Privacy Policy
Last updated: July 22, 2026
1. Controller
The controller responsible for data processing on this website is:
Adam Gabler
c/o IP-Management #10725
Ludwig-Erhard-Str. 18
20459 Hamburg
Deutschland
E-Mail: contact@getslash.site
(See our Impressum for full contact details.)
2. Where your data lives
SLASH is a plugin and chat companion for Unreal Engine. To keep this policy honest, we separate data by where it is actually processed, because these are governed very differently:
- On our servers (getslash.site) — your account, subscription, and the credit/usage records needed to run the service (Section 3).
- Only on your own device — your chat history, attachments, settings, and provider sign-in tokens. These are stored locally and are not transmitted to us (Section 4).
- With the AI and speech providers you choose — when you run a prompt or use dictation, that content is processed by Anthropic, OpenAI, or Microsoft through your own accounts and Windows settings, not through us (Section 5).
3. Data on SLASH servers
When you register and use the service, we process the following on our servers:
- Account and license data — your email address, a salted password hash, your plan, account timestamps, invite relationships, license status, and short-lived authentication, license-session, and password-reset records. Session and reset secrets are stored as hashes, not in reusable plaintext form.
Purpose: account, access, license, and support management. Legal basis: contract performance (Art. 6(1)(b) GDPR). Retention: while the account is active, subject to the shorter technical periods in Section 8. - Anti-abuse data — a normalized form of your email address and the IP address recorded at registration.
Purpose: preventing referral-bonus abuse during the closed beta (e.g. one person creating many accounts). Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Retention: 90 days after registration, or earlier when the account is deleted. - Subscription & billing data — your plan, credit balances, subscription dates, your Stripe customer reference, and billing history (amount, currency, description, timestamp, Stripe transaction ID). Card data is handled by Stripe; we never receive or store full card numbers.
Purpose: running the subscription and credit system, invoicing, refunds, and legal accounting. Legal basis: contract performance (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)). Retention: booking records are kept for the applicable statutory period; the exact period depends on the record category. Stripe applies its own retention rules. - Usage, credit, and session audit data — for each successfully authorized tool request, we record the tool name, its credit cost, the account it belongs to, and the timestamp. We also keep the random receipt, reservation, charge/refund, and license-session identifiers and status needed to prevent duplicate charges and reconcile credits.
Purpose: authorizing tools, deducting and refunding credits, preventing replay, and understanding aggregate usage. These records do not contain your prompts, AI responses, attached files, or Unreal project content. Legal basis: contract performance (Art. 6(1)(b)) and legitimate interest in reliable service operation (Art. 6(1)(f)). Retention: see Section 8. - Invite administration data— invite codes, their creator and redeemer account references, and creation/use timestamps. A code creator sees only whether and when a code was used, not the redeemer's email. Authorized operator access may include account email addresses when needed for invite administration, abuse review, or support.
Purpose: controlled registration, referral credits, and abuse prevention. Legal basis: contract performance (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)). - Technical / server logs — like any web service, our hosting layer processes connection metadata (e.g. IP address, request time, browser type) to operate and secure the site.
Purpose: operation, stability, and security. Legal basis: legitimate interest (Art. 6(1)(f)). Retention: logs are rotated by size rather than by a guaranteed number of days; see Section 8.
SLASH does not ask for or store your Anthropic or OpenAI API key on our servers.
4. Data stored only on your device
The SLASH Chat application stores the following locally on your computer (under your Windows user profile). This data stays on your machine and is not transmitted to or stored on our servers:
- Chat history — your conversation transcript per project, including your messages, the assistant's replies, and a record of tool actions. SLASH encrypts its own conversation store with Windows current-user data protection.
- Attachments — pasted images are copied into SLASH's local attachment folder. Files you select remain at their original local paths. When you send a message, supported selected content is provided directly to the AI provider you chose; unsupported binary files are identified by name but are not uploaded by SLASH Chat.
- Settings and installation state — your model, provider selection, language and update preferences, Unreal Engine installation path, and the installed plugin package's hash and installation time.
- SLASH credentials — if you choose “Stay signed in,” the launcher stores its SLASH session with Windows current-user data protection. Its local plugin-credential store uses the same protection. Until the MCP server's encrypted-credential cutover is complete, the launcher may also place the license credential in Claude Code's per-user local configuration so the MCP server can start. During an active provider command, SLASH Chat temporarily creates a minimal app-owned MCP configuration containing that credential; it removes the generated file when the command ends and sweeps stale copies on startup. Launcher sign-out asks the launcher to remove the Claude configuration value; the chat's “Delete all local data” action removes its app-owned copies.
- Provider sign-in tokens — if you sign in to the ChatGPT (OpenAI) provider, the sign-in token created by that provider's command-line tool is stored in SLASH's local Codex folder. Claude credentials and provider-side session files are managed in Claude Code's local configuration folder (including a custom
CLAUDE_CONFIG_DIR, if set). - Local diagnostics — the launcher may write one redacted local crash report capped at 64 KB. The chat may write a redacted crash log capped at 128 KB. Both are swept on their respective application startup once older than 14 days. Development/debug chat builds may additionally create a local debug log; release builds omit that debug logging.
- Update checks — the chat requests public version metadata for only your selected AI command-line provider from the npm registry. No prompt, attachment, SLASH credential, or provider token is included in that request.
Because this data is local, you control it directly. Deleting SLASH's local data removes SLASH-owned history, pasted-image copies, settings, diagnostics, and its app-owned Codex data. Original files you attached remain where you stored them, and Claude Code data must be removed or signed out through Claude Code's own configuration. Account deletion on this website cannot erase files or provider data on your device.
5. AI & speech providers you choose
SLASH does not include, host, or resell any AI model or speech service. When you run a prompt or use voice dictation, your content is processed by the provider youconnect through your own account or your own Windows settings. Our servers do not receive or store your prompts, the AI's responses, your attached files, or your dictated audio.
- Anthropic (Claude) — if you use the Claude provider, SLASH connects to your own Claude account through Claude Code. Your prompts, the conversation, and any files you attach are exchanged directly between Claude Code and Anthropic under your own agreement with Anthropic. Anthropic (USA) acts independently under its own terms and privacy policy: anthropic.com/legal/privacy.
- OpenAI (ChatGPT / Codex)— if you use the ChatGPT provider, SLASH connects to your own ChatGPT account through OpenAI's Codex command-line tool (you sign in via OpenAI's browser login). Your prompts, the conversation, and any files you attach are exchanged directly between that tool and OpenAI under your own agreement with OpenAI. OpenAI (USA) acts independently under its own terms and privacy policy: openai.com/policies/privacy-policy.
- Microsoft (voice dictation)— the optional dictation feature uses Windows' built-in online speech recognition. When you use it, your spoken audio is processed by Microsoft's online speech service via Windows, and requires Windows' “online speech recognition” setting to be enabled. This is governed by your Windows and Microsoft privacy settings: privacy.microsoft.com/privacystatement. If you do not use dictation, no audio is processed.
These providers are located in / transfer data to the USA and other countries. Because you engage them directly through your own accounts and OS settings, that processing is governed by your own agreements with them, not by us.
6. Service providers used by us
The following providers process data on our behalf to run the website and service:
- Stripe — payment and subscription processing. Stripe receives the payment and customer data needed for that service and may process it in countries described in its privacy notice. stripe.com/privacy.
- Hostinger— hosting infrastructure used to operate the website and backend. Processing locations and safeguards are described in Hostinger's applicable service and privacy terms. hostinger.com/legal/privacy-policy.
The AI and speech providers in Section 5 are not processors acting for us — you use them directly through your own accounts and settings.
7. Cookies
We use a single essential cookie (slash_token) for authentication. This is a strictly necessary httpOnly, SameSite=Lax cookie. It expires after seven days or is removed when you log out; production sends it only over HTTPS. It is used only to keep you signed in, not for analytics or advertising. We do not use tracking, analytics, or advertising cookies, and we load no third-party tracking scripts.
8. Data Retention
- Account data: retained while your account is active. Deletion removes or anonymizes active account data immediately after successful password confirmation and subscription cancellation, except for records described below.
- Registration IP and normalized email: anonymized after 90 days, or earlier when the account is deleted.
- Tool authorization log: deleted after 180 days, or earlier when the account is deleted.
- Completed/released credit reservations and expired license sessions: deleted after 7 days. Credit charge/refund audit records are currently kept while the account is active and are deleted on account deletion.
- Used or expired password-reset records: deleted after 3 days. Stripe webhook idempotency identifiers are deleted after 90 days.
- Billing / accounting records: retained in minimized form for the applicable statutory period; depending on the document category and circumstances, statutory periods can differ. Stripe applies its own retention rules.
- Server logs: Docker service logs are rotated by size (up to three files of 10 MB per service in the current deployment). This is not a fixed time period; actual duration depends on traffic volume. Infrastructure outside this configuration may apply its own operational retention.
- Local data (Section 4) is retained on your device until you remove it; we cannot access or delete it for you.
9. Your Rights
Under GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure of your data (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
- Withdraw consent at any time (Art. 7(3))
While signed in, you can download your server-side account data or delete your account from the dashboard. Account deletion requires your current password, revokes licenses and sessions, cancels active subscriptions, and removes or anonymizes active data; minimized billing records remain where retention is legally required. You can also contact contact@getslash.site for access, correction, restriction, objection, or help with a verified request. For local content and data held by the providers in Section 5, use the controls on your device and the provider's own tools. You also have the right to lodge a complaint with a supervisory authority (Art. 77).
10. International Transfers
Our hosting and payment providers may process data in the locations and under the transfer safeguards described in their applicable service and privacy terms. The AI and speech providers you choose (Section 5) may process data in the USA and other countries; that transfer is governed by your own agreements with them.
11. Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS), hashed and salted passwords, and httpOnly cookies for authentication tokens.
12. Changes
We may update this privacy policy from time to time. The current version and its date will be published on this page. If a reliable notification channel is available, we may additionally notify registered users of significant changes.