a readability choice. No statistical work establishes that age and gender should weigh exactly the same.

The display threshold

Below 30 French Voxers with both age and gender on file, no index is published. That threshold of 30 is a product heuristic, not a statistical guarantee: it rules out obviously absurd cases, it does not turn a small panel into a reliable sample.

Rounding always works against us

The displayed percentage is rounded down, never up, and 100 % is reserved for an exact match: a panel half a point off displays 99 %, not 100 %. Rounding to the nearest value would have allowed a perfect score to be announced for a panel that is not perfect — unacceptable for a figure meant to be quoted.

Current behaviour

Today, this index displays no percentage at all

The embedded INSEE reference carries a verification flag that has not yet been cleared: its values have not been copied and frozen from the official table we cite. As long as that is the case, the computation is refused and the product shows "Calibration in progress" instead of a percentage. This is not a failure, it is the intended behaviour, written into the code: an index computed on provisional values would be an invented but credible statistic — precisely what VoxPop exists to fight.

Check it yourself: open any poll carrying a representativeness badge. Until calibration is done you will read "Calibration in progress", never a number. We would rather show nothing than show an unreliable figure.

Anonymity, in numbers

"Anonymous" is an unverifiable promise as long as the thresholds are not stated. Here are ours. They apply to every published demographic distribution: age, gender, country, political leaning, religion.

Floor of k ≥ 5

No demographic cell is published below 5 people. Cells that are too small are merged into an "other" bucket; if that bucket itself stays under 5, it disappears entirely. No headcount between 1 and 4 is ever exposed.

Headcounts quantised in steps of 5

Every published headcount is rounded to the nearest multiple of 5, including the panel size shown next to the index. The rounding is deterministic, not random: querying the same statistic ten times returns exactly the same value ten times. Random noise, by contrast, can be cancelled out by averaging several responses.

Capped number of requests

Aggregate statistics cannot be queried in bursts: 10 calls per ten-minute window for the global dashboard, 30 for a poll's demographic data. An attack based on repeated observation requires a request volume the product refuses.

What these three measures concretely prevent

Reconstructing someone's profile by cross-referencing. Without a floor, a cell of one person under "religion" and a cell of one person under "political leaning" are enough to single somebody out in a small panel.

Spotting an arrival or a vote by before/after observation. Without quantisation, an observer who queries the statistics, waits for someone they know to sign up, then queries again, would see the "+1" appear simultaneously in exactly one cell of each distribution — reading their age, gender, country, political leaning and religion in one go.

The limit we acknowledge

Rounding does not absorb everything. When a real headcount crosses a rounding boundary, the jump of 5 remains observable and may coincide with the observed event: the residual leak is on the order of one observation in five per attribute. It is not zero. What closes it in practice is the cap on the number of requests, not the quantisation. We claim no absolute guarantee.

Your privacy first

Trust is worthless if it costs your privacy. VoxPop is built on the GDPR minimisation principle: we collect the minimum, you stay in control of everything.

Public results are always aggregates — never an identifiable individual answer.

Socio-demographic data (opinions, religion…) is optional and erasable at any time from the settings.

Permanent deletion of your account and data in one click from the settings. Full export in a portable format (right to data portability, GDPR art. 20) is available from the same page.

Identity verifications never travel in the clear: only cryptographic fingerprints are kept, never the documents themselves.

What our numbers do NOT say

A representativeness index can be made to say almost anything. Here are seven sentences nobody will be able to draw from our figures. We write them down before they are used against us, because a declared limitation is a method, while a discovered one is a scandal.

It certifies NOTHING about the balance of political or religious views

This is the most likely and most dangerous misuse. The index covers age and gender only, because those are the sole variables for which INSEE publishes a national pyramid. The census measures neither political leaning nor religion: we therefore have no reference to compare our panel against on those dimensions, and we will not fabricate one. A panel perfectly matched on age and gender can be massively skewed politically. Our index will see none of it, and must never be quoted as though it did.

Age and gender are compared separately, not crossed

We compute a gap on the age distribution, a gap on the gender distribution, then average them. We do not compare the age × gender cross-table. Direct consequence: a panel made mostly of young men and older women can post a flattering score while neither of the two corresponding real populations is properly represented. This is a structural limit of the index, not a setting to be tuned.

VoxPop is not a random representative sample

Polling institutes draw their respondents at random from the population. We draw nobody at random: Voxers sign up on their own. It is a self-selected panel, and no weighting corrects that participation bias — we apply none. Resembling the population on age and gender does not make a volunteer panel equivalent to a probability sample. The index measures a structural resemblance, not inferential validity.

Below the thresholds, we publish nothing at all

No index below 30 usable Voxers, no demographic cell below 5 people. These gaps in the data are deliberate and will stay visible. We prefer an empty cell to a figure carrying a margin of error so wide it no longer means anything.

Representativeness only covers France

It is the only population reference embedded in the product. Voxers from other countries vote, count in the results and appear in the per-country statistics — but no representativeness index is computed for them, and the French index does not take their answers into account.

Under-18 Voxers appear in the "18-24" bracket of the charts

Sign-up is open from age 15 (digital age of consent in France, GDPR art. 8). In the age breakdown charts, the bracket labelled "18-24" in fact groups every Voxer aged 24 or under, minors included. The representativeness index, on the other hand, excludes them: the INSEE reference covers people aged 18 and over, and a Voxer under 18 falls into no bracket of that calculation.

The "other" gender is excluded from the index calculation

The French census offers no equivalent to that answer: we have no reference value to compare it against. The Voxers concerned are therefore removed from the index's gender dimension and from the panel size it uses. They remain counted everywhere else: in the votes, in the results, in the published gender statistics. This is a limitation of the census, not a judgement on our part.

A feature that was built, then withdrawn before release

Consensus by demographic segment — showing, for each age bracket or gender, how answers to a poll break down — was built and tested. It was never released. An internal review run against our own code showed that publishing a segment's headcount next to the per-option percentages makes the masked cells recoverable by simple subtraction, immediately so on a closed question, and that repeating the same segment across several questions rapidly erodes the protection provided by rounding. The flaw lay in the combination of those elements, not in an implementation bug. The feature was removed from the repositories. It will come back in a form that publishes no headcount, or it will not come back.

Method changelog

Changing a calculation method or a threshold without saying so is what discredits a producer of figures. Every change is logged here, with its date. This log starts at the introduction of the index and will not be rewritten retroactively.

July 2026

Introduction of the representativeness index

Adoption of Duncan's index of dissimilarity on age and gender, INSEE reference for France aged 18 and over, equal weighting of the two dimensions. Display threshold set at 30 usable Voxers. Percentage rounded down, 100 % reserved for an exact match. Index computed for the overall panel and poll by poll.

July 2026

Anonymity floor, quantisation and request caps

Application of a k ≥ 5 floor and deterministic quantisation in steps of 5 to every published demographic distribution (age, gender, country, political leaning, religion), as well as to the panel size shown next to the index. Caps introduced on the number of calls to the statistics endpoints.

July 2026

Withdrawal of consensus by demographic segment

Feature built then withdrawn before any release, after a re-identification path was demonstrated. Details in the section above.

In progress

Calibration of the INSEE reference

The embedded reference is not yet marked as verified: the index stays on "Calibration in progress" and displays no percentage. Its activation will be logged here, with its date and the exact vintage of the INSEE data used.

Our transparency commitment

This page faithfully describes the actual state of our safeguards, including those still being rolled out. When a protection is under construction, we say so. VoxPop's numbers are only worth this honesty — it is our only asset.

VoxPop

The platform where every voice matters. Connect, share, and impact your community.

Contact

E-mail

contact@voxpopapp.app

Office

Lotissement Taapuna, Lot 20, Punaauia, Tahiti

© 2026 VoxPop. All rights reserved.

Status

Cookies

Security