Privacy
Short version: everything you post is public, we never ask who you are, and you can have any post removed instantly.
What we collect
What you type. Wall posts, the option you pick on a card, and the optional role / age / gender / location fields next to the post box. All of it is optional except the post itself.
A session cookie. One first-party, HTTP-only cookie so the site can tell that two answers came from the same person without knowing who that person is. It is what makes “did they answer a second card?” measurable.
A one-way hash of your IP. Not the address itself — an HMAC of it, stored for abuse prevention and rate limiting. It cannot be reversed back to an address.
No third-party analytics, no advertising trackers, no account, no email address.
Bot protection
Posting and answering are protected by Cloudflare Turnstile, which checks that a submission came from a person rather than a script. Almost always it runs invisibly and you will never know it ran. Occasionally it asks you to tick a box that says “Verify you are human” — there are no puzzles and no images to identify.
To do that, Cloudflare receives technical signals from your browser (including your IP address and basic device and browser characteristics). It does not receive what you typed. Cloudflare's handling of that data is governed by the Turnstile Privacy Addendum. Turnstile does not set cookies for cross-site tracking and is not used for advertising.
Why it exists here: this site pays for a language model on every wall post, so an unprotected form is someone else's free compute and our bill. It also keeps scripted submissions out of a dataset whose entire value is that it reflects what real people think.
What happens to it
Wall posts are public the moment you submit them. Card answers are published only in aggregate — as counts and percentages, never as “this person picked B”. Free-text card answers are stored but never displayed publicly.
The aggregate dataset is intended for public release under CC0, so that anyone can check our numbers. Session hashes and IP hashes are never part of it.
Automatic redaction
Before anything is saved, email addresses, phone numbers and @handles are stripped out and replaced with a marker. This runs on both wall posts and free-text card answers.
It cannot catch everything — a name, an employer, a detail that identifies someone by context. That is what the report control is for.
Removing a post
Every wall post has a Report control. One report removes the post immediately — no queue, no review. We would rather take down ten fine posts than leave one up that shouldn't be.
Removed posts are hidden everywhere and excluded from the published dataset. For anything else — including a card answer, which has no report control because it is never shown publicly — email support@aigutcheck.com.
How long it is kept
Indefinitely, and we would rather say so than imply otherwise. The point of this project is a record of what people expected from AI at a given moment; a dataset that deletes itself on a schedule cannot do that. Removal on request is the control that matters here, and it is immediate.
Changes
If what we collect or publish changes materially, this page changes with it and the change is noted here rather than made quietly.
Questions: contact@aigutcheck.com · About · Back to the wall