Sloppy logoSloppy

Sloppy privacy policy

Effective date: 7 October 2026. Sloppy is published and operated under the public name magara corp. Contact: magara-corp@proton.me.

Sloppy displays community reports about suspected AI-generated or AI-assisted web content and applies the browsing rules you choose. It does not run an AI detector or AI model. Community judgments are opinions, not proof of how content was made.

Local processing and consent

When you open Sloppy on an eligible public HTTP(S) page, it reads the current tab URL locally, canonicalizes it, and hashes the domain and page. Fragments and common tracking parameters are removed; remaining functional query parameters are retained and sorted before hashing. The content picker describes only an element’s structural tag path, positions and an allowlisted semantic role. It excludes text, HTML, IDs, classes, form values and media URLs. The structural description is processed within the extension and combined with the hashed parent page to create a page-scoped content hash. It is not a browser or device fingerprint.

The first manual community lookup waits for your “Check community reports” action after an in-product disclosure. Automatic checks, warnings, blocking and hiding start off. Enabling one in Settings provides its disclosure and requests optional website permission. Denial leaves manual reporting available. Toolbar badges summarize checks that have occurred; the default badge setting does not enable automatic checks.

On desktop Firefox 140 and later, community communication also requires Firefox’s optional native data permissions. The declarations cover linkable domain/page and structural content hashes, reports, installation identifiers and authorization material, and infrastructure metadata such as IP addresses and user agents. They do not mean that raw content, passwords or precise GPS location are collected. The manifest declares no required data collection and explicitly lists optional categories; it does not claim that Sloppy never sends data. Denial or revocation stops lookups and queued retries and preserves local choices and credentials. Revocation does not delete existing server reports. Re-enable community access to perform authenticated server deletion, which also transmits the installation identifier and credential.

Information transmitted

Community lookups send a bounded set of target scopes and SHA-256 target hashes to the shared Sloppy API. Reports send protocol version, scope, target hash, a separate hashed parent-page key for selected content, your Slop / Not slop / Unsure vote, zero or more of six AI-use labels, timestamp and a random installation UUID. Report creation, updates and deletion also send a separate random 256-bit installation credential in an authorization header. The database stores its SHA-256 hash, not the credential itself. Credentials are never included in community aggregate responses.

Enabling an automatic or page-changing feature causes repeated hashed domain/page lookups as you visit eligible public pages. Hiding additionally checks hashes for likely content elements. Manual content selection may also look up a selected content hash. Sloppy does not upload raw page URLs, page titles, selected text, HTML, cookies, form contents, media URLs, browsing-history records or browser/device fingerprints. Local domain overrides never become community reports.

Hashes minimize transmitted detail; they are deterministic, stable and linkable. Common domains and URLs may be guessed by hashing candidates. Repeated lookups can be associated with the same target, and installation IDs group reports. These identifiers are not inherently anonymous.

Purpose, aggregation and sharing

We use this information to provide community lookup/reporting, compute aggregates, authorize changes and deletion, secure the service and limit abuse. One installation has one current report per scope/target. Updating replaces its vote. Unsure votes count in totals and label counts but not the Slop / Not slop ratio. With the current default server configuration, fewer than five eligible votes are unrated; at least 60% Slop is community-reported Slop, at most 40% is Not slop, and qualifying results between those thresholds are disputed. These counts are installation reports, not verified independent people. Your personal thresholds change local interventions, not server verdicts.

Other users can retrieve aggregate totals, ratios and label counts for the same target. Individual installation IDs, credentials and credential hashes are not returned in aggregates. Railway hosts the API, PostgreSQL and private encrypted backup bucket and processes data needed to operate that infrastructure. Authorized operators have administrative access. Human access to nonpublic data is limited to specific support with your consent, security/abuse investigation, legal obligations, or aggregated operational information. No data is sold or used for advertising, profiling or unrelated purposes.

Sloppy’s use and transfer of information complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Transfers are limited to providing the stated functionality, necessary security, and legal obligations. There is no remote executable code, advertising SDK or AI service.

If you email support, Proton Mail processes your email address, message and any attachments you choose to send. We use that correspondence to respond and resolve support or privacy requests, and may retain it as needed for that request, security or legal obligations. Sloppy does not automatically collect your email address. Ask us about deleting support correspondence; do not include secrets.

Local storage and installation authorization

Your browser stores the consent flag, installation UUID and credential, settings, domain overrides, cache, pending offline votes, submitted-report references and last selected content target. There is no Sloppy user account. The credential is a bearer secret: someone who obtains it can modify that installation’s reports. Losing it can prevent deletion. A UUID alone does not prove ownership. Earlier UUID-only reports cannot be safely claimed with a new credential; contact us for help without sending credentials. Creating a new installation does not recover or silently delete old reports.

Retention and deletion

Accepted reports and credential hashes remain in the active database until authenticated deletion. Reports can be updated or individually removed in the popup. In Settings, “Delete server reports and clear local data” deletes the current installation’s server reports and credential binding before clearing local identity, settings, cache, pending work and optional permissions. If server deletion fails, Sloppy retains the identity and local data for retry. Pending offline reports remain local until you retry or discard them; they are not silently submitted. Cache duration is configurable.

Uninstalling Sloppy or clearing browser storage outside its Settings bypasses server deletion and may orphan reports. Without a retained credential or independent ownership evidence, we may be unable to identify or authorize deletion of an orphaned installation. For privacy or deletion assistance, email magara-corp@proton.me. Never email the installation credential, recovery keys, cookies or passwords.

Daily logical database backups include report metadata and credential hashes and are encrypted before upload to a private Railway bucket. The decryption key is retained outside Railway. After a new upload is downloaded and verified, the job prunes recognized backups strictly older than seven days. It preserves prior copies when a new backup fails. Pruning errors, outages, account suspension or the spending cutoff can therefore retain deleted records and the last successful backup beyond seven days, until successful cleanup resumes. We cannot promise an absolute seven-day deletion deadline. Before a restored database returns to service, deletion requests since the recovery point need reconciliation.

Infrastructure metadata and security

The API may use client IP addresses only in ephemeral memory for rate limiting and has no raw-IP database column. Application logs omit credentials, target hashes, raw IPs, query strings, cookies and bodies. PostgreSQL statement/parameter logging is suppressed. Railway HTTP edge logs process client IP and user-agent metadata; documented Hobby log retention is seven days. Public-page visits also reach that infrastructure, even without authentication. Provider access and retention are separate from application database storage.

Extension traffic to the production API uses HTTPS; API-to-database traffic uses Railway’s private encrypted network. Backup contents are encrypted with age before HTTPS upload. Same-account backups do not cover every provider/account failure; a usage cutoff can stop the API, database and backup job and suspend bucket access, while retained storage remains billed. These measures reduce risk but do not guarantee uninterrupted service or prevent every unauthorized disclosure.

Other servers and policy changes

Settings can direct Sloppy to a different API. Future lookups and reports then go to that server, whose operator and policies may differ; this policy describes the shared service above. Sloppy rejects browser-internal, file, local/private and non-HTTP(S) targets and does not enable private/incognito use. We update this page when behavior or processing changes and show the effective date. For questions, contact magara-corp@proton.me.