Privacy Policy
This revision is effective August 30, 2026. Website: neuroslop.net. Service owner: the independent operator of the Neuroslop project; contact: info@neuroslop.net, Telegram **@AITextChecker** (hereinafter "we"). The Neuroslop service checks texts for machine clichés and rewrites them in natural language.
What data we collect
- Email address and password hash: upon registration. The password is stored only as a scrypt hash with a salt and cannot be recovered from the hash.
- Google account data (identifier, email, name): if you sign in via Google.
- Telegram data (identifier, name, username): if you sign in via Telegram.
- Technical device data: browser user-agent, IP address, login time. Needed for the device list in the account and protection against unauthorized access.
- Texts you submit for humanization on the website, through the API, or in the Telegram bot are
transmitted to an AI provider for rewriting. In the Telegram bot, text may also be sent to the provider for optional neural analysis of a checking result. The ordinary deterministic website check runs on our server without sending the text to that provider. A successful humanization made by a signed-in, verified account through our same-origin website may also enter the protected, time-limited quality sample process described below. API, bot, unverified-account, and cross-origin humanizations do not enter that process.
- The ordinary RubricLock check runs locally in your browser and sends neither the assignment nor
the draft anywhere. Only when you separately start the paid “Deep Review” and tick its explicit consent box are both texts sent to an AI provider to answer that request. The feature requires a signed-in, verified account. We do not use these texts for training.
- The ordinary comparison of an original and revised version runs locally in your browser. Only
when you separately start the paid Deep Meaning Review and explicitly consent are both versions sent to an AI provider for semantic comparison. The feature requires a signed-in, verified account, and the texts are not used for training.
- The local EvidenceLock check does not send the claim or supplied source excerpt to our server.
Only when you separately start the paid deep review and explicitly consent are the claim and source excerpt sent to an AI provider to answer that request. The feature requires a signed-in, verified account, and these texts are not used for training.
- If you explicitly report a checking result, we retain only an anonymous diagnostic aggregate:
the selected error direction, server score, text-length range, and marker-type identifiers. The checked text, feature vector, matched excerpts, account ID, and Telegram ID are not written to the website feedback log. This signal is ineligible for automatic training or LLM review and is used only for aggregate statistics and manual investigation of systematic drift.
- A website humanization, explicitly requested RubricLock Deep Review, Deep Meaning Review, or EvidenceLock response is kept for up to
24 hours in a separate AES-256-GCM-encrypted live replay cache. This lets us return a lost HTTP response without charging again. The main billing database keeps only a hashed settlement marker, never the source or rewritten text. The browser keeps a random request identifier and a short text-free fingerprint in `sessionStorage`. The replay database and its separate `0600` key are excluded from deploy/ rollback snapshots and runtime backups; expired rows are removed by a `secure_delete` sweeper.
- In the Telegram bot, the source and generated result may likewise be retained for up to 24 hours
in a separate AES-256-GCM-encrypted outbox solely to resume delivery after a network failure. The outbox and its separate `0600` key are excluded from runtime backups. Its encrypted payload is removed after confirmed delivery, leaving only a short-lived technical tombstone.
- Public API rewrite responses: only when an API client explicitly sends an `Idempotency-Key`, we keep the terminal response encrypted with AES-256-GCM for up to 24 hours so a lost HTTP response can be replayed without another model call or charge. We retain hashes of the API key, request key, and request fingerprint; the raw `Idempotency-Key` is not stored. Without this header no response cache is created.
- Minimal first-party measurement of public pages is collected before an analytics choice and
under “Essential only”: fixed events are immediately summed by UTC day, language, and canonical path. Cookies, IP, user/session/device IDs, fingerprints, user agents, referrers, search queries, and text are not stored, and this table contains no individual visit rows.
- Extended anonymized visit statistics (pages, device, on-site behavior) are processed through
Yandex Metrica and Google Analytics only after consent; see the Cookie Policy.
- First-party content attribution: after a successful check on a landing page or a deliberate transition from an article or content
landing page into the editor or toward an API key, we retain only the page path, content type, and locale for 30 days so we can understand which material leads to a check, humanization, or registration. This marker contains no user text, article title, or search query.
Protected humanization quality samples
When collection is enabled in “Data and privacy,” a successful humanization made by a signed-in, verified account through our same-origin website may be retained as a quality sample under the published `humanize-quality-v2` practice. This does not change access, price, charges, limits, or the delivered result. The stated basis is our legitimate interest in measuring and improving rewrite reliability; the account holder can object at any time by turning collection off.
A sample contains the source text, humanized result, locale, selected tier, scores before and after rewriting, and an optional quality label. If an authorized operator reviews the pair, it also contains the manual review status and time. The record includes the policy version, collection time, a random sample ID, and keyed pseudonymous account and request tokens used to prevent duplicates and enforce owner controls. We use approved pairs only to evaluate, test, tune, and train Neuroslop's algorithms. A user label never auto-approves a pair: an authorized operator must inspect it in the protected review queue first.
Automated safety checks reject a sample when they detect contact or payment details, credentials, government identifiers, another likely secret, or a declaration indicating that the text concerns an identifiable minor. These checks reduce risk but cannot guarantee detection. Do not submit another person's personal data, children's data, confidential information, or material you do not have the right to use. If prohibited content is identified later, we delete the active record.
We keep each sample for no more than 30 days in a separate database. Its text payload is encrypted with AES-256-GCM using a separate key. The database and key are excluded from application-managed deploy/rollback snapshots and runtime backups. In “Data and privacy,” the owner can download active samples, turn future collection off and delete all active samples immediately, or turn collection on again. The same requests can be made through our contacts after account verification. A text-free keyed preference remains while collection is disabled so we can honor that choice. A separate text-free withdrawal time remains for up to 24 hours to stop an already-running request from recreating a deleted sample.
Text you submit for an ordinary website check is analyzed on our server in memory and is not stored: only the text length and score remain in the usage log, plus the anonymous diagnostic aggregate described above when you explicitly submit a report. Checked texts are never sent to analytics. Optional neural analysis in the Telegram bot is processed by the AI provider only to answer that request; the text itself is not written to the bot log. For a RubricLock Deep Review, the usage log contains only the assignment and draft lengths, language, criterion and outcome counts, payment source, and cost—never the texts or quotations. For a Deep Meaning Review, the usage log contains only both version lengths, locale, bounded change counts and categories, the derived score, payment source, and cost—never either text, quotations, or model explanations. For an EvidenceLock deep review, the usage log contains only the claim and source-excerpt lengths, locale, verdict, bounded risk counts by severity, payment source, and cost—never either text, quotations, or model explanations.
When you move from a content landing page to the editor, the browser temporarily stores the landing-page path, the "check" or "humanize" intent, and the creation time in `sessionStorage`. It is removed after the first successful matching action or treated as expired after 30 minutes; it survives the authentication round trip and contains no text.
Why we use it
- Account login and its protection (verification codes, device list).
- Accounting for the free daily limit and paid credits.
- Measuring article and landing-page effectiveness without storing checked text.
- Quality evaluation and improvement using protected, manually reviewed `humanize-quality-v2` pairs.
- Responding to inquiries and account security notifications.
Who we share with
We do not sell to anyone. An AI provider processes text for humanization, an explicitly requested RubricLock Deep Review, Deep Meaning Review, EvidenceLock, and optional neural analysis in the Telegram bot under the applicable processing terms. A payment provider processes payment data; we do not store card numbers. Anonymized visit statistics are processed by Yandex Metrica and Google Analytics under their own policies. Upon lawful request by government authorities, data may be disclosed to them.
How long we store
Account and credit balance: as long as the account exists. Usage logs: up to 12 months. Daily identifier-free first-party aggregates: up to 430 days. Encrypted website humanization, RubricLock Deep Review, Deep Meaning Review, and EvidenceLock replay responses: up to 24 hours in the live cache only; that cache is excluded from deploy/rollback snapshots and runtime backups. Opt-in encrypted public API idempotency responses: up to 24 hours in the live cache; that transient table and its separate replay key are excluded from new deploy/rollback snapshots and runtime backups. Deleting the API key removes its live receipts immediately. The encrypted Telegram outbox remains in live storage for no more than 24 hours and is excluded from runtime backups; its payload is removed immediately after confirmed delivery. An eligible `humanize-quality-v2` record remains for no more than 30 days in a separate active database whose text payload is encrypted with AES-256-GCM using a separate key and is excluded from application-managed backups. Automatic cleanup removes it when the period expires; it is deleted from the active database immediately when collection is disabled or deletion is requested. A text-free keyed preference remains while collection is disabled. A text-free keyed withdrawal marker may remain for up to 24 hours solely to reject an in-flight request started before deletion. You can request account deletion by email to the service owner at info@neuroslop.net or via support on Telegram: **@AITextChecker**.
Your rights
You can download active quality samples, turn future collection off, delete those samples before the 30-day limit, correct your data, or request account deletion under “Data and privacy” in your account. For other requests, write to info@neuroslop.net or Telegram **@AITextChecker**. We respond within 10 business days.
Changes to the policy
The updated version is published on this page. Significant changes will be announced in the service interface. A material change to the purpose, data categories, or retention period applies only prospectively after an updated notice and policy version; existing samples keep the controls and maximum retention disclosed when they were collected.