Privacy
This page says what plopslop stores, why it stores it, how long it keeps it, and how to get rid of it. It covers plopslop.com and nothing else. Last updated 25 August 2026.
What changed on 25 August 2026, in one place. The picture game is open and is no longer described here as a design. A model now reads every picture as it is fetched and plopslop keeps one estimate and a block of measurements per picture. Your points in that game come from whether you read a picture the way the model did. Both games now record how long a call took on plopslop's own clock as well as the figure your browser reports, and plopslop now rebuilds a nightly summary of how each player plays. The sections below say what all of that holds.
This is a draft under legal review. The parts marked below are not settled yet. Everything it says about what plopslop stores was read from the code that runs the site on the date above.
Signed out, plopslop stores almost nothing
The whole site reads without an account. Signed out, plopslop stores nothing about what you open. Your followed topics, muted words, country, theme, and the topics you tap most sit in your browser and never reach the server.
One thing does happen on the server. To lean the feed towards where you are, your network address is looked up once against a copy of the DB-IP country database that sits on plopslop's own machine. The answer is a two-letter country code. The address is not stored, the code is kept in your browser for 7 days so the lookup is not repeated, and nothing is sent to anyone else. A country you pick in preferences always wins over it. IP Geolocation by DB-IP.
Opening the account page is the other exception. Asking for a signup puzzle writes a puzzle row, and a signup or a sign-in attempt puts a count against a salted hash of your network address, whether or not an account is ever made. Both are described under keeping bots out below.
What an account stores
Your account itself:
- your username, which is public on the leaderboard
- a scrypt hash of your password, never the password itself. Accounts made with a username carry no email address at all, which is also why there is no password reset and no way to recover a lost password.
- your Google email address and your Google account id, only if you chose to sign in with Google
- a salted hash of the device cookie your browser carried at signup
- a salted hash of the random id your browser made for itself, if it was carrying one when you signed up or first signed in on it. Your account adopts that id once and never replaces it.
- the date the account was created
Staying signed in:
- one row per signed-in device, holding a hash of the session token, when it was made, when it expires, and when it was last used
Keeping bots and password guessing out:
- attempt counters, as a count and a timestamp against a salted hash. A counter goes up on a failed sign-in and also on every signup, every request for a signup puzzle, and every Google sign-in, whether they succeed or not. The username, the email, and the network address are reduced to a hash with a server secret before anything is written, and an IPv6 address is cut to its /64 block first. None of the three is ever stored in the clear.
- one row per puzzle the signup form hands a browser, holding a random salt, the answer, and an expiry. Those rows say nothing about the person solving them. The puzzle is served by plopslop, so no third-party captcha sees your visit.
What you set:
- followed topics, muted keywords, and country
What you open, signed in:
- each article you open from plopslop, with the time
- the weights that learning produces, one per topic, source, and country
Every call you make in the game:
- the article, your call of slop or top, the mode, and the time
- how you made the call: a swipe, a tap, or a key
- the estimate the system had at that moment, whether or not you chose to see it, and whether your call matched the system
- in Deep mode, the reasons you tapped, any line you wrote, and whether that line passed the gate that keeps keyboard runs out
- the signs of machine writing the reveal showed you, when the system called the article slop
- two measures of how long you took: the number of milliseconds your browser reports, and plopslop's own, counted on the server from the moment the card was dealt. The second is the one the quality summary below uses, because a number the browser supplies cannot be trusted to penalise itself.
- whether you opened the article before you judged it
- how sure you said you were, and the points the round paid
- how many other players had already judged that card and whether you agreed with them. That is recorded on every call and shown to nobody.
- whether your call went the way our software did, and the time the round was settled, which is the moment you called it. A call is paid in full at once and nothing about your score waits on anybody else.
- which detector and which version produced the score you saw
- which round of the sitting it was, and a random id for the browser tab so rounds can be grouped
- which pool the card was drawn from and how likely it was to be dealt, so the shape of the deck can be corrected for later
- whether you challenged the result
Every card the game deals you:
- the article, its place in the deck, the mode, the tab id, and the time. This is how plopslop can tell a card you skipped from a card you never saw. In Quick bites, also which passage of the article you were shown.
What you bring to the game:
- for every link or text you paste at Bring your own: the text itself, kept privately and shown to nobody but you, the link and the title when there was one, a hash of the text, its word count, the estimate and the signs the system found, which detector produced them, your own call with the reasons you tapped and any line you wrote, and the times. Nothing here is listed anywhere or joined to the feed.
The walkthrough:
- the date you finished or skipped it, so it never runs twice
What plopslop works out about the way you play:
- one row per player, rebuilt every night from your own article game calls and the cards you were dealt over the last 90 days. It holds how many calls you made, how many cards you were dealt, how many days you played, how many browser tabs you played from, how often you skipped a card, your middle answer time, what share of your answers came in under 1.5 seconds, how often you call slop, how one-sided that is, your longest run of the same call, how often you say you are sure, and how often you open an article before judging it.
- two agreement figures and the gap between them: how often you agree with other people on the same article, and how often you agree with them across different articles. The first is a signal and the second is a shared habit, so the gap is what says whether your calls carry information. A single quality number is computed from those, and it decides how much weight your calls carry when the labels are used.
That row is about you and it is not shown to you or to anyone else. It never touches the leaderboard. Nothing in it is derived from the detector or from whether you agreed with it, so it stays an independent read on whether a set of labels is worth anything. It is deleted with your account.
Pictures in the picture game
The picture game is closed while its deck is rebuilt. The rows below were collected while it was open, between 25 and 26 August 2026, and are kept as described. This section was first published before the game opened, because under India's DPDP Act the purpose of collecting something has to be stated before the collecting starts and cannot be added later, and it stays here for the same reason.
The picture game shows you a picture and asks you to call it slop or top. The pictures come from public web pages and public posts, fetched by the same crawler that reads articles. That crawler honors robots.txt on every fetch and identifies itself as plopslopbot. You cannot upload a picture to plopslop, and plopslop never asks you for one. Playing needs a signed-in account, the same as the article game.
What plopslop keeps about a picture:
- a small copy, about 320 pixels on its long side, made when the picture is fetched. It is kept while the picture waits for the deck and while it is in the deck, and deleted when the picture leaves. A picture that never reaches the deck has its copy deleted 30 days after it was fetched. The original file is never stored.
- the address the picture came from, so the reveal can link back to the original, the address of the page it sat on, the article it was found in, and the caption the publisher wrote for it, up to 500 characters. A caption is the publisher's own words and it sometimes names the person in the photograph.
- its width and height, the size of the file in bytes, and its type
- three fingerprints of the original file. They are short numbers that let plopslop spot the same picture twice, and no picture can be rebuilt from them.
- when it was fetched, when it entered the deck, and when it left
- whether a face check ran, what it answered, and which detector answered. That is a yes or no about whether a face is in the frame. No measurement of anyone's face is taken and nobody is identified. Pictures are not kept out of the deck for containing a person.
- one machine estimate per model of how likely a machine made the picture, kept as a probability and shown as a whole percent. It is taken while the picture is being fetched, on the original file, before the small copy is made. Stored with it are the name and version of the model, whether it read the original or the small copy, and the date it ran. Pictures fetched before 25 August 2026 carry an estimate read off the small copy instead, and the record says which.
- a block of measurements taken from the original while it was still in memory, kept after the file itself is gone, because a small copy destroys all of them. There are three parts. A row of 768 numbers that describes the picture to the model. A grid of 4 by 4 cells with five measurements in each cell, which is what lets plopslop compare where a player's gesture started against what was in that part of the picture. And a forensic part: whether the file carried EXIF data and how many tags, the camera make and model and the editing software when the file named them, whether a timestamp and a location block were present, whether it carried a colour profile, its compression fingerprint, and ten numbers describing its noise, its frequency content and its block structure. None of it renders a picture and none of it is about a player.
Before any of that, every address plopslop considers goes into a discovery queue. A row there holds the address, the page it came from, when it was seen, and, when the picture was turned away, why: too small, a duplicate, blocked by robots.txt, undecodable, an error from the server, or a face found while the face gate was switched on. A turned-away address is never fetched again and nothing else about it is kept.
The picture reaches you inside the page plopslop sends. Your browser never asks the site the picture came from for anything, so that site is never told you are here or which card you were dealt.
A model reads every picture, and this is the one thing in the picture game that is about the picture rather than about you. The estimate is computed once, stored against the picture, and is the same number for every player dealt that card. Your call does not change it. It does decide your points: a round pays 10 when your call went the way the model did and nothing when it did not, whatever certainty you gave. A picture no model has read yet pays a flat 2 either way. The article game works the same way against its own detector. The model runs on plopslop's own server, so no picture and nothing measured from a picture is sent to another company to be scored. The numbers it produces are in the nightly backup like everything else, and only the stored small copies are kept out of that. After your call the reveal shows the estimate and how often the model is right.
Every call you make in the picture game:
- the picture, your call of slop or top, and the time
- how sure you said you were, and the points the round paid. Certainty is stored and pays nothing in this game.
- two measures of how long you took: the number your browser reports, and plopslop's own, counted on the server from the moment the card was dealt
- how many other players had already judged that picture and whether you agreed with them. That is recorded on every call and shown to nobody, because seeing a count of strangers before you look changes what you see.
- whether your call went the way the model did, and the time the round was settled, which for a picture is the moment you called it
- whether the round showed you the estimate afterwards, which every round now does
- how you answered, which is a swipe, a button, or a key
- where on the picture your gesture started, as a position on a grid 1000 steps across and 1000 steps down
- how many times your swipe changed direction, as a count
- how far you zoomed in, as a percentage of the size the card was dealt at, and where you zoomed if you did
- which pool the picture was drawn from and how likely it was to be dealt, the round of the sitting, and a random id for the browser tab so rounds can be grouped
Every card the picture game deals you:
- the picture, its place in the hand, the tab id, which pool it came from, how likely it was to be dealt, and the time. This is how plopslop can tell a card you skipped from a card you never saw.
One thing is left out on purpose. plopslop records where your gesture started and never the path your pointer took to get there. About 30 features of a single touch stroke are enough to pick one person out of a crowd, which makes a pointer path a biometric. It is not sent to the server and it is not stored.
The deck can contain pictures of people. A picture of an identifiable person is personal data about that person, and plopslop does not filter those out, so a picture of you could appear. If one does, say so and it comes out. You do not have to explain why and you do not need an account to ask.
Nothing about who is in a picture is worked out or kept. No names, no face template, no measurement of anyone's features, and no attempt at recognition of any kind. A face detector does run over every picture as it is fetched, and it answers one question, whether there is a face in the frame. Three things are kept from it: that the check ran, what it answered, and which detector answered. The setting that would drop a picture for containing a person is off, so that answer is written down and no picture is kept out for it. While that setting was on, addresses turned away for it kept the reason and nothing else.
Anyone can ask for a picture to be taken out, for any reason. Write to hello@plopslop.com with the address of the picture or of the page it sits on. It leaves the deck and its small copy is deleted. The terms set out the same route for rights holders.
plopslop never puts the name of a site next to a call about a picture. The reveal shows the address the picture came from and links to it, which is a pointer back to the source rather than a verdict about whoever runs it.
To be completed before launch. Name how fast a picture removal is done and who answers those requests, and confirm that a picture taken out cannot be dealt again when the deck next rotates.
What sits on your device
Cookies, none of them shared with anyone:
- the session cookie, so you stay signed in. Your browser holds it for up to 365 days, and the server stops accepting it 90 days after you last use it.
- the device cookie, one random id that lasts 400 days. It exists so one browser cannot create accounts in bulk.
- two cookies that live for 10 minutes during Google sign-in, one holding a random nonce that blocks a forged sign-in and one holding the page to send you back to. Both are cleared when sign-in finishes.
- a fourth cookie that lives for 10 minutes, set only when you start a Google sign-in, holding the random id your browser made for itself so the new account can adopt it. This is the one cookie a script in the page can read, because a script in the page is what sets it. Every other cookie above is written by the server and no script can read any of them.
plopslop sets no other cookies. Your topics, muted words, country, theme, and the tally of topics you tap stay in your browser storage and are never sent anywhere. The random browser id lives there too. It leaves your browser only when you create an account or sign in.
Why plopslop holds each of these
Each purpose stands on its own. Nothing here is bundled into one blanket consent.
- Running your account. The username, the password hash, the Google identity, and the session rows exist so you can sign in and stay signed in.
- Running the games and the leaderboard. Judgments and dealt cards produce your score, your accuracy, and your rank, and they stop the same card being judged twice for points. In the picture game the position your gesture starts at, the zoom, and the count of direction changes are also used to learn which parts of a picture people react to.
- Keeping abuse and bots out. The hashed attempt counters, the signup puzzle, and a device signup counter cap how many accounts one browser or one network can make and how fast passwords can be guessed. Both games also cap how many calls one account can make, at 30 a minute and 300 an hour across the two.
- Keeping the scoring independent. The salted device hash on your account is read when a game scores you. Two accounts created on the same browser count as one contributor, so they are not treated as separate people and cannot score each other. Nobody is blocked by it.
- Weighting the labels. The nightly summary of how you play decides how much weight your calls carry when the labels are used. A player who answers in under a second, or who calls everything the same way, contributes less than one who does not.
- Making the feed yours. Your preferences, the articles you open while signed in, and the weights learned from them order your feed. This only ever happens on an account, and the account page says so.
- Improving and calibrating plopslop's detection. Judgments from many players are the human check on the detector. They are used to measure where it is wrong and to train and evaluate later versions. The estimate stored against each picture is what those calls get compared with, which is how plopslop measures where the picture model is wrong. The measurements taken from each original picture are what a better model would be trained on, and they are kept for that.
- Publishing aggregate statistics. Counts and rates drawn from many players, such as how often people match the detector, get published as numbers about the crowd.
- Publishing or licensing a dataset of judgments. The calls players make are collected so that they can be released as a dataset for other people to work with, either free or under a paid licence. Any release carries no usernames and no email addresses. The section below says what that means for you.
In the words the law uses: running the account and the games is what you signed up for, keeping abuse out and improving the detection are plopslop's legitimate interests, and the training use, the aggregate use, and the release of judgments rest on the licence in the terms.
To be completed before launch. A lawyer needs to confirm the legal bases named in this section against the GDPR and India's DPDP Act, and say whether any of them should instead be handled as an explicit consent at signup. Releasing a dataset under a paid licence is the one most likely to need its own consent rather than a licence buried in the terms.
Your judgments become a dataset
This is the plain version. plopslop is building a record of how people judge machine-made work, in writing and in pictures, and the games are where that record comes from. Every call you make is stored and used to test plopslop's detection, to train and evaluate later versions of it, and to publish aggregate results. That is the point of the games rather than a side effect of them.
plopslop intends to release that record as a dataset, either free or under a paid licence, so that other people can study how humans judge machine-made work. This was written down before the picture game collected its first call, because a purpose has to be stated before collection starts and cannot be bolted on later. Playing is how you agree to it. If you would rather your calls were not in a dataset, do not play. Reading plopslop needs no account and no calls.
Your username is attached to your judgments inside plopslop, because that is how the leaderboard and the judged-once rule work. It is not attached to anything published. Published results are counts and rates about many players. A released dataset carries the judgments with no usernames and no email addresses in it. For image judgments that includes the gesture positions described above, which are positions on a picture and hold nothing about you.
A dataset that has been released cannot be recalled. Copies are with other people from that point on. Deleting your account takes your rows out of plopslop and out of every release after that, and it cannot reach the ones already out.
What is public about you
Your username, your score, how many rounds you have played, your rank, and the accuracy figure the leaderboard shows. Nothing else about you appears anywhere on plopslop. There are no profile pages.
No trackers, none at all
plopslop runs no third-party analytics, no advertising scripts, no social widgets, no tracking pixels, and no fingerprinting. Fonts are served from plopslop's own server. There is no analytics product on this site at all, so nothing about your visit is measured for anyone.
Two companies are involved at all, and neither watches you browse. Google holds the nightly backup copy of the database, which is everything on this page except the stored copies of pictures. And if you choose to sign in with Google, Google learns that you signed in to plopslop.
Accounts are for adults
You need to be 18 or older to create an account. Both games measure how accurate each player is and rank players against each other, and plopslop will not run that on children. India's DPDP Act treats everyone under 18 as a child and does not allow behavioural monitoring of them, which is what a per-player accuracy figure and a leaderboard are. There is no parental consent route, because plopslop is not built to verify a parent and would rather say so than pretend. If plopslop learns that an account belongs to someone under 18, the account is deleted. Reading plopslop needs no account and is open to anyone. The terms say the same thing.
Being straight about how that is enforced: the signup form does not ask your age and plopslop does not verify it. The rule is stated here and in the terms and it is acted on when plopslop learns an account belongs to someone under 18. There is no age gate on the form today.
How long each thing is kept
- Account, preferences, learned weights, reading events, judgments, dealt cards, what you brought to the game, and the walkthrough date. Kept while the account exists. Nothing here expires on its own today.
- The nightly summary of how you play. One row per player, replaced every night and computed from a rolling 90 day window, so it forgets anything older than that on its own. The row is deleted with the account.
- Picture judgments and pictures. A call keeps its full row for 180 days and is then meant to be rolled into counts per picture that carry no player and no timing. The deck holds about 2,000 pictures at a time. A picture leaves it once 40 people have judged it or after 30 days, whichever comes first, and the small copy is deleted in the same pass. A picture that never reaches the deck has its small copy deleted 30 days after it was fetched, and at most 4,000 such copies are held at once. Those copies stay out of the nightly backup, which leaves them out by name. The machine estimate and the measurements taken from the original are kept with the picture record after the small copy goes, so a later model can be measured against them. They name a model and a date and no player.
- Sessions. A session stops working 90 days after you last use it, and 365 days after it was issued. Signing out deletes that session row. Signing out everywhere deletes all of them.
- Attempt counters. The sign-in counter is cleared the moment you sign in successfully. Otherwise a counter stops counting once its window passes, between 10 minutes and 24 hours depending on which one it is. Those rows hold no readable data, and plopslop has no scheduled job that sweeps them yet.
- Signup puzzles. Valid for 10 minutes, single use, and deleted an hour after they expire.
- The device signup counter. A device may create 2 accounts in 30 days. The salted device hash behind that limit stays after the window passes.
- Backups. The database is dumped nightly. 14 daily copies and 8 weekly copies are kept, so the oldest copy is at most 56 days old.
- Server logs. Standard web server request logs record network addresses, as every web server does. They exist to keep the site up and to trace faults, and nothing in them is joined to an account or a judgment. plopslop's own code writes no email address, password, session token, or network address into a log.
To be completed before launch. Set and state a retention period for server request logs, and add a scheduled sweep for stale rate-limit rows so this section can name a number instead of describing the mechanism. One picture promise above still needs code: the nightly job that rolls a 180 day old call into counts per picture. No such job exists today, so picture calls are kept in full for now. The backup exclusion is done and shipped.
Deleting your account
The account page has a delete button. It runs at once and takes the account row, the username, the password hash, the Google identity, the two salted hashes the account holds, every session, your preferences, your learned weights, your reading events, the nightly summary of how you play, every judgment you made in either game, and every card you were dealt.
Being honest about what deletion cannot undo:
- A model already trained on your judgments keeps what it learned. There is no way to untrain a model on one person's rows.
- Aggregate numbers already published stay published. They cannot be recalled.
- A dataset already released stays released, and it holds the rows it held on the day it went out. Those rows carry no username and no email address.
- Counts already rolled up per picture stay, and so do the machine estimate and the measurements stored against a picture. They hold no player, so nothing in them points at you.
- The hash of your browser id goes with the account. Signing out rotates the id in your browser, which starts a fresh one.
- Backups taken before the deletion hold a copy until they age out, which is at most 56 days.
- The device signup counter keeps its salted hash, so deleting an account does not hand back the slot it used.
Your rights
Wherever you read from, plopslop treats these as yours: to know what is held about you, to get a copy of it, to correct it, to delete it, to object to a use of it, to withdraw a consent you gave, and to complain to a regulator. Readers in the EU and the UK have these under the GDPR. Readers in India have them under the DPDP Act.
What works today, without asking anyone:
- The account page shows the identity plopslop holds for you and lets you change your preferences.
- The delete button removes everything listed above, in one step.
- Signing out everywhere ends every session at once.
Two gaps, stated rather than glossed over. There is no button that exports your judgments as a file yet. A username is set once and cannot be edited, so the only way to change it is to delete the account and make another.
To be completed before launch. Add a contact address for privacy requests, a route for people to complain, and the name of the person or company answering them. The mailbox has to receive mail before it is named here, because a policy that lists a dead address is worse than one that lists none.
A reader in the EU or the UK may complain to their national data protection authority. A reader in India may complain to the Data Protection Board of India.
Where plopslop runs
plopslop runs on one rented virtual server, with its own database on that server. Nightly backup copies go to Google Drive. plopslop is run from India, so data reaches India wherever you read from.
To be completed before launch. Name the country the server sits in, name Google Drive as the backup processor with its terms, and have a lawyer set out the transfer basis for readers in the EU and the UK.
Changes to this page
The date at the top changes whenever this page does. A change that affects what plopslop collects or what it does with it will be said plainly at the top rather than slipped into a paragraph.