Privacy Policy
Last updated: September 8, 2026
This Privacy Policy describes how RS Labs, the operator of Slate ("we", "us"), collects, uses, and shares information when you use the Slate mobile application, web portal, website, and related services (the "Service"). Slate is a project management app for small businesses and for personal use. Our business contact address is 200 N Saint Clair St, Toledo, OH 43604, USA.
Information you provide
Before signup, your profile and workspace choices stay on your device as an unfinished setup. Setup drafts expire after seven days; the web draft is also limited to the current browser tab. These choices are sent to Slate when you create your account. The setup draft does not store your email address or password.
- Account info: name, email, optional phone number, and password (hashed).
- Organization data: work orders, clients, photos, time entries, vacation requests, invoices, documents (including any signatures in uploaded documents), and the people you invite to your workspace.
- Optional inputs: dictated voice notes (transcribed on-device when possible) and questions you send to "Iris".
Information collected automatically
- Crash and error diagnostics, including device model, OS version, and stack traces, used to find and fix bugs.
- Product usage telemetry, such as which features are opened, associated with your account ID. We do not send your name, email, or work-order content as analytics event properties.
- Location coordinates may remain in existing workspace settings. This version of Slate does not request device location.
How we use information
- To run the Service: store and sync your data, send the messages and notifications you ask for, and let your teammates collaborate.
- To improve the Service: detect crashes, debug issues, and prioritize fixes.
- To respond to you when you contact support.
- We do not sell personal information, and we do not use your work-order content to train third-party AI models.
AI features and data processing
Slate offers AI-powered features under the name "Iris." When you send a message to Iris, your question and relevant excerpts from your workspace data are sent to a third-party AI provider to generate a response. The excerpts may include:
- Work order names, statuses, dates, and field values relevant to your question.
- Client names and contact details associated with matching work orders or invoices.
- Invoice numbers and amounts.
- Messages and activity notes attached to work orders.
- Team member names and time entries (admin-only queries).
- Photos, when you use photo analysis: the full image — not just a caption — is sent to our AI provider so it can describe the photo and read details like serial numbers or damage. We send an image only when you trigger analysis on it.
The full content of all your work orders is never sent in a single request — only the excerpts the system determines are relevant to your specific question. Your entire workspace is not exposed to AI providers.
Iris uses Anthropic (Claude) for conversational responses, tool use, and photo analysis, and OpenAI for the text embeddings that power search indexing. To keep search current, Slate also generates embeddings of your workspace content (work orders, messages, notes, clients, invoices, and document text) automatically in the background — so OpenAI may receive excerpts of this content even when you are not actively chatting with Iris. Which provider handles a given task is fixed by the type of task, not your plan tier.
Anthropic and OpenAI do not use commercial API inputs to train their models by default. Their standard policies generally retain API inputs and outputs or abuse-monitoring logs for up to 30 days, with exceptions for legal requirements, safety and abuse investigations, and features with longer storage. Slate does not promise zero provider retention.
Workspace owners and admins can disable Iris in Settings → Iris. The workspace switch prevents new Iris requests and background search-indexing work from being accepted. Work already in progress may finish, and disabling Iris does not delete information previously sent to a provider. Photo analysis, the HR assistant, and ambient screen context also have separate controls.
For EU-region organizations, photo analysis is disabled by default and remains off until our EU data-processing terms for image transfer are finalized. Other AI features that do not require image transfer operate normally.
Data transfers and processing agreements
Slate is operated from the United States. Our service providers may process information in the United States and other countries where they operate. A workspace region setting does not, by itself, guarantee that every provider processes all information only in that region.
For information your organization uploads about its clients and employees, your organization determines the purposes of processing and Slate processes it to provide the Service. Contact support@slateapp.org for information about applicable processing agreements and international-transfer safeguards before using Slate for data subject to specific residency or contractual requirements.
We keep the list of sub-processors below current and update it when we add or change a provider; material changes are reflected by updating the “Last updated” date at the top of this Policy.
Sub-processors
We rely on a small number of vendors to operate the Service. These sub-processors only receive the data they need to perform their function:
- Supabase — managed Postgres database, file storage, and authentication.
- Cloudflare — website hosting, content delivery, traffic security, and website traffic measurements where enabled. Receives web request information such as requested pages, browser/device information, and network information needed to deliver and protect the site.
- Anthropic (Claude) — generates Iris’s conversational answers, tool use, and photo analysis. Receives your question plus the relevant excerpts (and, for photo analysis, the full image) needed to respond.
- OpenAI — generates the text embeddings that power search. Receives excerpts of your workspace content (work orders, messages, notes, clients, invoices, document text), including automatically in the background as content is created or changed, so Iris can search it. Neither AI provider uses commercial API data to train its models by default.
- Sentry — crash and error reporting. Receives diagnostic data such as device model, OS version, and stack traces.
- PostHog — product analytics and feature flags. Receives your Supabase user ID (not your name or email) and usage events like "opened work order screen".
- Apple and Google — push notification delivery and app distribution.
Your choices
- You can edit your profile and update your password from Settings.
- You can request a copy of all data associated with your account by emailing support@slateapp.org with subject 'Data Export Request'. We will respond within 30 days.
- You can request account deletion from Profile → Delete Account. Workspace ownership requirements apply. Shared workspace records may remain available to other members, as explained in Data retention and the Terms.
- You can disable optional permissions (camera, microphone, photo library, location) at any time in your device settings.
Data retention
We retain account and workspace information to provide the Service. Account deletion removes sign-in access and deletes the account profile. Shared workspace records may remain for other members, and stored files, backups, and operational records can remain after account access is removed. Contact support@slateapp.org for a request concerning specific records or files. Retention may also be necessary for legal obligations, resolving disputes, or preventing fraud.
Children
Slate is not directed to children under 16 and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can delete it.
Changes to this Policy
We may update this Privacy Policy as Slate evolves. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you in-app.
Contact
Questions about this Policy or your data? Contact RS Labs at support@slateapp.org, or write to 200 N Saint Clair St, Toledo, OH 43604, USA.