Legal
SlopSquash Privacy Policy
contents
- 1. Who we are and what this policy covers
- 2. The short version
- 3. Definitions
- 4. Data we collect
- 5. What the Extension sends, and when
- 6. The Verdict Cache
- 7. Community reports
- 8. Payments
- 9. Creator program
- 10. Cookies and local storage
- 11. How we use personal data
- 12. How we share personal data
- 13. International transfers
- 14. Retention
- 15. Security
- 16. Your rights (all users)
- 17. European Economic Area, United Kingdom, and Switzerland
- 18. California residents (CCPA / CPRA)
- 19. Nevada residents
- 20. Virginia, Colorado, Connecticut, Texas, and other US states
- 21. Children
- 22. Deleting your account
- 23. Automated decisions
- 24. Do Not Track and Global Privacy Control
- 25. Changes to this policy
- 26. Contact
1. Who we are and what this policy covers
SlopSquash is operated by William Freire, doing business as Slop Squash, a sole proprietorship operating from New York, United States, with a mailing address at 300 West 109th Street, New York, NY 10025, United States ("SlopSquash", "we", "us", "our").
This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It applies to:
- the SlopSquash browser extension for Chrome and Firefox (the "Extension");
- the website at slopsquash.com, including the account pages and the creator portal (the "Website");
- the API at api.slopsquash.com (the "API");
- the administrative console at admin.slopsquash.com (the "Admin Console"); and
- our email communications with you.
Together these are the "Service". This policy does not cover third-party websites on which the Extension displays its overlay. Those sites are governed by their own privacy policies.
Capitalized terms not defined here have the meaning given in the SlopSquash Terms of Service.
2. The short version
- We collect the minimum needed to run an account, bill you, and analyze the content you ask us to analyze.
- We never see your card number. Stripe handles payment. If you are a creator, Stripe also handles your payouts, and we never see your bank account or tax details.
- The Extension sends the text of posts and comments it analyzes, and the URLs of images it analyzes, to our API. It does not send the page URL (only the hostname), and it does not send your browsing history.
- For images, our API fetches the image file from that URL and sends the file, with no account data and no page information, to OpenAI's content provenance API (and, when enabled, Google's AI Content Detection API) to check for watermark and Content Credentials signals.
- "On-device only" mode sends nothing to us, and therefore nothing to those providers.
- Verdicts are cached by a hash of the content and shared with all users. The cache never contains your identity.
- We do not sell personal data, we do not share it for cross-context behavioral advertising, and we run no ads and no third-party ad trackers.
- You can delete your account at any time from the Account page on slopsquash.com, or by emailing privacy@slopsquash.com.
3. Definitions
"Personal data" means information that identifies, relates to, or could reasonably be linked to you. "Content" means text, images, or other material on a third-party web page that the Extension analyzes. "Content Hash" means a one-way cryptographic digest of a piece of Content that cannot be reversed to recover the Content. "Verdict" means the output of our detection pipeline for a piece of Content: a label (human, uncertain, or ai), a score from 0 to 1, and explanatory notes. "Verdict Cache" means our shared database of Verdicts keyed by Content Hash. "Processor" means a company that processes personal data on our behalf and under our instructions.
4. Data we collect
The table below lists each category of personal data we collect, where it comes from, why we use it, and the legal basis we rely on where the GDPR or UK GDPR applies.
| Category | Examples | Source | Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|---|---|---|
| Account data | Email address, display name, hashed password (PBKDF2-SHA256; we never store the password itself), email verification status, date you accepted the Terms, account role, suspension status, timestamps | You | Creating and securing your account, signing you in, contacting you about the Service | Contract |
| OAuth profile | Provider name (Google or GitHub), the provider's user ID for you, the email address and name the provider returns | Google or GitHub, when you choose to sign in with them | Creating or linking your account without a password | Contract |
| Session data | Session token identifiers, token type (web or extension), creation, expiry, and last-used timestamps | Generated by us | Keeping you signed in on the Website (14 days) and in the Extension (90 days) | Contract |
| Billing data | Stripe customer ID, Stripe subscription ID, plan, subscription status and billing period, one-time purchase records (Stripe session ID, plan, amount), payment failure reasons, timestamps of checkout attempts | You (via Stripe Checkout) and Stripe | Providing paid features, fulfilling your purchase, preventing fraud, tax and accounting | Contract; Legal obligation (tax and accounting); Legitimate interests (fraud prevention) |
| Content submitted for analysis | Text of posts, comments, and similar user-generated content; URLs of images and the image files our API fetches from those URLs; the hostname of the page (for example reddit.com), never the full URL |
Your Extension, when network detection is enabled; image files from the public web page that hosts them | Producing a Verdict, including sending image files to provenance verification providers (Section 5.2); enforcing daily usage limits; per-site usage statistics | Contract (delivering the detection you requested); Legitimate interests (abuse prevention) |
| Verdict Cache entries | Content Hash, content kind (text or image), score, label, detector signals, notes, recheck result, the source URL of an image, hit count, timestamps | Generated by our detectors and, for Pro users, the vision-language-model recheck | Returning consistent Verdicts quickly to every user; improving accuracy over time | Legitimate interests (operating and improving the Service). Not personal data about you: no user identifier is stored |
| Community reports | Content Hash, your user ID, whether you reported the Content as AI or human, timestamp | You, when you click "Report as AI" or "Report as human" | Blending community judgment into Verdicts; detecting report abuse | Legitimate interests; Contract |
| Usage counters | Daily counts of detection and recheck requests, keyed by your user ID or, for signed-out requests, a hashed IP address | Generated by us | Enforcing tier limits (Free: 400 detections per rolling 24 hours; Pro: 5,000 detections and 300 rechecks) and rate limiting | Contract; Legitimate interests |
| Extension settings | Per-site enable or disable, sensitivity preset, auto-block toggle, on-device-only toggle, extension token | You | Making the Extension behave the way you configured it | Stored locally in your browser. Not transmitted to us except the token used to authenticate API calls |
| Creator program application | Display name, platforms, channel URL, audience size, pitch, the email address you want payout notices sent to, application status, the output of automated review (decision, confidence, reasons, risk flags), human reviewer notes | You; publicly available metadata we fetch from the channel URL you provide (page title, Open Graph title and description, meta description) | Reviewing your application; running the program | Contract (the Creator Program Terms); Legitimate interests (fraud prevention) |
| Referral and commission data | Referral link slug, visitor hash (a salted SHA-256 of IP address, user agent, and calendar day), landing path, conversions (referred user ID, plan, amount paid, commission, status), payout records (amount, date, status, Stripe transfer ID) | Generated by us; Stripe | Attributing sign-ups, calculating and paying commissions, tax reporting | Contract; Legal obligation (tax) |
| Creator payout account | Stripe Connect account ID, onboarding status, whether Stripe has enabled payouts, whether Stripe has outstanding requirements, timestamps. Your identity documents, bank account details, and tax forms are collected and held by Stripe, not us (Section 9) | Stripe (account status events); generated by us | Knowing whether and where we can pay your commissions; showing payout status in the creator portal | Contract (the Creator Program Terms) |
| Referral cookie | The sv_ref cookie containing the referral slug |
Set when you visit a creator's referral link | Applying the referral discount at checkout within 30 days | Legitimate interests; Consent where local law requires it for non-essential cookies |
| Technical and log data | IP address, user agent, request path, response status, timing, error details | Your browser or Extension, via Cloudflare | Security, debugging, abuse detection, capacity planning | Legitimate interests (security and operations) |
| Support communications | Your email address and the content of messages you send us | You | Answering your requests | Contract; Legitimate interests |
| Admin Console audit data (staff only) | Staff email, IP address, action, target record, timestamp | Generated when staff act in the Admin Console | Accountability for administrative actions | Legitimate interests |
We do not collect precise geolocation, biometric data, health data, government identifiers, or any of the categories of "sensitive personal information" listed in the California Privacy Rights Act other than account login credentials (which we store only in hashed form and use only to authenticate you). Creators who set up payouts give government identifiers, bank account details, and tax information to Stripe directly; we do not receive them (Section 9).
5. What the Extension sends, and when
This section is the authoritative description of the Extension's network behavior. It matches the "Data handling summary" in our store listings.
5.1 In every mode
The Extension talks only to api.slopsquash.com. It does not contact any other server. It does not read or transmit your browsing history, your bookmarks, your passwords, form fields, or the contents of pages other than the user-generated Content it is analyzing. It does not transmit full page URLs. It does not capture screenshots.
The Extension keeps a small amount of data locally in your browser: your extension token, your settings, and a per-tab memo of recent Verdicts (in chrome.storage.session, cleared when the browser closes).
5.2 Free tier, network detection enabled (the default)
When you scroll a supported page, the Extension identifies posts, comments, and images near your viewport and:
- Runs on-device writing-pattern analysis on text. This happens entirely inside your browser.
- Sends batches of up to 25 text items (up to 8,000 characters each) to
/v1/detect/textso we can run provenance checks (such as Google SynthID, where available) and look up the Verdict Cache. - Sends batches of up to 12 image URLs to
/v1/detect/image. Our server fetches the image from that URL (up to 8 MB) to read its Content Credentials (C2PA), EXIF, and IPTC metadata. The Extension never uploads image bytes on the Free tier. - Sends the fetched image file to OpenAI's content provenance API (
api.openai.com/v1/content_provenance_checks) to check for SynthID watermark and Content Credentials signals, and, once we are granted access and have enabled it, to Google's AI Content Detection API for the same purpose. These providers receive only the image file. They do not receive your account data, your extension token, the page hostname, or the page the image appeared on. Google states that its AI Content Detection API does not store or retain processed images. OpenAI's handling of the image is governed by OpenAI's API data usage policy. You can turn this off entirely with the Extension's on-device-only mode (Section 5.4). - Optionally includes the hostname of the page (for example
x.com) so we can produce per-site usage statistics. The path, query string, and fragment are never sent.
If you are signed in, requests carry your extension token so your daily limit is applied to your account. If you are not signed in, requests are anonymous and limited per hashed IP address.
The text you send is processed in memory to produce a Verdict. We do not store the text in the Verdict Cache. We store only its Content Hash and the resulting Verdict.
5.3 Pro tier
Everything in 5.2 applies, with higher daily limits. In addition:
- Recheck. When you click "Recheck", the Extension sends the text, or the image URL, to
/v1/detect/recheck. Our API passes it to a vision-language model or a text model running on Cloudflare Workers AI and receives back a probability and notes. The result is written to the Verdict Cache against the Content Hash and is returned to every user who later encounters the same Content. The Verdict Cache entry never records who requested the recheck. - Auto-block and per-site rules. These are enforced locally. Your allow-lists and per-site rules are stored in your browser and are not sent to us.
5.4 On-device only mode
If you enable "on-device only" in the Extension popup, the Extension sends nothing to us. Detection is limited to the on-device writing-pattern heuristics and to Content Credentials it can read from same-origin images. No text, no image URLs, no hostnames, and no usage counts leave your browser, and consequently no image file is sent to OpenAI or Google on your behalf. Your extension token remains stored locally so you can re-enable network detection later.
5.5 Signed-out use
You can use the Extension without an account. In that case there is no account data, and API requests are rate limited by a hashed IP address that is kept only as a daily counter.
6. The Verdict Cache
The Verdict Cache is the shared memory of the Service. Every entry is keyed by a Content Hash. An entry contains the kind of Content, a score, a label, the signals produced by each detector, human-readable notes, an optional recheck result, the source URL of an image (so that the same image seen on two sites resolves to one Verdict), and a hit count.
An entry never contains a user ID, an email address, a session identifier, an IP address, or the text that was analyzed. Because entries are not linked to any person, we treat them as anonymous data and retain them indefinitely. Deleting your account does not remove Verdict Cache entries, because nothing in them refers to you. See Section 22 for what you can ask us to remove.
The source URL of an image can, in rare cases, identify a person (for example, a profile-picture URL that contains a username). If you believe a Verdict Cache entry contains a URL identifying you and you want it removed, email privacy@slopsquash.com with the URL. Our support staff can purge individual entries.
7. Community reports
When you click "Report as AI" or "Report as human", we store one record per user per Content Hash containing your user ID, your vote, and a timestamp. Reports are tallied (AI versus human) and blended into the Verdict for that Content when three or more reports exist. Your individual vote is never shown to other users; only the counts are. Report records are deleted when you delete your account.
8. Payments
All payments are processed by Stripe, Inc. through Stripe Checkout and the Stripe customer portal. Your card number, expiry date, and security code are entered on pages served by Stripe and are never transmitted to or stored by SlopSquash. We receive and store your Stripe customer ID, subscription ID, plan, status, billing period, and the amount and date of one-time purchases. Stripe's handling of your payment data is governed by Stripe's own privacy policy at stripe.com/privacy.
Before checkout, we run a small set of automated fraud checks: your email must be verified, disposable email domains are rejected, and we apply per-account velocity limits and a cool-down after declined payments. These checks use only the data described in Section 4.
9. Creator program
If you apply to the creator referral program, we collect the application data described in Section 4 and review it in two stages:
- Automated review. Your application, together with public metadata we fetch from the channel URL you provided, is sent to a large language model operated by DeepSeek. The model returns a recommendation (approve, reject, or manual review), a confidence score, reasons, and risk flags. We store this output on your application record. DeepSeek receives only the application fields and the fetched metadata; it does not receive your account password, billing data, or detection activity.
- Human review. An application is automatically approved only if the model recommends approval with confidence of at least 0.8, and automatically rejected only if the model recommends rejection with confidence of at least 0.9. Everything else, including any error or timeout, goes to a member of our staff, who makes the decision. You may ask us to have any automated decision reviewed by a person by emailing creators@slopsquash.com; we will do so and tell you the outcome. Rejected applicants may reapply after 30 days.
When someone visits your referral link, we record a visit keyed by a salted hash of the visitor's IP address, user agent, and calendar day. The hash is used only to count unique visits per day and cannot be reversed to identify the visitor. When a referred user makes a first payment, we record the conversion, the amount actually paid, and the commission owed.
Payouts through Stripe Connect. Commissions are paid only through Stripe Connect. To be paid, you complete a Stripe-hosted onboarding flow in which Stripe verifies your identity, collects your bank account details and tax information (IRS Form W-9 or W-8), and opens a Stripe Express connected account for you. Stripe collects that information directly and processes it as an independent controller under its own privacy policy at stripe.com/privacy and the Stripe Connected Account Agreement, which you accept during onboarding. SlopSquash never receives your identity documents, bank account number, or tax forms. Stripe sends us only the connected account identifier, whether the account is enabled for payouts, and whether Stripe needs more information from you, and we store that so the creator portal can show your payout status. When your approved commissions reach the payout minimum, we transfer the amount to your connected account and record the transfer identifier, amount, date, and status; Stripe then pays your bank. Where the law requires, Stripe prepares tax information returns (such as Form 1099) using the information you gave it. The email address you enter on the creator application is used only for notices about your application, commissions, and payouts; we do not send money to it. Financial records of conversions and payouts are retained for seven years for tax purposes.
10. Cookies and local storage
We use a deliberately short list of cookies and storage items. Our separate Cookie Policy lists each one. In summary:
slopsquash.session(localStorage on slopsquash.com): your session token. Strictly necessary for signing in. Removed when you sign out; the underlying session expires after 14 days.sv_ref(cookie on.slopsquash.com, 30 days, SameSite=Lax): the slug of the creator whose referral link you followed, so the referral discount can be applied at checkout.- Extension storage: your extension token (90 days), your settings, and per-tab Verdict memos.
- Cloudflare may set operational cookies (such as
__cf_bm) for bot mitigation on our hosts, and Cloudflare Access sets an authorization cookie for staff on admin.slopsquash.com. - Stripe, Google, and GitHub set cookies on their own domains when you use Checkout or sign in with them.
We use no analytics cookies, no advertising cookies, and no third-party trackers of any kind.
11. How we use personal data
We use personal data only for the following purposes:
- To provide the Service, including creating your account, authenticating you, producing Verdicts, and syncing your tier to the Extension.
- To process payments, manage subscriptions, and provide receipts through Stripe.
- To run the creator program, including reviewing applications, attributing referrals, and paying commissions.
- To send transactional email: email verification, password reset, creator program decisions, payout notices, billing notices, and notices about changes to our terms or policies. We use Cloudflare Email Service to send these. We do not currently send marketing email. If we begin to, every such email will include an unsubscribe link and, where required, we will ask for your consent first.
- To keep the Service secure, enforce usage limits, detect fraud and abuse, and investigate violations of our Terms.
- To improve detection accuracy by maintaining the anonymous Verdict Cache and aggregate detector statistics.
- To respond to your support requests and legal requests.
- To comply with law, including tax, accounting, and lawful requests from public authorities.
We do not use personal data for advertising, for building profiles of you for advertising, or for training machine learning models on your account data. Content you submit for analysis is used to produce a Verdict for that Content; the Verdict is cached anonymously.
12. How we share personal data
12.1 Processors
We share personal data with the following companies, which process it on our behalf under written contracts that restrict their use of it to providing services to us:
| Processor | What they do for us | Data they process |
|---|---|---|
| Cloudflare, Inc. | Hosting for the API, Website, and Admin Console (Workers, D1, KV); content delivery network; request logging; Workers AI (the models used for Pro Recheck); Cloudflare Access (staff access to the Admin Console); Cloudflare Email Service (transactional email) | All data described in Section 4 transits or is stored on Cloudflare infrastructure. Workers AI receives Content submitted for Recheck. Email Service receives your email address and the message content |
| Stripe, Inc. | Payment processing, subscription management, customer portal, tax calculation where enabled; creator payouts through Stripe Connect (connected accounts and transfers) | Your email, name, payment details (entered directly with Stripe), and purchase history. For creators: the connected account identifier, its payout status, and the transfers we send to it. Stripe collects creators' identity, bank account, and tax information directly during Connect onboarding and processes it as an independent controller under its own privacy policy (stripe.com/privacy), not as our processor; see the note below this table |
| OpenAI, LLC | Image provenance and watermark verification (content provenance API) on the Free and Pro tiers | Image files sourced from public web pages, fetched by our API from the image URL the Extension saw. No account data, no page information. OpenAI's API data usage policy governs its handling of the image |
| Google LLC (AI Content Detection API) | Image provenance and watermark verification, used when enabled (once we are granted access) | Image files sourced from public web pages, fetched by our API from the image URL the Extension saw. No account data, no page information. Google states that it does not store or retain processed images |
| Google LLC (OAuth) | OAuth sign-in, when you choose "Sign in with Google" | Google receives our request to authenticate you; we receive your email, name, and Google subject ID |
| GitHub, Inc. | OAuth sign-in, when you choose "Sign in with GitHub" | GitHub receives our request to authenticate you; we receive your email, name, and GitHub user ID |
| DeepSeek | Automated first-pass review of creator program applications only | Application fields (display name, platforms, channel URL, audience size, pitch, payout notice email address) and public metadata fetched from your channel URL. No other personal data is ever sent to DeepSeek |
Stripe is our processor for the data in the row above except the information it collects from creators for Stripe Connect. For a creator's identity verification, bank account details, and tax information, and for its own fraud prevention and legal obligations, Stripe is an independent controller: it decides how that data is used and retained under its own privacy policy and the Stripe Connected Account Agreement, and requests about that data should be directed to Stripe.
12.2 Other disclosures
We may also disclose personal data:
- to comply with a subpoena, court order, or other legal process, or a lawful request from a public authority, after reviewing it for validity and scope;
- to protect the rights, property, or safety of SlopSquash, our users, or the public, including to enforce our Terms and investigate fraud;
- to a successor in the event of a merger, acquisition, reorganization, or sale of assets, in which case this policy will continue to apply and you will be notified;
- to our professional advisers (lawyers, accountants, auditors) under confidentiality obligations; and
- with your direction or consent.
12.3 What we do not do
We do not sell personal data. We do not share personal data for cross-context behavioral advertising. We do not disclose personal data to data brokers. We do not permit third parties to collect data about you through the Service for their own purposes.
13. International transfers
We are based in the United States, and our processors operate globally. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal data will be transferred to the United States and may be transferred to other countries where our processors operate. Image files sent for provenance verification are processed by OpenAI and Google in the United States. DeepSeek may process creator application data outside your country, including in the People's Republic of China. Stripe processes the identity, bank, and tax information it collects from creators in the United States and other countries under its own transfer safeguards, described in Stripe's privacy policy.
Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and, for the UK, the International Data Transfer Addendum to the Standard Contractual Clauses) with each recipient, supplemented by additional safeguards where appropriate. You may request a copy of the relevant clauses by emailing privacy@slopsquash.com.
14. Retention
| Data | Retention period |
|---|---|
| Account data, OAuth links, extension settings synced to the account | Until you delete your account or ask us to delete it. Deletion is completed within 30 days of a verified request |
| Sessions | Web sessions expire after 14 days; extension tokens after 90 days; either is deleted immediately on sign-out or account deletion |
| Email verification and password reset tokens | Until used or expired, then deleted |
| Content submitted for analysis (text, image URLs, fetched image files) | Processed in memory and not stored by us. Image files are discarded after the provenance check; Google states it does not retain processed images, and OpenAI's API data usage policy governs its retention. Request metadata may appear in logs for up to 30 days |
| Verdict Cache | Indefinitely. Entries contain no personal identifier |
| Community reports | Until you delete your account |
| Usage counters | Daily counters are kept for 30 days. Aggregated statistics with no identifiers may be kept longer |
| Billing and purchase records | 7 years after the transaction, for tax and accounting law |
| Creator applications | Until you delete your account. If you were approved, financial records of conversions and payouts are kept for 7 years after the last payout even if the rest of your account is deleted |
| Referral visit hashes | 13 months |
| Referral conversions, commissions, payouts (including Stripe transfer IDs) | 7 years, for tax law |
| Creator payout account status (Stripe connected account ID, onboarding and payout status) | Until you delete your account or leave the program; the connected account ID is kept with payout records for 7 years. The identity, bank, and tax information Stripe holds on your connected account is retained by Stripe under its own policy and legal obligations, not by us |
| Request and error logs | 30 days |
| Support email | 2 years after the thread closes |
| Admin Console audit log | 7 years |
When a retention period ends we delete or anonymize the data. Backups are overwritten on a rolling schedule and deleted data is removed from them within 90 days.
15. Security
We take reasonable technical and organizational measures to protect personal data, including:
- transport encryption (TLS) for every connection to the Website, API, and Admin Console;
- passwords stored as PBKDF2-SHA256 hashes with per-user salts and 100,000 iterations;
- payment card data handled exclusively by Stripe, a PCI DSS Level 1 service provider;
- session tokens that expire, are revocable, and are never placed in URLs;
- rate limiting, abuse detection, and per-user velocity limits;
- the Admin Console gated behind Cloudflare Access with staff identity verification, role-based permissions, and an immutable audit log of every administrative change;
- no secrets stored in source code; secrets held in Cloudflare's encrypted secret store; and
- a small team with least-privilege access.
No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
16. Your rights (all users)
Regardless of where you live, you can:
- Access the personal data we hold about you.
- Correct inaccurate account data (your name can be changed on the account page; email privacy@slopsquash.com for anything else).
- Delete your account and associated personal data (Section 22).
- Export your account data in a machine-readable format.
- Object to processing based on our legitimate interests, and we will stop unless we have compelling grounds to continue.
- Withdraw consent where processing is based on consent, without affecting processing that occurred before withdrawal.
To exercise any right, email privacy@slopsquash.com from the email address on your account, or include enough information for us to verify that you are the account holder. We respond within 30 days (45 days for California requests, extendable once by 45 days with notice). We will not discriminate against you for exercising your rights. We do not charge a fee unless a request is manifestly unfounded or excessive.
17. European Economic Area, United Kingdom, and Switzerland
If you are in the EEA, the UK, or Switzerland, the GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection applies, and the following additional terms apply.
Controller. William Freire, doing business as Slop Squash is the controller of your personal data.
Data Protection Officer. We have not appointed a Data Protection Officer because our core activities do not consist of large-scale regular and systematic monitoring of individuals or large-scale processing of special categories of data (Article 37 GDPR). Privacy questions and requests go to privacy@slopsquash.com, which is monitored by the person responsible for privacy at SlopSquash.
Representative. We have not appointed a representative in the European Union or the United Kingdom under Article 27 GDPR / UK GDPR. If our processing of EU or UK residents' data ceases to be occasional, we will appoint one and name them here. Until then, EU and UK residents can exercise every right in this policy directly with us at privacy@slopsquash.com, and with their local supervisory authority.
Legal bases. The legal basis for each processing activity is listed in the table in Section 4. Where we rely on legitimate interests, those interests are: operating and securing the Service, preventing fraud and abuse, enforcing usage limits, improving detection accuracy through the anonymous Verdict Cache, and running the creator program. We have assessed that these interests are not overridden by your interests or fundamental rights, in particular because we minimize the data we collect, never link Verdicts to individuals, and do not use personal data for advertising.
Your rights. In addition to the rights in Section 16, you have the right to data portability, the right to restrict processing in certain circumstances, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects for you. Our creator application review (Section 9) uses automated processing, but any decision that is not a clear approval is made by a human, and you may request human review of any automated approval or rejection.
Complaints. You have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or place of an alleged infringement. In the UK, the authority is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first at privacy@slopsquash.com.
No obligation to provide data. You are not required to provide personal data to us, but we cannot create an account, take payment, or run network detection without the data described for those purposes.
18. California residents (CCPA / CPRA)
This section applies to California residents and supplements the rest of this policy. Terms used here have the meanings given in the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the "CCPA").
18.1 Categories of personal information collected
In the preceding 12 months we have collected the following categories of personal information, as listed in Cal. Civ. Code section 1798.140(v):
| CCPA category | Collected? | Examples | Sources | Business purpose | Disclosed to |
|---|---|---|---|---|---|
| A. Identifiers | Yes | Email, name, user ID, IP address, Stripe customer ID, Stripe connected account ID (creators), OAuth provider ID | You; Google; GitHub; Stripe; your browser | Providing the Service, billing, security | Cloudflare, Stripe, Google, GitHub (as processors) |
| B. Customer records (Cal. Civ. Code 1798.80(e)) | Yes | Name, email, payment records (card details, and creators' bank account and tax details, are held by Stripe, not us) | You; Stripe | Billing, support | Stripe, Cloudflare |
| C. Protected classifications | No | ||||
| D. Commercial information | Yes | Plan purchased, subscription status, purchase history, referral conversions, creator payouts | You; Stripe | Billing, creator program | Stripe, Cloudflare |
| E. Biometric information | No | ||||
| F. Internet or network activity | Yes, limited | Content you ask the Extension to analyze, hostname of the page, API request logs. We do not collect browsing history or full URLs | Your Extension; your browser | Producing Verdicts, security | Cloudflare (hosting, Workers AI); OpenAI and Google (image files only, for provenance verification) |
| G. Geolocation data | No precise geolocation. IP addresses in logs may indicate approximate region | Your browser | Security, rate limiting | Cloudflare | |
| H. Sensory data | No | ||||
| I. Professional or employment information | Yes, creator applicants only | Platforms, channel URL, audience size, pitch | You | Creator program review | DeepSeek, Cloudflare |
| J. Education information | No | ||||
| K. Inferences | Yes, creator applicants only | Automated review output (recommendation, confidence, risk flags) about a creator application | Generated by us with DeepSeek | Creator program review | Cloudflare |
| L. Sensitive personal information | Yes, limited | Account login credentials (stored only as a hash) | You | Authentication only | Cloudflare |
We do not use or disclose sensitive personal information for any purpose other than those permitted by Cal. Code Regs. tit. 11, section 7027(m), and we therefore do not offer a separate "Limit the Use of My Sensitive Personal Information" control. We do not collect personal information from consumers we know to be under 16.
18.2 Do Not Sell or Share My Personal Information
SlopSquash does not sell personal information and does not share personal information for cross-context behavioral advertising, and has not done so in the preceding 12 months. We have no actual knowledge that we sell or share the personal information of consumers under 16. Because we do not sell or share, no opt-out is needed. We nevertheless treat a Global Privacy Control signal from your browser as a valid opt-out request under the CCPA, and it will remain in effect for your browser.
18.3 Your California rights
You have the right to:
- Know what personal information we have collected about you, including the categories, sources, purposes, and the categories of third parties to whom we disclosed it, and to receive the specific pieces of personal information.
- Delete personal information we collected from you, subject to exceptions (for example, records we must keep for tax law or to complete a transaction you requested).
- Correct inaccurate personal information.
- Opt out of sale or sharing (not applicable, since we do neither) and limit the use of sensitive personal information (not applicable, since we use it only for authentication).
- Non-discrimination: we will not deny you the Service, charge a different price, or provide a different level of service because you exercised these rights.
To exercise these rights, email privacy@slopsquash.com or write to 300 West 109th Street, New York, NY 10025, United States. We will verify your request by matching it to the email address on your account and, if necessary, by asking you to confirm from that address. You may designate an authorized agent to make a request on your behalf; we will ask the agent for written authorization signed by you and may ask you to verify your identity directly. We respond within 45 days and may extend once by a further 45 days with notice.
18.4 Financial incentives
We do not offer financial incentives or price differences in exchange for the collection, retention, sale, or sharing of personal information. The referral discount described in the Creator Program Terms is a price promotion tied to a referral link, not to the provision of personal information.
18.5 Shine the Light
We do not disclose personal information to third parties for their own direct marketing purposes, so Cal. Civ. Code section 1798.83 does not require any further disclosure.
19. Nevada residents
We do not sell "covered information" as defined in Nevada Revised Statutes chapter 603A. Nevada residents may nonetheless submit a request directing us not to sell their covered information by emailing privacy@slopsquash.com with the subject "Nevada opt-out". We will record and honor it.
20. Virginia, Colorado, Connecticut, Texas, and other US states
If you live in Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Utah, Delaware, New Jersey, New Hampshire, Iowa, Nebraska, Tennessee, Minnesota, Maryland, or another state with a comprehensive privacy law, you have the rights to confirm whether we process your personal data, access it, correct it, delete it, obtain a portable copy of it, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. We do not engage in targeted advertising, do not sell personal data, and do not profile users for such decisions (the creator application review is described in Section 9 and is subject to human review on request).
To exercise a right, email privacy@slopsquash.com. We respond within 45 days, extendable once by 45 days with notice. If we decline your request, you may appeal by replying to our decision with the word "Appeal" in the subject line. We will respond to appeals within 45 days (60 days in some states) with a written explanation. If your appeal is denied, you may contact your state attorney general; for example, the Virginia Attorney General at oag.state.va.us, the Colorado Attorney General at coag.gov, the Connecticut Attorney General at portal.ct.gov/ag, or the Texas Attorney General at texasattorneygeneral.gov.
21. Children
The Service is not directed to children under 16, and you must be at least 16 to create an account. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us personal data, email privacy@slopsquash.com and we will delete it promptly.
Content analyzed by the Extension may have been written by anyone, including minors. The Extension analyzes the text of public posts to produce a Verdict and does not collect any information about the author beyond that text. Verdicts are opinions generated by software about the Content, not about the author.
22. Deleting your account
To delete your account, open the Account page on slopsquash.com, choose "Delete account", and confirm with your password (or, for accounts that sign in only with Google or GitHub, by typing your email address). Deletion is immediate: your account record, sessions, sign-in links, community reports, and creator application or link are removed at once; commission and payout records are retained for tax purposes as described in Section 14, with your identity replaced by an opaque id. Anonymous cached verdicts contain no account data and are unaffected. If you cannot sign in, email privacy@slopsquash.com from the email address on your account with the subject "Delete my account"; we will confirm the request by reply and complete deletion within 30 days. If you have an active Pro Monthly subscription, deletion cancels it; there is no refund for the remainder of the current period except as described in the Terms of Service. If you hold Pro Lifetime, deletion permanently forfeits it.
When your account is deleted:
- Your account record, OAuth links, sessions, extension tokens, and pending email tokens are deleted.
- Your community reports are deleted. Tallies that included your votes are recomputed.
- Your extension settings and tokens in your browser are not on our servers; remove the Extension or clear its storage to delete them locally.
- Your creator application is deleted. If you earned commissions, we keep the minimum financial records (amounts, dates, conversion references, Stripe connected account and transfer identifiers) for 7 years as required by tax law, separated from any other account data. Deleting your SlopSquash account does not close your Stripe connected account; you can close it with Stripe, and Stripe keeps the information it collected under its own policy and legal obligations.
- Billing and purchase records are kept for 7 years as required by tax and accounting law. Your Stripe customer record is retained by Stripe under its own policy; we can ask Stripe to delete it on request where law allows.
- Admin Console audit log entries that reference actions taken on your account are retained for accountability; they contain the action, target ID, and staff identity, not your account data.
- Verdict Cache entries are unaffected, because they contain no reference to you. If an image source URL in the cache identifies you, tell us and we will purge that entry.
- Request logs that may contain your IP address expire within 30 days on their normal schedule.
23. Automated decisions
The only automated decision in the Service that affects a person's rights or opportunities is the first-pass review of creator program applications, described in Section 9. Detection Verdicts are automated assessments of Content, not decisions about any person, and the Terms of Service prohibit using them to make decisions about individuals. We do not use automated decision-making for account suspension, billing, or pricing.
24. Do Not Track and Global Privacy Control
We do not track users across third-party sites, so there is nothing for a Do Not Track signal to disable. We honor Global Privacy Control signals as opt-out requests under applicable state law, as described in Section 18.2.
25. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email to the address on your account, or by a prominent notice on the Website and in the Extension, at least 14 days before the change takes effect. Continued use of the Service after the effective date of a revised policy means you accept it. The effective date at the top of this policy tells you when it was last revised. Prior versions are available on request.
26. Contact
- Privacy requests and questions: privacy@slopsquash.com
- General support: support@slopsquash.com
- Legal notices: legal@slopsquash.com
- Mail: William Freire, doing business as Slop Squash, 300 West 109th Street, New York, NY 10025, United States