At a glance#
- Who it’s for
- Annotators the project has authorized by name. Adults only; not a product for the public and not for children.
- What triggers collection
- A deliberate action by a signed-in annotator — labelling a post, adding it to the queue, or flagging it. Nothing else.
- What we receive
- The specific post you act on, the labels you apply, your account identifier, and your one-time setup answers.
- What we never receive
- Your bookmarks, your direct messages, your passwords or cookies, your activity on a website you did not ask the extension onto, or a conversation you did not flag.
- Where it goes
- Only to the project’s own service at
api.address-hate-dashboard.org, on Google Cloud infrastructure in the United States. - Who reads it
- Reviewers on your own team, and project administrators running the service. Organizations are kept separate from one another — see Who can read your work.
- Where we name you
- We may say publicly that your organization uses the extension and that you are one of its annotators — nothing about your individual work. See Where we name you.
- Getting it removed
- Delete your account from inside the extension, or email us — see Data deletion.
Who can use it#
The extension only works for annotators the project has authorized by name — project staff and vetted research partners. It is not a consumer product: we don't market it to the public, and without an authorized account it does nothing. It is not meant for children, and annotators must be adults.
What we collect#
Post content is sent to us only when a signed-in annotator takes a deliberate action — labelling a post, adding it to the queue, or flagging it. The extension runs on the sites listed below. On any other site it runs only when you explicitly ask it to — pressing “Annotate this page” in the toolbar popup, or the keyboard shortcut — to annotate an article or other web page you are reading, and only on that page.
To label a post accurately, the extension reads what those sites' own apps already load as you browse them — the posts and comments in the feed, thread, search results, or conversation you are viewing. That material is held briefly in memory on your device, is discarded when you reload or leave the page, and is never written to disk or sent to us unless you choose to annotate or flag a specific post. It does not read your bookmarks, your direct messages, your account settings, your passwords or cookies, or anything on a website you did not ask it onto, and it never modifies the requests those sites make.
Articles and other web pages. When you ask the extension onto a page that is not one of the sites above, you can label a passage you highlight, the article itself, or one of the reader comments under it, the way you would label a post. What is sent to us depends on which you chose: a highlight sends that passage alone; labelling the article sends the article’s own text (up to 12,000 characters) and, as context, the first few reader comments on the page; labelling a comment sends that comment’s text, the name shown beside it (and the profile link, when the name is one), when it was posted and the like count the page shows, with the comments it replies to and the article’s headline to say what it was under. Every one of them also carries the page's address, title, publisher, byline and date. Comments that a site loads from somewhere else (Facebook’s plugin and the like) are never read — the record only notes that they were there and which service they load from (its address without any query string). The one exception is Disqus, and only if you allow it: on a page whose comments are a Disqus thread, Chrome asks you once whether the extension may use disqus.com, and if you say yes it reads that thread the same way, when you ask it onto the page. Images on such a page are counted, never copied, and the extension leaves the page when you do.
- Content you choose to annotate — the text, author handle, and permalink of the specific post or comment you label, plus any adjacent thread comments you explicitly select as context.
- Your annotations — your answers to the questions your organization’s own question set asks. Depending on how that set is written, an answer can be a category chosen from a list, a yes or no, a rating, free text you type, or a mark on a passage you highlighted in the post. A highlight is stored as the position of that passage within the post text we already hold, not as a second copy of it. Because the questions are written by your organization rather than by us, the exact fields vary between studies — the editor shows you every question it is going to record, and you see your own answers before you submit.
- Which work it belongs to — the team you were annotating for and the project you filed the work under, so a study’s material can be gathered and reviewed together. These are labels on your submission; they are not additional content taken from the page.
- Media of annotated posts — images or video attached to a post you annotate are archived alongside it, so the annotation can be reviewed against what was actually posted. An image or video an AI assistant generated in your conversation is different: its address works only in your browser, so when you annotate one, the extension reads that file from the page and uploads it with your annotation. Nothing else on the page is read this way, and nothing is uploaded unless you annotate that image.
- Authentication data — your account identifier and a session token. If you use Google or Microsoft sign-in, the email address and name that provider gives us, used solely to authenticate you. Sign-in timestamps are kept on your account as a security audit trail. If a team lead invited you rather than an administrator creating your account directly, your email address, the date of the invitation and who sent it are held from the moment the invitation is issued — that is, before your first sign-in — so that the seat can be shown as waiting to be claimed. Declining simply leaves it unclaimed, and an administrator can remove it.
- Setup questionnaire — the one-time questions every annotator answers when they first sign in (education level, field of study, organization), used to describe the annotator pool in research. Deleted when your account is deleted.
- Annotation-status lookups — to show the “already annotated” badge, the extension sends the platform IDs of posts currently on screen (on the supported sites, while signed in) to the project's service and gets back which of them are annotated. IDs only — no post content — used solely to render the badge, and not kept as a browsing history.
- Optional coverage counts (off by default) — post-view tracking is disabled unless you opt in under Settings. If you enable it, the extension counts posts you scroll past on the supported sites and sends the count (numbers only — no content, no post IDs, no URLs) for annotation-coverage statistics. You can turn it off again at any time.
Flagging a conversation with an AI assistant#
Flagging works differently on AI assistants (ChatGPT, Claude, Grok, Gemini, DeepSeek, and Qwen) than on public platforms. A public post can be flagged by link, because a reviewer can open it. A conversation with an AI assistant is private to your account — nobody else can open it, and you can delete it at any time — so a flag there has to carry the material itself, or there would be nothing for a reviewer to look at.
When, and only when, you flag content in such a conversation, we receive:
- the assistant response you flagged, and the passage you selected within it;
- the prompt that produced it, because a response usually cannot be judged without knowing what was asked;
- up to six immediately preceding turns, for context;
- the assistant involved, timestamps, and any citations matching our reviewed-source list.
We do not collect a conversation you did not flag, we do not collect the rest of a conversation beyond those turns, and we do not monitor your use of AI assistants in the background. Deleting your account deletes the conversation evidence you contributed.
Images and video the assistant generated can be annotated on their own. When you annotate one, the extension reads that file from the page — nobody else can open it — and uploads it with your annotation, together with the prompts you wrote before it — not the assistant’s text around it. It is stored once per file inside your organization’s own archive. An image you do not annotate is never read.
Permissions and the sites it runs on#
Chrome shows you what an extension can reach before you install it. Here is the whole list, and what each item is for.
Permissions#
| Permission | Why we ask for it |
|---|---|
storage | Keep your submission outbox, your settings, and your recent work on your own device, so queued annotations survive a closed tab or a dropped connection. |
alarms | Wake the extension on a schedule to retry delivering queued annotations after a network or service interruption, so nothing you submitted is lost. |
identity | Offer the optional “Sign in with Google” and “Sign in with Microsoft” flows. Signing in with a username and password uses no permission at all. |
downloads | Save the file when you export your own annotations to a spreadsheet — only for that export, and only when you ask for it. |
activeTab | Let you annotate an article or any other web page you choose. Nothing runs on such a page until you press “Annotate this page” in the toolbar popup or the keyboard shortcut, and the access covers only that one tab, only until you leave it. The extension holds no standing permission for any other site. |
scripting | Load the extension’s own annotation script into the one page you just asked to annotate (see activeTab) — the same script it runs on the supported platforms, loaded on demand. It never loads into a page you did not ask it onto. |
https://disqus.com/* (optional — asked only when needed) | Let you annotate reader comments on a page whose comment section is a Disqus thread. Disqus shows its comments in a frame from disqus.com, which annotating the page alone cannot reach, so the first time you annotate such a page Chrome asks you whether to allow it. If you do, the extension reads that thread only when you ask it onto the page, the same way it reads the page; if you don't, nothing changes. |
Sites it runs on#
The extension asks for one host permission, and it is our own service (api.address-hate-dashboard.org) — that is where your submissions go and where the shared work queue and your history come from. It is the only server the extension ever contacts.
The platform sites below are the extension's content-script match list: the pages on which it can place the Annotate button and read the post you choose to label. Chrome names them at install for that reason. The extension runs on no other website, and sends nothing from these pages to anyone but us.
Social platforms#
| Platform | Sites |
|---|---|
| X | x.com, twitter.com |
| YouTube | youtube.com |
| Rumble | rumble.com |
| TikTok | tiktok.com |
| reddit.com, old.reddit.com | |
| instagram.com | |
| facebook.com | |
| 4chan | boards.4chan.org, boards.4channel.org, archive.4plebs.org |
| 8kun | 8kun.top |
| Bluesky | bsky.app |
| linkedin.com | |
| Mastodon and Truth Social | mastodon.social, truthsocial.com |
AI chat assistants#
| Platform | Sites |
|---|---|
| ChatGPT | chatgpt.com |
| Claude | claude.ai |
| Grok | grok.com |
| Gemini | gemini.google.com |
| DeepSeek | chat.deepseek.com |
| Qwen | chat.qwen.ai |
On X and YouTube the extension reads the site's own API responses in the page, because that is the only way to capture the exact post an annotator labelled rather than a re-render of it. On every other supported site it reads the rendered page only. In neither case does it modify requests, read credentials or cookies, or send anything anywhere until you act.
How it's used and shared#
The extension sends collected data only to the AddressHate project's own annotation service — the service that also serves this page — and we use it for hate-speech research and nothing else.
Service providers#
Two others handle data on our behalf, for this same research purpose and nothing else:
- Infrastructure — data is hosted on Google Cloud (Cloud Run, Cloud SQL, Cloud Storage) under the project's own accounts.
- AI processing — when the project's AI second-opinion or “explain” feature is used, the text of the annotated post (plus limited thread context, such as earlier comments or a video title) is sent to a third-party AI provider, which returns a suggested label or a plain-language explanation. We send post content only: never your name, email, account details, or usage data. That content is then handled under the AI provider's own terms, and those terms govern whether they retain it.
Who can read your work#
Your work is not published, and it is not visible to other annotators at large. It is read by:
- You — everything you have submitted, in your own history, wherever you are working from.
- Reviewers on your own team — a team lead signs work off, or asks for changes with a note. Where two people have judged the same item differently, both answers are shown side by side so the disagreement can be settled; your name is attached to your own answer there.
- Project administrators, for running the service and meeting our obligations.
Organizations are separated from each other. An organization’s annotations, queue, flags and archived media are readable inside that organization and not by another one, and several organizations keep their material in a database of their own. Overseeing many teams is a power within one organization; it does not reach across organizations. Only a project administrator does, and that access exists to operate the service.
Content you flag from a private conversation with an AI assistant is shown to reviewers without your identity attached.
Where we name you#
One use of your name happens outside the extension, so it is set out here as well as in the Terms. The project may state publicly — on our website, in presentations, in funding and grant reporting, in academic publications and in press materials — that your organization uses this extension, and that you are one of its authorized annotators, naming you in participant lists, acknowledgements and methodology sections.
You agree to this when you accept the Terms of Use at first sign-in, and we record which version you accepted. You can withdraw it: write to ksaiki@addresshate.org and we will stop naming you in anything published from then on. What is already printed, published or filed with a funder cannot be recalled — see Being named as a user in the Terms for the full clause.
Google user data (Limited Use)#
If you sign in with Google, the extension's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Your Google email and name are used only to authenticate you to the project's service. They are never sold, never transferred except as needed to provide or improve this tool, never used for advertising, and no human reads them except where you have asked us to, where it is needed for security, or where the law requires it.
If you sign in with Microsoft instead, the same holds for the email address and name your organization's Microsoft account provides: they authenticate you to the project's service and are used for nothing else. We request only the standard sign-in scopes (openid, profile, email) — we cannot read your mail, files, calendar or anything else in your Microsoft account, and we never receive your password.
Where it's held#
Annotations and account data sit on the project's own Google Cloud infrastructure (Cloud Run, Cloud SQL, Cloud Storage) in the United States, and only project staff can reach them. Annotators confirm at setup that they are in the United States, so we do not routinely move personal data across borders. If that changes we will update this page first.
What stays on your device#
The extension keeps your session, your settings, and a local outbox of submissions on your own machine. Anything still waiting to be delivered stays until it is; once delivered, the local copy is kept for up to 30 days so you can review and export your recent history, then removed. Signing out ends your session but leaves undelivered work alone so nothing is lost, and removing the extension from Chrome deletes all of it.
How long we keep it#
Account data — your identifier, sign-in history and setup answers — is kept while your account is active, and removed when you delete it.
Annotations are kept for the life of the research project, because removing them retroactively would invalidate published findings. If you delete your account they stay, but they are detached from you and attributed to a random pseudonym instead (see Data deletion, which also covers full erasure if you want it).
Server logs are kept briefly for routine operations and carry no annotation content.
Security#
Data travels over HTTPS, the backend is reachable only with an authenticated project account, and passwords are stored hashed, never in readable form. Your signed-in session is held in the extension's own private storage, out of reach of the web pages you visit. No system is perfectly secure, so we also limit what we collect and who can read it. If a breach ever does affect your personal data, we will tell you and any regulator we are required to notify, without undue delay.
Your choices and rights#
You can exercise any of the following by emailing ksaiki@addresshate.org. We will not treat you differently for asking.
- Get a copy of the personal data we hold about you, and know what we collect and who we share it with. Your own annotations are also exportable to a spreadsheet from inside the extension at any time.
- Correct anything inaccurate — including your setup answers.
- Delete your account and data — see Data deletion, which you can do yourself in the extension.
- Object to, or ask us to limit, a particular use of your data.
- Withdraw consent where you gave it. Post-view tracking is one example: it is off unless you opt in, and you can switch it back off in Settings whenever you like. Permission to name you as a user is the other — see Where we name you.
- Sign out to end your session and stop collection.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising — as those terms are used in California's privacy law. We have never done either.
If you are in a place with a data-protection regulator and you think we have mishandled your data, you have the right to complain to it. We would rather you came to us first so we can put it right.
Changes to this policy#
If we change this policy we will move the “Last updated” date at the top. For anything that materially affects you, we will tell annotators directly rather than leave you to spot it.
Contact#
Questions or requests: ksaiki@addresshate.org. Deletion has its own page: Data deletion.