slate

Privacy, plainly.

Effective July 18, 2026

The short version

Slate stores what you deliberately send it so you can read, watch, or listen later. We do not sell personal data, run ads, or use the browser extension to watch where you browse.

The Chrome extension

When you click Save to Slate, its anchored popup sends the HTTP or HTTPS URL and browser-provided title of that one page to slatereader.com over an encrypted connection.

  • It does not read or transmit page contents.
  • It does not collect browsing history in the background.
  • It does not read Slate cookies, passwords, or authentication tokens.
  • Its Slate-only host access saves through your existing signed-in Slate session and confirms the receipt inside the popup.
  • It does not navigate the page you are viewing. You may optionally open the saved item with Read in Slate.

Apple apps and extensions

Slate's iPhone, iPad, and Mac apps sync your queue with Slate and keep sanitized article copies on your device for offline reading. When you deliberately use Save to Slate from Share or Safari, the extension sends that one HTTP or HTTPS URL and its provided title to Slate. Extension access is limited to saving and can be disconnected in the app.

Apple processes App Store purchases. RevenueCat helps Slate verify whether the Slate lifetime purchase is active. The Apple apps do not link to a separate web checkout or include advertising analytics.

What Slate keeps

Slate may keep your account identifier and email; URLs and messages you save; extracted titles, authors, text, media type, and reading state; documents you upload to your library (the original PDF or EPUB file, its filename, extracted text, and rendered page images, stored privately); newsletter aliases and deliveries; podcast or YouTube sources you explicitly follow; agent access tokens you create (stored as hashes, with their names and last use); Apple device capture-token records; purchase entitlement; preferences; and limited operational logs needed to secure and troubleshoot the service. Slate links to podcast audio and YouTube video rather than copying those media files.

Podcast and YouTube sources

When you follow a podcast or YouTube channel, Slate stores the public feed address, source identity, and new item metadata needed to add releases to your queue. If you use the optional YouTube subscription chooser, Slate requests read-only access once, expires channel candidates after one hour and removes them during routine cleanup, and does not retain Google access or refresh tokens. Only channels you explicitly select are followed.

Gmail connect (optional)

If you connect Gmail, Slate asks Google for read-only Gmail access and stores encrypted access and refresh tokens plus your Google account email so the connection keeps working. To suggest newsletters, Slate reads message headers only — sender, subject, date, and mailing-list headers — from roughly the last 90 days, and keeps that sender list briefly cached. Nothing is added to your queue from a scan.

Only senders you explicitly add are imported. For those senders, Slate fetches the full messages, stores sanitized copies as items in your queue, and checks for new messages from those senders about every half hour. Slate never sends email from your account, never modifies your mailbox, and never reads senders you did not add.

Disconnecting Gmail immediately deletes the stored tokens, the watched-sender list, and cached scan results. Items already imported stay in your queue until you delete them.

Email capture

Your private Slate reading address is a replaceable capability: anyone who knows it can send material to your queue. It is randomly generated rather than derived from your identity, and older or replaced addresses stop resolving. Keep it private and replace it in Settings if it leaks.

Slate routes by the receiving SMTP envelope address, not the visible To or From display text. Messages are size-limited, attachments and remote images are not stored, active HTML is removed, repeated deliveries are deduplicated, and the internal delivery is freshness-bound and cryptographically signed. Email display names are not presented as verified identity.

Why

We use this information only to provide and protect Slate: authenticate you, build your private queue, extract readable copies, sync state, enforce limits, process purchases, prevent abuse, and fix failures.

Limited use

Information received from Google APIs is used and transferred in accordance with the Google API Services User Data Policy, including its Limited Use requirements. It is used only to provide the user-facing import feature, is not used for advertising or credit decisions, and is not used to train generalized AI models.

Service providers

Slate relies on named service providers: Supabase (database, authentication, and file storage), Vercel (hosting), Cloudflare (domain and email routing), Stripe (web payments), Resend (transactional email), and Google (sign-in and the optional Gmail and YouTube imports). In the Apple apps, RevenueCat verifies purchases and Sentry receives crash reports, as described below. They process data on Slate's behalf under their own security and privacy commitments. Slate does not sell your data or share it for targeted advertising.

Native app crash and explicit error reports may be sent to Slate's separate Sentry project. Slate disables default personal information, screenshots, view hierarchy, tracing, network capture, and URL or saved-content reporting. These diagnostics are not used for advertising or cross-app tracking.

Retention and control

Saved material remains until it or the account is deleted, subject to short-lived backups and records we must retain for security, fraud prevention, purchase reconciliation, or legal obligations. You can permanently delete your account inside the Apple apps under Settings → Delete account. You may also request access, correction, export, or deletion by emailing hello@slatereader.com. Slate uses only functional cookies: your sign-in session and a short-lived cookie during the optional Google connect flows — no advertising or analytics cookies. Retired reading addresses are permanently tombstoned: they stop resolving, are never forwarded, and are never issued to anyone else.

Security and changes

Slate uses encrypted transport, access controls, fresh request signing for email ingestion, strict content security policy, content sanitization, bounded public-web fetching, dependency monitoring, and abuse limits. Operational email logs use pseudonymous references rather than live reading addresses or message content. No system is perfect. Material changes to these practices will be posted here with a new effective date.