Who we are
AI Slop Detected is operated by [Operator legal name], [Registered postal address]. For the purposes of data-protection law, [Operator legal name] is the controller of the personal data described here (the “data fiduciary” under India’s Digital Personal Data Protection Act, 2023). You can reach us at [privacy@aislopdetected.com].
Scope
This policy covers the AI Slop Detected browser extension, the website at aislopdetected.com and its API. It does not cover the third-party pages and videos that people rate. We never fetch, host or store their content.
At a glance
- Installing and ordinary navigation make no request to us. Browser startup contacts the service only when retrying a deliberate vote still queued on this device.
- Opening the popup sends a SHA-256 fingerprint of a normalized page identity to check for an existing score. We do not attach your installation credential to that check.
- Casting or changing a vote sends the normalized public URL or YouTube video ID, your choice, optional fixed reasons, action source, extension version and a pseudonymous credential.
- We do not collect page text, selected text, comments, forms, cookies, account data, passive or unrelated browsing activity, or advertising identifiers. The normalized URLs you deliberately rate are product data.
- We do not sell personal data, use it for advertising, or share it with data brokers.
Data we process
| Field | Purpose | Retention |
|---|---|---|
| Normalized content identity | Merge equivalent public links and display content-level aggregate scores. | While at least one active rating exists or a live review requires it. Zero-vote visible records are removed. |
| Vote and fixed reason codes | Calculate community opinion and explain aggregate reasons. | Until retracted, contribution deletion or valid removal. |
| Pseudonymous installation credential digest | Enforce one active vote per installation and allow changes/deletion. | Deleted immediately with contribution history; empty inactive records are deleted after 30 days. |
| Deletion receipt | Prevent a delayed registration retry from recreating an installation identity after contribution deletion. It contains only the prior keyed credential digest and deletion time. | 30 days. |
| Source and extension version | Debug the product and measure its core workflows. | Stored with the vote; reported publicly only in aggregate. |
| Mutation replay record | Make vote retries idempotent after a lost response. It contains a request digest, content fingerprint and the current/prior fixed vote values needed to reproduce the response; aggregate results are not duplicated. | Up to seven days, removed earlier by contribution deletion. Prior records for an item are removed on retraction. |
| Rotating keyed network prefix | Short-term rate limiting and coordinated-abuse detection. | Rate-limit buckets expire within two hours; abuse signals within seven days. Raw IP addresses are not put in product tables. |
| Hash-only moderation tombstone | Prevent a hidden or blocked zero-vote URL from being recreated without retaining the URL itself. | While the restriction remains necessary, with periodic operator review. |
| Device-local pending vote | Retry a deliberate action after a network or service failure. It contains the normalized URL, content fingerprint, choice, fixed reasons, source, event ID, time and retry count. | On this device until delivered, superseded, retracted or erased with contribution history. |
| Review-request details and optional email | Investigate a correction, privacy or legal request and reply if possible. | While needed for an open case, reviewed for necessity at least every 90 days, then 90 days after resolution or rejection. |
| Moderation audit record | Show which operational action was taken and why. | One year. |
| Server request logs | Operate and secure the service. Our hosting provider records request metadata such as timestamps, status codes and the connecting IP address; we configure our own logging to omit request bodies, credentials, URLs and IP addresses. | Provider defaults, currently no longer than seven days. |
Why we process it, and on what legal basis
- To provide what you deliberately ask for: looking up a score; recording, changing, retracting or deleting your vote; handling a review request. Basis: performance of our terms with you and, for the extension’s first-use disclosure, your consent, which you can withdraw at any time by deleting your contribution history and uninstalling.
- To keep the service trustworthy: rate limiting, abuse-cohort analysis, freezes and moderation. Basis: our legitimate interest in preventing manipulation and abuse, or the equivalent legitimate uses recognised by the law that applies to you.
- To meet legal obligations and respond to lawful requests from authorities or rights-holders.
We do not profile you, and we make no automated decision that has legal or similarly significant effects on you. Automatic “freeze” holds affect only whether a content score is displayed, never a person.
Pseudonymous, not anonymous
A unique credential links votes made by one installation so duplicates can be prevented and contributions can be changed or deleted. This is pseudonymous data. Hashing and keying identifiers reduces risk but does not make personal data automatically anonymous. A deterministic page fingerprint can also be matched by someone who already knows or guesses the public URL; it is minimisation, not encryption.
URL minimisation
Before storage, fragments and known tracking parameters are removed. URLs with credentials, likely access tokens, private-network hosts or custom ports are rejected. The service never fetches, scrapes or previews a submitted page. A score lookup does not create a content record; only an explicit vote does.
Who we share data with
Cloudflare, Inc. provides hosting, content delivery, security and the database. It processes data on our instructions under its data-processing terms. GitHub, Inc. hosts our source code and runs a scheduled maintenance job; that job only calls our API and holds no personal data. There are no analytics, advertising or social-media trackers on the site or in the extension. We disclose information only when the law requires it, to investigate security incidents or abuse, or to protect rights and safety, and then only the minimum necessary. Public score pages show thresholded content-level aggregates only, never a reporter trail or hidden trust weights.
International transfers
Cloudflare operates a global network, so your data may be processed in a country other than the one you live in. Where that country is not recognised as providing equivalent protection, we rely on Cloudflare’s standard contractual safeguards and the transfer mechanisms recognised by the law that applies to you.
Retention
We keep data only as long as the table above says. Retention is enforced by a scheduled maintenance job and by the deletion controls described below. Data needed to defend a legal claim or comply with a legal hold may be kept for longer, in which case it is restricted from ordinary use.
Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict its processing, to withdraw consent, and to complain to a supervisory authority such as the Data Protection Board of India or your EU or UK data-protection authority. The fastest route for your own votes is the extension’s “Delete my contribution history” control, which works without contacting us. For anything else, use the review form or email [privacy@aislopdetected.com]. Because we hold no name or account, we may ask you to make the request from the installation concerned, or to give us the public score ID, so that we act on the right data. We do not discriminate against you for exercising your rights.
Children
The service is for adults. Do not use it if you are under 18. We do not knowingly process children’s data; if you believe a child has used the service, contact us and we will delete the associated installation data.
Security
Traffic uses HTTPS. Credentials are kept in extension-local storage and API requests use strict size, enum, origin, authentication and rate-limit checks. Secrets are stored only in the hosting provider’s secret store. No system is risk-free; report a security or privacy issue through Request a review or [privacy@aislopdetected.com], and we will prioritise it.
Your controls
You can change or retract any content vote in the extension. “Delete my contribution history” removes this installation’s votes, replay records, active credential digest, installation-linked rate buckets and abuse tags, writes a 30-day hash-only deletion receipt to prevent delayed recreation, then clears its local identity and outbox. A transient in-memory denial counter can remain in an already-running service instance until its one-hour window ends; it is not durable or used as product history. Uninstalling alone clears the local credential but cannot identify which server record to delete later, so use the deletion control first if you want server-side removal.
Chrome Limited Use
Our use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used only to provide or improve the extension’s single purpose, maintain security, comply with law or complete a user-requested deletion or review.
Changes
Material changes will be dated here and surfaced in the extension when they affect what is collected or how it is used. Earlier versions are available on request.
Contact and grievances
Privacy questions, rights requests and grievances: [privacy@aislopdetected.com], or by post to [Operator legal name], [Registered postal address]. Our grievance contact is [Name of the person who handles privacy requests]. Urgent privacy and security requests are prioritised, and we will tell you if a request needs more time or cannot be fulfilled.