Privacy Policy

Last updated: 2026-08-11

The AddressHate Annotator browser extension is a research tool used by authorized annotators to label hate speech on X, YouTube, Rumble, TikTok, Reddit, Instagram, 4chan, and the AI chat assistants for the AddressHate project. It explains what the extension collects, why, and where that data goes.

AddressHate decides how this data is used and is responsible for it. You can reach us at jmurry@addresshate.org.

Who can use it

The extension only works for annotators the project has authorized by name. It is not a consumer product: we don't market it to the public, and without an account it does nothing. It is not meant for children, and annotators must be adults.

What we collect

Post content is sent to us only when a signed-in annotator takes a deliberate action (labeling a post, adding it to the queue, or flagging it). The extension runs on X, YouTube, Rumble, TikTok, Reddit, Instagram, 4chan, and the AI chat assistants only, and on no other site (x.com, twitter.com, youtube.com, rumble.com, tiktok.com, reddit.com, old.reddit.com, instagram.com, boards.4chan.org, boards.4channel.org, chatgpt.com, claude.ai, grok.com, gemini.google.com, chat.deepseek.com, chat.qwen.ai).

To label a post accurately, the extension reads the responses those sites' own apps already load as you browse them — the posts and comments in the feed, thread, search results, or profile you are viewing. Those responses are held briefly in memory on your device, are discarded when you reload or leave the page, and are never written to disk or sent to us unless you choose to annotate a specific post. It does not read your bookmarks, your direct messages, your account settings, or anything on any other website.

Flagging a conversation with an AI assistant

Flagging works differently on AI assistants (ChatGPT, Claude, Gemini, Grok, DeepSeek, Qwen) than on public platforms. A public post can be flagged by link, because a reviewer can open it. A conversation with an AI assistant is private to your account — nobody else can open it, and you can delete it at any time — so a flag there has to carry the material itself, or there would be nothing for a reviewer to look at.

When, and only when, you flag content in such a conversation, we receive:

You see exactly what will be sent before it is sent, and you can remove the preceding context turns. Nothing is transmitted unless you then confirm; cancelling sends nothing. Your identity is not attached to the evidence annotators see.

We do not collect a conversation you did not flag, we do not collect the rest of a conversation beyond those turns, and we do not monitor your use of AI assistants in the background. Deleting your account deletes the conversation evidence you contributed.

Permissions and why we ask

PermissionWhy
Host access to x.com, twitter.com, youtube.com, rumble.com, tiktok.com, reddit.com, old.reddit.com, instagram.com, boards.4chan.org, boards.4channel.org, chatgpt.com, claude.ai, grok.com, gemini.google.com, chat.deepseek.com, chat.qwen.aiRead the post you annotate and place the Annotate button on those platforms. The extension runs on no other sites.
Access to the project's ingest serviceSend your annotations to, and read the shared work queue/history from, the project's own backend.
storageKeep your submission outbox, session, and settings on your device.
alarmsRetry delivering queued annotations if the network or service is briefly unavailable.
identityOptional “Sign in with Google.”
downloadsLet you export your own annotations to a file.

How it's used and shared

The extension sends collected data only to the AddressHate project's own annotation service, which serves this page, and we use it for hate-speech research and nothing else. We do not sell it, use it for advertising, pass it to data brokers, or use it to judge anyone's creditworthiness or lending eligibility.

Service providers

Two others handle data on our behalf, for this same research purpose and nothing else:

Google user data (Limited Use)

If you sign in with Google, the extension's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Your Google email and name are used only to authenticate you to the project's service; they are never sold or used for advertising.

Where it's held

Annotations and account data sit on the project's own Google Cloud infrastructure (Cloud Run, Cloud SQL, Cloud Storage) in the United States, and only project staff can reach them. The extension is issued only to annotators working in the United States, so we do not routinely move personal data across borders. If that ever changes we will update this page first.

On your device

The extension keeps your session, your settings, and a local outbox of submissions on your own machine. Anything still waiting to be delivered stays until it is; once delivered, the local copy is kept for up to 30 days so you can review and export your recent history, then removed. Signing out ends your session but leaves undelivered work alone so nothing is lost, and removing the extension from Chrome deletes all of it.

How long we keep it

Account data — your identifier, sign-in history and onboarding answers — is kept while your account is active, and is removed when you delete it. Annotations are kept for the life of the research project, because removing them retroactively would invalidate published findings; if you delete your account they stay, but they are detached from you (see Data Deletion, which also covers full erasure if you want it). Server logs are kept briefly for routine operations.

Security

Data travels over HTTPS, the backend is reachable only with an authenticated project account, and passwords are stored hashed, never in readable form. No system is perfectly secure, so we also limit what we collect and who can read it. If a breach ever does affect your personal data, we will tell you and any regulator we are required to notify, without undue delay.

Your choices and rights

You can exercise any of the following by emailing jmurry@addresshate.org. We will not treat you differently for asking.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising — as those terms are used in California's privacy law. We have never done either.

If you are in a place with a data-protection regulator and you think we have mishandled your data, you have the right to complain to it. We would rather you came to us first so we can put it right.

Changes to this policy

If we change this policy we will move the “Last updated” date at the top. For anything that materially affects you, we will tell annotators directly rather than leave you to spot it.

Contact

Questions or requests: jmurry@addresshate.org.