Skip to main content

Privacy

Privacy

Written to be read. If something here is unclear, treat that as our problem and tell us.

The short version

  • We do not store the text you paste. We store a one-way fingerprint of it.
  • We do not store full URLs. We store the domain only.
  • We do not sell anything you submit and we do not use it to train models.
  • You can delete your history at any time, entry by entry or all at once.
  • We load no third-party scripts, trackers or advertising.

What we collect

Anonymous identifier. Every visitor gets a random identifier in a signed, HTTP-only cookie. It exists so preferences and rate limits work without an account. It is not linked to any personal information.

Spoiler check records. For each check we store the game, whether the input was a link or text, the registrable domain if there was one, a SHA-256 fingerprint of the normalised input and the classification result. We do not store the submitted content, extracted page text or anything quoted from it.

Account information. If you create an account we store your email address and a scrypt hash of your password. We never store the password.

Progress and preferences. The progress you record and the protection level you choose.

Product analytics. Counts of named events such as “a spoiler check completed”, with a small set of allowed properties. The server drops any property that is not on the allowlist for that event, so submitted text, URLs and questions cannot reach analytics even if a client tried to send them.

Sending content to an AI provider

When assisted analysis is enabled, the content you submit is sent to the configured AI provider so it can be classified or answered. The operator of this deployment chooses that provider and the provider’s own terms apply to that transfer. API keys stay on the server and are never exposed to your browser. If no provider is configured, nothing leaves our servers and the offline classifier handles checks on its own.

Retention

Check records are kept for a configurable period, 30 days by default and can be disabled entirely by the operator. Signing out ends your session immediately. Deleting your history removes those records; it cannot be undone.

Logs

Server logs record operational events. They do not include submitted content, full URLs, question text or AI provider response bodies — provider errors can echo submitted content, so we discard those bodies rather than log them.

Contact

Questions or a deletion request: hello@example.com.

This page describes how the software behaves. It is not legal advice and an operator running their own deployment is responsible for their own compliance obligations.