How SlopSimple handles data.
Checks use an external detection service. Here’s what leaves your browser, what is saved, and how to pause it.
Updated 8 October 2026
Post text and creator identifiers.
When automatic checks are enabled and access permits checking, the extension reads eligible text posts on X and LinkedIn, including collapsed text already loaded in the page. It sends the post text, platform name and an available creator identifier to the SlopSimple service hosted on Cloudflare. Post text can contain personal information.
The creator identifier is an X handle, or a LinkedIn profile/company identifier extracted from the page. If a LinkedIn identifier is unavailable, the extension may use the visible creator name. Identifiers are limited to 100 characters and may identify a person.
The service sends post text to TypeSafe AI. If that service is unavailable, Google Gemini may be used; Gemini also receives the platform name. Creator identifiers are stored with results by SlopSimple and are not included in the detector request. Processing and retention by external providers are subject to their own policies.
The extension does not send your X or LinkedIn account credentials, cookies, post URLs, post IDs, direct messages or browsing history as check data. It does not analyze images, videos, comments or quoted-post text. Text checks cover eligible posts between 80 and 12,000 characters.
Saved results and request metadata.
The application database saves a fingerprint of normalized post text, platform, detector score, provider, available creator identifier, analysis timestamp and expiry timestamp. Results expire 30 days after analysis and expired records are removed by daily cleanup. Raw post text is not stored in our application database or application logs.
The fingerprint is derived from the post’s text and platform. It allows matching posts to saved results without storing the text itself; it should not be treated as anonymous data.
During a free trial, we temporarily link your account ID to checked post fingerprints and the UTC day to enforce each platform’s daily allowance across devices and networks. No raw post text is saved in these usage records. Records from earlier UTC days are removed by daily cleanup and are deleted if the account is deleted.
Cloudflare receives your IP address when you contact the service. SlopSimple uses a daily identifier derived from your IP address with a server-side salt to enforce usage limits. Expired counters are removed by daily cleanup. Hosting logs may retain request metadata according to Cloudflare’s settings.
Data kept in your browser.
The extension saves preferences, cached estimates and thumbs-up/down responses in local browser storage, without raw post text. Cached estimates include result metadata and may include the creator identifier returned by the service. The cache keeps up to 1,000 unexpired estimates.
Up to 1,000 feedback responses are kept locally. A new response for the same post replaces your earlier choice. Removing the extension removes its local data, but does not remove results or responses already saved to the SlopSimple service, and does not itself revoke a server token.
When you give feedback.
Choosing thumbs up or down sends your choice, the post fingerprint and a random response ID to the SlopSimple service. A linked extension authorizes the request with its connection token. The database stores feedback with the platform, detector score, provider and timestamps, without an account ID in the feedback record. Feedback expires 30 days after it is saved or updated, with expired records removed by daily cleanup.
The response ID allows retries and changes to update the same response. It belongs to that post’s response, rather than being a shared user or device ID. Feedback does not include raw text or post URLs. Its fingerprint can be associated with the saved analysis, which may contain a creator identifier.
If saving feedback to the service fails, the popup retains your local response. You can click your choice again to retry.
Your controls and extension permissions.
Automatic checks and filtering are enabled by default, subject to account access when subscription enforcement is enabled. The default filtering threshold is 80%; only posts with scores strictly above it are hidden after checking. You can adjust the threshold or turn filtering off in the popup. Turning off a platform stops new analyses on that site; turn both off to stop all new checks. Requests already underway may finish.
The extension requests storage permission for settings and results, scripting permission to start on already-open feeds, access to supported X/Twitter and LinkedIn domains for content scripts, and access to the SlopSimple service to perform checks. A detection score is an uncertain estimate, not proof of a post’s authorship.
SlopSimple does not use analytics cookies or advertising trackers. Website sign-in uses the essential cookies described below.
Website email sign-in.
When you sign in on the SlopSimple website, we send your email address and a one-time sign-in code to Resend for delivery. We store your normalized email address, account ID and account creation timestamp. Account records do not have an automatic expiry; signing out does not delete an account.
Login challenges contain your email address, challenge identifier hash, keyed code hash, browser-token hash, attempt count, delivery/consumption state and timestamps. They expire after 10 minutes. Successfully used challenges are removed, and expired challenges are removed by daily cleanup. Raw codes and session tokens are not stored in the database or application logs.
The website uses essential HttpOnly cookies for a sign-in challenge and your session. Challenge cookies expire after 10 minutes. Sessions expire after seven days or when you sign out. Server-side session records contain a token hash, account ID and timestamps; expired records are removed by daily cleanup.
Separate keyed identifiers derived from your email and IP address enforce login limits. Expired counters are removed daily. The extension does not send website sign-in cookies; account linking uses a separate connection token described below.
Subscription billing.
When you sign up for the free trial, we record your account trial start and end timestamps, to grant seven days of access and prevent repeat trials. No payment details are required for the trial. When you subscribe while signed out, Stripe collects your email in checkout embedded on our site. We retrieve it from the confirmed checkout to create or associate your account, then send a sign-in code to verify ownership. If you are already signed in, we send your account email and ID to Stripe to identify your billing customer. Stripe handles payment details in its embedded checkout and hosted account-management portal. SlopSimple does not store your card number.
Anonymous checkout uses an essential seven-day HttpOnly browser cookie whose hash is stored with the selected plan, checkout recovery key and Stripe session. Empty checkout contexts are removed after seven days; purchase recovery records are retained for reconciliation. We save Stripe customer, subscription and checkout identifiers, your selected plan, subscription status, trial and billing-period timestamps, cancellation status and records needed to prevent duplicate checkouts. These records are linked to your SlopSimple account and do not have an automatic expiry. Stripe’s handling and retention of payment and billing information are subject to its policies.
Subscription events from Stripe update your access status. The application stores processed event identifiers and timestamps to avoid processing the same event twice, rather than saving the full event payload.
Connecting your extension account.
Clicking Sign in in the extension opens this website and links your signed-in account automatically. The extension stores a random sign-in nonce, the opened tab ID and a ten-minute expiry locally to validate the handoff, and removes them after success or disconnect. A content script runs on SlopSimple website pages to handle sign-in on the login page and notify the extension after website sign-out. It does not send the durable extension token to the page.
Automatic sign-in uses a one-time authorization code to link the extension. The server stores its hash and your account ID; the code expires after 10 minutes. Generating a new code replaces your previous unused code. Successfully consumed codes are removed.
Connecting the extension exchanges that code for a separate random access token. The extension saves the token locally and sends it to SlopSimple to check subscription access and authorize checks. This associates extension requests with your account. The extension may also store the account email and access status returned by the service.
The server stores a hash of the extension token, your account ID and creation/expiry timestamps. Tokens expire after 90 days. Choosing Disconnect account attempts to revoke the server token and removes it locally. If revocation cannot be confirmed because of a connection failure, the popup says so; the server token may remain valid until expiry. Expired tokens and connection codes are removed by daily cleanup. Website sign-out revokes all extension tokens and unused connection codes for that account. The extension in the same browser immediately rechecks access, clears a revoked connection and restores filtered posts; other devices clear their connection at the next access check.
Daily identifiers derived from your IP address limit connection-code guesses and access checks. Connection codes, raw access tokens and post text are not written to application logs.
Account deletion and privacy requests.
Use Delete account in your account settings. A fresh email-code verification and explicit confirmation are required. Safari’s account-management page includes the same deletion controls.
If you have a Stripe billing customer, we first delete it to stop subscriptions immediately. Unused access ends, and deletion does not automatically issue a refund. Stripe may retain transaction history under its policies. If completion cannot be confirmed, deletion remains pending; new billing operations and account access are blocked, and you can retry from your account.
Successful deletion removes your account, sessions, extension connection codes and tokens, trial usage, billing account and linked checkout recovery records. Local extension data remains until you remove the extension. Shared post estimates and feedback contain no account ID and expire under their existing 30-day retention rules.
For privacy, billing and support requests, email support@slopsimple.com. Incoming support email is forwarded through Cloudflare Email Routing to the operator’s inbox.