Privacy Policy
The short version
- We run no servers for the extension. We never receive, see or store the posts you read, your API keys, your sign-ins or your settings.
- To judge a post, Rotty either runs a small model on your computer (nothing leaves it) or sends the post's text straight from your browser to the AI provider you choose.
- No ads, no analytics and no tracking in the extension. We don't sell or share anyone's data.
- This website keeps waitlist emails only until launch, keeps feedback you choose to send us, and counts page views without cookies.
1. Who we are
Rotty is a Chrome extension and a website (getrotty.vercel.app) made by Doplex Labs. Doplex Labs is a name used by a group of individual contributors; it is not a registered company. In this policy, “we”, “us” and “Doplex Labs” mean those contributors.
This policy covers the Rotty extension and this website. Using them is also subject to our Terms of Service. Questions: doplexlabs@gmail.com.
2. How the extension works
Rotty runs on reddit.com (including old.reddit.com), x.com (and twitter.com) and linkedin.com. It reads the posts, comments and replies on those pages so it can decide which to collapse. You choose how posts are checked:
- Rotty Local: a small model that ships inside the extension and runs in your browser. Posts are judged on your computer and are not sent anywhere. Nothing is downloaded to use it.
- Your own API key for OpenAI, Anthropic, Google Gemini or Groq.
- Continue with ChatGPT: your ChatGPT plan, through OpenAI’s Sign in with ChatGPT.
Nothing is sent to any AI provider until you pick one, in the setup assistant or in Settings.
3. What is sent to your AI provider
If you use an AI provider (anything other than Rotty Local), Rotty sends the following for each post, comment or reply it checks, directly from your browser to that provider over an encrypted (HTTPS) connection:
- The item’s visible text, cut to 1,200 characters, including any quoted or reshared text. Anything people wrote in that text, such as names or @mentions, is included as written.
- Its context: the site, whether it is a post, comment or reply, the subreddit or community, and for comments and replies the title and a short excerpt of the post they answer (on Reddit, the page title may stand in for the post title).
- For Reddit link posts, the linked website’s domain name.
- Two flags: whether self-promotion is normal in that community, and whether the same text appears more than once on the page.
Not sent: the author’s username or profile, your own account details, cookies, your browsing history, or anything from other websites. Item IDs are replaced with plain numbers before sending. Rotty also doesn’t send items shorter than 40 characters, posts by moderators and pinned posts, ads and promoted posts, anything you’ve allowlisted, or anything on a site you’ve turned off or while filtering is paused.
Reddit thread preview
On Reddit, when you point at a post in a feed for a moment (or press on it), Rotty loads up to 60 of that thread’s top comments from Reddit itself, using your existing Reddit session as the page would, so they can be checked before you open the thread. With an AI provider, those comments are sent to it under the rules above, even if you never open the thread. With Rotty Local, they are not judged or sent anywhere.
Other requests
- Connection warm-up: while an API key is saved, Rotty may send an empty request (no content, no key, no cookies) to that provider’s address when you open a supported site, at most once every two minutes, so the first real check is faster. This happens even while filtering is paused. Like any connection, it shows the provider your IP address and the time.
- Key check: when you add a key, Rotty sends two short built-in sample comments to confirm the key works.
4. Your AI provider
The provider you pick is an independent company. It receives the data in section 3 under your own account and agreement with it, and handles it under its own terms and privacy policy, including how long it keeps the data and whether it is used for training. It is not our service provider, and we have no access to your account or to what it receives.
- OpenAI (API keys and ChatGPT): openai.com/policies/privacy-policy
- Anthropic: anthropic.com/legal/privacy
- Google (Gemini): policies.google.com/privacy
- Groq: groq.com/privacy-policy
5. Continue with ChatGPT
This option uses OpenAI’s Sign in with ChatGPT for open-source apps. You sign in on OpenAI’s own page, and OpenAI registers Rotty for your account.
- Rotty creates a random install identifier and sends it to OpenAI during sign-in. On later sign-ins it also sends your previous sign-in token and email address as hints.
- Rotty stores on your device: the sign-in tokens, your ChatGPT account email and account ID, the client ID OpenAI issued and the install identifier. They are sent only to OpenAI (auth.openai.com and api.openai.com).
- Requests to judge posts go to OpenAI’s API with a setting asking OpenAI not to store them. Rotty only sends these requests; it does not open or read your ChatGPT conversations.
- While you sign in, and only then, Rotty redirects OpenAI’s return address (127.0.0.1:1455) to its own “Finishing sign-in” page.
- Sign out in Settings revokes the sign-in with OpenAI. Your email and the install identifier stay on your device so you can sign back in; removing the extension deletes them. You can see and cap Rotty’s usage in your ChatGPT settings.
6. What stays on your device
Rotty stores the following in Chrome’s extension storage on your computer. It is not synced to your Google account and is never sent to us:
- Settings, allowlists and API keys. Keys are stored unencrypted in extension storage, as in most extensions, and each is sent only to its own provider.
- Verdicts for items already checked (a score, category and reason, by item ID): kept 7 days, or until you clear them.
- Usage counts and estimated cost per day: kept 30 days.
- Your feedback: items you mark “Not slop” or hide yourself, with their text, post title, community and the page address (on X, a page address can include the author’s handle). Up to 2,000 entries, kept until you clear them. Your show and hide choices for single items are kept until you clear them.
- The last error message and timing information, to show you what Rotty is doing.
Settings lets you download your feedback as a file. It stays on your computer unless you choose to share it. Removing the extension deletes everything Rotty stored.
7. Layout reports
If a site changes and you click Report it in the toolbar popup, Rotty copies a short report to your clipboard and opens this website. The report contains the site and page path (with names and IDs masked), counts of the page’s own tag, test-ID and class names, counts of item statuses, the Rotty, prompt and Chrome versions, your operating system and your window size. It contains no post text or usernames. Nothing is sent unless you choose to send it to us, for example by pasting it into the Feedback chat (section 10). If you do, we use it only to fix Rotty.
8. What we don’t do
- We run no servers for the extension and never receive post text, keys, sign-ins or browsing data.
- The extension has no analytics, telemetry, crash reporting, ads or trackers, and loads no code from the internet: everything runs from code shipped in the extension.
- We don’t sell, rent or share user data, use it for advertising, or use it to judge creditworthiness or for lending. No person at Doplex Labs reads your data; we have no way to.
Rotty’s use and transfer of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
9. Permissions
storageandunlimitedStorage: to keep the settings, cache, counts and feedback in section 6 on your device without hitting Chrome’s default size limit.offscreen: to run Rotty Local in a hidden extension page. It reads nothing from the web and sends nothing anywhere.- Access to reddit.com, x.com, twitter.com and linkedin.com: to find and collapse posts, comments and replies, and to load Reddit thread previews (section 3).
- Access to api.openai.com, api.anthropic.com, generativelanguage.googleapis.com and api.groq.com: to call the provider you picked.
- Access to auth.openai.com and 127.0.0.1, and
declarativeNetRequestWithHostAccess: for Continue with ChatGPT only (section 5).
10. This website
- Waitlist. If you join, we keep your email address, when you signed up, which form you used, and a referral tag if the link you followed had one. We use it only to send one email when Rotty is on the Chrome Web Store. It is stored privately with our host, Vercel, and never sold or shared. We delete the whole list within 14 days of sending that email, and we’ll delete your address sooner if you ask.
- Feedback. If you send us a bug report, wrong call, feature request or other feedback through the Feedback chat, we keep what you write and pick there (the kind of feedback, the site and model, and your message), your email address only if you give it, your browser and operating system only if you agree to attach them, the Rotty version if you opened the chat from the extension, and when you sent it. It is stored privately with Vercel, read only by Doplex Labs, used only to fix and improve Rotty and reply to you, and never sold or shared. We keep it only as long as we need it for that, and we’ll delete it sooner if you ask. Please don’t include passwords, API keys or other sensitive information.
- Page views. We count visits with Vercel Web Analytics: pages viewed, the referring site, and country, browser, operating system and device type, in aggregate. It sets no cookies, stores no IP addresses and doesn’t follow you across sites; visitors are told apart only by a hash that is discarded within a day.
- Hosting. Like any web host, Vercel processes standard request data, such as IP addresses and browser details, to deliver and secure the site, under Vercel’s privacy policy.
- We set no cookies. Because we don’t track you across sites, browser “Do Not Track” signals don’t change anything here.
11. Your choices and rights
- In the extension: use Rotty Local to keep everything on your computer, turn off any site or kind of post, clear the cache and your feedback in Settings, sign out of ChatGPT, or remove your keys. Uninstalling deletes everything Rotty stored. Because we don’t hold any extension data, questions about what a provider received go to that provider.
- Waitlist and feedback: email us to see, correct or delete your address or feedback, or to withdraw your consent. We reply within 30 days.
- If you’re in the EEA, UK or Switzerland: we rely on your consent to keep your waitlist email and any feedback you send. You have the right to access, correct, delete, restrict or object to its use, to receive a copy, to withdraw consent at any time, and to complain to your local data protection authority.
- If you’re in California or another US state with privacy laws: we don’t sell or share personal information, or use it for targeted advertising.
12. Children
Rotty is not directed to children under 13, and we don’t knowingly collect personal information from them. If you believe a child has joined the waitlist or sent us feedback, email us and we’ll delete it.
13. Security
Requests to AI providers and to this website use HTTPS. Data Rotty stores stays in Chrome’s storage for the extension on your computer, so keeping your computer and Chrome profile secure protects it. If you think an API key was exposed, revoke it with your provider.
14. International users
This website, the waitlist and feedback are hosted by Vercel in the United States. If you join the waitlist or send feedback from elsewhere, what you send is transferred to and stored in the US.
15. Changes to this policy
If we change this policy, we’ll update the date at the top. If a change affects what the extension handles or where it sends it, we’ll say so in the extension before the change takes effect.
16. Contact
Doplex Labs: doplexlabs@gmail.com