Article 01
Who we are and what this policy covers
JudgeMyAI ("we", "us") is an AI evaluation company that supplies vetted domain experts — PhDs, MDs, lawyers, and engineers — to evaluate, red-team, and align large language models for frontier labs and regulated industries. Our registered address and legal entity details are available on request at legal@judgemyai.com.
This policy covers three groups: clients who engage evaluation services, expert talent who apply for evaluator roles, and visitors of judgemyai.com. Where a client engagement is governed by a signed Data Processing Agreement (DPA), that agreement prevails on the points where it is stricter.
Article 02
The data we collect — and nothing more
- Client evaluation data: model outputs, prompts, rubrics, and failure reports you submit for evaluation. This data is confidential by default, processed under NDA, and never used to train any model.
- Talent application data: identity and contact details, credentials and qualifications, work history, domain exam results, and calibration scores for evaluator applicants.
- Website data: pages visited, approximate region derived from IP, device and browser type, and referral source — collected without cross-site trackers.
- Communications: emails and form submissions you send to enterprise@, talent@, security@, press@, or privacy@judgemyai.com, retained as needed to resolve your request.
No precise geolocationNo biometric dataNo ad profilesNo social scraping
Article 03
How we use data
We process data only to deliver what you came to us for: assembling and calibrating expert cohorts for client engagements, assessing and paying evaluators, operating and securing this website, complying with legal obligations, and — where you explicitly opted in — sending occasional research updates you can unsubscribe from in one click.
We do not perform automated decision-making with legal effect on website visitors, and we never use client evaluation data for product development, benchmark publication, or model training without separate written authorization.
Article 04
Legal bases (GDPR)
- Contract: processing evaluation data and paying evaluators — the work you hired us for or were hired to do.
- Legitimate interest: site security, fraud prevention, and aggregate service-quality measurement, kept minimal and balanced against your rights.
- Consent: optional analytics cookies and research emails — withdrawable at any time with effect for the future.
- Legal obligation: tax, employment, and records retention where law requires.
Article 05
Cookies and tracking
Declining optional cookies costs you nothing functionally. We set no third-party advertising cookies, and we do not fingerprint devices.
Article 06
Sharing and sub-processors
We share personal data only with vetted sub-processors required to operate: cloud hosting with encrypted storage, transactional email delivery, and payroll providers for evaluator compensation. Every sub-processor is bound by data-protection terms, and the current list is available on request.
We disclose data to authorities only where legally compelled, and we notify affected clients unless prohibited by law. Client evaluation data is never shared between engagements, and never with model vendors.
Article 07
International data transfers
Our expert network spans 40+ countries, so data may be processed outside your region. Transfers rely on adequacy decisions or EU Standard Contractual Clauses, supplemented by encryption in transit and at rest and by transfer impact assessments for sensitive engagements. EU and UK client data can be confined to EU/UK processing on request at no additional cost.
Article 08
Your rights
Access & portability
Receive a copy of your data in a structured, machine-readable format.
Rectification
Correct inaccurate personal data, including application records.
Erasure
Request deletion, subject to legal retention duties (tax, employment).
Restriction & objection
Pause processing or object to legitimate-interest processing.
Withdraw consent
Revoke optional cookies and research emails at any time.
CCPA specifics
Know, delete, and opt out of any "sale" — we conduct none. No discrimination for exercising rights.
Exercise any right by emailing privacy@judgemyai.com. We verify identity proportionately and respond within 30 days at no charge. EU residents may lodge a complaint with their supervisory authority.
Article 09
Retention and security
- Client evaluation data: deleted per contract schedule at engagement close, default 90 days unless a longer archival term is signed.
- Unsuccessful applications: retained 24 months for future cohort matching, then deleted.
- Website analytics: aggregated or deleted within 12 months.
- Employment and tax records: retained as legally required.
Protection measures include AES-256 encryption at rest, TLS 1.3 in transit, per-client isolated environments, role-based access with least privilege, SOC 2 Type II and ISO 27001 aligned controls, and a 72-hour breach notification procedure to affected parties and regulators where required.
Article 10
Children, changes, and contact
Our services target organizations and adult professionals; we do not knowingly collect data from anyone under 16. If you believe a minor has submitted data, contact us and we will delete it promptly.
We may update this policy as services evolve. Material changes are announced on this page with a revised effective date at least 14 days before they apply. This version is effective August 16, 2026.
Privacy contact: privacy@judgemyai.com · Legal service: legal@judgemyai.com · Security disclosures: security@judgemyai.com (24/7, PGP available).