Slate

Privacy policy

What Slate, this website and the early-access form collect, what they are built to be unable to see, and how to have any of it deleted.

Last updated 15 September 2026 · Effective during the invite-only beta

Your notes are files on your own device. If you turn on sync, they are encrypted on your device before they leave it, with a key only your vault password can open, so the sync server stores data it cannot read. There are no analytics, no advertising, and nothing is sold.
Who this covers The early-access form This website Your Slate account Notes and sync Features that go online Service providers How it is used Retention Your rights Security Age Changes Contact

Who this covers

Slate is built and run by Adam Davis, an individual developer based in Florida, United States (“I”, “me”). This policy covers the website at slatenotes.app, the early-access signup form, the Slate desktop app for Mac, the web app at web.slatenotes.app, Slate accounts, and sync. The Slate Clipper browser extension has its own, narrower policy: Slate Clipper privacy policy.

The early-access form

When you request access, the form collects:

The form is hosted by HighLevel (LeadConnector), which stores these answers for me and sends the emails described below. HighLevel may set its own cookies inside the form, and may ask for your consent first where the law requires it.

I use this information to decide who to invite in each wave, and to email you: a confirmation, an invite with download and setup instructions, and short feedback check-ins while you are testing. There is no newsletter, and every email lets you unsubscribe.

This website

Your Slate account

Using Slate requires an account. It holds your email address and a password, which is stored only as a salted hash by the authentication provider. I never see it. Account emails, such as confirming your address or resetting your password, are sent through an email delivery provider.

Notes and sync

Slate's notes are ordinary files in a folder on your computer. The desktop app reads and writes them there. The web app works on a folder you open in your browser, and keeps its own settings in your browser's storage. Nothing about your notes leaves your device unless you turn on sync.

When sync is on, each note is encrypted on your device before upload. So are file and folder names: the server receives a keyed hash of each path, never the path itself. The encryption key is itself locked with your vault password, which never leaves your device. The server stores that locked key and the encrypted files, and cannot unlock either. Earlier versions of a note are kept the same way, so you can restore them.

To make sync work, the server can see:

Visible to the serverWhy
The vault's name, as you typed itSo your apps can show which vault they are connected to. Choose a plain name if that matters to you.
How many files, their encrypted sizes, and when they changedTo know what needs syncing, and to keep version history.
Device names you connect, their platform and app version, and when each last syncedSo you can see and manage which devices hold your vault.
Counts of files sent, received, merged or in conflict per syncThe sync activity list inside the app.

It cannot see note contents, titles, file or folder names, tags, links, or your vault password. If you lose your vault password, I cannot recover your synced data. That's the price of the design. The copies on your own devices are unaffected.

Clips from the Slate Clipper are sealed in the browser the same way, and held only until your app collects them.

Features that go online

Some optional features contact an outside service directly from your device, only when you use them. Nothing passes through me, and nothing is sent until you turn the feature on or use it.

Service providers

I use these companies to run Slate. Each handles data only to provide its service:

ProviderWhat forWhat it handles
HighLevel (LeadConnector)Early-access form, tester emailsForm answers, email address, email activity
SupabaseAccounts and sync storageAccount email, password hash, the encrypted sync data and metadata above
ResendAccount emailsEmail address, message content
VercelHosting this site, the web app, downloads and updatesRequest logs
Google FontsThe site's typefaceIP address, browser details

These providers are based in, or process data in, the United States. If you are outside the US, your information will be transferred there.

How it is used

I do not sell or rent your information, use it for advertising, or share it with anyone except the providers above, or where the law requires it.

If you are in the EU or UK, the legal bases are: your consent for the form and beta emails, which you can withdraw at any time; performing our agreement for your account and sync; and legitimate interests for security and abuse prevention.

Retention

Your rights

Wherever you live, you can ask me to show you the personal information I hold about you, correct it, export it, or delete it, and you can unsubscribe from beta emails at any time. Account deletion isn't in the app yet during the beta. Email me and it will be done. Residents of the EU, UK, California and other places with privacy laws have these rights by law, and you may also complain to your local data protection authority.

Send requests to privacy@slatenotes.app from the email address the request is about. I will reply within 30 days.

Security

Synced notes are end-to-end encrypted, connections use TLS, and each account's data is walled off at the database level. No system is perfectly secure. If a breach affects your information, I will tell you without undue delay.

Age

The Slate beta is for people 18 and older. I do not knowingly collect information from anyone younger. If you believe a minor has signed up, email me and I'll delete the information.

Changes

If this policy changes, the date at the top will change. If a change affects what is collected or how it is used, testers will be emailed before it takes effect.

Contact

Adam Davis · Florida, United States · privacy@slatenotes.app