Every panel says its answers come from real people. Almost none say how they know. We think that should be the first thing you ask, so here is the whole answer.
The problem we are solving
Paying strangers for opinions attracts three kinds of cheating. Scripts that answer at machine speed. Farms of phones run by one person. And people who are real but not paying attention. Each one needs a different check, and the checks only work if they are hard to fake cheaply.
Check one: the phone is a real phone
Every modern iPhone and Android phone has a small sealed chip that can sign a message in a way software can't imitate. When a head answers, the 50heads app asks that chip to vouch for three things:
- this is a real, physical device, not an emulator;
- it hasn't been rooted, jailbroken or tampered with;
- the app sending the answer is the one we published, unmodified.
Apple or Google checks the signature and tells us whether to believe it. If it doesn't check out, the answer never reaches you and the head isn't paid. This is why a script on a server can't answer 50heads questions at all, however clever it is.
Each answer in your results carries an attestation reference. It proves the answer came from a checked device without saying whose.
Check two: one real phone number per head
To be paid, a head verifies a phone number with a code by text or WhatsApp. Virtual numbers and VoIP numbers are refused. A number can belong to one account only.
Numbers are cheap in some places, so we don't stop there. Every month, a Tier 1 head who earned in that month confirms the same number again. It takes ten seconds for someone who still has their phone; it is expensive for a farm that rotates SIM cards.
Check three: a real identity, at Tier 2
Heads who want the higher-paying Tier 2 questions pass an ID and live-face check, once. It is run by a specialist provider, not by us. The provider checks the document, checks that the face in front of the camera matches it and is live, and checks the face against every other account so one person can't hold two.
We receive a yes or a no. The ID and face photos are deleted by the provider after its decision, within 30 days. We never see them. Tier 2 heads also get a three-second face check at random afterwards, so an account can't be verified once and then handed on.
Check four: attention
A verified person can still click without reading. So a few questions each day have answers we already know. Heads who get too many of them wrong stop seeing paid questions. We also hold back answers that arrive faster than the question could have been read, or in lockstep with other accounts, and review them.
What happens when we get it wrong
Automated checks make mistakes, and the people on the other end of them deserve a way out. Any head can appeal once a month, a person reads every appeal, and we publish how many we receive and uphold each quarter in our transparency note.
If we remove an answer after it has counted towards your result, you get the credit back and the result is recalculated.
What we keep
We keep as little as the checks need, for as long as they need it:
| What | How long |
|---|---|
| ID and face photos | Not kept by us; the provider deletes them within 30 days |
| Face match for duplicate accounts | With the provider while the account exists |
| Phone number | While the account exists, plus a scrambled copy for 12 months |
| Touch and timing signals | 90 days; summary patterns for up to 24 months |
| Answers | Never shown with a name |
The full detail is in our privacy notice and on how we verify.
Why publish it
Because "trust us" is not a verification method. If you can read how the checks work, you can decide whether they are good enough for your question, and you can hold us to them.