Garage Capital Ventures LLC operates zero-slop.ai and the hosted Zero Slop MCP and API services. This policy covers those services, the website, and information you choose to send us. The Terms of Service apply to hosted use.
The local skill and scorer
Scoring is Python that runs locally. On this website it runs in your browser through WebAssembly, so scoring does not upload your draft. The installed skill works inside the AI assistant you chose; that assistant's own data policy still applies. For example, ChatGPT or Claude may receive your draft and keep conversation history under its own settings and policy. Local scoring does not send drafts to Zero Slop, but using a hosted assistant can send them to that assistant.
Hosted editing inputs and results
Pressing rewrite on the demo or calling the remote MCP, CLI editing command or REST API sends the draft to the editing service. We receive the text, selected genre, optional audience, and diagnostic information used to check and edit it. This can include personal information you put in the draft or audience field. We use these inputs to provide the requested edit and check the result against the source.
We process the returned text, before and after scores, flagged phrases, warnings, status, and source and final checks. The result goes back to your browser, CLI, application, or MCP host. A host such as ChatGPT or Claude receives the tool result and handles it under its own policy. The hosted application processes draft, audience, diagnostic content, and rewrite in memory; it does not write that content to a database or demo cache. Selected numeric and categorical metrics are retained as described below.
Hosting and model providers
Cloudflare hosts the website, gateway, scoring service, analytics, and usage counters. When an edit needs a model, the service sends the draft, genre, and available audience and checks to Cloudflare Workers AI. If primary editing is unavailable or unusable, it may send that information through OpenRouter to a routed model provider. A request can therefore reach both services. Already-clear text can return without a model call.
OpenRouter requests require zero-data-retention (ZDR) routing and deny provider data collection. ZDR is a provider routing policy, not a promise that all operational records disappear. OpenRouter allows provider memory caching under ZDR. Provider processing and retention are governed by their own policies. Cloudflare's Workers AI data policy says customer content is not used to train models or improve its services without explicit consent. See OpenRouter's zero-data-retention policy. These policies do not set the retention periods for our analytics, usage counters, or your chosen host's conversation history.
Service metrics and their purposes
MCP service metrics include the tool and protocol version, client family and major client version, origin category, country and Cloudflare location, genre, scorer version, input and output sizes, scores and score bands, flag counts, status, completed checks, model-call counts, latency, and capacity failures. We use these records to measure usage and editing outcomes, diagnose failures, and manage capacity. They do not include the draft, audience text, rewrite, prompt, flagged phrases, IP address, full user-agent, cookies, email, or a stable user ID. Connections are counts, not people.
A separate lifetime counter keeps integer totals for initializations, tool calls, results, changed messages, warnings, failures, and capacity rejections. It contains no client or location fields and cannot identify an installation or person.
Shared usage limits
Hosted editing has a shared daily budget and per-client limits. Before a model call, the service reserves capacity. When the budget is exhausted or the gate is unavailable, it does not call the model. Local scoring does not consume this allowance.
To apply the same limit across the demo, MCP, CLI and API, the service derives a keyed hash from the connection IP and UTC date. The budget counter keeps that daily hash and counts, not the raw IP or draft. The identifier is a daily pseudonym. It changes daily and is not joined to analytics or used for advertising. People sharing a network may share a limit. Cleanup is scheduled after the UTC day; delayed cleanup can leave expired rows until it runs. Cloudflare recovery backups may retain earlier database states for up to 30 days; those states contain no drafts or raw IP addresses.
The API sandbox opens in local cleanup mode. It loads the editing tools onto your device without sending your draft or calling a model. Live mode sends text only when you press Send to live API. It does not save your draft in browser storage.
The website
The custom website analytics use no cookies or advertising tags. The custom event dataset does not store IP addresses, raw user agents, or an identifier that joins one visit to the next.
We measure page views, clicks, scroll depth, install and editing steps, and sharing and feedback activity to understand how the site works and where it fails. Records include the page path without query strings, event labels, referrer category, campaign parameters, mobile or desktop category, and site release. Coarse location fields include country, city, region, timezone, network organization, and Cloudflare location. Editing outcome events omit campaign and detailed location fields. Avoid putting personal information in campaign parameters. Cloudflare Web Analytics separately measures traffic and page performance.
Sharing metrics count the dialog opening, the selected provider, and observable system-share handoffs, cancellations, or failures. The system share sheet does not reveal which app you choose. A handoff is not a confirmed published post. Feedback metrics count form activity and endpoint acceptance, never your message or email address. These browser events respect Global Privacy Control and Do Not Track.
Enable Global Privacy Control or Do Not Track before loading the page to suppress custom browser events. Those choices do not disable hosted service metrics, usage limits, request receipts, Cloudflare Web Analytics, or infrastructure security records. You can choose local scoring or local cleanup to avoid submitting writing to the hosted editing service.
Hosted service metrics distinguish MCP, CLI, REST, and direct web editor calls, with result categories, model attempts, quota rejections, and latency. Offline CLI commands send no analytics. Service counts are not unique people or installs, and web endpoint success does not certify the browser’s final source checks.
For web editing requests, we also keep a random request ID, timestamps, response status and model-call count. These records contain no draft text, IP address or user account, and do not link separate requests. Reporting lookups stop returning these records after 48 hours. Background deletion can take longer if Cloudflare delays cleanup, and Cloudflare’s recovery backups may retain older database states for up to 30 days.
Cloudflare processes standard connection data, including IP addresses and request information, to deliver and protect the services. The gateway also enables operational logs and sampled traces. Application logs record events such as result status, text size, scores, timing, model routing, and failures. The custom analytics exclusions above do not mean infrastructure logs are absent. Retention for Cloudflare security, traffic, logs, traces, and Web Analytics depends on the product and account settings; our source does not establish one fixed deletion period for them.
Newsletter, feedback and support
If you subscribe, we send your email address to Resend to maintain the newsletter list and send updates. Use the unsubscribe link in newsletter messages to stop delivery. Unsubscribing can leave a contact or suppression record; it is not a promise to erase every provider record. The subscription code has no automatic expiry for contacts.
If you submit feedback, we send your message and optional reply address through Resend to the configured maintainer inbox so we can read and respond. Resend and the recipient's email provider process those messages. Support correspondence can contain any information you choose to include. The delivery code has no automatic deletion schedule for feedback or inbox copies. Do not submit confidential material as feedback; the terms explain how feedback may be used.
Resend's privacy policy covers its processing. You can request deletion of a newsletter contact, feedback, or support information through the contact routes below. Provider records and backups may have separate retention requirements; no fixed expiry is established by our website code.
Your local choices and private learning
The browser remembers whether you saw the install prompt or closed the newsletter bar, and your animation preference. Clearing site data removes those values. The API sandbox starts in local cleanup mode; sending to the live API is a separate choice. Native browser tools require confirmation before live editing. Through MCP, CLI, or REST, invoking the remote editing tool sends the supplied text. Disconnect the connector or stop calling it to stop future submissions; manage existing host history with that host.
Private learning in the installed skill requires your approval before recording edits, and separate approval before activating learned preferences. It can save edit evidence and preferences locally under $ZERO_SLOP_HOME (by default ~/.zero-slop). These files stay on your device unless you choose to share or export them. Sharing private learning for a reviewed contribution requires your explicit approval. You can inspect or delete those local files to remove the saved evidence and preferences. Hosted editing does not activate private learning.
Retention
Aggregate website and MCP telemetry is retained in Cloudflare Analytics Engine for three months, as documented in its retention limits. The daily report receives the same aggregate counts and quality statistics. It does not receive draft or rewrite content. Lifetime MCP totals and the dates when their counter started and last changed remain in a separate persistent counter indefinitely, until that counter is deleted. Random counter-event IDs prevent duplicate increments; entries older than one hour are removed on subsequent increments, so idle entries can remain longer. They contain no writing or client identity.
Daily report aggregates are processed by GitHub Actions and sent through Resend to the configured report recipient. Workflow report files are retained for 30 days. Delivered email copies have no automatic deletion schedule in the code. The three-month Analytics Engine limit does not erase exported reports or lifetime totals. Cloudflare's database recovery can retain prior counter, budget, and receipt states for up to 30 days after active records are removed.
Contact and deletion requests
For privacy questions, access or deletion requests, use the feedback form near the bottom of the home page or GitHub Discussions. Discussions are public: do not post drafts or personal details there. Security concerns can use the security policy. Identify the submission or contact you want us to find; do not send the draft again. We may need enough information to verify and locate your request. Aggregate records without a user identifier may not be attributable to you. We cannot delete your chosen host's conversation history. Records that providers hold independently are subject to their own deletion policies.
You can inspect the website source and skill and gateway source for the fields and controls described here. Material changes to this policy will appear with an updated date on this page.