Skip to content

Privacy Policy

Native checks stay on your device. Online checks run on hardware we own and operate, and are deleted after processing unless they are free-tier checks we keep to improve the detector.

Effective 7 October 2026.


Who we are

Numen Technologies Limited makes Slop or Not and is the data controller for the processing described here.

Numen Technologies Limited
Work Hub, 77 Camden Street
Dublin D02XE80
Ireland

Registered in Ireland with CRO number 677823.

For any privacy question or request, write to us at [email protected].

What this policy covers

This policy covers the slopornot.ai website, including the free online checker and the text cleanup that runs with it or on its own on our hidden character detector page, the clean-copy tool on our MCP page, the hosted MCP text-cleanup server at mcp.slopornot.ai, and the Slop or Not app for iPhone, iPad, and Mac. These work differently, so they are described in separate sections below.

It does not cover other companies. If you follow a link from our site to somewhere else, that site runs under its own privacy policy, and we are not responsible for what it does with your data.

We publish this policy in several languages. The English version is the one that controls. If a translation and the English text disagree, the English text applies.

The Slop or Not app

The app checks text and images on your device. The content you check is not uploaded to us and is not sent to any other company for the check. The app never calls the online checker described below, so nothing you check in the app reaches our servers. There is no account to create and no sign-up.

The app collects no data types, does not track you, and contacts no tracking domains. It carries no analytics SDK and no crash-reporting SDK.

Detection models are downloaded from Apple as on-demand resources the first time you need them. Apple sees the model download the way it sees an app download. It does not see what you check.

The app can turn on iCloud sync for your check history and your daily check allowance. That data goes to your own iCloud private database and your iCloud key-value store, under your Apple Account. We have no key and no access to it. You can turn sync off in the app, and the app keeps the data locally instead. Deleting the data is done through the app and through your iCloud settings.

To check a photo, the app reads the image you pick from your photo library or your clipboard. It reads only what you hand it. In some cases the app may use Apple's on-device Sensitive Content Analysis framework, which runs on your device and reports nothing to Apple or to us.

The app schedules reminders locally on your device, for example when your daily allowance resets. We do not run marketing push campaigns.

Purchases are handled by Apple through the App Store. We never see your payment details. Apple gives us anonymous sales and subscription reports, which do not identify you.

When you view your Slop or Not subscription details in your Apple Account, Apple can send our server at numen.ie the subscription's original transaction identifier, app and product identifiers, locale, a request identifier, the server environment and signing time. We verify the signed request and return a message identifier for Apple to display if you select Cancel Subscription. We choose the message by product and locale; we do not build a subscription profile or save the transaction identifier. This processing is separate from on-device detection and does not include anything you check in the app.

The free online checker

The online checker is different from the app. When you submit text or an image on the website, detection runs on machines we own and operate ourselves. No cloud AI vendor sees it. A paid check is never used to train anything. A free-tier check is kept to train and evaluate our own detector, as described below.

Your submission is retained only while the check is being performed and is deleted as soon as the check completes or fails permanently, unless it is a free-tier check, which we keep to improve the detector (see below). At that same moment we also erase the request metadata described below. A check already running when you decline completes under the identifier it was submitted with, and that identifier is erased when the check reaches its final state.

Once your check is accepted, the checker sends the text to a service we run that marks familiar phrases; an attempt blocked or refused before it starts never reaches it. The try boxes on our writing-tells pages send the passage you enter there to that same phrase-marking service. When a check completes, the checker also sends the same text to a service that looks for hidden characters, and the hidden character detector page sends the passage you enter there to that same service. Both process the text in memory only, never write it to disk, logs, or analytics, and discard it when the response is sent.

If you choose to copy the summary of flagged phrases or the cleaned text, it is placed on your device's clipboard and is never sent to us.

  • What you submit: the text or image you send. Paid checks are deleted after processing. Free-tier checks are kept as submitted, to train and evaluate the detector, together with the technical details we record from an image file, with any GPS coordinates removed from those details.
  • Request metadata: your IP address, your browser user agent, and the approximate country, region, and city derived from your connection. We use it to run the checker, to enforce the daily allowance, and to spot abuse. Your IP address and user agent are erased from our live database when the check reaches its final state and excluded from our nightly backups entirely; the approximate location is kept only in the request record described below. If your browser holds the analytics identifier, the job record holds it too and is erased with the rest of this metadata. For every free-tier submission, accepted or refused, we also keep a separate record of the request, without your IP address or full user agent: its outcome; the approximate country, region, and city of your connection, and whether it came through a VPN or a similar service; your browser, operating system, and device type; your language preferences; which page you used, the page or site that brought you there, and how you added the content; the type and size of what you submitted and, for an image, its age and a rough category of its file name and its extension, never the name itself; and a fingerprint of the content. We use it to understand how the free checker is used and to improve it, keep it for up to one year, and include it in our backups. Before a check is accepted, we check whether your connection comes through Tor, a commercial VPN, or iCloud Private Relay, to prevent abuse of the free allowance.
  • Job record: a row holding the status and timings of the check, with the content and metadata already removed. It is deleted after 30 days.
  • Result cache: an anonymized, irreversible record derived from the submitted content, paired with the result and kept for 30 days. The record cannot be turned back into your content.
  • Failure cache: for images that fail, the same kind of record paired with the failure reason, kept for 24 hours.
  • Daily allowance: anonymized, irreversible counters derived from your connection data and from the daily allowance identifier your browser holds. We never store your raw IP address. The counters are kept for two days, then deleted.

The checker is protected by Cloudflare Turnstile, so Cloudflare receives the connection data it needs to tell a person from a bot. Turnstile is a security measure, not an advertising product.

A result from the checker is an estimate. It is not proof of who wrote or made something, and accuracy varies with new models and with methods built to defeat detectors.

The hosted MCP text-cleanup server

The hosted MCP server at mcp.slopornot.ai is separate from both the online checker above and the MCP server bundled with the Mac app. It accepts requests from your AI agents over the internet. Submitted text is processed in memory only, is never written to disk, logs, or analytics, and is discarded the moment the response is sent. The hosted tools clean characters; they do not run the AI detection models.

  • Rate-limit key: your IP address, held in memory only to enforce a per-minute request limit. It is never written to disk and is discarded automatically; it is not used for anything else.
  • We send no analytics event for a hosted MCP tool call. Nothing about your request reaches our analytics service.

The clean-copy tool on our MCP page

An AI agent running in your browser can ask our MCP page to prepare clean copy from a passage the agent supplies. The passage goes to the same text-cleanup service the online checker uses: processed in memory only, never written to disk, logs, or analytics, and discarded the moment the response is sent.

The cleaned text that comes back is a different matter: our MCP workbench page holds it in your browser's own memory, on screen for the agent to accept or reject, for as long as that review is open. There is no timeout on it. It leaves memory only when the review is answered or the browser tab that holds the page closes; it never reaches our servers a second time and is never written to disk, logs, or analytics.

  • Rate-limit key: your IP address, held in memory only to enforce a per-minute request limit. It is never written to disk and is discarded automatically; it is not used for anything else.

The contact and support form

If you write to us through the form on the site, you send us your name, your email address, your message, and an optional screenshot. If you tick the anonymous option, your email address is stripped before the message leaves our server, and we have no way to reply.

We do not store form submissions. The message is relayed to our mailbox by our email delivery provider, and it then lives in our mail account for as long as we need it to answer you. Attached images are re-encoded and stripped of their metadata before they are sent on.

The form is protected by Cloudflare Turnstile and by a per-IP rate limit.

When you report a problem from a check result, or from a blocked-access screen, the site keeps a short summary in your browser so the support form can prefill it: the check type, verdict, and confidence percentages for a check result, or the block reason and your IP address for a blocked-access report. It stays until the form reads it or you close the tab, and it never leaves your browser until you press send.

Analytics

We measure how the site is used with an analytics tool we host ourselves on our own infrastructure and serve from our own domain. There is no Google Analytics, no tag manager, and no advertising pixel anywhere on this site.

It sets no cookies and builds no cross-site profile. It records page paths, the query string an inbound link carries (including campaign tags and advertising click IDs), referrers, your browser, operating system, device type, screen size, browser language, and an approximate location down to city level, derived from your IP address. It also records named events such as a button click, and a coarse summary of each check you run. Events carry no text or images you have checked. Where your browser holds the analytics identifier, these events carry it.

Your IP address is processed transiently to derive that approximate location. It is not stored.

The legal basis is our legitimate interest in understanding how our own site performs.

Analytics identifier

We keep a random identifier in your browser so that your visits to this site are counted as one visitor rather than many. It is issued by servers we run, contains nothing about you, and is sent only to those servers.

Clearing this site's data removes the identifier, and any identifier you are given after that is a new one.

If you are in the European Union, the European Economic Area, the United Kingdom, or Switzerland, we ask first: nothing is stored until you accept, and a decline is remembered until you close the tab. Elsewhere we rely on our legitimate interest. Where we ask first, an Analytics preferences link in the footer lets you withdraw at any time, which deletes the identifier.

Error reports

When something breaks, the site can send an error report to an error tracker we also host ourselves. The report describes the failure so we can fix it.

Before a browser error report is stored, query strings are stripped from URLs and identifiers are removed. The legal basis is our legitimate interest in keeping the service working.

The same error tracker also receives performance measurements: ordinary page loads and requests are timed and sent there even when nothing breaks, scrubbed the same way. We use those measurements only to keep the service fast and working, on the same legal basis and with the same handling as the error reports.

Cookies and browser storage

The table below is the complete list. One thing on this site can ask for your consent, and the banner exists for it alone: the analytics identifier described above. Everything else here needs none: the locale cookie only remembers which language to serve you, the daily allowance identifier only counts the free checks you run so that the checker can stay free, the free check count only remembers how many of today's free checks you have left, the analytics themselves set no cookies and stay on this one site, and Turnstile and Cloudflare's cf_clearance challenge cookie are security measures that protect the site rather than track you. We do not embed third-party video or social widgets on this site. If we ever do, the embed will not load until you click it.

NameTypePurposeDuration
NEXT_LOCALEFirst-party cookieRemembers the language you are reading the site in, so later visits land in the same one. Strictly necessary for delivering the site in that language.Until you close the browser
Theme preferenceFirst-party local storageRemembers whether you chose the light or the dark theme.Until you clear it
Announcement dismissalFirst-party local storageRemembers that you closed the announcement at the top of the page, so it stays closed.Until you clear it
Daily allowance identifierFirst-party local storageA random value so that the free checks you run in a day are counted against one visitor rather than many. It contains nothing about you, it is not the analytics identifier, and it is never tied to what you check. Strictly necessary for keeping the checker free and available.48 hours, after which it lapses and a new one takes its place
Analytics identifierFirst-party local storageA random value issued by our servers so that your visits are counted as one visitor. Not strictly necessary. Where the law requires, we ask before storing it; elsewhere we rely on our legitimate interest.Where we ask first, until you withdraw through the Analytics preferences link or clear your browser's site data. Elsewhere there is no set end: clearing your site data removes it
Analytics choiceFirst-party session storageRemembers that you declined the analytics identifier, so the banner does not reappear in this tab.Until you close the tab
Campaign labelFirst-party session storageWhen you arrive through a link that names one of our marketing campaigns, remembers that campaign name so that a download you start from the App Store during this visit is counted towards it.Until you close the tab
Report prefillFirst-party session storageCarries a short summary into the report form when you report a problem: the check type, the verdict, and the confidence percentages for a check result, or the block reason and your IP address for a blocked-access report.Until the form reads it, or until you close the tab; ignored after ten minutes
Cloudflare TurnstileThird-party security challengeTells a person from a bot on the checker and the contact form.Per challenge, set by Cloudflare
cf_clearanceCookie, set by CloudflareAppears only if Cloudflare has to challenge suspicious traffic, so that a visitor who passes the challenge is not asked again. It protects the site; it does not track you. On an ordinary visit it is never set.Short-lived, set by Cloudflare
Free check countFirst-party local storageRemembers how many free checks you have left today and when they reset, so the checker can show the count before your next check.Until you clear it; ignored once your free checks reset

Why we process data, and on what legal basis

What we doData involvedLegal basis (GDPR)
Run a check you asked for on the online checkerSubmitted text or image, IP address, user agent, approximate locationArticle 6(1)(b), taking steps at your request
Enforce the daily allowance and keep the checker availableAnonymized, irreversible daily counters derived from connection data and from a random identifier held in your browser; before a check is accepted, your IP address and country (the IP address is not retained by that check)Article 6(1)(f), our legitimate interest in a free service that survives abuse
Block bots on the checker and the contact formConnection data processed by Cloudflare TurnstileArticle 6(1)(f), our legitimate interest in security
Run a hosted MCP tool call you asked forSubmitted text, processed in memory and discarded when the response is sentArticle 6(1)(b), taking steps at your request
Prepare clean copy a browser agent asked for on our MCP pageSubmitted text, processed in memory and discarded when the response is sent; the returned clean copy then stays in the MCP workbench page's own browser memory until the agent's review is accepted, rejected, or the page closesArticle 6(1)(b), taking steps at your request
Enforce the per-minute rate limit on the online text cleanup, the phrase scan, the clean-copy tool on our MCP page, and the hosted MCP serverYour IP address, held in memory only and discarded automaticallyArticle 6(1)(f), our legitimate interest in protecting the free service
Answer a message you sent usName, email address, message, optional screenshotArticle 6(1)(b) and Article 6(1)(f), answering your request
Measure how the site is usedFirst-party page and event data, carrying the analytics identifier where your browser holds oneArticle 6(1)(f), our legitimate interest in improving our own site
Count return visits to this siteA random analytics identifier held in your browserArticle 6(1)(a), your consent, where we ask first; Article 6(1)(f), our legitimate interest, elsewhere
Diagnose errorsError reports and performance measurements with query strings stripped from URLs and identifiers removedArticle 6(1)(f), our legitimate interest in a working service
Meet legal obligations, including accounting and taxRecords Apple and our accountants requireArticle 6(1)(c), legal obligation
Provide the text cleanup that runs with a completed online check or on our hidden character detector pageSubmitted text, processed in memory and discarded when the response is sentArticle 6(1)(b), part of the check you requested
Select an App Store retention message and check its deliverySubscription transaction identifier, app and product identifiers, locale, request identifier, environment and signing time supplied by AppleArticle 6(1)(f), our legitimate interest in providing subscription information and checking message delivery
Train and evaluate our detector, and understand how the free checker is usedFree-tier submissions as sent and the technical details recorded from an image file, with GPS coordinates removed from those details; the free-tier request record described aboveArticle 6(1)(f), our legitimate interest in improving our own service

Who else is involved

We keep as much as possible in our own hands. Our analytics, our error tracking, our database, and the Mac that runs detection are all operated by us, not bought as a service, so they are not third parties receiving your data.

These providers process data on our behalf:

  • Our hosting provider - runs our servers.
  • Cloudflare - DNS, TLS, content delivery, Turnstile, the country code that tells us which consent rules apply to your connection, and encrypted off-site storage (R2) for backups and the free-tier checks we keep.
  • Our email delivery provider - delivery of messages sent through the contact form.
  • Apple - the App Store, purchases, iCloud sync of your own data, and delivery of the detection models.

We do not sell personal data, we do not share it for cross-context behavioral advertising, and the only AI model we train with it is our own detector, using free-tier checks as described above. We disclose data to a public authority only where the law requires it.

How long we keep things

The specific periods for the online checker are listed in the section above. In summary:

  • Submitted content: paid checks are deleted as soon as the check finishes; free-tier checks are kept to improve the detector.
  • IP address and user agent for a check, plus the analytics identifier where your browser holds one: erased from the live database at the same moment, and excluded from backups entirely. The free-tier request record described above, including the approximate location, is kept for up to one year.
  • Check job records: 30 days.
  • Result cache records: 30 days. Image failure records: 24 hours.
  • Daily allowance counters: two days, then deleted.
  • Text-cleanup submissions, from the online tool and from either MCP surface, and phrase-scan submissions from the online tool: discarded when the response is sent, never written to disk, logs, or analytics. Their rate-limit keys are held in memory only and discarded automatically.
  • Analytics: kept indefinitely as event records. Where your browser holds the analytics identifier, events from that browser carry it, and where we ask first, withdrawing stops that. The IP address behind a visit is not stored. Where an inbound link carried an advertising click ID, that ID stays part of the recorded URL.
  • Contact form messages: kept in our mailbox for as long as we need them to deal with your request.
  • App Store retention requests: processed in memory without database storage. We log only the verified request identifier, environment, product, locale, response status and processing time to diagnose delivery problems. The signed payload and subscription transaction identifier are not logged. The endpoint does not automatically delete these diagnostic log entries.

Our servers are backed up to encrypted off-site storage, and backups are kept for up to about six months. Content submitted to the checker, its job records, and the request metadata described above are excluded from the backups entirely. The technical details we keep with a free-tier check and the free-tier request record are included.

International transfers

We are an Irish company. The cloud servers that run this site and its APIs are hosted in the European Union. Some of the providers listed above are established in the United States and may process data there or in other countries.

The safeguard for each transfer depends on that provider's arrangement: either an adequacy decision or the European Commission's standard contractual clauses, as required by Chapter V of the GDPR. Contact us if you need the current details for a particular provider.

Security

Traffic to the site is encrypted in transit. Backups are encrypted. Access to production systems is limited to the people who need it.

No system is perfect, and we will not pretend otherwise. If we ever suffer a breach that puts your rights at risk, we will notify the Irish Data Protection Commission and, where the law requires it, you.

Children

Slop or Not is a general-audience product. It is not directed at children, and we do not knowingly collect personal data from children. If you think a child has sent us personal data through the contact form, write to [email protected] and we will delete it.

Changes to this policy

We update this policy when what we do changes. The effective date at the top always tells you which version you are reading. We keep a full revision history of this page, and we will share the relevant changes on request.

We do not ask you to click a box accepting it.

Your rights

Which rights you have depends on where you live. To exercise any of them, write to [email protected]. We answer within the time the applicable law allows, and there is no charge. We may ask you for enough information to be sure the request is really yours, and no more.

One honest limitation: most of what we hold about a check is deleted within seconds of the check ending, or is an anonymized record we cannot reverse, except the free-tier material described above. If your browser holds the analytics identifier, you can send us that value and we can find the analytics events recorded against it. If we cannot find data that identifies you, we will tell you so rather than invent a match.

European Union and European Economic Area (GDPR)

You have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent at any time where we rely on consent. Withdrawing consent does not affect processing that already happened.

Where we rely on legitimate interests, you can object on grounds relating to your particular situation, and we will stop unless we have compelling grounds that override yours.

Our lead supervisory authority is the Irish Data Protection Commission. You can complain to it, or to the authority in the country where you live. The list of national authorities is published by the European Data Protection Board.

United Kingdom (UK GDPR and Data Protection Act 2018)

You have the same set of rights described above. You can complain to the Information Commissioner's Office at ico.org.uk.

United States state privacy rights

If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you may have the right to know what personal information we collect, to get a copy of it, to have it deleted, to correct it, and not to be treated worse for exercising those rights. Not every right exists in every state.

We do not sell personal information and we do not share it for cross-context behavioral advertising, in any state, for any price. There is therefore no sale or sharing for a Global Privacy Control signal to stop, and we do not act on that signal. We do not use sensitive personal information for inferring characteristics.

To exercise a state right, write to [email protected]. If we cannot verify a request, we will say so and explain why.

Canada (PIPEDA)

You can ask what personal information we hold about you, how we use it, and who we disclose it to, and you can ask us to correct it. You can complain to the Office of the Privacy Commissioner of Canada.

If you are in Quebec, Law 25 gives you further rights, including rights around automated decisions and data portability. We do not make automated decisions that produce legal effects about you.

Brazil (LGPD)

You have the right to confirmation of processing, access, correction, anonymization or deletion of unnecessary data, portability, information about with whom we share data, and revocation of consent. You can complain to the Autoridade Nacional de Proteรงรฃo de Dados.

India (Digital Personal Data Protection Act 2023)

You have the right to access a summary of your personal data and our processing, to correction and erasure, to nominate someone to exercise your rights if you die or become incapacitated, and to a grievance route. Send grievances to [email protected], which is our contact point for this purpose.

Australia (Privacy Act 1988 and the APPs)

You can ask for access to the personal information we hold about you and ask us to correct it. If you are unhappy with how we handled a privacy matter, complain to us first at [email protected]. If our answer does not satisfy you, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au.

Contact us

Privacy questions, requests, and complaints all go to the same address: [email protected]

The terms that govern your use of this site are in our Terms of Use.