Privacy Policy
This Privacy Policy explains how Handkin ("we", "us", "our") collects, uses, shares and protects personal information when you use our website, the recording app, the annotation web platform and any related services (together, the "Services"). By using the Services you agree to the practices described here. If you do not agree, please do not use the Services.
Who we are
Handkin operates a crowdsourcing platform where contributors record short video episodes, label text and review AI-generated answers. The resulting data is used to train and evaluate AI and robotics systems for us and for the organizations we work with.
For the purposes of data protection law, we are the controller of the personal information described in this policy unless we state otherwise. You can reach us at [email protected].
Information we collect
We collect information you give us directly, information generated when you use the Services, and information from a small number of third parties.
- Account information: name, email address, country and city, preferred language, date of birth (to confirm you are 18 or older), and profile details such as the devices you own.
- Identity verification: when you verify your identity we collect the document images and selfie you provide, and the result returned by our verification provider. We do not use these to build a biometric profile beyond what is needed to confirm the match.
- Video and audio recordings: episodes you record through the app, including any faces, voices, surroundings, hands and objects that appear in them. Video may incidentally contain biometric identifiers, such as a face or voice. We treat all recordings as sensitive data and handle them as described in section 4.
- Labels, ratings and review answers: the text, selections and free-form feedback you submit on the annotation platform.
- Payout information: the payment platform you choose and the account identifier needed to pay you. Card and bank details are held by the payment provider, not by us.
- Usage and device data: app and browser version, device model, operating system, IP address, approximate location derived from it, pages viewed, tasks opened, upload timing, crash reports and diagnostics.
- Support communications: messages you send through the contact form, by email or in community channels, and our replies.
How we use information
We use personal information for the following purposes and on the legal bases noted where applicable.
- To run the Services: create your account, show you tasks available in your region, receive and review your submissions, calculate earnings and pay you (performance of a contract).
- To build datasets: recordings, labels and review answers are curated into datasets used to train, test and evaluate AI and robotics models, including models operated by our partner organizations (legitimate interests and, where required, your consent).
- To assess quality and prevent abuse: detect duplicate, staged or fraudulent submissions, enforce our terms and protect other contributors (legitimate interests).
- To improve the Services: understand how the app and platform are used, fix bugs and design better tasks (legitimate interests).
- To communicate with you: send task alerts, review outcomes, payout notices, support replies and, where you have opted in, product news (performance of a contract or consent).
- To comply with law: keep tax, payment and identity records where regulations require it (legal obligation).
Recordings, faces and biometric data
Recording tasks are designed to capture hands, objects and everyday environments, not people. We ask you to avoid filming other people and to obtain their consent when it cannot be avoided. Reviewers may reject episodes that show identifiable third parties who have not agreed to appear.
Recordings are encrypted in transit and at rest. Where our processing pipeline detects faces or other identifying details, we apply blurring or removal before a dataset is released to a partner unless the task explicitly required them and you consented to that at the time. We do not use recordings to identify you, to build facial-recognition templates, or to make automated decisions about you.
Because a recording may contain biometric information, some jurisdictions require specific consent before we collect it. Where that applies we will ask for that consent in the app and you may withdraw it at any time by contacting us, although episodes already incorporated into released datasets may not be retrievable.
How we share information
We do not sell personal information. We share it only in the following circumstances.
- Partner organizations: curated datasets containing recordings, labels and review answers, with identifying details minimized as described above. Partners are bound by contract to use datasets only for developing and evaluating AI and robotics systems.
- Service providers: hosting, storage, identity verification, payment platforms, email delivery, analytics and customer-support tools that process information on our behalf and under our instructions.
- Reviewers: trained reviewers, who may be contractors, see your submissions and your first name or a pseudonymous ID in order to grade them.
- Legal and safety: when required by law, subpoena or court order, or when necessary to protect the rights, property or safety of contributors, the public or us.
- Business transfers: if we merge, are acquired or sell assets, information may transfer to the successor, who must honor this policy.
Security and storage
We use encryption in transit (TLS) and at rest, access controls with least privilege, audit logging and regular reviews of who can reach recordings and personal data. Recordings are stored in access-restricted object storage in the region where the Services are hosted, and copies released to partners are delivered through controlled exports.
No system is perfectly secure. If we learn of a breach that affects your personal information we will notify you and the relevant authorities as required by law.
We keep account data for as long as your account is active and for up to seven years afterwards where tax and payment law requires it. Recordings and labels that have been incorporated into datasets are retained for as long as the dataset is in use. Identity verification images are deleted within 30 days of a decision unless law requires longer retention.
Your rights and choices
Depending on where you live, you may have rights under laws such as the EU and UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Canada's PIPEDA and similar regimes. Subject to those laws, you may:
- Access the personal information we hold about you and receive a copy in a portable format.
- Correct inaccurate information, or complete information that is incomplete.
- Delete your account and personal information, subject to retention required by law or for datasets already released.
- Restrict or object to processing based on our legitimate interests, including direct marketing.
- Withdraw consent where processing is based on consent, without affecting processing that took place before withdrawal.
- Opt out of any 'sale' or 'sharing' of personal information as those terms are defined under California law. We do not sell or share personal information for cross-context behavioral advertising.
- Not be discriminated against for exercising your rights.
- Lodge a complaint with your local data protection authority.
How to exercise your rights
You can update most account information from your settings. For anything else, email [email protected] from the address on your account, or use the contact form and choose the "Something else" topic. We may ask for additional information to verify your identity. We respond within 30 days, or sooner where local law requires it, and will tell you if we need more time.
International transfers
We operate globally and may transfer, store and process your information in countries other than your own, including countries that may not offer the same level of protection. Where we transfer personal information out of the European Economic Area, the United Kingdom or Switzerland, we rely on adequacy decisions, standard contractual clauses approved by the relevant authorities, or another lawful mechanism, together with additional safeguards where needed.
Age requirement
The Services are for adults only. You must be at least 18 years old, or the age of majority where you live if that is higher, to create an account. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with information, contact us and we will delete it.
Cookies and similar technologies
We use strictly necessary cookies to keep you signed in, remember your language and protect the Services against abuse. We use privacy-respecting analytics to understand overall usage. We do not use advertising cookies. You can control cookies through your browser settings; disabling necessary cookies will prevent you from signing in.
Changes to this policy
We may update this policy from time to time. When we make material changes we will notify you by email or through a notice in the app or on the platform before the changes take effect, and we will update the date at the top of this page. Continued use of the Services after the effective date means you accept the updated policy.
Contact us
Questions, requests and complaints about privacy can be sent to [email protected]. Please include "Privacy" in the subject line so it reaches the right team.