Legal
SlopSquash Cookie Policy
contents
1. Scope
This Cookie Policy explains every cookie and browser storage item that William Freire, doing business as Slop Squash ("SlopSquash", "we", "us") uses on slopsquash.com, admin.slopsquash.com, api.slopsquash.com, and in the SlopSquash browser extension. It supplements our Privacy Policy. "Cookie" means a small text file set by a website in your browser. "Storage" means browser mechanisms such as localStorage and extension storage that hold data without setting a cookie.
2. What we use
We use no analytics cookies, no advertising cookies, no social media pixels, and no third-party trackers. The complete list is below.
2.1 Cookies and storage we set
| Name | Type | Where | Purpose | Duration | Category |
|---|---|---|---|---|---|
slopsquash.session |
localStorage | slopsquash.com and admin.slopsquash.com | Holds your session token so you stay signed in. Sent to the API as a bearer token; not sent as a cookie | Removed on sign-out; the session expires 14 days after sign-in | Strictly necessary |
sv_ref |
Cookie (SameSite=Lax) | .slopsquash.com |
Records the slug of the creator whose referral link you followed so the 30% first-month discount can be applied at checkout and the sale attributed to that creator | 30 days | Functional (referral attribution) |
| Extension token | Extension storage (chrome.storage.local or Firefox equivalent) |
Inside the extension | Authenticates the extension's requests to the API as your account | 90 days, or until you sign out of the extension or uninstall it | Strictly necessary for signed-in use |
| Extension settings | Extension storage | Inside the extension | Per-site enable or disable, sensitivity preset, auto-block, on-device-only mode, Pro allow-lists and site rules | Until changed or the extension is uninstalled | Functional |
| Tab verdict memo | chrome.storage.session |
Inside the extension | Remembers verdicts already computed for content on the current tab so it is not re-analyzed while you scroll | Cleared when the browser closes | Functional |
2.2 Cookies set by our infrastructure provider
Cloudflare, which hosts our sites and API, may set the following on our domains. They are controlled by Cloudflare's security features and do not track you across other sites.
| Name | Purpose | Duration |
|---|---|---|
__cf_bm |
Bot mitigation; distinguishes automated traffic from humans | Up to 30 minutes |
cf_clearance |
Set only if you complete a Cloudflare security challenge, so you are not challenged again | Up to 1 year, typically shorter |
CF_Authorization |
Set only for SlopSquash staff on admin.slopsquash.com by Cloudflare Access after they authenticate | Per the Access session policy |
2.3 Cookies set by third parties on their own domains
When you pay, we redirect you to pages hosted by Stripe (checkout.stripe.com and billing.stripe.com). When you sign in with Google or GitHub, we redirect you to their sign-in pages. Those companies set cookies on their own domains under their own policies (stripe.com/privacy, policies.google.com/privacy, docs.github.com/site-policy). We do not control those cookies and they are not set on slopsquash.com.
3. What we do not do
- We do not set cookies on third-party websites. The extension draws its overlay in your browser and sets nothing on the sites you visit.
- We do not use cookies or storage for advertising, cross-site tracking, fingerprinting, or profiling.
- We do not sell or share cookie data.
- We do not load third-party analytics scripts.
4. How to control cookies and storage
Referral cookie. You can delete sv_ref at any time through your browser's site data settings for slopsquash.com. If you delete it before checkout, the referral discount will not be applied.
Session storage. Signing out removes slopsquash.session. You can also clear it through your browser's site data settings, which signs you out.
Extension storage. Sign out of the extension from its popup to remove the extension token. Removing the extension deletes all of its storage. Enabling "on-device only" mode in the popup stops all network requests to our API; local settings remain.
Browser controls. Every major browser lets you block or delete cookies and site data. See your browser's help pages: Chrome (Settings > Privacy and security > Third-party cookies and Site settings), Firefox (Settings > Privacy & Security), Safari (Settings > Privacy), Edge (Settings > Cookies and site permissions). Blocking strictly necessary storage will prevent sign-in.
Global Privacy Control and Do Not Track. We do not sell or share personal data, so there is nothing for these signals to opt you out of. We honor Global Privacy Control as an opt-out request under applicable state law regardless.
5. Consent
The items in Section 2.1 marked strictly necessary are required to provide a service you request and do not require consent. The sv_ref cookie is set only when you follow a creator's referral link; the landing page tells you that the link applies a discount. Where the law of your country requires consent for functional cookies, we will ask for it before setting sv_ref, and you may decline without losing access to the Service (you will simply not receive the referral discount).
6. Changes
We will update this policy whenever we add, remove, or change a cookie or storage item. The effective date at the top shows the last revision.
7. Contact
Questions about cookies: privacy@slopsquash.com. Mail: William Freire, doing business as Slop Squash, 300 West 109th Street, New York, NY 10025, United States.