Legal

Privacy Policy

This policy explains what Slop processes, why it is needed, how long it is kept, and the controls available to you.

Effective August 4, 2026

1. Who we are

Slop is operated by Gedcom AI LLC (“Slop,” “we,” “us,” or “our”). This policy applies to the Slop mobile application, website, and related services.

2. Information we collect

Account information

When you use Sign in with Apple, we receive an account identifier and may receive your name and email address, including an Apple private relay address if you choose to hide your email.

Content and analysis information

When you submit content, we process the image, video, or supported social-post link you choose. For a social-post submission, your request instructs Slop and its processors to resolve that specific URL and temporarily retrieve the associated media for analysis. We also process technical metadata needed to fulfill the request, such as media type, byte count, source platform, request fingerprint, provider-supplied title or author, timestamps, detector scores, verdicts, and usage counts.

Device and notification information

If you enable notifications, we process an installation identifier, Apple Push Notification service token, notification environment, and registration status. Notification payloads contain a job identifier and routing information—not submitted media or detector scores.

Operational information

We create redacted logs containing safe identifiers, timing, processing stage, outcomes, stable error codes, provider request identifiers, and operation counts. We do not intentionally log source URLs, media bytes, signed storage URLs, credentials, or notification tokens. Slop may send sanitized crash reports, performance traces, device and operating-system characteristics, app version, and diagnostic context to Sentry. Sentry diagnostics are configured without session replay, screenshots, view hierarchy capture, request bodies, or default personally identifying information.

Subscription information

If you buy or restore a subscription, Apple processes your payment. Slop receives and verifies Apple-signed transaction and renewal information such as product identifier, transaction identifiers, purchase and expiration dates, renewal status, and an account-linking token. Slop does not receive your full payment-card details.

3. How we use information

  • Authenticate you and maintain your account.
  • Analyze content you deliberately submit.
  • Return results, history, thumbnails, and notifications.
  • Apply plan limits and prevent duplicate submissions.
  • Verify purchases and maintain subscription access.
  • Protect, debug, monitor, and improve service reliability.
  • Comply with law and enforce our Terms.

We do not sell personal information, use it for targeted advertising, or track you across other companies' apps and websites.

Where applicable law requires a legal basis, we process account and submitted-content information to perform our contract with you; security, diagnostics, abuse prevention, and service improvement for our legitimate interests; notification information with your permission; and information needed to comply with legal obligations or protect rights and safety. You may withdraw notification permission through iOS Settings.

4. AI processing, visual media, and face data

Slop does not collect or derive biometric face data. Slop does not use facial recognition, facial geometry, facial landmarks, face embeddings, biometric templates, identity matching, or face-based authentication.

A photo or video you choose may incidentally contain a visible face. Slop processes the complete selected media only to estimate whether it may be AI-generated. Slop does not separately extract, label, identify, sell, or retain faces, and does not use submitted media for advertising or behavioral profiling.

After you provide explicit consent in the app, selected media is transmitted to Sightengine, operated by Kozelo SAS. Sightengine acts as Slop's AI-analysis data processor and processes the media on our behalf to provide the requested analysis. Slop does not submit media through Sightengine's Feedback API and does not authorize Feedback API use or model training with your submitted media.

For a supported social post, its URL is transmitted through RapidAPI to the selected media-resolution provider so that the post's photos or videos can be retrieved for the analysis you requested. The media may contain people or faces, but neither this retrieval nor Slop's analysis is used to identify those people.

Slop does not retain extracted face data because it creates none. Slop's raw-media retention is described below. Sightengine processes submitted media for the period needed to provide its services and as otherwise permitted or required by its service agreement and applicable law. Our processors are contractually required to process data on our behalf for defined purposes and to provide the same or equal protection required by this policy and applicable law.

AI analysis is an essential Slop function. If you do not consent, do not continue past the disclosure or submit media. You can prevent all future analysis by not submitting additional content and can delete retained Slop results or your account inside the app. You may also contact us to withdraw consent or request deletion assistance.

5. Media handling and retention

  • Native uploads: raw media is placed in private, transient storage only while the analysis runs. A reconciliation process removes stale transient objects older than 24 hours for terminal or missing jobs.
  • Social-post media: resolved media is fetched into a bounded temporary file for analysis and is not stored remotely by Slop as raw media or returned to you as a general-purpose download. The source URL is retained with the job so the app can direct you back to the original post.
  • History: Slop may retain a private, metadata-stripped thumbnail and analysis metadata until you delete the scan, delete your account, or we no longer need it to provide the service.
  • Account records: we retain account and security records while your account is active and as reasonably necessary for legal, fraud-prevention, and security obligations.

6. Service providers

We disclose information only as needed to operate Slop. As of this policy's effective date, the principal processors and the information they may receive are:

  • Apple: account authentication information, device push-notification registration and delivery information, and StoreKit purchase, renewal, and subscription-management data.
  • Supabase: account records, job metadata, usage records, device registrations, transient native uploads, and private metadata-stripped thumbnails.
  • Fly.io:encrypted application traffic and the temporary operational data processed by Slop's API and worker.
  • RapidAPI and the selected media-resolution provider: the specific supported social URL you direct Slop to resolve and the technical response needed to identify its media.
  • Sightengine (Kozelo SAS):the submitted or temporarily resolved media needed to perform the requested image or video analysis, together with provider request, model, usage, and sampling metadata. Sightengine acts as an AI-analysis data processor on Slop's behalf.
  • Sentry: sanitized application and server crash, performance, and reliability diagnostics. Slop disables session replay, screenshots, view hierarchy capture, request bodies, attachments, and default personally identifying information in its Sentry configuration.
  • Vercel: ordinary website request information, such as IP address, user agent, requested route, timestamps, and operational logs when you visit this public website.

These providers process information under written terms, privacy commitments, or data-processing agreements applicable to their role. We require processors to use information only for authorized service purposes and to maintain protection consistent with this policy and applicable law. Gedcom AI LLC does not use submitted media to train its own detection model. We will update this policy and, when required, request renewed consent before materially changing our AI processor or processing purposes.

We may also disclose information when required by law, to protect rights or safety, or in connection with a merger, financing, acquisition, or sale of assets, subject to appropriate protections.

7. Your choices and rights

You can decline notifications, delete individual scans, or delete your account inside Slop. Account deletion removes your profile, device registrations, job records, and stored Slop thumbnails, subject to limited legal or security retention.

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal information, and to appeal a response. Contact us to make a request. We may verify your identity before completing it.

See the account deletion guide for exact in-app steps.

8. Security and international processing

We use administrative, technical, and organizational safeguards designed to protect information, including private storage and authenticated access controls. No system is completely secure. Slop and its providers may process information in the United States and other countries where they operate.

9. Children

Slop is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can investigate and delete it.

10. Changes and contact

We may update this policy as Slop changes, including when we add or replace a material hosting, storage, media-resolution, detection, or notification provider. We will revise the effective date and provide additional notice when required.

Privacy questions and requests can be sent to contact@slop.gedcomai.com.