Privacy policy
What Ściema sees and what it sends.
Ściema is a Chrome extension. It places badges: ściema (scam), podejrzane (suspicious), OK, and a separate badge for a suspicious claim. This page describes version 0.2.5 and the proxy at https://proxy-production-6f75.up.railway.app. Contact: Paweł Mamcarz, [email protected].
Who it is for
The buyer is a parent or a school. An adult installs the extension. It does not create a child account and it does not ask for a name, an age, or an email address. The product page talks about pages a young person (about 10 to 17) may open. It is a tool for a parent or a school, not a separate service where a child signs up.
Page text
The content script runs on http and https pages. It looks for visible text blocks (article, paragraph, list, and similar) between 60 and 1200 characters. It considers at most 40 blocks on one page.
When the classifier is on, and the page is not on the private list, the extension sends the proxy at most 800 characters of that text, the hostname only (no path and no full URL), and the chosen sensitivity. It calls the proxy at most 16 times on one page. The proxy keeps at most 1200 characters after whitespace is collapsed.
The default address is https://proxy-production-6f75.up.railway.app. A custom address, including a local one, receives the same fields only after the user saves it and the browser allows that host.
The proxy forwards the snippet and the hostname to the Jev classifier (TypeSafe, System One). The TypeSafe key stays on the server. The extension never sees it. The reply is a verdict, a reason in Polish, and sometimes a claim layer. The snippet text is not echoed back.
Chat, mail, forms
On these hosts the classifier is not called, so the text is not sent to the proxy: web.whatsapp.com, mail.google.com, outlook.live.com, outlook.office.com, outlook.office365.com, messages.google.com. The same applies to private Discord messages (path /channels/@me) and to direct, messages, messaging, inbox, im, chat, and dm paths on Instagram, Facebook, Messenger, TikTok, Snapchat, X, Twitter, and LinkedIn.
On those pages only in-browser heuristics run. Form fields, textareas, and contenteditable regions are not badged and are not sent. The extension does not read a mailbox as a mailbox and does not build a chat history. It does not cover every webmail on the internet: a mail host that is not on the list is treated like an ordinary page.
What stays in the browser
chrome.storage.local holds sensitivity, demo mode, language (Polish), the classifier switch, proxy mode, the custom proxy URL, the cover switch, and the plan token if the user pasted one. The token field is a password input. There is no list of visited pages. Verdicts for the current tab stay in the script's memory until reload.
When the classifier is off, or the proxy does not answer, heuristics score the text in the browser and the text does not leave.
What the proxy does
The verdict cache lives in process memory. The key is a SHA-256 hash of the normalised text. An entry stores the Jev answers, the model name, and token counts, not the text itself. The default lifetime is 12 hours, and the cache holds at most 2000 entries. Hostname and sensitivity are not part of the key.
The evaluate log, when enabled, records the event, cache hit or miss, model token counts, the model name, and the character count. It does not include page text, hostname, IP address, or the API key.
The IP address is used for the demo rate limit (30 evaluations a minute from one IP in the code) and is kept in the in-memory counter. A daily cap per IP applies only when EVALUATE_DAILY_IP_CAP is set on the server. A paid plan counts 120 evaluations a minute and 2000 a day from a hash of the token, not from the IP. A parent and a school do not receive a list of opened pages.
Safe Browsing is optional. When the proxy has SAFE_BROWSING_API_KEY, it sends Google only the http(s) URLs extracted from the snippet, not the whole text. Without the key this step is skipped.
Fact Check Tools (ClaimReview) is optional too. When the proxy has FACT_CHECK_API_KEY (or the alias GOOGLE_FACT_CHECK_API_KEY or FACT_CHECK_TOOLS_API_KEY), the request carries a valid Parent or School token, and the claim layer has already flagged the snippet, the proxy sends Google at most 240 characters of that text. It looks for a public fact check. Demo mode without a token does not call this step. No hit does not mean the sentence is true. The Google key is not in the extension.
Payments
Checkout runs on the proxy, in Stripe. The extension does not collect a card number. Stripe receives the payment details. Checkout asks for a billing address and can collect a tax ID. After payment the proxy stores a plan token tied to the Stripe customer id. You paste the token in the extension settings. Cancelling the subscription revokes the token. Plans: Demo 0 PLN, Parent 12 PLN a month or 99 PLN a year, School 1490 PLN a year for 40 devices.
What we do not do
We do not sell data. We do not use it for advertising or for credit decisions. There is no remote code: the extension scripts ship in the package and are not downloaded from the network. Ściema runs in Chrome. It does not promise protection on a phone.