Privacy policy
What Slate, this website and the early-access form collect, what they are built to be unable to see, and how to have any of it deleted.
Who this covers
Slate is built and run by Adam Davis, an individual developer
based in Florida, United States (“I”, “me”). This policy covers the website
at slatenotes.app, the early-access signup form, the Slate
desktop app for Mac, the web app at web.slatenotes.app, Slate
accounts, and sync. The Slate Clipper browser extension has its own, narrower
policy: Slate Clipper privacy policy.
The early-access form
When you request access, the form collects:
- Your first name and email address.
- Your answers: which notes app you use now and what bothers you about it, your platform, roughly how many notes you have, and whether you would give weekly feedback.
- Where you came from, if the link you followed said so (for example, which Reddit post), and your time zone.
- Your consent to beta emails, with the time you gave it.
The form is hosted by HighLevel (LeadConnector), which stores these answers for me and sends the emails described below. HighLevel may set its own cookies inside the form, and may ask for your consent first where the law requires it.
I use this information to decide who to invite in each wave, and to email you: a confirmation, an invite with download and setup instructions, and short feedback check-ins while you are testing. There is no newsletter, and every email lets you unsubscribe.
This website
- No analytics, no ad trackers, and no cookies of its own. The site doesn't record which pages you read.
- The site is hosted by Vercel, whose servers keep standard request logs (such as IP address, browser, and the page requested) for security and operations.
- The typeface is loaded from Google Fonts, so your browser requests it from Google, which receives your IP address.
- Downloads and in-app update checks are served from this site. An update check sends your app's version and your IP address, as any web request does.
Your Slate account
Using Slate requires an account. It holds your email address and a password, which is stored only as a salted hash by the authentication provider. I never see it. Account emails, such as confirming your address or resetting your password, are sent through an email delivery provider.
Notes and sync
Slate's notes are ordinary files in a folder on your computer. The desktop app reads and writes them there. The web app works on a folder you open in your browser, and keeps its own settings in your browser's storage. Nothing about your notes leaves your device unless you turn on sync.
When sync is on, each note is encrypted on your device before upload. So are file and folder names: the server receives a keyed hash of each path, never the path itself. The encryption key is itself locked with your vault password, which never leaves your device. The server stores that locked key and the encrypted files, and cannot unlock either. Earlier versions of a note are kept the same way, so you can restore them.
To make sync work, the server can see:
| Visible to the server | Why |
|---|---|
| The vault's name, as you typed it | So your apps can show which vault they are connected to. Choose a plain name if that matters to you. |
| How many files, their encrypted sizes, and when they changed | To know what needs syncing, and to keep version history. |
| Device names you connect, their platform and app version, and when each last synced | So you can see and manage which devices hold your vault. |
| Counts of files sent, received, merged or in conflict per sync | The sync activity list inside the app. |
It cannot see note contents, titles, file or folder names, tags, links, or your vault password. If you lose your vault password, I cannot recover your synced data. That's the price of the design. The copies on your own devices are unaffected.
Clips from the Slate Clipper are sealed in the browser the same way, and held only until your app collects them.
Features that go online
Some optional features contact an outside service directly from your device, only when you use them. Nothing passes through me, and nothing is sent until you turn the feature on or use it.
- AI. AI is off until you choose a provider. If you connect one (for example Anthropic, OpenAI or OpenRouter), the text you send to it goes to that provider under its own terms and privacy policy. On the Mac, your API key is kept in the macOS keychain. In the web app it is held in memory for the session only.
- Weather. The place you set is looked up with Open-Meteo.
- Currency and crypto rates in the calculator come from public rate services (Frankfurter, ExchangeRate-API, CoinGecko). No personal data is sent.
- Music. The built-in player streams the stations or sources you pick, from those sources.
- Dictation. Voxtype transcribes on your Mac. Audio isn't uploaded. Speech models are downloaded only when you choose one.
- Phone features (KDE Connect) talk to your phone over your own local network only.
- Clipboard history stays on your device.
- Plugins run in a sandbox with no network access unless the plugin declares it and you approve it. If you publish a plugin, your publisher handle and the plugin itself are public.
Service providers
I use these companies to run Slate. Each handles data only to provide its service:
| Provider | What for | What it handles |
|---|---|---|
| HighLevel (LeadConnector) | Early-access form, tester emails | Form answers, email address, email activity |
| Supabase | Accounts and sync storage | Account email, password hash, the encrypted sync data and metadata above |
| Resend | Account emails | Email address, message content |
| Vercel | Hosting this site, the web app, downloads and updates | Request logs |
| Google Fonts | The site's typeface | IP address, browser details |
These providers are based in, or process data in, the United States. If you are outside the US, your information will be transferred there.
How it is used
- To run the beta: invite testers, provide accounts and sync, and send the emails described above.
- To improve Slate from the feedback you choose to give.
- To keep the service secure and prevent abuse.
- To comply with the law.
I do not sell or rent your information, use it for advertising, or share it with anyone except the providers above, or where the law requires it.
If you are in the EU or UK, the legal bases are: your consent for the form and beta emails, which you can withdraw at any time; performing our agreement for your account and sync; and legitimate interests for security and abuse prevention.
Retention
- Form answers and tester emails: kept while the beta and waitlist run, then deleted, or sooner if you ask.
- Your account and synced data: kept until you delete your account. Deleting it removes the account, the encrypted vault, its version history and device records.
- Server logs: kept for the provider's standard period.
- Anything on your own devices stays there until you delete it.
Your rights
Wherever you live, you can ask me to show you the personal information I hold about you, correct it, export it, or delete it, and you can unsubscribe from beta emails at any time. Account deletion isn't in the app yet during the beta. Email me and it will be done. Residents of the EU, UK, California and other places with privacy laws have these rights by law, and you may also complain to your local data protection authority.
Send requests to privacy@slatenotes.app from the email address the request is about. I will reply within 30 days.
Security
Synced notes are end-to-end encrypted, connections use TLS, and each account's data is walled off at the database level. No system is perfectly secure. If a breach affects your information, I will tell you without undue delay.
Age
The Slate beta is for people 18 and older. I do not knowingly collect information from anyone younger. If you believe a minor has signed up, email me and I'll delete the information.
Changes
If this policy changes, the date at the top will change. If a change affects what is collected or how it is used, testers will be emailed before it takes effect.
Contact
Adam Davis · Florida, United States · privacy@slatenotes.app