Slop Games · Yunsoo Jang
Privacy Policy
This policy describes the information Slop Games actually handles and the choices available to users.
2026-08-22.1 · 2026-08-22 · support@slop-games.com
1. Controller
Slop Games is operated in the Republic of Korea by Yunsoo Jang. Send privacy inquiries to support@slop-games.com.
2. Scope
This policy applies to the Slop Games catalog for submitting and discovering links to external web games. A third-party site's own policy and terms apply after you leave Slop Games.
3. Information handled
Public browsing does not require a Slop Games account. When you visit a page containing Google AdSense code, Google may nevertheless handle the advertising information listed below as part of serving ads.
- Site user ID, sign-in provider, provider account identifier, verified email, and account creation and update times
- An optional public creator name and one-line bio entered by the user
- Policy versions, confirmation of being at least 14, consent and withdrawal times
- Google session hash and creation and expiration times, plus temporary OAuth state hash, nonce, and PKCE verifier
- Game title, description, play URL, optional Git URL, category, tags, device support, cover image, operational publication status, and Draft, Unlisted, or Public visibility
- Creator-supplied structured discovery information: how to play, orientation, input methods, session length, engine, languages, project stage, accessibility features, AI use and AI disclosure, violence, gambling-like, and adult-content declarations
- Game indexing status, first-indexed and review times, private index reason, and row version used for concurrency
- Public game feedback and creator replies: signal, body, creation and update or deletion times, status, reply relationship, and internal author ID
- Feedback reports: report reason, report details, processing status, creation and update times, internal reporter and target identifiers, plus the private operator moderation reason on feedback
- Likes, bookmarks, anonymous Detail View and Play Intent aggregates stored in D1 by game ID and UTC date, ordinary reports, privacy requests, and operator actions
- Page URL and IP address, general location, browser, device and network information, advertising cookies or other identifiers, consent or opt-out signals, and ad impression or interaction information that Google AdSense may handle
4. Sources and purposes
We receive information from ChatGPT or Google sign-in, forms you complete, and your use of service features. We use it to verify submitters, provide account features, publish games, provide public game feedback and creator replies, run limited automated rules, handle private reports, operator review and rights requests, secure the service, and investigate failures. Reading feedback does not require sign-in. Creating or editing root feedback and posting creator replies require trusted sign-in, current policy consent, and a public creator profile. Filing a feedback report requires trusted sign-in and current policy consent, but does not require a public creator profile. Deleting one's own feedback or reply does not require renewed policy consent.
A Detail View may be counted after an in-site game detail renders, and a Play Intent may be counted when the final external-play action is selected. Detail View and Play Intent counts are stored by game ID and UTC date as anonymous application-layer aggregates in D1. No visitor ID, account, IP address, referrer, query, device, or browser information is stored with them. A Play Intent means that an external navigation was requested, and that external navigation may later fail. Verified gameplay or a Qualified Play event is not collected in external-link mode.
Google AdSense may handle advertising information to serve ads, control frequency, measure effectiveness, prevent fraud and abuse, and personalize ads according to user settings. The Slop Games application does not store AdSense advertising identifiers or visitor raw IP addresses in D1.
5. Public information
Draft, Unlisted, and Public visibility and Browse indexing are separate. Draft is owner-only, Unlisted is available by direct link, and Public may be directly available. Public availability does not guarantee Browse placement, indexing, or a featured placement. Browse includes only an operationally published game whose visibility is Public and whose separate index status is indexed.
A directly available game may expose its title, description, play URL, optional Git URL, category, tags, device marks, cover image, and aggregate Play Intent and like counts. Its structured discovery information is creator-supplied and public. If the creator saved a profile, the entered name and one-line bio may also appear. Private index reasons, internal review records, row versions, submitter email, and internal owner data remain nonpublic.
Published game feedback shows its signal, body, current public creator display name or the ‘Profile hidden user’ label, creation time, update time, edited state, and a Creator badge on a creator reply. Email, sign-in provider, internal user ID, reporter information, feedback report reason, details, status, creation and update times, current reporter email, and operator moderation reasons are not public.
Changing a creator display name updates existing feedback. Deleting the public profile makes the API return no public name and the client shows ‘Profile hidden user’, but the feedback remains public until the author deletes it or an operator moderates it. Limited rules block obvious email, phone-number, and web-address patterns, but they do not guarantee detection of every item of personal information, so users must not enter contact details or personal information in a public creator profile, feedback, or reply.
6. Retention and deletion
OAuth state expires after 10 minutes and a Google sign-in session after 30 days. Account, public creator profile, submission, like, bookmark, and cover data are generally retained while the related account or game remains. Publication and index fields, structured discovery information, and daily aggregates are retained for the life of the game. On game deletion, daily aggregates and structured discovery information are deleted before the game row.
Published, hidden, or operator-removed feedback and replies are retained according to their relationship to the author or game and operational needs. Individual deletion removes feedback or a reply from public view and clears its body, signal, and operator moderation reason, but the internal author ID is privately retained on the deleted row for ownership and account-state handling and, for a deleted creator reply, same-owner reactivation. The internal author ID is not public or included as an export field. Account de-identification or game deletion instead sets the internal author ID to null as well.
Exact retention for feedback reports, reporter identifiers, operator moderation reasons, and audit records depends on the confirmed operator policy and any necessary dispute or legal preservation decision. This policy does not promise an invented number of days. A feedback reference row becomes eligible for guarded cleanup only after its internal author ID has been nulled and related report and audit retention permits it; replies are removed before roots. No physical-deletion date is promised.
When game deletion is approved, the game is first unpublished and deletion of private R2 cover objects is confirmed before related D1 data is deleted or de-identified as appropriate. Provider backup practices and dispute preservation may require additional time under provider policy and applicable law.
7. Providers and international processing
The operator is the controller that determines the purposes and means of processing Hosted Data collected through Slop Games. Under the ChatGPT Sites Terms and Sites Data Processing Addendum, OpenAI acts as a processor of Hosted Data to host, maintain, and support the Site. OpenAI Sites provides site functions including ChatGPT authentication, Worker execution, D1 database, and private R2 object storage.
Google is the OAuth/OpenID Connect authentication provider. Slop Games requests only the openid and email scopes and does not store Google access tokens or refresh tokens.
Google AdSense is an advertising service provider and may handle page URLs and IP addresses, general location, browser, device and network information, advertising cookies or other identifiers, consent or opt-out signals, and ad impression or interaction information. Information may be processed or stored outside the Republic of Korea, and specific processing and retention depend on Google's official policies, user settings, and regional consent status. This description does not state that legal compliance or external legal review has been completed.
9. Operations and security logs
The Slop Games application does not store visitor raw IP addresses in D1. The hosting provider may process network information for operations and security, and Google AdSense may process IP addresses and other network, request-time, browser, device, cookie, and event information for ad delivery, measurement, and abuse prevention. Application error logging is designed not to include emails, authentication secrets, full report details, or URL query strings.
10. Automated rules
Submission checks cover HTTPS, metadata, restricted copy, cover format, size and dimensions, and current policy state, and may route some information to operator review. Ownership, legality, safety, malware freedom, a content or age rating, and factual accuracy are matters this limited review does not verify.
Limited format, contact, and spam rules are applied before publication; feedback and creator replies that pass are automatically published. Those rules do not determine legality, ownership, safety, or that the content is free of personal information, and they do not automate legal, copyright, or complete harmfulness review.
11. User rights
A signed-in user's JSON export includes visibility, indexStatus, firstIndexedAt, indexReviewedAt, and structured discovery information for submitted games. It excludes private indexReason, rowVersion, the game record's internal submitter ID and submitter email. Nonpersonal daily aggregate metrics are not included. The account email may appear separately in the account section. Game deletion follows unpublishing and confirmed cover removal, then deletes discovery metadata and metrics before the game row.
A signed-in user can edit or stop publishing creator information from My page, review held data, download a JSON export, or request correction, deletion, or restriction from the account and privacy surfaces. The JSON export includes the user's root feedback, creator replies, and filed feedback reports with their reasons, details, statuses, and timestamps. It excludes other users' private identifiers and operator moderation reasons. Individual deletion of one's own feedback or reply does not require renewed consent; it removes the item from public view and clears its body and signal. The internal author ID stays private on that deleted row for the limited ownership and account-state purposes described above; it is not an export field. Account or game de-identification also nulls that private author link before the row can later be physically cleaned up when related retention permits.
Account deletion remains a manual operator workflow. For a verified request, authored feedback and replies are de-identified as deleted, and the internal reporter ID is separated after the feedback-report retention decision, before account data is deleted or de-identified. If you cannot sign in, you may use the privacy email, and we may verify identity to the minimum extent needed.
You can turn off personalized ads in Google Ads Settings. Where a regional Google Privacy & messaging notice has been published, you can use it to change advertising consent or sale-and-sharing opt-out choices.
12. Users under 14
Account features are limited to users at least 14. We do not collect a full date of birth; we record only self-confirmation of the minimum age. Contact support@slop-games.com if you believe a child's information was handled improperly.
13. Safeguards
We use OAuth state, nonce, PKCE, ID Token verification, hashed session storage, same-origin and intent-header checks, private R2 storage, and security headers. Dynamic HTML that runs AdSense uses a fresh CSP nonce for each response. The Sites-served static home page keeps a self-only script CSP and includes only Google's account-verification meta tag instead of the AdSense advertising script. No technical measure removes every risk.
14. Contact and changes
Contact: support@slop-games.com. Material changes will carry a new version and effective date, and we may require renewed consent before further account-feature use.