Privacy
Last updated: September 24, 2026
The short version: FaceSlop runs in your browser. The photos you open, the things you make and your library stay on your device unless you choose to post, schedule or describe something. There are no ads, no analytics trackers and no selling of data. The only things our server holds are what the scheduler and Pro need, listed below.
This policy covers the FaceSlop web app at faceslop.com, published by the developer of FaceSlop and SkyPost ("we", "us"). By using FaceSlop you agree to it.
1. What stays on your device
Almost everything. FaceSlop keeps the following in your browser's own storage, not on our servers:
- Pictures and results. Photos you open, faces you swap in, stickers, text layers, backdrops, camera-bubble recordings, long-post drafts, the finished pictures and videos, and your library.
- Settings. Layout, your camera and microphone choice, whether you agreed to the ALT text service, a cached copy of your Pro status, your own download mark if you set one, and which Bluesky account you last used.
- Face finding. The face and hair models run inside your browser (MediaPipe). Your photo is never sent anywhere to find a face.
- Camera and microphone. Used only while you record a camera bubble, and only after your browser asks you. Recordings stay on your device unless you export or post them.
- Post readings. If you sign in, the like, repost and reply counts of your posts are read from Bluesky's public API and kept on your device to draw the charts. Pro keeps a longer history, still on your device.
Clearing the site's data in your browser removes all of it. Nothing here is a tracking cookie.
2. Bluesky sign-in and posting
You sign in with Bluesky's own OAuth flow on your Bluesky server (your PDS). You never type a password into FaceSlop, and the tokens Bluesky issues stay in your browser. When you post, the text, pictures and video go straight from your browser to your PDS and to Bluesky's video service, under Bluesky's privacy policy. Importing your posts reads your public feed. Signing out removes the tokens; you can also revoke FaceSlop from your Bluesky account settings at any time.
3. The scheduler (this is the part on our server)
Scheduled posts can go out while FaceSlop is closed. To do that, our server needs a grant of its own. When you connect the scheduler, it stores:
- your Bluesky DID, handle and PDS address, and the OAuth session your PDS issued to the scheduler, kept encrypted at rest;
- each scheduled post's text and its pictures or video, until the moment it is posted, after which the media is deleted; the resulting post link is kept for about a month so you can see what went out;
- a session cookie (
fs_sched, up to 180 days, only on faceslop.com) so the server knows it is you, and nothing else in cookies; - an audit line for each connect, schedule, post, hold or failure with the time and your IP address, kept to answer "what happened to my post", and IP-based rate limiting to keep the service up.
Disconnecting the scheduler revokes its grant, deletes its record of your account and removes any pending posts and their media. The scheduler runs on a server we rent from Hetzner.
4. Pro and payments
Payments are handled by Stripe. We never see your card number. Stripe collects a billing address at checkout. So that one membership covers both FaceSlop Pro and SkyPost Pro, your entitlement (your Bluesky DID, Stripe customer id, the email you gave Stripe, plan and status) is stored by the SkyPost backend at skypost.app, which the same developer runs. Tips through the donation link are handled by Stripe too.
5. Optional ALT text
If you choose to have a picture described, a copy no larger than 1024 pixels is sent to alttext.org, which writes the description. This only happens when you press Describe after agreeing to it, and an ALTtext Pro key you enter is kept only in your browser.
6. What we do not do
- No ads and no advertising or analytics trackers.
- No selling or renting of your data.
- No copy of your photos or videos on our servers, except a scheduled post's media until it is posted.
- No password of yours anywhere; sign-in is Bluesky's own OAuth.
- No third-party requests from the page itself: the typefaces, the face models and the code all come from faceslop.com.
7. Keeping and deleting data
Local data is yours to delete in the app or by clearing site data. For the scheduler, disconnect it to delete your account there. For Pro, cancel through the billing portal in the Pro panel; to have the entitlement record deleted, contact us with your Bluesky handle.
8. Children
FaceSlop is not directed at children under 13, and Bluesky itself requires users to be at least 13. We do not knowingly collect personal data from children.
9. Your regional rights
Depending on where you live (for example the EEA and UK under the GDPR, or California under the CCPA), you may have rights to access, correct, delete or port your personal data and to object to some processing. Contact us to exercise them. We do not "sell" or "share" personal information as California law defines those terms.
10. Services we rely on
| Bluesky / AT Protocol | your account, posts and the OAuth grants |
|---|---|
| Stripe | payments, billing portal and tips |
| SkyPost backend | the shared Pro entitlement, run by the same developer |
| alttext.org | optional picture descriptions |
| Hetzner | hosting for the site and the scheduler |
11. Changes
If this policy changes in a way that matters, the date at the top changes with it. Using FaceSlop after that means you accept the new version.
12. Contact
Questions or data requests: reach the developer on Bluesky at @skypost.app.