Privacy
[Legal entity name] operates Slashbot. This explains what we collect, what we never see, and what you can ask us to do about it.
Last updated 15 August 2026
The short version
Slashbot runs on your computer. Your bots, your threads, your bot memory, and your connected-account tokens are stored in ~/.slashbot on your own machine. We never receive your messages, your mail, or your files. What we hold is limited to what is needed to run an account and take a payment.
What we collect
- Account — your email address and the identity provider you signed in with (GitHub or Google), handled by Supabase on our behalf. We do not store a password.
- Subscription — your customer record, subscription status, and trial start date, held by Stripe. We never see or store your card details.
- Licence check — when the app verifies your access, it sends a signed token identifying your account. We log that a check happened, not what you were doing.
What stays on your computer
- Every bot, thread, card, and message.
- Bot memory files.
- Secrets and connected-account tokens.
- Everything your bots read — mail, files, repos, calendars.
None of this is transmitted to us, and there is no cloud sync. Note that prompts your bots send to the model do travel to Grok under Grok’s own privacy policy, and content you ask a bot to fetch or send travels to whichever plugin provider you connected.
Why we are allowed to hold it
Under the GDPR, we process your account and subscription data to perform our contract with you. We keep billing records where we have a legal obligation to do so. We do not sell personal data, we do not run advertising, and we do not build profiles.
Who processes data for us
- Supabase — authentication and account records.
- Stripe — payments, subscriptions, and billing records.
- Composio — the OAuth handshake when you connect a plugin. The resulting tokens are stored on your computer.
These providers act as processors under contract, and transfers outside the EEA rely on Standard Contractual Clauses.
Cookies
We set a session cookie so you stay signed in, and a short-lived cookie that remembers where to send you after sign-in. That is all. No analytics cookies, no trackers, no consent banner needed.
How long we keep it
Account data is kept while your account exists. If you delete your account we remove it within 30 days, except billing records we are required to retain for accounting purposes — typically ten years, depending on jurisdiction.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to our using it. Email [contact@getslashbot.com] and we will respond within one month. If you are unhappy with the outcome, you can complain to your local data protection authority.
Children
Slashbot is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
If we change this policy materially we will say so on this page and, for significant changes, email you before they take effect.
Contact
[Legal entity name]
[Registered address]
[contact@getslashbot.com]