Last updated September 25, 2026
Account information
When you sign in with Google or GitHub, ToneBench receives the identity fields needed to create and secure your reviewer account: provider account identifier, email and verification status when supplied, display name, and avatar. Your public handle, name, bio, and profile links are fields you choose to add or edit.
If a Google- or GitHub-hosted avatar is displayed, your browser requests it directly from that identity provider. The provider therefore receives your IP address and ordinary request metadata. ToneBench restricts avatars to approved Google and GitHub hosts and sends the request with no referrer, but does not proxy the image.
Reviews and feedback
We store your selected outcome, feedback when supplied, timing needed for integrity checks, validation status, and awarded Contribution Points. The public rating interface never receives or displays source identities for an assignment.
Feedback on an accepted review may be checked asynchronously for relevance and spam by the DeepSeek V4.1 Flash model, served by Fireworks through OpenRouter. The check receives the same anonymous task context, exact Passage A and Passage B text, displayed selection, and feedback that you saw; it does not receive model, provider, source, rank, reviewer name, email, or account identifier. ToneBench requests only Fireworks, disables fallbacks, denies provider data collection, and allows only zero-data-retention endpoints. OpenRouter still processes the request and may retain operational metadata under its policies. See OpenRouter’s privacy policy.
The result can approve or deny feedback credit; it never changes your preference vote, a model’s score, Reviewer Rating, or trust. ToneBench stores the verdict, reason category, routed model/provider, token and cost metadata, errors, and cryptographic hashes that bind the exact request and response. It does not store the provider’s raw response. A single spam verdict creates no abuse penalty; only a repeated pattern may create low-severity evidence for later review.
Public visibility is opt-in
Your reviewer profile is private by default. If you opt in to the public leaderboard, your chosen public name, handle, title, Contribution Points, Reviewer Rating, badges, and approved X, LinkedIn, or GitHub links may appear. You can opt out again from your profile.
Integrity and abuse protection
ToneBench uses rate limits and one-way hashed abuse signals to detect duplicate or automated activity. These signals help protect the benchmark without publishing raw identifiers. They are not used to advertise to you or build a marketing profile.
When the optional Cloudflare Turnstile check is enabled, your browser connects directly to Cloudflare to complete an anti-spam check. Cloudflare receives your IP address, browser and challenge request metadata, and the opaque assignment identifier used to bind the check to one comparison; it does not receive your selected outcome or optional feedback from ToneBench. See Cloudflare’s privacy policy.
Retention after deletion
Deleting your account clears your live public-profile fields and email, removes linked OAuth identities and pending sign-in flows, revokes active sessions, and scrubs optional free-text vote feedback. It does not erase the benchmark-integrity record. Vote outcomes, timing and validation status, assignments, reputation and badge events, moderation and abuse records, audit records, and account statistics remain linked under a stable, non-public research pseudonym so aggregate results stay reproducible and resistant to manipulation. These retained records are pseudonymized and internally linkable, not anonymous or fully de-identified; they cannot be used to sign in or make the deleted profile public again.
Routine maintenance prunes revoked session records, including keyed IP signals and hashed browser signals, once they are more than 30 days old, and prunes request-rate records containing a keyed IP signal after 90 days. Other integrity and audit records may be retained long term. ToneBench never stores the raw IP address in these application records.
To prevent delete-and-recreate abuse, ToneBench keeps a one-way keyed HMAC of each deleted Google or GitHub account identifier for 180 days. The tombstone does not contain the raw provider identifier and is removed by maintenance after the hold. During that period, the same provider identity cannot create a fresh reviewer reputation. After the hold, it may create a new account, but the deleted account is not restored or relinked.
Your controls
- Edit public fields or leaderboard visibility at any time.
- Export the account, OAuth identity, contribution, badge, and vote data associated with your signed-in account.
- Delete the account after a deliberate confirmation. A recent sign-in is required for this sensitive action.
These controls are available on your reviewer profile. Deletion permanently closes the old account and removes it from live public profiles and leaderboards; it cannot recall copies of information that someone else saved while the profile was public.
Scope and questions
This summary applies to the ToneBench human review area. The broader Towards AI site may have additional notices for its own services. For questions, use the Towards AI contact page.