What is collected, how long it is kept, and who can read it
Every category below exists for a stated operational reason. Where a category is held by a processor rather than by Cortext, the row says so.
Who inside Cortext sees it
Access is scoped by role, not by seniority. Pod leads see your work product and quality record on their own project and nothing else — not your payout, not your tax form, not your identity documents.
The payments team sees payout and tax records and no work product. The trust team can see across both, and every one of those accesses is logged against a ticket reference.
In the twelve months to June 2026, quarterly access reviews flagged four accesses with no linked ticket. All four were staff error, all four are recorded in the trust register, and the register is what the next review is checked against.
What labs receive
Work product, the quality metrics attached to it, and a stable pseudonymous contributor ID. Not your name, email, CV, country or credential documents.
Two exceptions, both opt-in and both stated on the posting before you apply: projects where a lab requires attributed authorship, and projects where a regulator requires the reviewing clinician to be identifiable. Declining either removes you from that project and nothing else.
Labs never receive telemetry, sign-in history or payment data, and no lab has ever been given a contributor roster.
Processors and where data sits
Identity verification, the two payout rails, transactional email, error monitoring and cloud hosting. Each is contracted as a processor, bound to the same retention limits, and listed with its role in the privacy policy.
Primary hosting is in the United States with a read replica in the EU; work product for projects with a data-residency requirement stays in the named region and is not replicated out of it.
Data-subject requests — access, export, correction, deletion, objection — go to privacy@cortext-ai.uk and are answered within 30 days for every contributor, not only where a law requires it.
It is not sold, and there is no advertising product to sell it into. It is not used to train models — your work product trains a lab's model under that lab's contract, but your profile, telemetry and support history are not training data for anything.
Task routing is not driven by security signals. Nobody is offered less work because of where they signed in from, and the routing rules are quality, credential and availability only.
There is no productivity score, no activity leaderboard and no ranking published to other contributors.
What you may not disclose, and what you always may
Lab projects run under the confidentiality terms in the contributor agreement plus a project-specific NDA you accept at onboarding. The boundary is narrower than most people assume in one direction and wider in the other.
Not disclosable
- The identity of the commissioning lab, including hinting at it. Most NDAs make the client name the most protected item in the whole agreement.
- Model names, version strings, system prompts, completions, and any output you were shown.
- Rubric text, gold-set items and grading criteria — publishing these destroys the measurement for everyone still on the project.
- Unreleased capabilities, roadmap detail and anything you infer about a system that is not public.
- Failure modes you found while red-teaming, including after the project ends and including in academic work, unless the lab has published them.
- Other contributors' identities, and anything you learn about them from a shared workspace.
Always disclosable
- That you work with Cortext. You can list it on a CV, a LinkedIn profile or a grant application.
- Your work in general terms — evaluating model output in clinical medicine, annotating agent trajectories, writing reference answers in tax law.
- What you are paid. Cortext does not impose pay confidentiality on contributors, and discussing your rate with anyone, including other contributors, is never a breach.
- Anything you need to tell a lawyer, an accountant, a doctor or a therapist, all of whom are bound by their own duties.
- A report to a regulator, a court or a law-enforcement agency. No NDA on this platform prevents lawful whistleblowing, and no clause will be read as trying to.
- The existence of a dispute with Cortext and its outcome. Settlements here are not gagged.
Red-teaming work, and what Cortext owes you for doing it
Some projects require deliberately provoking a model into harmful output so a lab can stop it happening in production. That work is valuable and it is genuinely unpleasant. These rules are the ones that stop it damaging people, and they are enforced as policy rather than offered as a courtesy.
- 01
Informed consent, per category, before you apply
Every red-teaming posting names the specific harm categories it covers — violent content, self-harm and suicide, hate and harassment, sexual content involving adults, extremism, weapons and CBRN uplift, cyber-offensive capability, fraud and manipulation — with an example of intensity for each, before you apply and before you see any rate.
You consent category by category, not to the project as a whole. Declining a category filters those tasks out of your queue permanently and has no effect on your quality score, your rate, or what else you are offered.
No red-teaming project may be entered through a general project invitation. The consent screen is mandatory and cannot be skipped by an operations decision. - 02
Content warnings on every task
Each task opens behind a warning that names the category and the intensity band, so nothing arrives without notice. The warning is generated from the task metadata rather than written by hand, which means it cannot be omitted when a batch is loaded in a hurry.
Skipping a task after reading the warning costs nothing. Skips on flagged categories are excluded from throughput metrics entirely, so a contributor who skips heavily and a contributor who skips nothing look identical to the routing system.
- 03
Exposure limits, applied by the tool
Ninety minutes of continuous work on flagged categories, four hours in a day and twelve hours in a pay week. The task tool enforces all three: it stops issuing flagged tasks and offers unflagged work from your other contracts instead.
The limits are not raised on request and cannot be waived by a pod lead or a lab deadline. They came out of a review of how quality scores and reported wellbeing move together on this work, and both move in the same direction past those thresholds.
- 04
Wellbeing support that Cortext cannot see
Contributors on red-teaming projects get six confidential counselling sessions a year with an independent provider, in their own language where available, paid for by Cortext and booked directly with the provider.
Cortext receives an invoice with a session count and nothing else — no names, no notes, no dates matched to individuals. Using the benefit is invisible to your pod lead, to the trust team and to routing.
The provider is contractually barred from disclosing participation to Cortext, including in aggregate small enough to identify anyone. - 05
The right to leave, mid-batch, without penalty
You can end a red-teaming contract at any point, in the middle of a task, without giving a reason or notice. Every tracked hour is paid on the normal cycle, no hours are removed for an incomplete batch, and no quality mark is recorded against the exit.
It does not affect your other contracts, your standing, or future matching, and the exit reason field is optional and unread by routing. This is stated in the project brief in the same words.
Cortext does not take engagements requiring the generation, review or annotation of child sexual abuse material, in any form, at any rate. Three commissioned projects have been declined on this basis since 2024 and the position is not commercially negotiable.
If apparent CSAM ever appears in a task: stop, do not download it, do not screenshot it, flag the task and email the trust team immediately. Reports are escalated within one hour to the commissioning lab and, where the law requires it, to the relevant reporting body. You will not be asked to review it again.
Cortext also declines projects targeting real identifiable private individuals, and projects where the harmful output would be deployed rather than studied.
Email trust@cortext-ai.uk and say only as much as you want to. Safety reports are triaged the same day, and the first reply never asks you to describe the content again.
You can ask for three things separately: removal from the category, removal from the project, and a wellbeing referral. Asking for one does not trigger the others.
Nothing about a wellbeing request is visible to the pod lead. What they see is that a contributor is no longer routed that category, which is the same thing they see when someone declines it at consent.
Commitments that are testable, not aspirational
Each of these is a rule an operations decision can break, which is what makes it worth writing down. Where one is broken, the remedy is named.
Impersonation is the largest threat to people who do this work
Remote, well-paid, application-based work paid weekly in USD is close to ideal bait, and the scams built around it are specific enough to recognise once you have seen them written down.
- Ask you to pay anything — no application fee, onboarding fee, training fee, equipment charge, background-check charge or refundable deposit. Money moves from Cortext to you and never the other way.
- Ask for your bank password, card PIN, online-banking one-time code, or remote access to your device.
- Pay in cryptocurrency, ask you to open a crypto wallet, or send a payout to a wallet address.
- Send you a cheque or an advance and ask you to return part of it. That is the overpayment scam, and the cheque always bounces after your transfer has cleared.
- Send an SMS, call you, or ask for a code from a text message. There is no phone channel and no phone verification of any kind.
- Ask you to move to WhatsApp or Telegram for onboarding, or send an employment contract as an attachment that asks you to enable macros.
- Ask for your password, your two-factor code or a recovery code — not in an email, not in a support thread, not ever.
The pre-approved recruiter
A message on LinkedIn, Telegram or WhatsApp saying you are pre-approved for AI-training work at a stated hourly rate, often quoting a real Cortext project title lifted from the board.
The ask arrives two messages later: a deposit for a laptop, a fee for a background check, or a small payment to secure the slot. Cortext recruiters never make first contact on a messaging app and never quote a rate before an application exists.
The lookalike task tool
A near-identical clone of the sign-in page on a domain that reads correctly at a glance — a hyphen inserted, a word appended, a different suffix. It harvests the password and then the two-factor code in real time.
Check the domain character by character before you type anything. Cortext signs in only at https://cortext-ai.uk, and mail comes only from cortext-ai.uk.
The payout upgrade
An email saying your payout method needs re-verification, or offering instant payouts at a better rate, linking to a form that asks for online-banking credentials.
Payout details are only ever changed by you, signed in, with a 48-hour hold afterwards. If you receive a confirmation that your payout destination changed and you did not change it, that is an account compromise — email security immediately.
The task reseller
Someone offers to sell you access to Cortext tasks, or to subcontract their own tasks to you for a share of the rate, usually through a freelance marketplace.
Both sides of that arrangement violate the contributor agreement. The buyer loses money and gets nothing; the seller loses their account, because work must be done by the identified person who was screened for it.
The fake incident email
A message styled as a status notification — an outage, a suspended payout, a compliance hold — with a link to verify your account inside a short deadline. Urgency plus a deadline is the whole mechanism.
Real incidents are posted on the status page, and no genuine incident email asks you to sign in through a link to release a payout. Open the site yourself and check.
The credential harvester
A form asking for a full scan of your passport, licence and a selfie, sent by email rather than collected in the account. Medical and legal credentials are worth more resold than any single payout is.
Cortext collects identity documents once, inside the account, through the verification vendor. Nobody at Cortext will ever email you asking for a copy of your ID.
How to verify a message is really from Cortext
- The sender domain is exactly cortext-ai.uk. Not a subdomain of something else, not a hyphenated variant, not a different suffix. Check the address, not the display name.
- Every link points at https://cortext-ai.uk. Hover before clicking; on a phone, long-press to preview.
- Anything important also exists inside your account. A real payout notice, contract, assessment invitation or policy change is visible when you sign in yourself, without using the link.
- No genuine message creates a deadline measured in hours, and no genuine message threatens account closure if you fail to click.
- Contracts are accepted in the account, never as an attachment. A document that asks you to enable macros is not from Cortext.
- If it still looks plausible and you are unsure, forward it — do not reply to it — and wait for an answer. Nothing legitimate is lost by waiting a day.
What Cortext does about impersonation
Forward suspicious mail with full headers to security@cortext-ai.uk. Disclosures and reports get a first response within 72 hours for disclosures, and phishing reports are actioned faster than that because the takedown clock matters more than the reply.
In the twelve months to June 2026, 17 lookalike domains were taken down at a median of four days from report, and 62 impersonation accounts were removed from messaging and professional networks.
Cortext publishes the sending domain, keeps SPF, DKIM and DMARC enforced at reject, and does not use marketing subdomains for transactional mail — so a message from anywhere else is wrong regardless of how it reads.
If you lost money to something using the Cortext name, report it here anyway. Cortext cannot recover funds, but the report drives the takedown and the warning to everyone else.
The rules that run the other way
Labs buy identified human judgement. Everything below breaks that promise, which is why the consequences are heavier than they would be for a quality problem.
Multi-accounting
One account per person, verified against one identity document and one tax form. Second accounts are usually opened to retake a failed assessment or to claim a referral bonus on a self-referral.
Detection uses the device and payout-destination graph rather than a single signal. A confirmed case closes every linked account, forfeits balances on the duplicates and claws back referral bonuses paid on them.
Generative output on human-judgement tasks
Submitting model-generated text as your own evaluation or reference answer is the one failure that makes the delivery worthless to the lab, so it is treated as fraud rather than as a quality issue.
Signals are stylometric drift against your own earlier writing, paste-burst timing, and divergence between gold-set performance and free-response quality. Projects that require tool use say so in the brief; those are the only place model output belongs in a submission.
Plagiarism
Reference answers copied from published sources without attribution, or lifted from another contributor's submission in a shared workspace. Duplicate-content hashing runs across every submission on a project, not only against the public web.
Quoting a source correctly is fine and often expected; passing it off as original reasoning is not. Where a lab has already been billed for the affected items, those hours are removed.
Identity fraud and subcontracting
Someone else taking your assessment, sharing your login, or doing your tasks for a cut. The screened person and the working person must be the same person, and that is the core commitment behind every project on the platform.
The same applies to misrepresenting location on a project with a data-residency requirement — using a residential proxy or a VM to appear inside a region you are not in is an integrity finding, not a technicality.
How to report a concern
Use the address that matches the problem — the queues have different triage rules and different on-call coverage. Everything is email; there is no phone line and no anonymous phone hotline.
Conduct concerns, content that affected you, pressure to work outside the platform, retaliation, integrity findings you want to contest, and anything you would rather not send to a general queue.
trust@cortext-ai.ukPhishing and impersonation, suspected account compromise, and vulnerability disclosure. Include full headers on a forwarded message where your mail client allows it.
security@cortext-ai.ukAccounts, projects, assessments, the task tool and payments questions that are not a safety matter. Support routes anything that belongs to trust or security without asking you to resend it.
support@cortext-ai.uk- 01
You report it
Write from the address on your account where you can, and include what happened, when in UTC, the project or account involved, and what you want to happen. You never have to re-describe distressing content — a category and a task ID is enough.
You can ask to report without your name attached to the case file. Say so in the first line. Anonymity limits what can be investigated, because some findings need a named account to check, and the reply will say plainly where it hit that limit.
- 02
It is acknowledged and triaged
Acknowledgement within one business day, and the same day for anything flagged as a safety matter — that queue has out-of-hours cover, unlike the general support queue.
Triage sets severity and assigns an owner in the trust team. Reports touching content safety, a payout failure or a suspected compromise skip the queue entirely.
- 03
It is investigated
Ten business days is the target for a standard investigation, and the case owner writes to you at ten if it is going to take longer, with the reason and a revised date. Cases involving a lab take longer because the lab has to be brought in.
You will be asked follow-up questions by email and never by phone. Nobody investigating a report will call you.
Access to your record during an investigation is logged against the case reference and reviewed quarterly, like every other access. - 04
You are told the outcome
You get the finding and what changed as a result. What you will not get is the detail of any action taken against another individual — that is their data, and the same protection applies to you when someone reports you.
If you disagree with the outcome, reply within 14 days and it is reviewed by someone who did not decide it.
Reporting in good faith never affects your task routing, your rate, your quality score or your standing on any project — including when the report is about the pod lead on that project, and including when the finding does not go your way.
Retaliation is itself an integrity violation and is investigated as one, whether it comes from Cortext staff or from another contributor.
If your work volume drops after you report something, ask for a routing audit. The matching system logs why each contributor was or was not offered each batch, so the question has a factual answer rather than an assurance, and you will be shown it.
Send vulnerability reports to security@cortext-ai.uk. First response within 72 hours for disclosures, a triage decision within five business days, and an agreed disclosure timeline after that — 90 days by default, shorter where a fix ships sooner.
Good-faith research within scope will not be met with legal action. Out of scope, and not covered by that: testing against real contributor accounts or data, social engineering of staff or contributors, denial-of-service testing, and anything that degrades the payout run.
There is no paid bounty programme. Reporters are credited in the disclosure register with their permission, and Cortext will confirm a fix in writing for a public write-up.
Cortext is an email-only organisation and cannot respond to an emergency in real time. If someone is in immediate danger, contact your local emergency services first — that is always the right order, and nothing in the contributor agreement or any NDA prevents it.
Once anyone at immediate risk is safe, tell trust@cortext-ai.uk so the project can be paused and the lab notified. Safety reports are the one category with out-of-hours cover, and pausing a project mid-batch has never required an approval chain.
Related documents
This page states what Cortext does. The legal documents state what it is bound to, and they win where the two ever differ.
Privacy policy
The full processing record: categories, legal bases, processors, transfers, retention and your rights.
Read it →Terms of service
The contributor agreement, including confidentiality, intellectual property, contractor status and termination.
Read it →Help centre
The operational detail behind most of this page — assessments, quality reviews, payouts, taxes and account security.
Read it →