Privacy Policy
Last updated 25 August 2026
The short version: finding AI slop happens entirely inside your browser. Your writing is sent to our servers only when you click a button that rewrites it, and never otherwise. The extension has no analytics at all. The website counts page visits with Google Analytics, which sees addresses and never your writing. We do not record what you write or which sites you visit.
What the extension reads
When you focus a text box, comment field or editor on a page, the extension reads the text in that field so it can underline AI clichés. It does not read the rest of the page, other tabs, your browsing history, or your bookmarks.
Password fields are never read. Neither are search boxes, code editors (Monaco, CodeMirror, Ace), or any element marked data-slop-ignore.
Where the analysis happens
In your browser. The full detection catalogue ships inside the extension, so finding a cliché involves no network request at all. You can confirm this in DevTools: type into any editor with the Network tab open and nothing is sent.
When your writing leaves your browser
Only when you ask for it. Specifically:
- You click Smash the AI Slop or a whole-draft rewrite. The draft is sent to our API, rewritten, and returned. It is used for that request only.
- You click Open this draft in Studio. The draft is passed to the Studio tab through the extension's own storage. It is not put in the URL, so it does not reach browser history or server access logs.
Applying an individual suggestion, using Fix all, and everything the underlines do are local operations. They send nothing.
Google Docs
Google Docs paints text to a canvas, so the extension cannot read it from the page. It instead requests the document's own plain-text export from Google, using the session you are already signed into. That text is analysed in your browser and is not sent to us unless you request a rewrite.
What is stored on your device
Held in the extension's local storage and never transmitted:
- Your account email, plan, and API key, once you connect an account
- Words you chose to never flag again
- Sites you switched the extension off for
- Where you dragged the panel, and whether you have seen the first-run tips
Your password is never stored by the extension, and never passes through it when you use one-click connect.
What is stored on our servers
For an account: your email address, a hashed password (scrypt, so we cannot read it), your API key, your plan, and a per-day count of rewrites for quota enforcement.
Drafts sent for rewriting are processed to produce the result and are not retained as a stored record. No plan sends your draft to a language model or any other third party. The rewriting is rule-based and runs on our own server, and the model clients that could once have sent it were deleted from the codebase.
What we never collect
No tracking pixels, session recording, fingerprinting, advertising identifiers or ad networks, in the extension or on the site. The extension carries no analytics whatsoever: nothing about what you write, or where you write it, is measured. The website counts page visits, which is covered in the next section. We do not build a profile of you and we do not sell or share data with anyone.
Analytics on the website
The website uses Google Analytics 4 to count page visits and see which pages people arrive on. It sets its own cookies and Google receives your IP address, which it uses to derive an approximate location and then discards. This runs on the website only. The Chrome extension does not load it.
It never sees your writing. Drafts are sent to our API inside a POST body and are never put in a URL or a query string, so nothing you type is in the page addresses Analytics records. It is also the only third-party script on the site.
You are asked before it is allowed to store anything. On your first visit every consent signal is set to denied, so Analytics cannot write a cookie or record an identifier until you press Accept all, or tick Analytics under Choose what to allow. Press Reject all and it stays denied.
To change your mind later, use Cookie settings in the footer of any page. A browser Do Not Track setting or an ad blocker also stops it loading. Nothing about the product stops working whichever you choose.
Why the extension can run on every site
The extension requests access to all sites because the editor you write in could be on any of them: LinkedIn, Gmail, your CMS, an internal tool. Requesting them individually would mean the extension simply failed to work wherever we had not thought of.
Because that access is broad, there is a per-site switch: open the extension on any page and turn Run on this site off. Nothing is read there afterwards. You can also disable underlining everywhere from the same panel.
Every permission the extension asks for
Chrome shows a single summary when you install anything. This is the full list, what each one is for, and what it does not allow.
| Permission | Why it is needed | What it does not do |
|---|---|---|
| activeTab | Read the text of the editor on the tab you are looking at, so it can be underlined. | Grant access to any other tab, or to a tab you are not on. |
| storage | Keep your settings, your personal word lists and your sign-in on your own device, and hand a draft to the Studio tab without putting it in a URL. | Sync anything to us. This is local browser storage. |
| contextMenus | Add the right-click entry that checks a selection. | Read anything. It only adds a menu item. |
| scripting | Attach the underline layer to an editor that loads after the page does, which most modern composers do. | Run code we fetch at runtime. Everything shipped is in the package. |
| Host access to removeaislop.com | Reach our API to sign you in and to rewrite a draft when you ask for one. | Send anything on its own. Every call follows a click. |
| Host access to localhost | Let the extension talk to a development server. Present so the same build works for us and for you. | Anything on your machine. It reaches one port on your own computer, which normally has nothing listening on it. |
| docs.google.com | Google Docs paints text to a canvas, so it needs its own adapter to read the document at all. | Reach Drive, Gmail or any other Google product. |
| Content script on all sites | Your editor could be on any site. Covered in the section above, together with the per-site switch that turns it off. | Send any page anywhere. The checking runs inside your browser. |
Limited use of data
Our use of information received from Google APIs, and of anything the extension reads on the pages you visit, follows the Chrome Web Store User Data Policy, including its Limited Use requirements. In practice that means the data is used to provide the feature you asked for and nothing else: it is not sold, not transferred to anyone except as needed to run the product, not used for advertising, and not used to determine anybody's creditworthiness or for lending purposes. No human at RemoveAISlop reads your drafts.
The extension carries no analytics of any kind. The Google Analytics described above runs on the website and is not part of the extension.
Deleting your data
Sign out in the extension to remove the account details held on your device. To delete your account and its server-side record, email support@removeaislop.com from the address on the account.
Changes
If this policy changes in a way that affects what we collect, the date above changes and the change is described in the product changelog.