What is unmask.shield?

unmask.shield is a browser extension that reads the language on any web page — or in your emails and messages — and flags phrases that abstract, sanitise, or conceal real-world physical harm. Think of it as a real-time translator between institutional language and what that language actually means for people and the environment.

What kind of language does it flag?

Language that describes harm to people, communities, or ecosystems in abstract, technical, or bureaucratic terms — making the harm sound neutral, inevitable, or even positive. Examples:

  • "Managed retreat" → forced relocation of communities from their land
  • "Collateral damage" → civilian deaths or injuries in military operations
  • "Workforce restructuring" → mass job losses affecting livelihoods
  • "Carbon offsetting" → continuing emissions while paying to avoid reducing them
  • "Flux migratoires" → reducing human beings to a statistical flow

The phrase library draws from four legal and scientific frameworks: the Rome Statute (ICC), Geneva Conventions (AP I), UN Declaration of Human Rights, and Planetary Boundaries science. Detected phrases link back to the specific article or boundary they relate to.

Who is this for?

Anyone who reads or writes in institutional, corporate, government, or policy contexts. Specifically useful for:

  • Journalists and researchers analysing official communications
  • NGO and advocacy workers reading policy documents and press releases
  • Corporate employees who want to catch their own language before it goes out
  • Anyone who reads sustainability reports, government statements, or HR communications and wants a second opinion on the language

Installation

unmask.shield installs as a standard Chrome extension. It takes about 60 seconds.

1
Open the Chrome Web Store Install directly from the unmask.shield listing, or search for unmask.shield in the Chrome Web Store. The extension is listed under the publisher unmask.tools.
2
Click "Add to Chrome" Chrome will ask for permission to read page content on websites you visit. This is required for the extension to scan text — no content is sent anywhere without your explicit consent.
3
Pin the extension Click the puzzle-piece icon (⊞) in your Chrome toolbar, find unmask.shield, and click the pin icon. This keeps the shield icon permanently visible so you can see detection counts at a glance.
4
Get a free key (optional but recommended) Phrase matching works without any key. To unlock AI Detection — which catches euphemistic language beyond the phrase library — register for a free key. Takes 30 seconds, no credit card needed.
5
Visit any page and start reading Navigate to a news article, policy document, corporate press release, or sustainability report. Flagged phrases are highlighted directly on the page. Click any highlight to see the plain-language translation and legal anchor.
Does it work on Firefox?
Firefox support is in development. The Chrome extension uses Manifest V3; a Firefox-compatible port (MV2) is planned. Sign up for the newsletter on the pricing page to be notified when Firefox support launches.
Do I need to create an account?
No account is required for phrase detection — it works immediately after install. If you want AI Detection, you need a free API key. Registration just requires an email address; there is no password and no account dashboard (yet — one is planned).
Is the extension free?
Yes. The free Personal tier includes unlimited phrase matching across all supported languages, PDF scanning, email and message scanning, the Invoke Protocol, and the phrase library. AI Detection has a daily limit of 50 scans on the free tier. Paid tiers increase the AI limit and add API access.

Feature overview

unmask.shield has several distinct capabilities. Here is what each one does in plain terms.

🔍

Language Detection

Scans any web page for phrases from the detection library. Highlights them directly on the page, colour-coded by severity. Works on all sites — news, government, corporate, academic.

🤖

AI Detection

A second pass using a language model that catches euphemistic language beyond the fixed phrase library. Finds novel constructions and context-dependent abstraction that phrase matching would miss.

✉️

Email & Message Scanning

Scans emails you receive and — optionally — flags language in compose windows as you write. Works in Gmail, Outlook Web, Slack, Teams, WhatsApp Web, and more.

📄

PDF Scanning

PDFs can't be scanned directly by the browser extension. Instead, paste the PDF text into the extension's PDF panel to scan it. Useful for policy documents, reports, and legal filings.

🛡️

Invoke Protocol

When you're using an AI chat (Claude, ChatGPT, Gemini), the extension can inject a framing prompt into the conversation that instructs the AI to apply human rights and environmental constraints to all its responses.

📚

My Phrase Library

Add your own phrases to flag — in any language, with your own severity level and plain-language translation. Useful for sector-specific jargon not in the base library.

How do I use PDF scanning?

When you have a PDF open in your browser, the extension popup shows a PDF panel automatically. Open the PDF, select all text (Ctrl+A / Cmd+A), copy it, and paste it into the PDF panel. Click "Scan pasted text" and the extension will highlight flagged phrases directly in the pasted text.

This works for any PDF — reports, policy documents, legal filings, press releases. The text is processed entirely in your browser; nothing is sent to a server.

How does the Invoke Protocol work?

The Invoke Protocol is a framing prompt you insert at the start of an AI conversation. It instructs the AI to apply the UDHR, Geneva Conventions, Rome Statute, and Planetary Boundaries as hard constraints on every response — treating people and the environment as primary, not as externalities.

When the extension detects you're on Claude, ChatGPT, or Gemini, it can inject this prompt directly into the chat input. On other platforms, it copies the prompt to your clipboard for manual paste.

This works in a conversation context — it doesn't modify the AI permanently, just sets a frame for that conversation.

Detection & scoring

Understanding what the numbers and labels in the extension mean.

What do Critical, High, and Medium mean?

Critical — language that abstracts killing, torture, forced detention, mass deportation, ecocide, or planetary tipping point transgression. Anchored to the Rome Statute of the ICC and Geneva Convention absolute prohibitions.

High — language that abstracts serious but non-lethal harm: forced displacement, ecosystem collapse, mass livelihood destruction, critical resource deprivation. Anchored to UDHR economic and social rights and Planetary Boundaries thresholds.

Medium — language that abstracts institutional and structural harm: greenwashing, labour abstraction, governance euphemism, colonial-pattern framing. These phrases are harmful in aggregate and systemically, rather than in a single instance.

What is the Risk Score?

The Risk Score is a weighted sum of detections: each Critical phrase scores 10 points, High scores 4, Medium scores 1. It gives a single number you can use to compare documents.

It's deliberately weighted heavily toward Critical — a document with one critical phrase is riskier than one with twenty medium phrases. The score is unbounded; a long policy document might score 200+.

What is Prevalence per 1,000 words?

Prevalence per 1k normalises the detection count by document length, so you can compare a 500-word press release with a 20,000-word report fairly. A prevalence of 3.0 means three flagged phrase occurrences per thousand words.

High prevalence (3.0+) in a short document is more significant than the same score in a long one — the language is denser with abstraction. The extension colour-codes prevalence: sparse (blue), moderate (amber), dense (red).

Why does something get flagged that I think is harmless?

The extension flags phrases based on their documented institutional usage patterns — not necessarily their meaning in every context. "Managed retreat" as a term in a climate adaptation plan is technically correct but still worth surfacing, because the phrase abstracts the lived experience of forced relocation.

If you think a detection is wrong in its specific context, use the "Figure of speech" button in the tooltip. This records your feedback and helps improve future detection accuracy. It does not remove the highlight from the page — it just marks it as evaluated.

What are community-confirmed phrases?
When extension users click "Real use — confirmed" on a detection, it is recorded anonymously. Phrases confirmed by multiple users across different pages are promoted to the base library via a weekly review process. This helps the library grow with real-world language patterns.
Can I see a live example of detection in action?

Yes — open the Dense Language Test page with unmask.shield enabled. It contains deliberately dense institutional language drawn from six sectors: military briefings, displacement programmes, corporate restructuring, austerity policy, environmental strategy, and governance abstraction.

You should see 120–140 flagged phrases underlined across the page. Hover any phrase for its plain-language translation and the international law anchor that makes it a detection. The Risk Score in the extension will climb well above 100 — a useful benchmark for calibrating what "high risk" looks like on a real document.

This page is also useful after updating the extension to verify nothing has broken in detection accuracy.

AI Detection

AI Detection adds a second layer on top of phrase matching — catching language the fixed library would miss.

What does AI Detection do that phrase matching doesn't?

Phrase matching only catches exact phrases (or close variants) that are in the library. AI Detection reads the full text in context and can identify:

  • Novel euphemisms not yet in the library
  • Paraphrases and circumlocutions that mean the same thing
  • Context-dependent abstraction — phrases that are neutral in most contexts but harmful in the document you're reading
  • Multi-sentence patterns that together constitute a harmful framing even if no individual phrase triggers
Which AI backends does it use?

The extension tries backends in priority order:

  • unmask.tools API — cloud AI via your API key. Most accurate, uses your daily limit.
  • Chrome AI (Gemini Nano) — on-device AI built into Chrome. No daily limit, no API key needed. Only available on supported Chrome versions.
  • Ollama (local LLM) — if you have Ollama running locally, the extension can use any model you have installed. No daily limit, fully private.

If none of these are available, AI Detection is skipped and only phrase matching runs.

What counts toward my daily AI limit?
One AI scan = one page analysed via the unmask.tools API. Long pages are split into chunks and each chunk counts as one scan. Chrome AI and Ollama do not count toward the limit — only unmask.tools API calls do. The limit resets at midnight UTC.

Phrase libraries

Beyond the built-in global library, unmask.shield lets you build and import your own phrase sets — for personal use or across your whole organisation.

What is My Phrase Library?

My Phrase Library lets you add your own phrases to detect — beyond the built-in library. You choose the phrase, its plain-language translation, its severity level, and the language. Custom phrases are stored locally in your browser and never shared.

This is useful for sector-specific language: HR jargon in your organisation, legal euphemisms in a particular jurisdiction, financial abstractions common in your industry, or phrases in languages not yet well-covered by the base library.

What is the Company Repository?

The Company Repository is an organisation-level phrase library you import from a file — as opposed to My Phrase Library, which you build phrase-by-phrase in the extension. Once loaded, the extension flags phrases from your company list alongside the standard detection library.

Phrases from the Company Repository appear with a MY COMPANY badge in the detection panel so they're always distinguishable from globally sourced phrases. They are never sent to the unmask.tools global index — your organisation's vocabulary stays entirely private.

How to import:

  • Open the extension popup → My Phrase Library → Company Repository tab
  • Upload a .json file — array of phrase objects, see format below
  • Click Load — the extension confirms how many phrases were imported

JSON file format

[ { "phrase": "workforce restructuring", "translation": "Mass job losses affecting livelihoods and community stability.", "severity": "high" }, { "phrase": "collateral damage", "translation": "Civilian deaths or injuries in military operations.", "severity": "critical" }, { "phrase": "managed retreat", "translation": "Forced relocation of communities from their land." // severity is optional — defaults to "medium" if omitted } ]

Valid severity values: critical, high, medium. All three fields support any language.

The repository persists in local browser storage until you clear it or upload a new file. It is not synced across devices.

On Team and Enterprise plans, admins can host the JSON file on their own infrastructure and connect it by URL — phrases are fetched on startup without ever passing through unmask.tools servers. IT can also deploy the URL silently via MDM. See the Company Repository Setup guide.

Supported platforms

unmask.shield can scan emails and messages in your browser — both content you receive and (optionally) language you write before sending.

Platform Reading scan Compose scan Notes
📧 Email & Messaging
Gmail✓ Yes✓ Yesmail.google.com
Outlook Web✓ Yes✓ Yesoutlook.office.com + variants, MCAS proxy
Proton Mail✓ Yes✓ Yesmail.proton.me
💬 Messaging & Chat
WhatsApp Web✓ Yes✓ Yesweb.whatsapp.com
Telegram Web✓ Yes✓ Yesweb.telegram.org (K + A)
Slack✓ Yes✓ Yesapp.slack.com
Microsoft Teams✓ Yes✓ Yesteams.microsoft.com
Discord✓ Yes✓ Yesdiscord.com
Google Chat✓ Yes✓ Yeschat.google.com
LinkedIn messaging✓ Yes✓ Yeslinkedin.com
🤖 AI Chat
Microsoft Copilot✓ Yesn/acopilot.microsoft.com, m365.cloud.microsoft
ChatGPT✓ Yesn/achatgpt.com
Google Gemini✓ Yesn/agemini.google.com
Claude✓ Yesn/aclaude.ai
📄 Document Editors (clipboard scan)
Word Online✓ Yes*n/aCtrl+A → Ctrl+C → Scan in popup
Google Docs & Slides✓ Yes*n/aCtrl+A → Ctrl+C → Scan in popup
PowerPoint Online✓ Yes*n/aCtrl+A → Ctrl+C → Scan in popup
OneNote Online✓ Yes*n/aCtrl+A → Ctrl+C → Scan in popup
PDF files✓ Yes*n/aCtrl+A → Ctrl+C → Scan in popup
* Document editors use a clipboard-based scan — inline highlighting not possible due to proprietary rendering.
✗ Not supported
Signal Desktop✗ No✗ NoNative app — browser extension can't access
Outlook Desktop✗ No✗ NoNative app — browser extension can't access
Apple Mail✗ No✗ NoNative app — browser extension can't access
Google Meet (chat)✗ No✗ NoChat text not accessible in DOM
How do I turn email and message scanning on?
Email and message scanning is off by default. To enable it, open the extension popup and toggle Emails & Messages to on. The setting is saved and applies across all supported platforms.
Why is it off by default?
Email and message content is more personal and sensitive than public web pages. We default to off so you can make an explicit choice to enable it — rather than having the extension silently scan your inbox from day one.
How does scanning work on AI chat platforms (ChatGPT, Copilot, Gemini, Claude)?
On AI chat platforms, the extension scans the responses as they appear — no toggle needed, it works with your main Language Detection setting. When a flagged phrase appears in a response, it's underlined and counted in the badge. You can also use the Invoke Protocol button in the popup to inject a legal framing prompt directly into the chat input, so the AI applies IHL constraints from the start of the conversation.
How does scanning work on document editors (Word, Google Docs, PowerPoint, OneNote)?
Document editors like Word Online and Google Docs use proprietary rendering engines that don't expose their text to browser extensions for direct scanning. Instead, unmask uses a clipboard scan: select all text in the document (Ctrl+A), copy (Ctrl+C), then click Scan in the extension popup. The results appear in the Detections panel just like a normal scan — click any phrase to copy it, then use the editor's own find bar (Ctrl+F) to locate it in the document.

Compose scanning

When email and message scanning is enabled, the extension also scans what you're writing — in real time, before you send.

What exactly is compose scanning?

Compose scanning watches your compose window (the box where you write an email, Slack message, Teams chat, etc.) and flags problematic language as you type — before you send. It works like having a second reader looking over your shoulder, pointing out language that abstracts harm.

The flagged phrases appear in the extension popup and badge, not injected into the compose box itself. Your message text is never modified.

Does compose scanning slow down my typing?
No. The scan runs on a 400ms debounce — it waits until you pause typing before checking. There is no processing on every keystroke. The phrase matching runs entirely locally in your browser, so there is no network latency either.
Is my draft text sent to a server?
Phrase matching in compose windows is always local — nothing leaves your device. If you have AI Detection enabled and the extension also runs an AI scan on your compose text, that text is sent to the unmask.tools API (or processed locally via Chrome AI or Ollama, depending on your settings). AI Detection on compose windows is only triggered after a longer pause (not on every keystroke) and only if you have AI Detection enabled.

Privacy & data

🔒

Short version: phrase detection runs entirely in your browser. No page text, email content, or personal data is collected or transmitted unless you explicitly opt in to specific features (AI Detection, global dataset contribution). Read the full Privacy Policy for details.

What data does the extension collect?

By default, the extension collects nothing. All phrase matching happens locally in your browser. The only data stored is in your browser's local storage: your detection results for the current page, your custom phrase library, and your settings.

Optional data collection (each requires explicit opt-in):

  • AI Detection via unmask.tools API — the text of the page being scanned is sent to our API to run the AI model. The text is not stored after processing.
  • Global dataset contribution — if you enable "Contribute to global dataset" in the extension popup, confirmed detections (phrase + domain, no personal data) are shared anonymously to help improve the library.
Does the extension read my emails?

Only if you enable Email & Message Scanning. When enabled, the extension reads the text content of the current page — which, on Gmail for example, includes the email you're viewing. This reading happens entirely in your browser; no email content is sent anywhere.

If AI Detection is also enabled, the page text (including email content) may be sent to the unmask.tools API for AI analysis. If you want to use email scanning with full privacy, use Chrome AI or Ollama as your AI backend instead — both process text on-device.

How is AI Detection processed?

Depends on the backend:

  • unmask.tools API — text is sent over HTTPS to our Supabase Edge Function, processed by the AI model, and the detections are returned. The text is not stored.
  • Chrome AI (Gemini Nano) — entirely on-device. Nothing leaves your browser.
  • Ollama — processed by a model running on your own computer. Nothing leaves your machine.
What is the global dataset — what gets shared?

When you enable Contribute to global dataset in the extension, confirmed detections are shared anonymously to help improve the phrase library for everyone. Specifically, what gets sent:

  • The detected phrase (e.g. "workforce restructuring")
  • The domain it was found on (e.g. "reuters.com") — never the full URL or page title
  • The severity level
  • Whether you marked it as "Real use" or "Figure of speech"

What is never sent: page content, email or message text, your identity, your IP address, or any other personal data. Contributions are anonymous and cannot be traced back to you.

Phrases confirmed by multiple independent users across different domains are reviewed weekly and may be promoted into the base detection library — improving detection for all users.

Does the Company Repository send our internal phrases to unmask.tools?

Never. The Company Repository is designed so your organisation's phrase list never passes through unmask.tools infrastructure.

When you connect a URL-based repository (Team / Enterprise), the extension fetches your JSON file directly from the URL you provide — your own intranet, S3 bucket, SharePoint, or GitHub repo. The request goes from the employee's browser to your server. unmask.tools is not in that path.

Once loaded, phrases are cached in the browser's local storage and matched entirely on-device. Three technical controls ensure company phrases can never leak into the global dataset, regardless of the employee's sharing settings:

  • Every company phrase is stored with an isLocal: true flag.
  • The global dataset submission filter in content.js explicitly blocks any detection where isLocal is true, before the submission even reaches the network layer.
  • Company phrase detections are visually distinct (MY COMPANY badge) and are excluded from the public detection report at the rendering layer.

For the URL-based setup guide, hosting requirements, and MDM deployment instructions, see Company Repository Setup.

Data flow reference — for security officers

A complete summary of what data is processed where. Use this to validate unmask.shield against your organisation's data handling requirements.

DataLeaves the device?Reaches unmask.tools?Stored?
Page text — phrase matching Never Never Never — matching runs in-browser
Page text — AI Detection (unmask.tools API) Yes, if AI Detection enabled Yes — sent to ldm-analyze Edge Function Never — discarded after scoring
Page text — AI Detection (Chrome AI / Ollama) Never Never — fully on-device Never
Email & message content Never (phrase matching only) Never Never
Company phrase list (URL-based repo) Never Never — fetched directly from your server Never
Company phrase detections Never Never — isLocal flag blocks submission at source Never
Global dataset contribution (phrase + domain) Only if opted in Yes — anonymous, no personal data Yes — anonymised, no user identifier
API key usage count Yes Yes — used to enforce tier limits Yes — count only, no query content
Custom / personal phrase library Never Never — stored in browser local storage only Local only

Infrastructure note: All web traffic to unmask.tools and api.unmask.tools passes through Cloudflare's network (DNS, CDN, Edge Workers). Cloudflare sees IP addresses and standard HTTP request metadata (URL, user agent, timestamps) for every page visit and API call. No page content, email text, or personal account data is shared with Cloudflare beyond this network-layer metadata. This processing is necessary to deliver and protect the service (Art. 6(1)(f) GDPR). Cloudflare participates in the EU-US Data Privacy Framework. Cloudflare privacy policy →

For security officer review requests or Data Processing Agreement inquiries, contact hello@unmask.tools.

How do I delete my data?
Local data (custom phrases, settings, detection history) is deleted when you uninstall the extension or clear Chrome's extension storage. If you have an API key, email hello@unmask.tools to have your key and any associated data removed from our database.

Plans & billing

What's included in the free tier?
The free Personal tier includes everything except API access:
  • Unlimited phrase detection on all websites
  • Email & message scanning (all supported platforms)
  • PDF scanning
  • Invoke Protocol for AI chats
  • My Phrase Library (custom phrases)
  • 50 AI Detection scans per day
Paid tiers increase the AI limit and add access to the REST API for integrating detection into your own tools.
How do I get an API key?
For the free tier: register here — your key is delivered to your email instantly. For paid tiers: purchase on the pricing page via Stripe; your key is delivered to your email immediately after payment.
Can multiple people share one key?
Yes — on Team and Enterprise tiers, one key covers the whole organisation. The daily AI limit is shared across all users of that key. Pro is a single-seat key.
How do I cancel my subscription?
Email hello@unmask.tools or cancel directly from the Stripe billing portal link in your subscription email. Your key stays active until the end of the current billing period, then reverts to the free Personal tier limits.
My key isn't working — what do I do?
Check that you pasted the key correctly in the extension's AI Detection section (it starts with ldm_). If it says "Key not yet activated", check your email for the activation message. If the problem persists, email hello@unmask.tools.
Is there a rate limit beyond the daily AI cap?
Phrase matching has no rate limit. AI detection is capped by your daily limit only — there is no per-minute or per-second throttle. If you need very high burst throughput for API integrations, contact us about Enterprise.

RSS feed

The Institutional Double-Speak Wire is a public feed of newly verified phrases from the global index — open to anyone, no key required.

How do I subscribe?
Feed URL: https://unmask.tools/feed.xml
  • Feedly: paste the URL into the search bar and click "Follow"
  • Inoreader / NewsBlur / NetNewsWire: use "Add feed" or "Subscribe" and paste the URL
  • Email digest (Kill the Newsletter, Blogtrottr): paste the URL to receive entries as email
  • Zapier / Make / n8n: use the RSS trigger with the feed URL to pipe detections into Slack, Notion, or any workflow

The feed updates every Monday when the community promotion pipeline runs. Only phrases with a verified human consensus score are included.

What does each feed item contain?

Each entry includes the detected phrase as the title, its plain-language translation and severity level in the description, the international law anchor it maps to, and the date it was promoted into the global index.

Counter badge

A live SVG badge and JSON API showing detection activity — embeddable anywhere, no key required.

How do I embed the phrase counter on my website or README?
The counter badge is a live SVG served from a public endpoint — no key or sign-up required.

Badge URL

https://api.unmask.tools/counter

Embed in HTML

<a href="https://unmask.tools" title="institutional language tracker">
  <img src="https://api.unmask.tools/counter"
       alt="phrases unmasked — unmask.tools"
       height="20">
</a>

Embed in a GitHub README (Markdown)

[![phrases unmasked](https://api.unmask.tools/counter)](https://unmask.tools)

Fetch the count as JSON (for dashboards or CI scripts)

curl -H "Accept: application/json" \
  https://api.unmask.tools/counter
# → {"detected_today":642,"total_detected":1453,"unique_phrases":339}

The badge reflects the live count of detected phrases today, total ever detected, and unique phrases in the global index. It refreshes every 5 minutes.

Quickstart

The REST API is available on Team and Enterprise tiers. Get your key on the pricing page.

Your first request

# Phrase matching only (no AI, no daily limit used) curl -X POST \ https://ghoriibggfxahkkvvkpi.supabase.co/functions/v1/ldm-analyze \ -H "Authorization: Bearer <your-key>" \ -H "Content-Type: application/json" \ -d '{"text": "The energy transition will require managed retreat of coastal communities."}'
# With AI detection (counts against your daily limit) curl -X POST \ https://ghoriibggfxahkkvvkpi.supabase.co/functions/v1/ldm-analyze \ -H "Authorization: Bearer <your-key>" \ -H "Content-Type: application/json" \ -d '{"text": "...", "options": {"ai": true}}'

Endpoint

POST https://ghoriibggfxahkkvvkpi.supabase.co/functions/v1/ldm-analyze

One endpoint, two modes. Phrase matching is always free and unlimited. AI detection is tier-gated with a daily limit.

Request

Headers

HeaderRequiredValue
AuthorizationYesBearer <your-api-key>
Content-TypeYesapplication/json

Body

{ "text": "string — the text to analyse (max 10,000 characters)", // required "options": { "ai": true }, // optional — enable AI detection (paid tiers, uses daily limit) "lang": "en" // optional — language hint for AI (default: "en") }

Response

{ "detected": [ { // Phrase match (from library) "phrase": "managed retreat", "normalizedPhrase": "managed retreat", "translation": "Forced relocation of communities from their physical land...", "legalRef": "UDHR Art. 13 — Freedom of Movement", "severity": "high", "occurrences": 1, "communityConfirmed": false }, { // AI detection (when options.ai = true) "phrase": "managed retreat of coastal communities", "translation": "Forced displacement of people from their homes due to climate impacts", "legalRef": "UN Guiding Principles on Internal Displacement", "severity": "high", "confidence": 92 } ], "meta": { "phraseCount": 3, "riskScore": 7, // critical×10 + high×4 + medium×1 "wordCount": 14, "prevalencePer1k": 214.3, // detected phrases per 1,000 words "ai": true, "tier": "pro", "aiUsedToday": 1, "aiDailyLimit": 300 } }

detected[ ] fields

FieldTypeDescription
phrasestringThe detected phrase as it appears in the text
translationstringPlain-language description of the physical reality it conceals
legalRefstringCitation to Rome Statute, Geneva Conventions, UDHR, or Planetary Boundaries
severitycritical high mediumHarm severity level
occurrencesnumberTimes the phrase appears (phrase matches only)
confidencenumber 0–100AI confidence score (AI detections only)
communityConfirmedbooleanWhether the phrase was community-confirmed via the extension

meta fields

FieldDescription
riskScoreWeighted sum: critical×10, high×4, medium×1 — useful for ranking documents
prevalencePer1kDetected phrases per 1,000 words — useful for comparing documents of different lengths
aiWhether AI detection ran in this request
aiUsedTodayAI scans used today (only present when options.ai = true)
aiDailyLimitYour tier's daily AI scan limit

Error codes

StatusMeaningWhat to do
401Missing or invalid API keyCheck your Authorization header
403Key not yet activatedCheck your email — activation is instant for all tiers
429Daily AI limit reachedPhrase matching result is still returned. Upgrade or wait until midnight UTC for reset
400Invalid request bodyCheck JSON format and that text field is present and under 10,000 chars
405Wrong HTTP methodUse POST

On 429, the response still includes detected from phrase matching — you don't lose the result, just the AI layer.