Legal

Privacy Policy

What Cortext Labs, Inc. collects about contributors and site visitors, why it collects it, who it goes to, how long it is kept, and what you can make us do about it.

Version 3.1 · Published 18 June 2026 · Effective 20 July 2026 · Supersedes Version 3.0, effective 3 February 2026
These are the operative terms, not a summary
This policy forms part of the contract between you and Cortext Labs, Inc. — the same agreement as the Contributor Terms of Service and the Cookie Policy. It binds Cortext Labs, Inc. to everything written here, and it is what a regulator would hold us to. Where a sentence says we do not do something, it means we do not, and starting to do it requires a new version of this document and 30days’ notice to you.

01Scope, and who this policy is for

This policy describes what Cortext Labs, Inc. does with personal data about contributors — the domain experts who apply to, are assessed for, and work on projects through the Cortext marketplace — and about visitors to cortext-ai.uk. It is version 3.1, published 18 June 2026 and effective 20 July 2026. It replaces version 3.0, effective 3 february 2026.

Read it alongside the Contributor Terms of Service, which governs the working relationship, and the Cookie Policy, which covers browser storage in detail. Where this policy and an engagement-specific privacy notice disagree, the engagement notice controls for that engagement only, and we will have told you so before you accepted it.

What this policy covers

  • Creating an account, applying to a listed opportunity and being screened.
  • Identity and credential verification, including the checks run by the vendors listed in section 8.
  • Assessments, work trials, engagements and the work product you deliver through the platform.
  • Payouts, tax documentation and payment records.
  • Support correspondence, trust-and-safety reports and appeals.
  • Ordinary website use — page requests, error reports and product analytics.

What it does not cover

  • What an AI-lab client does with work product after delivery. From delivery the client is an independent controller of that material under its own notice, and we cannot answer for it. Section 5 explains what is delivered.
  • Applications for staff roles at Cortext. Those are covered by a separate recruitment notice sent with the application acknowledgement from careers@cortext-ai.uk.
  • Sites we link to. A link is not an endorsement of anyone else’s privacy practices.

02The controller, and how to reach a person about it

Cortext Labs, Inc. is a corporation incorporated in Delaware, United States, with its registered business address at 1 Sansome Street, Suite 3500, San Francisco, CA 94104, United States. For everything described in section 3, Cortext Labs, Inc. is the controller — it decides why the data is processed and how. We are not acting as a processor for a client when we collect your application, your CV or your payment details, and no client instructs us on those.

The vendors in section 8 are processors: they act only on our documented instructions under a written data processing agreement that includes confidentiality obligations, security requirements, sub-processing controls and deletion or return of data at the end of the contract.

Our data protection officer can be reached at privacy@cortext-ai.uk. Every address we publish is an email address monitored by the Cortext privacy team. There is no telephone support line and no telephone route into the privacy team; we do not operate a phone channel of any kind, and we will never call you about a data request.

03What we collect, why, and on what legal basis

The categories below are exhaustive for the platform as it stands. Where a legal basis is legitimate interests, we have carried out a balancing assessment and you can request a summary of it from privacy@cortext-ai.uk. Where the basis is consent, refusing costs you nothing except the specific feature described.

Account and contact data

Full legal name, email address, country and city of residence, time zone, preferred working language, account password hash, sign-in timestamps and the referral code you arrived with, if any. We use it to create and secure the account, to route you to the right regional deployment, to send transactional email about applications, engagements and payouts, and to credit a referrer.

Legal basis. Performance of a contract, GDPR Article 6(1)(b), for account creation and transactional messages. Legitimate interests, Article 6(1)(f), for account security and abuse prevention.

Identity verification data

A government photo ID, a selfie taken for liveness matching, date of birth and the pass-or-fail outcome of the check. The images and the liveness video are captured directly by Veritas ID and are never held on Cortext systems; we receive the outcome, a reference number, the document country and the verified name and date of birth. Some engagements additionally require criminal-record, sanctions or professional-licence screening, which is disclosed on the listing before you apply.

Legal basis. Legal obligation, Article 6(1)(c), for sanctions and anti-money-laundering screening. Performance of a contract, Article 6(1)(b), for verifying that the person being paid is the person engaged. Where biometric liveness matching is treated as special category data, we rely on your explicit consent, Article 9(2)(a), collected on the verification screen itself; you can decline, and the consequence is that we cannot onboard you.

Professional and CV data

Your CV or résumé, employment history, education, degrees, publications, professional licence and registration numbers, specialist areas, languages and self-declared seniority, plus the verification result for each claim we check. Roughly 61% of applicants clear credential verification; the record of why an application did not is part of this category.

Legal basis. Steps taken at your request prior to entering a contract, Article 6(1)(b). Legitimate interests, Article 6(1)(f), in keeping evidence of the claims a matching decision rested on, so a disputed decision can be reconstructed.

Assessment submissions and work product

Assessment answers and scores, work-trial output, and everything you produce on an engagement: ratings and rankings, written reference answers, rubric scores and the reasoning behind them, critiques, adversarial prompts, annotated agent trajectories, code and transcripts. We also keep reviewer scores, quality metrics, inter-rater agreement figures, timestamps, and the audit trail of which items were accepted, revised or removed. If a screening interview is recorded, the recording and its transcript sit here too — recording is optional and the interview runs whether or not you agree to it.

Legal basis. Performance of a contract, Article 6(1)(b), for scoring, payment and delivery. Legitimate interests, Article 6(1)(f), for quality control, rubric calibration and detecting recycled or machine-generated answers. Consent, Article 6(1)(a), for interview recording and for any use of work product beyond the engagement it was created for — see section 5.

Payment and tax data

Payout method, the country of the receiving account, payout history, amounts, currency, failed-payment reasons, and the tax documentation required for your status — Form W-9 for US persons, Form W-8BEN or W-8BEN-E otherwise. Bank account numbers and taxpayer identification numbers are collected and stored by Stripe or Wise on their own screens. Cortext sees a masked account reference, the payout status and the amount, never the full account number and never your full taxpayer identification number.

Legal basis. Performance of a contract, Article 6(1)(b), for paying you. Legal obligation, Article 6(1)(c), for tax reporting and financial record-keeping.

Device, usage and log data

IP address, approximate country and region derived from it, browser and operating system, device type and screen size, referring page, pages requested, timestamps, session duration, feature usage, error traces and page-performance timings. Analytics is first-party and collected without cross-site identifiers. Error reports have request bodies and form values redacted at the point of capture, before they leave your browser.

Legal basis. Legitimate interests, Article 6(1)(f), for security, fraud and bot detection, and for keeping the service working. Consent, Article 6(1)(a), for analytics and performance cookies, given through the banner and withdrawable at any time — see section 16.

Communications

Support tickets, emails to any published Cortextaddress, appeal submissions, trust-and-safety reports you make or that are made about you, and the internal notes a reviewer or agent adds to them. Reports about another contributor are held separately and the reporter’s identity is not disclosed to the subject except where the law requires it.

Legal basis. Performance of a contract, Article 6(1)(b), for support connected to an engagement. Legitimate interests, Article 6(1)(f), for dispute history, pattern detection in safety cases and defending legal claims.

04What we deliberately do not collect

A privacy policy that only lists what a company takes is half a policy. The following are things the platform is capable of doing and does not do. Changing any of them is a material change and would trigger the notice period in section 17.

  • No advertising or cross-site tracking. We set no advertising cookies, embed no ad-network pixels, run no retargeting, and buy no audience data from data brokers. There is no advertising business here to fund.
  • No phone number and no phone verification. Cortext has no telephone channel at all, so we never ask for a mobile number, never send SMS codes and never call you.
  • No screen recording, keystroke logging or webcam proctoring. We do not install software on your machine and we do not monitor what you do outside the platform interface. Assessments are scored on what you submit, not on how you were sitting.
  • No precise location. We derive a country and region from your IP address for routing, tax and sanctions purposes. We do not request GPS permission or collect device location.
  • No social-media graph. We do not scrape or purchase your social profiles, connections or posts, and there is no social sign-in.
  • No credit checks or salary history. Rates are published on the listing before you apply, so there is nothing to gain from asking what you currently earn.

05How work product is used to train and evaluate AI models

This is the section most contributors are looking for, so it is stated plainly. The work you do on a Cortext engagement exists in order to train and evaluate AI models. Your ratings, reference answers, rubric scores, critiques, adversarial prompts and trajectory annotations are collected, quality-checked, packaged and delivered to the AI-lab client that commissioned the project, and that client uses them to train, fine-tune, align, reward-model or benchmark its systems. If you would rather your output were not used that way, the correct decision is not to accept the engagement.

The basis we rely on

For work product created under an accepted engagement, the basis is performance of a contract, GDPR Article 6(1)(b). Training use is the purpose of the engagement, it is stated on the listing and repeated in the engagement letter you countersign, and the rate you are paid is consideration for it. Ownership is a separate question from data protection and is dealt with in the intellectual property section of the terms.

For any use beyond the engagement it was created for — reuse of a completed delivery on a second project, inclusion in a public benchmark or an open dataset, or release of work product under your name — the basis is your separate explicit consent, Article 6(1)(a), captured per use, per project. We do not treat the original engagement as blanket permission. Consent records are kept for the period in section 10 precisely so that what you agreed to, and when, can be proved.

What is in the delivery, and what is not

  • Work product is delivered under a pseudonymous contributor identifier, together with the credential category that qualified you for the project — for example “licensed physician, cardiology, 8+ years” — and the quality scores for the items in the batch.
  • Your name, email address, CV, ID document, date of birth, payout details and support history are not delivered to clients and are not part of any training set we produce.
  • A small number of engagements require named, attributable expert authorship, because the client needs to evidence who wrote a reference answer. Those listings say so on the card, before you apply, and require a separate consent at acceptance. You can work on Cortext indefinitely without ever taking one.
  • Anything you type into a submission becomes part of the delivery. Do not put personal data about yourself or about a third party — a patient, a client, a colleague — into work product. The content standards require de-identification and we reject items that breach them.

Models Cortext trains itself

Separately from client work, we train internal, non-generative models on submission text and metadata: duplicate-answer detection, machine-generated-text scoring, reviewer drift detection and fraud scoring. These are classifiers, they produce a score and nothing else, and they exist to protect the pay of contributors doing the work honestly. The basis is legitimate interests, Article 6(1)(f), and you can object under section 12. We do not train generative models on your work for our own products, and we do not sell datasets.

The limit we cannot get around

You may withdraw a consent given under this section at any time, and withdrawal is effective for all future use: the material is pulled from any dataset not yet delivered, excluded from future deliveries and flagged in our records. It is not retroactive. Where work product has already been delivered and a client has already trained on it, the model weights cannot be unwound, and neither Cortext nor the client can extract your contribution from them. We tell you this before you consent rather than after you withdraw.

06Automated decisions in screening, and your right to human review

Parts of screening are automated. Under GDPR Article 22 you have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, and access to paid work is exactly that kind of effect, so this section sets out which steps are automated and how to get a person to look again.

Automated with no human in the loop

  • Assessment scoring against a gold set. Domain assessments are scored automatically against a reference set with a pass mark of 80%. A score below the mark ends the application for that role and starts a 30-day wait before a retake.
  • Eligibility filters. Country of residence against sanctions and export-control lists, and the 18-plus age check. A hard block here is deterministic and we cannot override it in the cases where the law forbids the engagement.
  • Duplicate and machine-generation scoring. Submissions are scored for duplication against other submissions and for signs of generated text. A high score does not itself end anything — it queues the item for a reviewer.

Never automated

No account suspension, no offboarding, no removal of hours and no rejection on integrity grounds takes effect on an automated signal alone. A named reviewer makes the decision, records a reason against the specific rubric clause or policy provision, and that reason is shown to you. Automated flags are wrong often enough that they are not permitted to be the last step.

Asking for human review

Email privacy@cortext-ai.uk or support@cortext-ai.uk with the application or engagement reference and a sentence on why the outcome is wrong. You have the right to obtain human intervention, to express your point of view, and to contest the decision. Review is carried out by someone who was not part of the original decision. We acknowledge within 5 business days and decide within 10 business days; where an assessment item is found to be mis-keyed we correct the gold set, rescore everyone affected by it and tell them, not only the person who complained.

07Who we disclose personal data to

Cortext Labs, Inc. does not sell personal data, does not share it for cross-context behavioural advertising, and does not disclose contributor contact details to clients as a lead-generation service. Disclosure happens in the following circumstances and no others.

AI-lab clients

Clients receive work product, the pseudonymous contributor identifier, the credential category that qualified you, and quality metrics for the delivery. They become independent controllers of that material on delivery and process it under their own notice and their own agreement with Cortext, which prohibits them from attempting to re-identify contributors. They do not receive your name, email address, CV, ID document or payout details unless you have consented to named attribution as described in section 5. Clients are not listed as subprocessors in section 8 for that reason.

Payment processors

Stripe and Wise receive your name, country, email address, payout instrument details and the amount payable, and collect your tax forms directly. They act as controllers of the payment instrument data they hold for their own regulatory obligations and as our processors for the payout instruction.

Identity, sanctions and background verification vendors

Veritas ID receives your ID document and liveness capture; Northgate Trust Compliance receives your name, date of birth and country for list screening; Certram Screening receives what a specific client-mandated background check requires, and only for engagements where that check is disclosed on the listing before you apply.

Other recipients

  • Subprocessors — hosting, storage, email, e-signature, ticketing, analytics and transcription, all listed in section 8.
  • Professional advisers — auditors, accountants, insurers and outside counsel, under professional confidentiality obligations, on a need-to-know basis.
  • Corporate transactions — a buyer or investor in a merger, acquisition or asset sale, under a confidentiality agreement, with personal data disclosed in aggregate or pseudonymised form during diligence wherever that is workable. If a transaction completes and the controller changes, we will tell you before your data is processed under a different notice.
  • Law enforcement, regulators and courts— where we are compelled by valid legal process, or where disclosure is necessary to establish, exercise or defend legal claims. We require lawful process rather than an informal request, we push back on demands that are overbroad, and we notify the affected contributor unless a court order or statute prohibits it or there is a genuine risk to someone’s safety.
  • Emergencies — where there is an imminent risk of serious harm to any person, we disclose the minimum necessary and log every such disclosure.

08Subprocessors

These are the processors that handle contributor personal data on our instructions. Each is bound by a written data processing agreement incorporating the GDPR Article 28 terms, the relevant transfer mechanism from section 9, and a requirement to notify us of a security incident without undue delay.

SubprocessorCategoryWhat it processes for usWhere processing happens
Stripe, Inc.PaymentsContributor payouts, payout account onboarding, collection of Form W-9 and Form W-8BEN, and delivery of Form 1099-NEC to US contributorsUnited States; Ireland for EEA and UK payout accounts
Wise Payments Ltd.PaymentsLocal-currency payouts in corridors Stripe does not serve, including most of sub-Saharan Africa and parts of South AsiaUnited Kingdom; Belgium for EEA transfers
Veritas ID, Inc.VerificationGovernment photo-ID capture, document authenticity checks and selfie liveness matching during contributor onboardingUnited States; Ireland for EEA and UK contributors
Certram Screening Ltd.VerificationCriminal-record, sanctions and professional-licence screening for the small number of engagements whose client requires itUnited Kingdom; regional partners in 41 countries
Northgate Trust Compliance B.V.VerificationSanctions, export-control and politically-exposed-person list screening against OFAC, UK HMT, EU consolidated and UN listsNetherlands
Cadence Cloud, Inc.InfrastructureApplication hosting, the primary contributor database and encrypted database backupsUnited States (us-east-1); Ireland (eu-west-1) for EEA and UK contributors
Halyard Object Storage, Inc.InfrastructureEncrypted storage of CVs, assessment submissions, work product and delivery archivesUnited States; Germany for EEA and UK contributors
Beacon Grid Networks, Inc.InfrastructureContent delivery, TLS termination, DDoS mitigation and bot management at the network edgeGlobal edge network; logs aggregated in the United States
Relayline Mail, Inc.CommunicationsTransactional email — sign-in links, application status, engagement offers, payout notices and hour-adjustment noticesUnited States
Quillmark eSign Ltd.OperationsElectronic signature and storage of engagement letters, confidentiality agreements and IP assignment agreementsIreland
Helpmesh, Inc.OperationsSupport ticketing and the email queue behind every address on the contact pageUnited States
Tandem Analytics ABAnalyticsFirst-party product analytics — page views, funnel completion and feature usage, collected without cross-site identifiersSweden
Sitewatch Telemetry, Inc.AnalyticsError reporting, crash traces and real-user performance monitoring, with request bodies and form values redacted at captureUnited States; Ireland for EEA and UK traffic
Aurora Speech, Inc.OperationsTranscription of recorded screening interviews where a contributor has consented to recordingUnited States

We publish changes to this list before they take effect. To be notified in advance, email privacy@cortext-ai.uk asking to be added to the subprocessor notification list; we give 30days’ notice before a new subprocessor begins processing contributor data, except where an existing vendor must be replaced urgently for security or continuity reasons, in which case we notify as soon as the change is made and explain why. If you object to a new subprocessor, tell us and we will explain the alternative; where there is none, your remedy is to close the account, and we will process the closure without the usual retention of account data beyond what section 10 requires.

09International transfers and standard contractual clauses

Cortext operates from the United States and works with contributors in around 130 countries, so personal data does cross borders. We hold account records for contributors in the EEA and the UK in the Ireland deployment, and their CVs, submissions and work product in Germany, and route their requests there. Data still moves to the United States for support, payouts, engineering access to diagnose faults, and delivery to clients based there.

The mechanisms we rely on

  • EU standard contractual clauses.The European Commission’s clauses of 4 June 2021 (Decision 2021/914), Module Two for controller-to-processor transfers and Module Three where a processor onward-transfers, incorporated into every relevant vendor agreement.
  • UK transfers. The UK International Data Transfer Addendum to the EU clauses, issued under section 119A of the Data Protection Act 2018.
  • Swiss transfers. The EU clauses with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner.
  • Adequacy and certification. Where a recipient is covered by an adequacy decision, or is self-certified to the EU-US Data Privacy Framework and its UK extension, we rely on that instead of clauses and say so in the vendor record.
  • Other regimes. Transfers involving contributors in Kenya are handled under the Data Protection Act 2019 and the transfer conditions in its regulations; transfers involving contributors in India are handled under the Digital Personal Data Protection Act 2023.

We carry out a transfer impact assessment for each importer in a jurisdiction without an adequacy decision, covering the laws that could compel access, the vendor’s record of government requests, and the technical measures — encryption in transit and at rest, key separation, and the redaction described in section 11 — that reduce the exposure. Redacted copies of the clauses and of the relevant assessment are available on request from privacy@cortext-ai.uk.

10How long we keep each category

We keep personal data for the period set out below and then delete it or aggregate it beyond re-identification. Where a period is driven by a statutory obligation we cannot shorten it on request; where it is driven by our own operational need we usually can, and the table says which is which.

DataRetentionClock startsWhy it is not shorter
Account and profile data24 monthsLast sign-inContributors return between engagements; after that the record is deleted.
CV, work history and professional claims24 monthsLast application or engagement activityMatching to new projects, and evidence of the claims a hiring decision rested on.
Assessment submissions and scores36 monthsDate of submissionRubric calibration, appeal handling and detection of recycled answers.
Recorded screening interviews and transcripts12 monthsDate of interviewAppeals and reviewer quality audits. Deleted earlier on request unless an appeal is open.
Identity verification result7 yearsEnd of the last engagementAnti-money-laundering and sanctions record-keeping. Cortext keeps the pass or fail outcome and a reference number, never the ID images.
ID images and liveness video30 daysCompletion of the checkHeld by Veritas ID, not by Cortext, and deleted from their systems on that schedule.
Background screening summary5 yearsDate of the reportClient audit obligations. The underlying report stays with the screening provider.
Work product delivered to a client7 yearsDate of deliveryProvenance and audit of what was delivered, to whom, and under which consent.
Payment records and payout history7 yearsEnd of the tax year of paymentUS federal and state record-keeping obligations.
Tax forms (W-9, W-8BEN) and 1099-NEC copies4 yearsEnd of the tax year of the final paymentIRS retention requirement for withholding certificates.
Signed agreements — engagement letters, NDAs, IP assignments10 yearsEnd of the engagementStatutory limitation periods for contract and IP claims.
Support tickets and email correspondence36 monthsTicket closureDispute history and pattern detection in trust and safety cases.
Security and access logs24 monthsDate of the eventIncident investigation and account-takeover analysis.
Product analytics events13 monthsDate of the eventYear-over-year comparison. Aggregated and stripped of identifiers after that.
Consent records — AI training, recording, safety projects10 yearsWithdrawal or expiry of the consentProving what was consented to, and when, for as long as the data it covers exists.
Suppression list and deletion request logIndefiniteDate of the requestThe minimum record needed to honour the request — an email hash and a date, nothing else.

How deletion actually works

A deletion request is actioned on live systems within 30 days. Encrypted database backups are on a 35-day rotation and are not edited in place, so deleted records persist in backup media until that rotation completes; they are not restored into production except in a disaster-recovery event, and if that happens the deletion is reapplied as part of the recovery runbook. When an account is deleted we retain one suppression record — a hashed email address, the date of the request and the request type — because it is the minimum needed to honour the request and to prove we did.

11Security measures

Security is described here in enough detail to be checkable. It is not a claim that nothing can go wrong.

  • In transit. TLS 1.2 or higher on every connection, HSTS on all cortext-ai.uk hostnames, and modern cipher suites only. Plain-text HTTP is redirected, never served.
  • At rest. AES-256 for the database, the object store holding CVs and work product, and every backup. Keys are managed in a dedicated key service, rotated annually, and separated from the data they protect so that access to storage alone is not access to content.
  • Access control. Role-based access on a least-privilege model, mandatory multi-factor authentication with hardware keys for all staff, no shared accounts, and production access through short-lived credentials that expire automatically. Access to work product is limited to the delivery team and reviewers assigned to that project. Entitlements are reviewed quarterly and revoked the same day someone leaves.
  • Logging. Administrative and data-access actions are logged to append-only storage retained for 24 months, and reviewed on any integrity or account-takeover investigation.
  • Redaction at capture. Error and performance telemetry strips request bodies and form values in the browser, before the report is transmitted, so a crash report cannot carry a half-typed CV out with it.
  • Testing. An independent penetration test at least annually and after any material architecture change, an annual SOC 2 Type II examination, dependency and container scanning on every build, and a vulnerability disclosure programme.

Reporting a vulnerability

Email security@cortext-ai.uk. We acknowledge within 72 hours, we do not pursue legal action against researchers acting in good faith within the published scope, and we credit reporters who want to be credited.

If there is a breach

Where a personal data breach is likely to result in a risk to your rights and freedoms we notify the lead supervisory authority within 72 hours of becoming aware of it. Where the risk is high we notify affected contributors directly and without undue delay, describing what happened, what data was involved, what we have done and what you should do. We do not delay notification to finish the investigation first.

One honest caveat about this build

The current release keeps sign-in state and the in-progress application in your browser’s local storage rather than in a server session — the keys cortext_auth and cortext_pending_job described in the cookie policy. Anyone with access to your device can therefore read them. Do not use a shared or public computer for Cortext until server-side sessions ship.

12Your rights under the GDPR and UK GDPR

If you are in the EEA, the UK or Switzerland you have the rights below. In practice we extend the same handling to every contributor regardless of where they live, because running two standards produces mistakes.

  • Access. A copy of the personal data we hold about you and the information in this policy, confirmed against your account record.
  • Rectification. Correction of inaccurate data and completion of incomplete data. Note that we correct the record of a credential claim; we do not rewrite the assessment score that resulted from it.
  • Erasure. Deletion where the data is no longer necessary, where you withdraw the consent it rested on and there is no other basis, or where you successfully object. It does not override the statutory retention periods flagged in section 10.
  • Restriction. Processing paused while an accuracy dispute or an objection is being decided.
  • Portability. The data you provided to us, in a structured, commonly used, machine-readable format — JSON and the original files — and transmission direct to another controller where technically feasible.
  • Objection. To any processing based on legitimate interests, including the internal classifiers in section 5. We stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is for legal claims — and if we rely on that, we explain why.
  • Withdraw consent. At any time, without affecting the lawfulness of processing before withdrawal.
  • Automated decisions. Human intervention, an opportunity to be heard, and the right to contest — see section 6.

How to make a request, and what happens next

Email privacy@cortext-ai.uk from the address on your account, saying which right you are exercising. There is no form to fill in and no fee. If you email from a different address, or if there is any sign of an account-takeover attempt, we will ask you to verify — normally by confirming from the account address, and only in a genuinely suspicious case by a verification check. We will not demand a fresh copy of your passport just to answer an access request.

We respond within one month of receiving the request. Where a request is complex, or where you have made several, we may extend by up to two further months, and if we do we will tell you within the first month and say why. If we refuse a request in whole or in part we will tell you which exemption applies, what we are withholding and why, and how to challenge it — including the escalation in section 19. We charge a reasonable fee only for a manifestly unfounded or excessive request, and we have never yet charged one.

13California privacy notice — CCPA and CPRA

This section applies to California residents and uses the definitions in the California Consumer Privacy Act as amended by the California Privacy Rights Act. Independent contractors are covered consumers under the CPRA, so it applies to contributors as well as site visitors.

The two statements people look for first

Cortext Labs, Inc. does not sell personal information and does not share personal information for cross-context behavioural advertising. We have not done so in the twelve months preceding the effective date of this policy, and we have never knowingly sold or shared the personal information of anyone under 16. There is no “Do Not Sell or Share My Personal Information” link on this site because there is nothing for it to switch off. If that ever changes, this policy changes first, with the notice period in section 17.

Categories collected in the last twelve months

  • Identifiers — name, email address, IP address, account identifier.
  • Customer records under Civil Code section 1798.80(e) — CV, employment and education history, payment information.
  • Protected classifications — date of birth, and nationality where it appears on an identity document. Collected for age and sanctions checks, never used for selection.
  • Commercial information — engagements accepted, hours approved, payout history.
  • Internet or network activity — pages requested, feature usage, error and performance telemetry.
  • Geolocation — coarse country and region derived from IP address only.
  • Audio and visual information — the liveness capture, and a screening interview recording where you consented to one.
  • Professional or employment information — licences, registrations, specialisms, seniority, assessment scores and reviewer quality metrics.
  • Inferences — the internal quality and integrity scores described in section 5.
  • Sensitive personal information — government identifier and identity document, account log-in credentials, financial account information in combination with an access code, and biometric information used for liveness matching.

Sources, purposes, recipients and retention for each category are in section 3, section 7 and section 10 and are not restated here.

Limiting the use of sensitive personal information

We use sensitive personal information only for the purposes permitted by Civil Code section 1798.121(a) without an opt-out — verifying identity, preventing fraud, providing the service you requested, ensuring security, and complying with law. We do not use or disclose it to infer characteristics about you. That means there is, strictly, nothing for a limitation request to restrict. You may still send one to privacy@cortext-ai.uk and we will confirm in writing what we do with each element rather than dismissing the request.

Your California rights and how we handle them

  • Know and access — the categories and specific pieces of personal information collected, the sources, the business purpose and the categories of recipients, for the twelve-month period or longer if you ask.
  • Delete — subject to the statutory exceptions in section 1798.105(d), which for us are mainly tax, anti-money-laundering and contract-limitation records.
  • Correct — inaccurate personal information, taking into account its nature and the purpose of processing.
  • Opt out of sale or sharing — available in principle; inapplicable in fact, for the reason above.
  • Limit use of sensitive personal information — as described above.
  • Non-discrimination — we will not deny you work, change your rate, or degrade the service because you exercised a right. We will say plainly where a deletion makes something impossible: delete the payment record and we cannot pay you; delete the account and open engagements end.

Send requests to privacy@cortext-ai.uk. We confirm receipt within 10 business days and respond within 45 calendar days, extendable once by a further 45 days with notice. An authorised agent may act for you with written permission signed by you, and we will still verify your identity directly. Requests are logged and the log is retained for 24 months as the regulations require.

Notice of financial incentive

The referral programme pays a bonus for a referred contributor who reaches the qualifying hours threshold, which requires us to keep the referral code, the referrer’s identity and the link between the two. The value of the incentive is the bonus itself, and it is calculated on what a referred contributor is worth to us over an engagement, not on any valuation of your personal information. Participation is voluntary, you opt in by sharing a referral link, and you can withdraw by emailing referrals@cortext-ai.uk. Terms are on the rates section of the terms.

14Other US state privacy laws

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey and other states with comprehensive privacy statutes have rights to confirm processing and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale and certain profiling. Use privacy@cortext-ai.uk for all of them.

  • We do not conduct targeted advertising, we do not sell personal data, and there is nothing to opt out of on either count.
  • The only profiling in scope is the screening described in section 6. You may opt out of it, and the consequence is that we cannot complete an application that depends on an assessment score.
  • We obtain consent before processing sensitive data where the state statute requires it, which for us means identity documents and biometric liveness data.
  • Appeals. Where a state statute gives a right of appeal against a refused request, you have 60 days from our decision to appeal by replying to it. We respond within 45 days with a written explanation. If the appeal is denied you may complain to your state attorney general, and we will give you the contact route in the same reply.

15Age requirement and children’s data

Cortext is for adults. You must be at least 18 years old to create an account, apply to an opportunity or be paid, and the same threshold applies everywhere we operate regardless of the local age of majority. The requirement is repeated in the eligibility section of the terms.

Date of birth is confirmed during identity verification against a government document, so the check is not a self-declared tick box. We do not knowingly collect personal data from anyone under 18, we operate no under-18 tier, and no part of the marketplace is directed at children.

If we learn that an account holder is under 18, we suspend the account immediately, pay any hours already worked and accepted through the normal payout run, and delete the personal data within 30 days except the suppression record described in section 10. To report an underage account, email trust@cortext-ai.uk. A parent or guardian who believes a child has provided us with personal data should write to privacy@cortext-ai.uk and we will delete it without requiring a formal request.

16Cookies, analytics and browser storage

We set 14 cookies in total and write 4keys to your browser’s local storage. Every one of them is named, categorised and explained in the Cookie Policy, which is version 2.4, effective 20 July 2026. The short version:

  • Strictly necessary cookies — session, anti-forgery, regional routing and bot detection — are set without consent because the service does not function without them.
  • Functional, analytics and performance cookies are set only after you accept them in the consent banner. Choosing “essential only” leaves them unset, and nothing about your application or your pay changes as a result.
  • Analytics is first-party and carries no cross-site identifier. There are no advertising cookies and no third-party tracking pixels.
  • Your consent answer is itself stored locally under cortext_cookie. Clearing site data clears it and the banner returns.

To change your answer, clear site data for cortext-ai.uk in your browser and respond to the banner again. Browser-level controls for Chrome, Safari, Firefox and Edge, and how we treat Do Not Track and Global Privacy Control signals, are set out in the cookie policy.

17Changes to this policy

The version number, publication date, effective date and superseded version are printed at the top of this page. This is version 3.1, published 18 June 2026, effective 20 July 2026, superseding version 3.0, effective 3 february 2026.

For a material change — a new purpose, a new category of recipient, a new legal basis, a longer retention period, or any change to section 5 — we give at least 30days’ notice before it takes effect. Notice goes by email to the address on your account and by a banner in the product; we do not rely on you noticing a changed date. The notice summarises what changed and why, in plain terms, and links to the previous version.

Non-material changes — corrected typos, clearer wording, a replacement subprocessor in a category we already disclose — take effect on publication and are noted in the version history. Prior versions are archived and a copy of any of them is available on request from legal@cortext-ai.uk.

If you object to a material change, you can close your account before the effective date and the change never applies to you. A consent you have already given under section 5 is dated against the policy version in force when you gave it, and a later version does not silently widen it.

18Contacting the privacy team

Every route into the privacy team is by email. There is no telephone number, no callback request and no chat widget; the ticketing system behind these addresses is the same one that handles support, and privacy correspondence is flagged and routed to the data protection officer rather than to a general agent.

  • Privacy requests, questions and the data protection officer privacy@cortext-ai.uk. First reply within 5 business days; substantive response within the deadlines in section 12 and section 13.
  • Legal notices, prior policy versions and transfer documentation legal@cortext-ai.uk.
  • Security vulnerabilities and suspected account compromise security@cortext-ai.uk, acknowledged within 72 hours.
  • Everything elsesupport@cortext-ai.uk.
  • By post — Data Protection Officer, Cortext Labs, Inc., 1 Sansome Street, Suite 3500, San Francisco, CA 94104, United States. Post is slower and the statutory clock still runs from receipt, so email is better.

19Complaining to a supervisory authority

You can complain to a data protection authority about how we handle your personal data. You do not have to come to us first, and nothing in this policy or the terms of service — including the arbitration agreement — takes that right away or requires you to arbitrate a complaint to a regulator.

We would rather you told us first, because most complaints are a missed email or a misunderstanding about a retention period and we can fix those in days. Write to privacy@cortext-ai.ukwith “Complaint” in the subject line: we acknowledge within 5 business days and give a written outcome within 30 days.

Where to complain

  • EEA — the supervisory authority in the member state where you live, where you work, or where the alleged infringement took place. Any of the three is valid and you choose.
  • United Kingdom— the Information Commissioner’s Office.
  • Switzerland — the Federal Data Protection and Information Commissioner.
  • California — the California Privacy Protection Agency, or the California Attorney General.
  • Kenya — the Office of the Data Protection Commissioner.
  • India — the Data Protection Board of India.
  • Elsewhere — your national or state authority. If you cannot identify it, ask us and we will point you to it, including where the complaint is about us.