Trust & safety

What we hold, what we owe you, and what we will not do.

This page is the contributor-facing half of the trust documentation: the data Cortext keeps and who can read it, the confidentiality you are bound by, the consent and wellbeing rules on red-teaming projects, the treatment you are entitled to on rates and rejected work, the scams built specifically for people who do this job, and the conduct that ends an account.

Applies to every contributor on the platform · last reviewed 1 July 2026 · concerns to trust@cortext-ai.uk, acknowledged same day for safety reports
Your data

What is collected, how long it is kept, and who can read it

Every category below exists for a stated operational reason. Where a category is held by a processor rather than by Cortext, the row says so.

Identity
Legal name, date of birth, country of residence and the result of the document check — pass or fail, document type, issuing country, expiry. The image of your ID is held by the verification vendor and deleted on their 30-day schedule. Cortext never stores a scan. Kept for the life of the account plus 12 months.
Credentials
Licence and registration numbers, degree certificates, registry links, publication and repository links, plus the verifier's note recording what was checked and against which authority. Kept for the life of the account; deleted with it.
Application material
CV, written responses, assessment answers and scores, interview notes and the interview recording. Recordings are retained 12 months for dispute purposes. Rejected applications are deleted after 24 months whether or not you ask.
Work product
Everything you submit on a project — evaluations, reference answers, rubric edits, red-team transcripts, trajectory annotations — plus the review decisions attached to it. Delivered work belongs to the commissioning lab under the contributor agreement and cannot be recalled from them after delivery.
Task telemetry
Timer start and stop events, idle detection after 6 minutes, task open and submit timestamps, and paste events on assessment items. No screenshots, no keystroke logging, no webcam access, and nothing to install. Kept 18 months.
Payment data
Payout destination, tax form, statements and transfer records. Bank details and card numbers are held by Stripe or Wise; Cortext stores the last four digits and the rail reference. Retained 7 years because tax law requires it, including after an account closes.
Security signals
IP address, coarse location, device and browser fingerprint, and sign-in history. Used for fraud detection and account-takeover defence, not for productivity monitoring or for deciding what work you are offered. Kept 24 months.
Correspondence
Support threads, dispute filings and trust reports. Kept 36 months, or for the life of an open matter if that is longer.
01

Who inside Cortext sees it

Access is scoped by role, not by seniority. Pod leads see your work product and quality record on their own project and nothing else — not your payout, not your tax form, not your identity documents.

The payments team sees payout and tax records and no work product. The trust team can see across both, and every one of those accesses is logged against a ticket reference.

In the twelve months to June 2026, quarterly access reviews flagged four accesses with no linked ticket. All four were staff error, all four are recorded in the trust register, and the register is what the next review is checked against.

02

What labs receive

Work product, the quality metrics attached to it, and a stable pseudonymous contributor ID. Not your name, email, CV, country or credential documents.

Two exceptions, both opt-in and both stated on the posting before you apply: projects where a lab requires attributed authorship, and projects where a regulator requires the reviewing clinician to be identifiable. Declining either removes you from that project and nothing else.

Labs never receive telemetry, sign-in history or payment data, and no lab has ever been given a contributor roster.

03

Processors and where data sits

Identity verification, the two payout rails, transactional email, error monitoring and cloud hosting. Each is contracted as a processor, bound to the same retention limits, and listed with its role in the privacy policy.

Primary hosting is in the United States with a read replica in the EU; work product for projects with a data-residency requirement stays in the named region and is not replicated out of it.

Data-subject requests — access, export, correction, deletion, objection — go to privacy@cortext-ai.uk and are answered within 30 days for every contributor, not only where a law requires it.

What Cortext does not do with contributor data

It is not sold, and there is no advertising product to sell it into. It is not used to train models — your work product trains a lab's model under that lab's contract, but your profile, telemetry and support history are not training data for anything.

Task routing is not driven by security signals. Nobody is offered less work because of where they signed in from, and the routing rules are quality, credential and availability only.

There is no productivity score, no activity leaderboard and no ranking published to other contributors.

Confidentiality

What you may not disclose, and what you always may

Lab projects run under the confidentiality terms in the contributor agreement plus a project-specific NDA you accept at onboarding. The boundary is narrower than most people assume in one direction and wider in the other.

Not disclosable

  • The identity of the commissioning lab, including hinting at it. Most NDAs make the client name the most protected item in the whole agreement.
  • Model names, version strings, system prompts, completions, and any output you were shown.
  • Rubric text, gold-set items and grading criteria — publishing these destroys the measurement for everyone still on the project.
  • Unreleased capabilities, roadmap detail and anything you infer about a system that is not public.
  • Failure modes you found while red-teaming, including after the project ends and including in academic work, unless the lab has published them.
  • Other contributors' identities, and anything you learn about them from a shared workspace.

Always disclosable

  • That you work with Cortext. You can list it on a CV, a LinkedIn profile or a grant application.
  • Your work in general terms — evaluating model output in clinical medicine, annotating agent trajectories, writing reference answers in tax law.
  • What you are paid. Cortext does not impose pay confidentiality on contributors, and discussing your rate with anyone, including other contributors, is never a breach.
  • Anything you need to tell a lawyer, an accountant, a doctor or a therapist, all of whom are bound by their own duties.
  • A report to a regulator, a court or a law-enforcement agency. No NDA on this platform prevents lawful whistleblowing, and no clause will be read as trying to.
  • The existence of a dispute with Cortext and its outcome. Settlements here are not gagged.
How long it lasts
Confidentiality survives the end of a project and the end of your account. General project information is protected for three years after your last task on it; trade secrets, unreleased capabilities and discovered failure modes are protected indefinitely, which is standard for this kind of engagement and is stated in the NDA before you accept it.
Tooling rules
Do not paste project content into any tool that is not the Cortext task tool. That includes translation sites, grammar checkers, note apps that sync to a third party, and any generative assistant. This is the single most common accidental breach and it is almost always well-intentioned.
Screenshots
No screenshots of task content, including in a support ticket. Support is trained to ask for a task ID instead, and a screenshot sent to support is deleted from the thread when it is spotted.
If you breach it
Accidental disclosure reported promptly is handled as an incident, not a punishment — tell trust@cortext-ai.uk the same day and the priority becomes containment. Deliberate disclosure ends the account and exposes you to a claim by the lab directly, which Cortext cannot settle on your behalf.
What Cortext will not ask of you
No non-compete, no exclusivity, no restriction on working for other AI-training platforms, and no clause assigning anything you build outside a Cortext project. If a project brief appears to say otherwise, that is an error — report it before you accept.
Content safety

Red-teaming work, and what Cortext owes you for doing it

Some projects require deliberately provoking a model into harmful output so a lab can stop it happening in production. That work is valuable and it is genuinely unpleasant. These rules are the ones that stop it damaging people, and they are enforced as policy rather than offered as a courtesy.

  1. 01

    Informed consent, per category, before you apply

    Every red-teaming posting names the specific harm categories it covers — violent content, self-harm and suicide, hate and harassment, sexual content involving adults, extremism, weapons and CBRN uplift, cyber-offensive capability, fraud and manipulation — with an example of intensity for each, before you apply and before you see any rate.

    You consent category by category, not to the project as a whole. Declining a category filters those tasks out of your queue permanently and has no effect on your quality score, your rate, or what else you are offered.

    No red-teaming project may be entered through a general project invitation. The consent screen is mandatory and cannot be skipped by an operations decision.
  2. 02

    Content warnings on every task

    Each task opens behind a warning that names the category and the intensity band, so nothing arrives without notice. The warning is generated from the task metadata rather than written by hand, which means it cannot be omitted when a batch is loaded in a hurry.

    Skipping a task after reading the warning costs nothing. Skips on flagged categories are excluded from throughput metrics entirely, so a contributor who skips heavily and a contributor who skips nothing look identical to the routing system.

  3. 03

    Exposure limits, applied by the tool

    Ninety minutes of continuous work on flagged categories, four hours in a day and twelve hours in a pay week. The task tool enforces all three: it stops issuing flagged tasks and offers unflagged work from your other contracts instead.

    The limits are not raised on request and cannot be waived by a pod lead or a lab deadline. They came out of a review of how quality scores and reported wellbeing move together on this work, and both move in the same direction past those thresholds.

  4. 04

    Wellbeing support that Cortext cannot see

    Contributors on red-teaming projects get six confidential counselling sessions a year with an independent provider, in their own language where available, paid for by Cortext and booked directly with the provider.

    Cortext receives an invoice with a session count and nothing else — no names, no notes, no dates matched to individuals. Using the benefit is invisible to your pod lead, to the trust team and to routing.

    The provider is contractually barred from disclosing participation to Cortext, including in aggregate small enough to identify anyone.
  5. 05

    The right to leave, mid-batch, without penalty

    You can end a red-teaming contract at any point, in the middle of a task, without giving a reason or notice. Every tracked hour is paid on the normal cycle, no hours are removed for an incomplete batch, and no quality mark is recorded against the exit.

    It does not affect your other contracts, your standing, or future matching, and the exit reason field is optional and unread by routing. This is stated in the project brief in the same words.

Hard limits on what Cortext will accept from a lab

Cortext does not take engagements requiring the generation, review or annotation of child sexual abuse material, in any form, at any rate. Three commissioned projects have been declined on this basis since 2024 and the position is not commercially negotiable.

If apparent CSAM ever appears in a task: stop, do not download it, do not screenshot it, flag the task and email the trust team immediately. Reports are escalated within one hour to the commissioning lab and, where the law requires it, to the relevant reporting body. You will not be asked to review it again.

Cortext also declines projects targeting real identifiable private individuals, and projects where the harmful output would be deployed rather than studied.

If a task has already affected you

Email trust@cortext-ai.uk and say only as much as you want to. Safety reports are triaged the same day, and the first reply never asks you to describe the content again.

You can ask for three things separately: removal from the category, removal from the project, and a wellbeing referral. Asking for one does not trigger the others.

Nothing about a wellbeing request is visible to the pod lead. What they see is that a contributor is no longer routed that category, which is the same thing they see when someone declines it at consent.

Fair treatment

Commitments that are testable, not aspirational

Each of these is a rule an operations decision can break, which is what makes it worth writing down. Where one is broken, the remedy is named.

Rates are posted before you apply
Every posting shows the rate, the unit and the expected volume before the first application step. No project reveals its rate after an assessment, and no rate is negotiated downward after a contributor is admitted.
Rates are not localised
A project pays one rate for one level of work, wherever the contributor lives. Cortext does not price by country of residence, which is why the network average of $68 an hour is quoted without a regional footnote.
Rate changes are prospective only
A rate change takes effect at least 14 days after it is announced and never applies to work already done. A project that needs a lower rate re-posts as a new project; it does not quietly reprice the queue you are already in.
Unpaid work has a ceiling
30 minutes. Screeners shorter than that are unpaid; anything longer is paid at the posted rate whether you pass or fail, and the Friday run releases it on the normal cycle.
Trials are paid either way
A work trial is real work at the posted rate, paid in full whatever the outcome. Cortext does not accept unpaid sample work from contributors, and a project that asks for it is misconfigured.
Rejected work comes with written reasons
Every rejected item names the failed rubric dimension and carries the reviewer's note. A rejection with no reason attached is treated as an internal error and the hours are reinstated by default when it is reported.
Appeals go to someone new
14 days to dispute removed hours, decided in 10 business days by a reviewer who had no part in the original decision. About one dispute in five succeeds. If you disagree with the adjudication, it escalates to the quality office and then to the Chief Quality Officer, who is the only executive able to halt a project on quality grounds.
Rework is paid
Time spent fixing an item sent back for a better justification is tracked and paid like any other time. Only work rejected as unusable produces removed hours, and removals never exceed the hours attached to the failed items.
Nothing is deducted beyond what is itemised
Removed hours, the 1% instant-payout fee, a clawed-back referral bonus and US backup withholding where a TIN fails validation. There is no platform commission taken from your rate and no penalty deduction of any kind.
Ramp-downs come with notice
Five business days before a project stops issuing tasks, with the last day stated. Where a lab pulls faster than that, tracked hours are still paid in full on the Friday run.
No exclusivity, no non-compete
You may work for competing platforms, for the labs directly, and for anyone else. Cortext asks for none of those restrictions and will not add them.
Fraud & scams

Impersonation is the largest threat to people who do this work

Remote, well-paid, application-based work paid weekly in USD is close to ideal bait, and the scams built around it are specific enough to recognise once you have seen them written down.

Cortext will never
  • Ask you to pay anything — no application fee, onboarding fee, training fee, equipment charge, background-check charge or refundable deposit. Money moves from Cortext to you and never the other way.
  • Ask for your bank password, card PIN, online-banking one-time code, or remote access to your device.
  • Pay in cryptocurrency, ask you to open a crypto wallet, or send a payout to a wallet address.
  • Send you a cheque or an advance and ask you to return part of it. That is the overpayment scam, and the cheque always bounces after your transfer has cleared.
  • Send an SMS, call you, or ask for a code from a text message. There is no phone channel and no phone verification of any kind.
  • Ask you to move to WhatsApp or Telegram for onboarding, or send an employment contract as an attachment that asks you to enable macros.
  • Ask for your password, your two-factor code or a recovery code — not in an email, not in a support thread, not ever.
PATTERN

The pre-approved recruiter

A message on LinkedIn, Telegram or WhatsApp saying you are pre-approved for AI-training work at a stated hourly rate, often quoting a real Cortext project title lifted from the board.

The ask arrives two messages later: a deposit for a laptop, a fee for a background check, or a small payment to secure the slot. Cortext recruiters never make first contact on a messaging app and never quote a rate before an application exists.

PATTERN

The lookalike task tool

A near-identical clone of the sign-in page on a domain that reads correctly at a glance — a hyphen inserted, a word appended, a different suffix. It harvests the password and then the two-factor code in real time.

Check the domain character by character before you type anything. Cortext signs in only at https://cortext-ai.uk, and mail comes only from cortext-ai.uk.

PATTERN

The payout upgrade

An email saying your payout method needs re-verification, or offering instant payouts at a better rate, linking to a form that asks for online-banking credentials.

Payout details are only ever changed by you, signed in, with a 48-hour hold afterwards. If you receive a confirmation that your payout destination changed and you did not change it, that is an account compromise — email security immediately.

PATTERN

The task reseller

Someone offers to sell you access to Cortext tasks, or to subcontract their own tasks to you for a share of the rate, usually through a freelance marketplace.

Both sides of that arrangement violate the contributor agreement. The buyer loses money and gets nothing; the seller loses their account, because work must be done by the identified person who was screened for it.

PATTERN

The fake incident email

A message styled as a status notification — an outage, a suspended payout, a compliance hold — with a link to verify your account inside a short deadline. Urgency plus a deadline is the whole mechanism.

Real incidents are posted on the status page, and no genuine incident email asks you to sign in through a link to release a payout. Open the site yourself and check.

PATTERN

The credential harvester

A form asking for a full scan of your passport, licence and a selfie, sent by email rather than collected in the account. Medical and legal credentials are worth more resold than any single payout is.

Cortext collects identity documents once, inside the account, through the verification vendor. Nobody at Cortext will ever email you asking for a copy of your ID.

How to verify a message is really from Cortext

  • The sender domain is exactly cortext-ai.uk. Not a subdomain of something else, not a hyphenated variant, not a different suffix. Check the address, not the display name.
  • Every link points at https://cortext-ai.uk. Hover before clicking; on a phone, long-press to preview.
  • Anything important also exists inside your account. A real payout notice, contract, assessment invitation or policy change is visible when you sign in yourself, without using the link.
  • No genuine message creates a deadline measured in hours, and no genuine message threatens account closure if you fail to click.
  • Contracts are accepted in the account, never as an attachment. A document that asks you to enable macros is not from Cortext.
  • If it still looks plausible and you are unsure, forward it — do not reply to it — and wait for an answer. Nothing legitimate is lost by waiting a day.

What Cortext does about impersonation

Forward suspicious mail with full headers to security@cortext-ai.uk. Disclosures and reports get a first response within 72 hours for disclosures, and phishing reports are actioned faster than that because the takedown clock matters more than the reply.

In the twelve months to June 2026, 17 lookalike domains were taken down at a median of four days from report, and 62 impersonation accounts were removed from messaging and professional networks.

Cortext publishes the sending domain, keeps SPF, DKIM and DMARC enforced at reject, and does not use marketing subdomains for transactional mail — so a message from anywhere else is wrong regardless of how it reads.

If you lost money to something using the Cortext name, report it here anyway. Cortext cannot recover funds, but the report drives the takedown and the warning to everyone else.

Platform integrity

The rules that run the other way

Labs buy identified human judgement. Everything below breaks that promise, which is why the consequences are heavier than they would be for a quality problem.

01

Multi-accounting

One account per person, verified against one identity document and one tax form. Second accounts are usually opened to retake a failed assessment or to claim a referral bonus on a self-referral.

Detection uses the device and payout-destination graph rather than a single signal. A confirmed case closes every linked account, forfeits balances on the duplicates and claws back referral bonuses paid on them.

02

Generative output on human-judgement tasks

Submitting model-generated text as your own evaluation or reference answer is the one failure that makes the delivery worthless to the lab, so it is treated as fraud rather than as a quality issue.

Signals are stylometric drift against your own earlier writing, paste-burst timing, and divergence between gold-set performance and free-response quality. Projects that require tool use say so in the brief; those are the only place model output belongs in a submission.

03

Plagiarism

Reference answers copied from published sources without attribution, or lifted from another contributor's submission in a shared workspace. Duplicate-content hashing runs across every submission on a project, not only against the public web.

Quoting a source correctly is fine and often expected; passing it off as original reasoning is not. Where a lab has already been billed for the affected items, those hours are removed.

04

Identity fraud and subcontracting

Someone else taking your assessment, sharing your login, or doing your tasks for a cut. The screened person and the working person must be the same person, and that is the core commitment behind every project on the platform.

The same applies to misrepresenting location on a project with a data-residency requirement — using a residential proxy or a VM to appear inside a region you are not in is an integrity finding, not a technicality.

How a case is decided
Automated signals never close an account on their own. Every case is reviewed by a person in the trust team against the evidence, and the contributor is told which finding is alleged and what the evidence shows in summary. In 2025, 9% of automated flags were dismissed at human review.
Consequences, in order
A warning with the evidence for a first, low-severity finding. Removal from a project for a repeated or moderate one. Account closure for fraud, identity misuse or a deliberate confidentiality breach. Forfeiture applies only to balances earned through the conduct itself, never to unrelated work already delivered.
Appeals
14 days from the notice, decided by a trust reviewer who had no part in the original case, with a written outcome. An appeal pauses closure unless the finding involves an active security or safety risk.
What is referred onward
Payment fraud and credential forgery are reported to the relevant authority and, where a licence was forged, to the issuing body. Cortext does not report ordinary integrity findings to employers, regulators or other platforms.
Reporting

How to report a concern

Use the address that matches the problem — the queues have different triage rules and different on-call coverage. Everything is email; there is no phone line and no anonymous phone hotline.

Trust & safety

Conduct concerns, content that affected you, pressure to work outside the platform, retaliation, integrity findings you want to contest, and anything you would rather not send to a general queue.

trust@cortext-ai.uk
Typical first reply: same day for safety reports
Security

Phishing and impersonation, suspected account compromise, and vulnerability disclosure. Include full headers on a forwarded message where your mail client allows it.

security@cortext-ai.uk
Typical first reply: 72 hours for disclosures
Everything else

Accounts, projects, assessments, the task tool and payments questions that are not a safety matter. Support routes anything that belongs to trust or security without asking you to resend it.

support@cortext-ai.uk
Typical first reply: under 24 hours
  1. 01

    You report it

    Write from the address on your account where you can, and include what happened, when in UTC, the project or account involved, and what you want to happen. You never have to re-describe distressing content — a category and a task ID is enough.

    You can ask to report without your name attached to the case file. Say so in the first line. Anonymity limits what can be investigated, because some findings need a named account to check, and the reply will say plainly where it hit that limit.

  2. 02

    It is acknowledged and triaged

    Acknowledgement within one business day, and the same day for anything flagged as a safety matter — that queue has out-of-hours cover, unlike the general support queue.

    Triage sets severity and assigns an owner in the trust team. Reports touching content safety, a payout failure or a suspected compromise skip the queue entirely.

  3. 03

    It is investigated

    Ten business days is the target for a standard investigation, and the case owner writes to you at ten if it is going to take longer, with the reason and a revised date. Cases involving a lab take longer because the lab has to be brought in.

    You will be asked follow-up questions by email and never by phone. Nobody investigating a report will call you.

    Access to your record during an investigation is logged against the case reference and reviewed quarterly, like every other access.
  4. 04

    You are told the outcome

    You get the finding and what changed as a result. What you will not get is the detail of any action taken against another individual — that is their data, and the same protection applies to you when someone reports you.

    If you disagree with the outcome, reply within 14 days and it is reviewed by someone who did not decide it.

Non-retaliation, in enforceable terms

Reporting in good faith never affects your task routing, your rate, your quality score or your standing on any project — including when the report is about the pod lead on that project, and including when the finding does not go your way.

Retaliation is itself an integrity violation and is investigated as one, whether it comes from Cortext staff or from another contributor.

If your work volume drops after you report something, ask for a routing audit. The matching system logs why each contributor was or was not offered each batch, so the question has a factual answer rather than an assurance, and you will be shown it.

Security disclosure

Send vulnerability reports to security@cortext-ai.uk. First response within 72 hours for disclosures, a triage decision within five business days, and an agreed disclosure timeline after that — 90 days by default, shorter where a fix ships sooner.

Good-faith research within scope will not be met with legal action. Out of scope, and not covered by that: testing against real contributor accounts or data, social engineering of staff or contributors, denial-of-service testing, and anything that degrades the payout run.

There is no paid bounty programme. Reporters are credited in the disclosure register with their permission, and Cortext will confirm a fix in writing for a public write-up.

Emergencies

Cortext is an email-only organisation and cannot respond to an emergency in real time. If someone is in immediate danger, contact your local emergency services first — that is always the right order, and nothing in the contributor agreement or any NDA prevents it.

Once anyone at immediate risk is safe, tell trust@cortext-ai.uk so the project can be paused and the lab notified. Safety reports are the one category with out-of-hours cover, and pausing a project mid-batch has never required an approval chain.

Related documents

This page states what Cortext does. The legal documents state what it is bound to, and they win where the two ever differ.

Privacy policy

The full processing record: categories, legal bases, processors, transfers, retention and your rights.

Read it →

Terms of service

The contributor agreement, including confidentiality, intellectual property, contractor status and termination.

Read it →

Help centre

The operational detail behind most of this page — assessments, quality reviews, payouts, taxes and account security.

Read it →

Something here is not being honoured?

Say so. Trust reports are acknowledged same day for safety reports, investigated by someone with no stake in the project, and answered with a finding rather than a reassurance.

Email trust & safetyRead the help centre