GomiMon privacy information

GomiMon stores pet progress, the locally chosen pet name, detector preferences, and any pending leaderboard meal events in the browser. Selected Reddit post/comment or X home-feed text is sent to the GomiMon detector service only after the user signs in with Google (or Apple in Safari) and chooses manual checking, automatic AI checking, or a semantic content filter. The Ads filter uses Reddit's explicit promoted marker or X's verified Ad header locally and does not send the post to the service.

The service forwards the assessed text and the post title/body and any rendered quoted-post context to TypeSafe for model estimates. A proposed public GomiMon name is also sent to TypeSafe when it needs an all-ages appropriateness check. The service stores your Google and/or Apple account identifier, verified email address (including an Apple private relay address when used), available display name, revocable session metadata, daily usage counters, and hashed assessment metadata (result label, category probabilities, model, rubric version, and truncation state). It does not retain raw post text after the request completes. Rejected name checks are cached by name hash rather than raw name. The TypeSafe API key is never included in the extension. Google or Apple handles sign-in; GomiMon does not receive your provider password. The extension stores its GomiMon session token locally so you remain signed in.

Safari asks for explicit permission before sending post text, quoted context, or a proposed public pet name to TypeSafe. The browser records the consent version, choice, and time. You can decline or withdraw permission in Settings while retaining your local pet, manual feeding, and local ad filtering. Withdrawal cancels pending checks and clears cached scores; it cannot recall a request already received by the service. Third-party processing is subject to TypeSafe's privacy practices as well as this notice.

Apple web sign-in credentials needed to revoke authorization are encrypted on the backend, with the encryption key kept separately from the database. When you delete your account, the service deletes your account data and requests revocation from Apple. If Apple is unavailable, only the encrypted revocation credential and retry metadata remain until revocation succeeds. The app reports that revocation is pending. Provider accounts are linked only when you explicitly request it while signed in; matching email addresses never cause accounts to merge.

The extension also keeps a lazy, account-scoped local cache of scores (not hide/show decisions) for up to 24 hours, 1,000 entries, or approximately 2 MB, whichever limit is reached first. Entries contain revision, numeric probabilities, result metadata, and timestamps; they do not contain post text. The cache is used before a new network/quota request and is cleared on sign-out or account deletion.

The local Slop history stores the latest 100 consumed items with a short text excerpt (up to 280 characters), source, time, and feeding mode on this device. Clear history in the popup removes these entries without changing pet progress or the total count.

The public leaderboard can be viewed without signing in. Joining is optional and publishes only the reserved GomiMon name, evolution, meal count, and rank. The service stores the private account-to-profile relationship and idempotent meal events used for weekly totals. Leaving hides the profile but preserves the score and name reservation; deleting the account removes the profile, reservation, and meal events.

Free accounts receive 1,000 successful detector checks per UTC day; GomiMon Plus provides 10,000. A check includes AI or topic analysis and counts whether or not a post is eaten. Cached results within 24 hours and failed requests do not use additional checks. Name safety checks use a separate small rate limit and do not consume detector quota. Users can sign out or delete their GomiMon account from the popup; account deletion removes service-side account, session, usage, cached-result metadata, leaderboard data, and the reserved name.

GomiMon does not post, report, or flag Reddit or X content, and its feed changes are visible only in the local browser. Images and video are not sent for analysis in this release. Detector labels are experimental model estimates, not claims about authorship.

The Safari Mac App Store version is free and does not offer purchases or billing links. The following billing details apply only to versions where billing is available.

Subscriptions use Stripe-hosted Checkout and Customer Portal. GomiMon sends Stripe your account email and a random account identifier to associate your purchase with your account. Stripe collects and processes payment information; GomiMon does not receive or store your full card number. GomiMon stores Stripe customer and subscription identifiers, subscription status, payment coverage dates, cancellation and payment-recovery dates, pending checkout metadata, and processed webhook event identifiers. The extension temporarily stores the account identifier and timing of pending billing refreshes, but does not store payment details.

Canceling through Manage billing ends renewal while preserving access until the paid period ends. Deleting your GomiMon account cancels the subscription immediately before account deletion completes; if cancellation cannot be confirmed, deletion remains pending and can be retried. Deletion does not automatically issue a refund. A minimal billing record containing the random account key, Stripe identifiers, and cancellation state is retained to prevent late payment events from restarting a deleted account's subscription. Stripe may retain invoices and transaction records according to its own retention requirements. These are separate from the detector and leaderboard data removed on account deletion.