Golda Alert privacy policy
Golda alerts you how much antisemitic content you consume. Detection and counts stay on your device unless you opt in to Golda Intel.
Last updated: 30 September 2026
Golda Alert (“Golda,” “the extension”) is a Chrome/Brave browser extension published by Horseradish Labs. Golda is the product; Horseradish Labs is the maker. It does not create accounts or ask for your name. Detection, counts, and the experience log stay on your device. Version 2 adds an optional intelligence network and an optional plan check on your Golda user ID. YouTube caption reading spends 1 token a minute. Page text does not.
Single purpose
Golda’s only purpose is to detect antisemitic tropes, slurs, eliminationist anti-Zionism, and known personalities in the web pages you have open, alert you on the page, and keep a local count of those encounters so you can see how much of that content you are exposed to. If you opt in, Golda can also contribute stripped alerts to a shared intelligence feed. Golda follows the ADL’s reading of antisemitism and anti-Zionism and categorizes hits using the ADL Center on Extremism / Antisemitism Uncovered taxonomy (Jewish power, disloyalty, greed, deicide, blood libel, Holocaust denial, and antisemitic anti-Zionism), plus IHRA hostility toward Jews, extremist symbols, and conversion targeting. Ordinary criticism of Israeli government policy is not treated as an incident. Golda also flags missions whose purpose is to convert Jews away from Judaism (for example a site posing as Jewish in order to evangelize Jews). Ordinary Christianity, churches, and other faiths are not treated as incidents. It does not block sites, inject ads, or provide unrelated browsing tools. On Lite or Premium, Golda can blur a flagged post on the page until you tap View Threat.
What Golda does on the page
When Golda is on duty, a content script may read text that is already on the web page you have open (for example post text and names). That scan happens in your browser. Matching uses on-device detectors for tropes, slurs, denial of Jewish self-determination, missions that target Jews for conversion away from Judaism, and known personalities you have enabled. Watchdog, Holocaust education, and encyclopedia sites that inform about antisemitism (for example stopantisemitism.org and cyberwell.org) are skipped so reporting is not counted as an incident. Golda’s own “today’s report,” hosted intel feed, homepage, and other site copy (listing, account, and legal pages) are skipped the same way so listing tropes is not counted as an incident. On ronileibovitch.com/golda detection is skipped. That visit is not an incident.
Golda does not upload page contents or YouTube transcripts. The overlay loads its stylesheet from the extension package. Other network requests are optional: Golda Intel if you opt in, Parent watch if a parent connects a device, a plan status check for your user ID, and — only when tokens or a founder grant are on — YouTube’s caption file for the video you have open.
Golda tokens
Golda Lite scans text already on the page. There is no monthly plan.
Activating Golda is pay as you go: load tokens with Stripe on the Google
email you sign in with at golda.horseradish.ai. Packs are $4 for 400
tokens, $10 for 1,000, and $25 for 2,500. A caption minute spends 1
token. A live minute spends 1 token. An image spends 2 tokens. Page-text
scanning does not spend tokens. A token balance unlocks the service and
never writes users.plan. An earlier subscription, if you
still have one, keeps its included use until it lapses. Manage that
leftover subscription from the Stripe Customer Portal on the account page.
Censor threats activate when tokens are loaded, or on a founder grant: Golda blurs a flagged post in your tab until you tap View Threat. That overlay is not uploaded and does not spend tokens. YouTube captions download that video’s caption file to your device when tokens or a grant are on. Each caption minute spends 1 token. Caption text is not uploaded to Golda. If YouTube has no captions, Golda may transcribe that tab’s audio on your device with Whisper. Each live minute spends 1 token. Audio is not uploaded.
Image reading: Golda may copy pixels from images and canvases already on the page you have open, run OCR on your device, and scan the resulting text with the same detectors. Image bytes and OCR text are not uploaded to Golda. Each image spends 2 tokens. A token balance does not write your plan.
Live speech: when a tab is playing audio and no caption file exists, Golda may capture that tab’s sound, transcribe it on your device with Whisper, and scan the text. Audio is not uploaded. Each live minute spends 1 token.
The extension stores a session token, your Google email, any leftover plan or founder grant, and a cached token balance so it can meter the service. Payments are processed by Stripe. Firebase Auth holds the Google sign-in. The first time you sign in, Golda may email Horseradish (roni@horseradish.ai) that a new account exists, with the Google email on that account. That notice is not sent again for the same account. When signed in as Horseradish, the operator may review aggregate account metrics (signed-in counts, plan mix, lifetime incidents, and bytes of content Golda veiled).
Golda Intel (opt-in)
Path of least resistance: you opt in on your machine, in the Golda popup, next to On duty. That is the master switch. You can also share a single alert from Golda’s briefing without turning the switch on. The website is where the shared feed can be read — it is not where you grant permission.
When you contribute, Golda sends:
- The detector id, detector kind, and type of antisemitism (what was flagged).
- The site hostname (for example x.com). For a post on X, Reddit, Instagram, or Facebook, a stripped permalink may also be stored so Golda can reopen that post later. Query strings, titles, and page text are not sent. The public Intel feed still shows the site, not the link.
- A time, and your Golda user ID for this browser (for example G-A1B2C3D4).
- A coarse location of where you were when you shared the experience: city, region, and country inferred from the network request, plus your timezone. Not a street address, GPS pin, or IP address on the public feed.
She does not send page text, excerpts, titles, cookies, or your name. Intel is off by default. Turning it off stops new contributions; it does not erase reports already on the network.
Opted-in reports are stored in Google Cloud Firestore for Golda Intel. Each record is the detector id, kind, type of antisemitism, hostname, optional stripped social permalink, time, Golda user ID, and coarse place. Firestore is not used to store page contents or your legal name. Client apps cannot read or write that database directly; only the Intel API can.
Parent watch records are also stored in Firestore: detector id, kind, site, time, and which parent account they belong to. They are not mixed into the public Intel feed. Only that parent, signed in, can read today’s watched incidents on the report page.
What is stored, and where
Counts and settings are saved with Chrome’s
storage.local API on the browser profile that installed Golda.
That store is local to that profile on that device. It is not synced to a
Golda cloud, a Golda account, or this website.
Local data may include:
- Your on/off settings (duty, tropes, personalities, whether to alert the same incident again on a page, Golda Intel).
- Today’s incident count (shown on Golda’s placard and the toolbar badge) and the calendar date used to reset that daily count.
- An all-time alert count shown in the popup.
- Keys that mark which posts or pages were already counted today, so the same item is not tallied twice.
- A short experience log (up to 50 entries) with time, what matched, and the page title and URL of that encounter.
- A Golda user ID for this browser (shown in the popup) and a local node id used to keep that user ID stable.
- Whether you are signed in, your Google email, your plan, and a cached credit balance.
Each Chrome or Brave profile has its own tally. Two people, or two profiles on the same computer, do not share a count.
Permissions
Each permission is used only for the single purpose above. Page contents and your tally are not sent unless you opt in to Golda Intel or a parent connects Parent watch, and even then only a stripped report is sent.
-
storage — to save on-device settings (on/off, which
detectors are enabled, whether Intel sharing is on), today’s incident
count, the all-time count, keys that prevent double-counting the same
post, a short experience log (time, what matched, page title, URL), and
a local queue of stripped Intel reports waiting to send, a Golda user ID
for this browser, a local node id used to keep that user ID stable, and
plan and caption-minute status for this browser, and a parent-watch token
if this device was connected with an invite code.
This data stays in
chrome.storage.localon the browser profile that installed Golda until you opt in to send a stripped report or a parent watch is connected. - activeTab — used only when you click Summon Golda in the popup. That sends a test ping to the tab you are looking at so you can confirm Golda still appears. It is not used to read other tabs in the background.
- offscreen — used so tokenized image reading and live speech can run on-device OCR and Whisper in a hidden document. Image pixels and tab audio stay in that document. They are not uploaded.
- tabCapture — used only for tokenized live speech, to hear the tab that is already playing audio when no caption file exists. Golda does not capture other tabs or your microphone.
- Host access (http and https pages) — Golda must run on ordinary websites (for example a news site or X/Twitter) because that is where antisemitic language appears. A content script reads text already shown on the page, matches it against on-device detectors, and may show the Golda overlay. Tokenized image reading may fetch an image already displayed on that page so OCR can run on your device. Host access is not used to inject third-party scripts or to upload the page.
- golda.horseradish.ai and golda-intel.vercel.app — used to send or read stripped Intel reports after you opt in or tap Share, and to check or redeem your token balance for your user ID. It is not used to upload page contents or YouTube transcripts.
- youtube.com — used only when tokens allow captions, to fetch the caption/transcript file for the YouTube video you have open. That file is scanned on your device. It is not used to upload videos or to read your YouTube account.
Remote code
Golda does not execute remote code. All JavaScript ships inside the extension package. The overlay loads its stylesheet and Golda image from that same package (Chrome’s extension URL), not from a CDN or other website. There is no eval of downloaded scripts, no remotely hosted workers, and no third-party analytics tags.
Data use
Website text is read locally in order to detect antisemitic language. Page titles and URLs of flagged encounters may be stored locally in the experience log. That information is not transmitted off the device unless you opt in to Golda Intel or Parent watch is connected. Opted-in Intel reports include a Golda-assigned user ID (not your name or email), the site hostname, a coarse city/region/country from the share request, and — only for X, Reddit, Instagram, and Facebook — a stripped post permalink with tracking parameters removed. Parent watch sends the parent the detector name, site, time, and optional permalink — not page text, not captions, and not a transcript. Intel does not send page text, titles, or a full browsing history. It is not sold, not used to target advertising, and not used to determine creditworthiness. Golda does not collect health or financial information, or authentication secrets.
We certify that:
- User data is not sold to third parties.
- User data is not used or transferred for purposes unrelated to Golda’s single purpose.
- User data is not used or transferred to determine creditworthiness or for lending purposes.
What we do not do
- Golda is not a general consumer ad network. We do not inject ads into third-party websites Golda watches. Detection stays on your device. Golda may show limited sponsorships on Intel and/or the hosted report: “this Intel brought to you by” or “this report sponsored by” a named Jewish or Israeli business. Sponsors do not receive page text, YouTube transcripts, or a name from the public Intel feed (the User column is already hidden). Golda may later load a tightly scoped sponsorship or ad unit on Golda’s own Intel, report, or account pages only — never on the sites you browse.
- No third-party analytics in the extension.
- No sale of browsing data or counts.
- No hosting of a per-person antisemitism score on our servers. Intel is a stripped, opt-in threat feed, not a score about you. Plan billing uses your Google email on the Golda Intel site if you sign in to load tokens.
How to clear data
Removing Golda Alert from Chrome or Brave deletes the extension’s local storage, including counts and the experience log. You can also clear site and extension data from your browser’s settings.
Children
Golda Alert is not directed at children under 13. Do not use it to collect information from children under 13. Parent watch is for ages 13 and up: a parent or guardian with tokens loaded generates an invite code, and a teen pastes it in the extension on their own browser. The parent then receives a stripped ping (what Golda spotted, which site, and when) plus those incidents on today’s report. Golda does not send page text, captions, or a transcript to the parent. Email notices, when configured, are at most one every 30 minutes per watched device. On Friday morning the same parent also receives one short week letter per watched device: how many incidents, which sites, and total attention saved. The Parental Controls switch on the account stops both.
If you sign in, Golda may also send a weekly plain-text recap to that Google email: your two watch totals (threats detected and bytes of censored content) plus a stripped summary of the public Intel report (incident count, sites, types, places, and recent shares). Type and site only. No page text. Write golda@horseradish.ai if you want that mail to stop.
Changes
If this policy changes in a material way, we will update this page and the “Last updated” date. Continued use after an update means you are using Golda under the revised policy.
Contact
Golda by Horseradish. Questions about this policy or the extension: open an issue on GitHub.
Homepage: https://golda.horseradish.ai/