Ally · A Chrome extension
Measures what a page does to your choices
Ally measures the choice architecture of the pages you visit — the geometry, contrast, wording and click depth of the options put in front of you — and turns it into evidence you can hand to someone else. Everything runs on your device. Nothing is uploaded, because there is nowhere to upload it to.
Free, GPL-3.0, and open source. Chrome. Edge and Brave work, with caveats noted below. Not Firefox, not Safari.
Before you click download
Ally is not in the Chrome Web Store. There is no store button on this page because there is no listing to point at; no developer account exists yet.
Installing it today means downloading a zip file, unzipping it, and adding the folder to Chrome by hand. It takes about two minutes. There is no account and no sign-in, and nothing in the file executes — it is not an installer, it is a folder of files Chrome reads.
We would rather you learn that here than after the download.
SHA-256 · 8f4d4c58e0c043097c3811ebd53249302c670333bc182dcbdc9c4959d8d87b48
With no store signature and no public repository to compare against, this hash is the only integrity check available. Check it if you want to: shasum -a 256 ally-plugin-0.1.0.zip on macOS or Linux, certutil -hashfile ally-plugin-0.1.0.zip SHA256 on Windows.
What Ally does
Ally measures the interface, not the person reading it. When a cookie banner makes Accept a large filled button and Reject a line of grey text three clicks away, that difference is a number: pixel area, contrast ratio, font size, click depth. Ally computes the number and shows you the working.
Every finding is an arithmetic measurement of the live DOM — pixel geometry, WCAG contrast ratios, click depth, computed styles. No inference, no model, no network call.
There is one feature. Ally measures and reports. It does not block anything, change anything, hide anything or fix anything, and it never modifies the page it is looking at.
This is what a measurement looks like when you open the panel: prominence 1.00 means the decline control has no button behind it at all. It is a bare text link styled to look like a choice. That is a measurement, and it is not arguable.
What it measures
Ally does not have a list of bad websites. It has a list of measurements, and it runs them on whatever page you are on.
Cookie banners and consent choices
Whether agreeing is made easier than refusing, and by how much. Ally takes five ratios between the accept and the decline control — pixel area, label contrast, button contrast against the surface, font size, and clicks to reach it — and combines them as a geometric mean, so one ten-fold gap cannot be cancelled out by four ratios of one. It also reports the plainer cases: no way to refuse at all, refusal buried in a submenu, a decline control with no button behind it, boxes ticked before you touch them, a choice missing from the accessibility tree, refusal costing ten or more extra tab stops, only the accept button animating, refusal worded as self-criticism, and a banner that comes back in the same session after you already declined. Consent-or-pay is classified and never scored, because whether paying to refuse is lawful is a live question and the tool has no view.
Urgency, scarcity, and numbers with nothing behind them
Countdown timers that contradict themselves: the same “ends today” seen on two different days, or a timer that resets on reload. Live counters — “14 people are viewing this” — whose value moves with no network request behind it in the same window. A number that moves with nothing behind it was not observed, it was generated.
Money, offers and checkout
A recurring charge measured against the offer beside it — its type size and contrast, or its absence from the offer’s own surface entirely, which carries a verdict of its own. Also: charges named at the checkout that were not named at the advertised price, a priced line item that appeared between two pages with no click of any kind in between, and an amount advertised in one currency and charged in another.
Feeds and attention
Autoplay with the next item already queued, so continuing is the default and stopping is the action. A stopping cue with more feed beneath it, measured in pixels. Streak counters. “Someone is waiting for your reply.” Notification prompts that return after a refusal. Sponsorship disclosures too: whether one exists, and its type size and contrast against the content it labels. That disclosure is almost always present; what gets measured is how visible it is.
Patterns aimed at people least able to absorb them
Age gates that record an answer rather than check one. Randomised rewards with no published odds. Credit promoted above paying outright at checkout. All three are pattern-matched rather than measured, and the project calls them the highest-stakes rows here.
The way in versus the way out
Record a signup, record the cancellation, and compare them: clicks, pages, loops, pages that exist only to argue back, and any finding met on the way. “Two clicks to subscribe, fourteen to cancel” is the sentence this exists for. The verdicts are comparable effort, harder to leave, substantially harder to leave, and cancellation pushed offline when the journey ends by telling you to telephone someone. Recording is off until you press Record, and it runs on one tab.
The parts it could not read
Ally reports its own blind spots on every page rather than staying quiet about them: closed shadow roots, cross-origin frames it could not enter, and canvas regions covering a quarter of the screen or more with no DOM behind them, counted and named. A large canvas is reported as unanalysable, never as evasion — it is a map or a chart far more often than a hidden consent wall. If a detector throws, the panel says so: these measurements were not made, so this page has not been fully checked. That is a bug in the tool, not a finding about the site. If a community rule silenced a detector, the panel names the rule, the reason its author gave, and who they were.
Absence of findings is not a clean bill of health — it means nothing this tool currently measures was detected.
What you can do with a finding
Every finding carries a basis rather than a confidence score. Proof means two of the page’s own statements contradict each other. Measured means an arithmetic gap between two controls. Heuristic means pattern-matched language — the first thing to doubt if a finding looks wrong.
There is no confidence number. A reader can act on “this was measured” or “this was pattern-matched”. Nobody can act on 0.82.
Findings are classified under two published taxonomies — Mathur et al. (2019) and EDPB Guidelines 03/2022 — and left empty where neither scheme’s own definition fits. Each finding also names the provision that a pattern of that kind is normally assessed under: GDPR Article 7, DSA Article 25, DMA Article 5(2) and 13(6), the Unfair Commercial Practices Directive, CPRA symmetry-in-choice, FTC Act section 5, Consumer Rights Directive Article 22, WCAG.
It does not assert that any site is breaking the law. It reports measurements and a taxonomy classification. Legal conclusions are for lawyers and regulators. Nothing on this page, and nothing the tool prints, is legal advice.
You can export a finding as JSON, Markdown, HTML, a one-line summary, or a body ready to paste into a bug tracker. Bundles are versioned, deterministic and SHA-256 tamper-evident, and they carry replication instructions and a surface fingerprint, so someone else can run the same check and see whether they get the same answer.
One visit is not enough. Press “Keep this capture” and Ally counts agreeing visits: seen too few times to publish, seen consistently, this site varies by visit, could not reproduce. Three agreeing captures are asked for before a finding about a named company is more than an anecdote. A single capture cannot tell a policy apart from an accident.
Read this before you install
What Ally gets wrong
An evidence tool with an unknown false-positive rate is an opinion with numbers attached, so the number is stated rather than promised. The extension prints the second of the paragraphs below — the error rate — in every panel that has findings, and in every export. It belongs on this page for the same reason.
There is no accuracy figure
There is no published precision or recall figure, because there is no labelled corpus to compute one against. Building one needs multiple independent human annotators over a thousand-plus real choice surfaces, and that has not been done. So there is no percentage anywhere in this product, and the code refuses to print one.
The one field measurement that exists is unflattering
In the tool’s own words: “Known error rate: in an early sweep of 63 real sites, 9 of 18 findings were wrong. 8 were traced to specific causes and fixed with regression tests, but the tool has no precision figure because there is no labelled corpus to compute one against. Check the measurements above rather than taking the verdict on trust.”
Absence of findings is not a clean bill of health
It means nothing this tool currently measures was detected. A quiet page may be a fair page. It may also be a page built in a way Ally cannot read, which is why the panel prints the count of what it could not read alongside the silence.
Nobody has used it yet
Ally is in early development: 184 of 250 checklist items, and not published anywhere. No users, no reviews, no install base, no track record. What it is short of is distribution, an accuracy figure, and a second pair of hands. If you install it today you are the first pass of testing, not the beneficiary of someone else’s.
It can be evaded
Trivially, and by design decisions we are not going to reverse. An interface drawn on a canvas defeats every detector. A wording lexicon misses any phrase that is not in it. A site can serve a fair page to anyone who looks like a researcher. The one asymmetry in the tool’s favour: evading a measurement of choice architecture means changing the choice architecture.
Sites can detect it
Overlay element ids are randomised on every page load, the analysis bundle has no guessable path, and nothing is written to a page until you reveal a finding, so a passive page learns nothing. That is reduced, not prevented. Anything drawn on a page can be found by something determined enough to look for its shape.
The scores are ordinal
The obstruction score says one flow is more obstructed than another. It does not say 23% unfair. Two scores are comparable only when they come from two flows on the same site. Its weights are published so you can disagree with them: offline-only exit 25, each retention interstitial 8, each loop 5, each excess click 2, each finding met on the way 4.
Where you are sitting changes what you see
Consent surfaces are commonly served on IP address, so a reader outside the EU or the UK will simply see fewer consent walls. That is a property of the sweep rather than of the sites.
About two minutes
Install it by hand
These steps exist because Ally is not in the Chrome Web Store. When it is, this section becomes one button and these steps move underneath it for anyone who still wants the file.
Chrome is the browser these steps were written and checked against. Edge and Brave work the same way with one difference each, noted further down.
If the toggle is greyed out
One thing first, because it is not your fault if it happens: if the Developer mode toggle in step 4 is greyed out, your employer or your school has turned it off with a Chrome policy. You can confirm at chrome://policy. There is nothing you can do from your side, and nothing is wrong with your download.
Download the file
Ally 0.1.0, 219 KB, a .zip. The SHA-256 is at the top of this page if you want to check it. Nothing in the file runs. It is not an installer; it is a folder of files Chrome reads.
Unzip it, then move the folder somewhere permanent
On macOS, double-click the zip; Safari may have already expanded it for you, in which case you will see both a zip and a folder. On Windows, right-click the zip, choose Extract All, then Extract. Both name the folder after the archive, so you should end up with a folder called ally-plugin-0.1.0 with manifest.json sitting directly inside it. Now move that folder somewhere you will not tidy up later — Documents/ally-plugin-0.1.0, not Downloads. Chrome identifies the extension by that exact folder path and reads it from there at every launch. Move it, rename it, or empty your Downloads folder later, and Ally either loses all its settings or disappears without an error.
2a · If you are on Windows, read this one twice
Double-clicking a zip in Windows Explorer only previews it. It looks like a folder and behaves like one, but nothing has been extracted. You have to use Extract All. This is the single most common reason step 6 fails.
Open the extensions page
Type or paste chrome://extensions into a new tab and press Enter. It is not a link on this page because Chrome blocks web pages from linking to chrome:// addresses; a clickable one would silently do nothing. The menu route works too: the three-dot menu, then Extensions, then Manage Extensions.
Turn on Developer mode
The toggle is at the top right of the extensions page, labelled Developer mode. Turn it on and leave it on. Since Chrome 133, extensions loaded from a folder are bound to this toggle: turn it off and Chrome disables Ally. This is a permanent change to your browser’s configuration that the manual route forces on you, and a store install would not.
Click Load unpacked
Three buttons appear at the top left once Developer mode is on: Load unpacked, Pack extension, Update. Click the first. Ignore the other two — Update in particular does not do what its name suggests, and there is a section on that below.
Select the folder, not a file
In the picker, click the ally-plugin-0.1.0 folder once to highlight it, then press Select or Open. Do not open the folder and choose manifest.json. Do not point at the zip.
Confirm it loaded
An Ally card appears on the page and a message reads Extension loaded. There is no “Add extension?” dialog and no permission prompt; Chrome does not show one for a manual install. If you are used to store installs, the missing dialog reads like a failure. It is not. If you see Failed to load extension or Could not load manifest instead, you selected the wrong folder — the one you want is the folder with manifest.json directly inside it, so go up one level, or the zip was never actually extracted.
Pin it to the toolbar
Click the puzzle-piece icon to the right of the address bar, find Ally in the list, and click the pin beside it. The card’s Details page has the same option. Without this, Ally works but is invisible, which also reads as a failed install.
Reload a page, then click the icon
Ally’s content script runs when a page loads, so any tab that was already open before the install has nothing on it. Open or refresh an ordinary http or https page, then click the Ally icon.
How to remove it, which takes two actions rather than one
Click Remove on the Ally card at chrome://extensions, then delete the ally-plugin-0.1.0 folder yourself. Chrome does not delete it for you. The exit belongs next to the entrance.
What Chrome will tell you about Ally
It will say full access
Chrome will say Ally can read and change your data on every site. That is Chrome describing the content script, which matches http and https pages, and it is the same sentence it shows for any extension that reads pages. Reading the page is the measurement. The reading happens on your device, there is no network code in the extension, and nothing is transmitted. The manifest asks for activeTab and storage and declares no host permissions. In the puzzle-piece menu Ally is grouped under “Full access — These extensions can see and change information on this site.” On the Details page it reads “This extension can read and change your data on sites.” We would rather you meet those sentences here than after a page that told you there were only two permissions.
Leave site access on all sites
Leave Site access set to On all sites. Chrome offers On click, On specific sites, and On all sites, and On all sites is the default. Tightening it to On click withholds the content script and Ally quietly stops measuring — which looks like a broken extension rather than a setting.
It will say it cannot be reviewed
Chrome will keep saying Ally can’t be reviewed by the Chrome Web Store. That is accurate. It is a statement about where the file came from, not a finding about what it does. If you ever turn Developer mode off, Chrome greys Ally out, shows that exact line, and adds a page-level notice reading “Developer Mode Off. Some extensions were disabled.” Turn Developer mode back on and Ally comes back.
It will print your folder path
The Details page prints the full path to your folder under “Loaded from”. That is normal for a folder install. It is Chrome telling you where it read the files, and nothing more.
Older versions of Chrome nagged about developer-mode extensions on every launch. Current Chrome does not.
After it is pinned
The first five minutes
Ally does not run on chrome:// pages, the Chrome Web Store, the built-in PDF viewer, or file:// pages. Nothing is broken when the icon does nothing there.
Point it at a page with no banner at all, first. What you get back is the “not a clean bill of health” message, plus counts of the closed shadow roots, unenterable frames and canvas regions Ally could not read. Seeing what the tool says when it finds nothing is the fastest way to calibrate what it says when it finds something.
- A page with no banner at all, first.
- Then a European news site’s cookie banner — the densest source of the asymmetry measurement.
- Then a free-trial signup page, for the recurring-charge disclosure: what gets measured is how small and faint it is next to the offer, or whether it is on the offer’s surface at all.
- Then a checkout with fees.
- Then, if you have twenty minutes, record a subscription signup and its cancellation and compare the two.
If you are outside the EU or the UK you will simply see fewer consent walls, because consent surfaces are commonly served on IP address. That is a property of where you are sitting, not of the sites.
There is also a demo page here, built to be measured: one labelled section per pattern, no network requests, no cookies. You already know the answer on that page, so you can check the tool rather than take its word. Its last section is a balanced two-button choice that Ally should report nothing about — if the panel flags anything there, that is a false positive and worth telling us about.
If you would rather not install anything yet, there is a smaller trial: open a page with a cookie banner, open DevTools, and paste the contents of asymmetry-console.js — it sits at the root of the zip — into the console. It prints the asymmetry measurement and nothing else.
Other browsers
Chrome is the one supported browser. The rest of this list is what we know, and what we have not checked.
The browser the steps above were written and checked against.
The same, with one difference that will otherwise break step 4: the Developer mode toggle is at the bottom left of the sidebar, not the top right. The address is edge://extensions and the button still reads Load unpacked. Edge also shows its own standing notice about extensions that did not come from the Microsoft Store.
Identical to Chrome at brave://extensions, and it inherits the same Chromium developer-mode binding. One caveat that matters for a measurement tool: Brave Shields suppress some consent surfaces and trackers before Ally ever sees them, so Ally reports fewer findings in Brave. That is a property of the browser, not of the sites — the same reasoning that applies to where in the world you are sitting.
Not tested. The page is opera://extensions and the button reads Load unpacked extension…, but unpacked extensions are widely reported not to survive a restart in some Opera configurations. We are not going to publish steps we cannot stand behind.
Should work, untested. Arc has been in maintenance mode since 2025; it still runs Chrome extensions but gains no features. Reach the page through the Arc menu, then Extensions, then Manage Extensions, since Arc’s command bar hides chrome:// addresses.
They work the same way.
No. Ally is a Chrome Manifest V3 extension with a service worker. It does not install in either, and there is no build that does.
A real cost of the manual route
There is no auto-update
An extension installed from the store updates itself, silently, within hours. A folder never does. Ally 0.1.0 stays 0.1.0 until you download a new zip yourself. Ally also cannot tell you that an update exists, because it makes no network requests at all. That is the same property that keeps your browsing on your device, and this is what it costs.
How you will know: this page carries the current version number, at the top and on the button. Check back, or email us and we will tell you when it changes.
The Update button is a trap
The Update button on chrome://extensions does not update anything. For a folder install it re-reads the folder from disk and then reports “Extensions updated”. Clicking it will make you believe you are current when you are not, which is worse than not knowing.
The correct way to update, when there is something to update to: download the new zip, replace the contents of your existing Ally folder, keep the folder exactly where it is and keep its name unchanged, and click the circular reload arrow on the Ally card. Do not unzip somewhere new and load that. Chrome derives the extension’s identity from the folder path, so a new path is a new extension — your settings and kept captures are gone, and the old copy is still loaded alongside it.
One consequence of the same mechanism: every person’s copy of Ally has a different extension ID, because the ID is a hash of their folder path. There is no shared identifier for this extension, so no instruction, script or support reply should ever ask you for one.
Nothing is transmitted
What leaves your device
Nothing. That is not a policy, it is a property of the build.
- Permission · activeTab
- Permission · storage
- Host permissions · none
There is no server, no endpoint and no account. There is no fetch, XMLHttpRequest, WebSocket or sendBeacon call site anywhere in the extension. One test blocks every off-origin request, confirms the extension still measures and still renders its panel with the network down, and confirms nothing off-origin was even attempted. Another greps the source for those call sites, and a third checks that the grep would catch one if it were there.
Two permissions, both used, both justified against the shipped manifest by a test: activeTab and storage. A third, scripting, was requested, found never to be called, and removed rather than justified. There are no host permissions, and a test asserts the manifest declares none. activeTab exists for one thing: a screenshot you tick a box for, on the tab you invoked Ally on. Chrome grants it on the toolbar click and it expires.
Ally does measure pages as you browse. The content script is declared against http and https on all frames, and that is the honest description — it is not the same as sending anything anywhere. The top frame of an ordinary page always loads the analysis module; the gate is for everything else. It is 1.3kB of code, and a subframe has to be at least 20,000 square pixels and contain consent vocabulary before the module is loaded into it, so a page with thirty ad frames does not parse the detector suite thirty-one times.
Where things are kept. Settings live in storage.local, deliberately not storage.sync, because sync would upload your browsing preferences — including your excluded-site list — to Google’s servers. Per-tab findings live in storage.session and die when the browser closes. Kept captures live in storage.local, written only when you press “Keep this capture”, and hold a fingerprint and a list of finding ids: enough to say whether two visits agreed, not enough to reconstruct a page. “Forget them” deletes them.
Form values are never read. Not scrubbed afterwards — never read. During a recording you started, a step stores a field’s name, its type, and a true or false for whether it was non-empty. There is nowhere in the schema for a value to go.
Sharing is always a separate action you take on purpose, and you see the artefact before it goes anywhere. The panel previews both: the full report headed for the clipboard, and the shorter body a tracker link would carry. Before either can leave, control labels and URLs are scrubbed for credentials, tokens, email addresses and session ids in the path, query and fragment, and the number of removed items is printed in the report. Scrubbing works from a denylist, so it is a floor rather than a promise.
Screenshots are opt-in per report and off by default, the warning appears whether or not the box is ticked, and the image is previewed before it can be saved. A screenshot captures pixels, and pixels cannot be scrubbed.
No account, no sign-in, no sync, no telemetry. There is a telemetry: false flag in the defaults purely so that the absence is written down somewhere.
Ally never changes the page it measures. A test strips the overlay’s own elements and asserts the rest of the document is byte-identical before and after a pass, with focus and scroll position unmoved. The overlay is off by default; the tool is silent unless asked. The toolbar badge is a neutral grey count — the badge reports, it does not alarm.
One limit worth stating rather than smoothing over: anyone with your unlocked Chrome profile can read Ally’s storage the same way they could read any other extension’s. The mitigation is that there is very little there.
You choose where it runs: everywhere except sites you exclude, or only on sites you list.
When Ally is in the Chrome Web Store
Not submitted. No developer account exists yet and no listing has been created. It is on the roadmap. The extension is built so that a rejection would cost distribution and nothing else — no server, no licence check, no store-dependent behaviour — because it has to keep working when loaded from a folder.
When there is a listing, this page changes in one place. The install section becomes a single button, and the manual steps move underneath it for people on managed machines, people running a fork, and people who would rather not use the store. The steps do not disappear.
What a store listing would change
One-click install, silent updates, sync across your signed-in Chrome profiles, an uninstall that also cleans up after itself, no Developer mode toggle to leave on, and a reviews and report-abuse channel that does not exist today. An IT administrator could deploy it to a team, which is not possible for a folder install at all.
What it would not
What Ally measures, the two permissions, the absence of any network request, the licence, the error rate, or anything else on this page.
Two things to be plain about while there is no listing. Nobody at Google has looked at this code, so no part of this install carries a review or an endorsement — the trust case is the two permissions, the absence of network code, the GPL-3.0 licence this is published under, and the documentation shipped inside the download. And Chrome’s Safety Check, the mechanism that flags extensions as unsafe, malicious or unpublished, works from store-derived signals. An extension loaded from a folder has none, so it is not something Safety Check reports on. That silence is not a clearance. It is the same shape as the sentence this tool prints about the sites it measures: absence of findings is not a clean bill of health.
For the record, on the data-collection questionnaire a listing would require, every category — personally identifiable information, health, financial, authentication, personal communications, location, web history, user activity, website content — is answered No. Nothing is collected, because nothing is transmitted.
What Ally does not claim
Some of these are enforced by tests that fail the build, not by editorial care. The three the plugin enforces on its own source — no claim about minds, no claim that a site broke the law, no claim of certainty — are enforced on this page too, by a test in this repository that runs the same three patterns over this file. The list is here so you can hold the page to the same standard as the code.
- That any site has broken any law. Ally never says that. It names the provision that a pattern of that kind is normally assessed under. Whether a particular interface infringes depends on facts a browser extension cannot observe. Nothing here is legal advice.
- Anything about minds. Ally measures interface structure — geometry, contrast, wording, click depth. It does not claim to know what you are thinking, feeling or intending. This project began as an idea about predicting responses to page elements; nothing in it measures a person, so the claim was removed and a test now fails the build on any sentence that reaches for it.
- That it uses AI. There is no model, no machine learning, and nothing inferred. Every finding is either measured or pattern-matched, never guessed by a model, and a test fails the build the day that stops being true.
- A confidence score. Every finding says what kind of evidence is behind it — proof, measured, or heuristic. A number like 0.82 would be invented precision.
- An accuracy, precision or recall percentage. The only honest number this project has is a count, and the code refuses to print a percentage in the accuracy note.
- That it protects you. Ally does not block, fix, remove, hide or defend against anything. There is no second feature, and it never changes the page it measures.
- That it catches everything. Coverage of a catalogue of patterns is coverage of a catalogue. It is not a protection figure, and it does not make a quiet page a safe one.
- That sites cannot detect it, that it is invisible, or that it is undetectable.
- That its scores can be compared between sites. Two obstruction scores can be compared with each other only when they come from two flows on the same site.
- That exports are anonymised. Scrubbing works from a denylist, which makes it a floor, and pixels in a screenshot cannot be scrubbed at all.
- That the code is unminified. The shipped bundle is minified to fit an 8kB-per-frame budget. That is not obfuscation, and it is not a transparency claim either.
- That it works in Firefox or Safari.
If Ally gets something wrong about a site
Free, and GPL-3.0. The source will be published. It is not published yet, which is why there is no repository link on this page and no issue tracker to point you at. The copyleft is deliberate: a tool that exists to hold interfaces accountable should not be forkable into something closed and declawed. One gap worth naming rather than leaving to be found: the licence text itself is not yet inside the zip. That is a packaging omission, not a change of terms, and it ships with the next build.
The download carries its own documentation, written before this page and more detailed than it — seven documents: limitations, methodology, the threat model, the corrections process, the irreversible-decision log, the roadmap, and the store disclosure the all-No data-collection table above is taken from. Where this page and those files disagree, the files are the ones we maintain — with one exception. Two of them tell you to open a GitHub issue, and there is no public repository to open one on. Until there is, the email address below is the intake channel they mean.
There is a corrections process, written down and shipped inside the download. If Ally reports something about a site and the measurement is wrong, we reproduce it, fix it if it is wrong, and publish the reply if it is not. A confirmed false positive becomes a test fixture in the same change that fixes it. If a community rule names your site and you dispute it, the rule is suspended while the dispute is open.
The boundary is the point: that is the whole difference between a corrections process and a deletion service.
Two caveats we would rather state than have you discover. The corrections register is empty, because nothing has been reported yet. And a takedown process with a single decision-maker is a single point of capture — that weakness is named in the document rather than argued away.
To report a false positive, a bug, or a page Ally read wrong, email support@quintally.com. Include the address of the page, what Ally said, and what you think it should have said. There is no public issue tracker yet, so that address is the whole process.