How Slashy protects your data
Your email, calendar, and memory are protected by audited controls, strong encryption, and strict data handling.
Data privacy
Do you use customer data to train AI models?
No. We do not use customer data to train our own models or any third party models. Your data will never be used to train another company's models, and our agreements require AI providers not to train on it.
Which AI providers do you use?
We use multiple AI providers to optimize for speed, accuracy, and cost. Our agreements require these providers not to retain or train on Slashy customer data:
- OpenAI
- Anthropic
- Groq
- Fireworks AI
- Novita AI
- OpenRouter
- Concentrate
- Cartesia
- LiveKit
- Deepgram
- Reducto
Infrastructure & security
Storage of customer data
All customer data is stored on encrypted filesystems in PostgreSQL databases, which run on AWS cloud servers in the United States. Here is exactly what we store:
Email metadata (subject lines, sender and recipient, timestamps, labels), email content (message bodies and attachments), and calendar events are stored in our PostgreSQL database. This data remains encrypted until you disconnect your Google account, at which point it is deleted within the timeline below. Access is tightly controlled and used only to provide the services you have chosen.
We store your conversations with the Slashy AI agent to provide context and improve your experience. All conversations are encrypted.
The AI agent stores key facts it learns about you, your work patterns, and preferences to provide personalized assistance. All memories are encrypted and can be viewed or deleted at any time.
We maintain restricted logs for debugging and support. The information they contain is described in our Privacy Policy, and access is limited to team members who need it to provide support.
Settings, custom labels, and UI preferences are stored to personalize your experience.
All data is encrypted in transit with TLS 1.2+ and at rest with 256 bit AES encryption.
What security measures do you have in place?
We use multiple layers of security controls:
- Encryption: TLS 1.2+ for data in transit and 256 bit AES for data at rest
- SOC 2 Type II: independently audited controls
- Regular security testing: independent penetration testing and internal reviews
- Infrastructure security: AWS and Supabase provide physical and network security with strict access controls
- Secure authentication: OAuth 2.0 with Google, no password storage
- Data isolation: logical separation of customer data with row level security policies
How does Slashy access my email and calendar?
Slashy connects to your Google account using OAuth 2.0, Google's secure authorization protocol. We only request the minimum permissions necessary to provide our service (read, send, and manage emails and calendar events). You can revoke access at any time through your Google Account settings. We never store your Google password or have access to accounts you haven't explicitly connected.
Google compliance: Slashy has completed a CASA (Cloud Application Security Assessment) Tier 2 assessment and follows the Google API Services User Data Policy.
What are your backup and disaster recovery capabilities?
We maintain backup and recovery procedures as part of our security program. Backup retention follows the timelines described in our Privacy Policy and contractual commitments. Enterprise customers can request current recovery documentation during security review.
What email security standards do you support?
Emails sent through Slashy inherit Gmail's SPF, DKIM, and DMARC protections. Since Slashy sends through your connected Gmail account, all outgoing messages automatically benefit from Google's email authentication and spoofing protection.
How do you protect against prompt injection?
Prompt injection is a technique where an attacker tries to override an AI system's instructions with malicious text. Slashy uses several safeguards to reduce that risk:
- Input handling: user inputs and email content are sanitized before processing
- Content boundaries: structured boundaries separate untrusted content from system instructions
- Length limits: content limits reduce the ability of adversarial input to overwhelm the context
Compliance and auditing
Which independent assessments have you completed?
- SOC 2 Type II: independent examination of our security controls
- CASA Tier 2: Cloud Application Security Assessment
Can I get a copy of your penetration test results?
We conduct independent security testing and can share available documentation with prospective enterprise customers under NDA. Contact us at privacy@slashy.com to request the current materials.
How do you review your security controls?
Independent assessments, penetration testing, internal reviews, and automated scanning are used to evaluate our controls. Contact us for the dates and scope of the current reports.
How do you handle data breaches?
In the unlikely event of a data breach, we follow a strict incident response protocol:
- Notification: customers notified without undue delay as required by applicable law and contract
- Containment: immediate isolation of affected systems
- Forensics: full forensic analysis to determine scope and root cause
- Remediation: implementation of fixes and preventive measures
- Cooperation: full cooperation with relevant authorities and regulators
Do you have a bug bounty program?
Yes. Slashy maintains a responsible disclosure program for vulnerabilities in our production applications and services. We review good faith reports and provide updates as they are triaged and remediated.
How to report
Email security@slashy.com with a clear description of the issue, reproduction steps, and the potential impact. Please do not publicly disclose the vulnerability until we have confirmed remediation.
Program rules
- Only test against accounts you own. Do not access, modify, or exfiltrate data belonging to other users.
- Stop testing and report immediately if you encounter any user data.
- Do not perform denial of service, volumetric, or social engineering attacks.
- Do not use automated scanners that generate significant traffic.
- Give us a reasonable window to remediate before any public disclosure.
Out of scope
- Missing security headers, cookie flags, or SPF/DMARC configuration without demonstrated impact
- Self XSS, clickjacking on unauthenticated pages, or issues requiring physical access to a device
- Rate limits, brute force, or account enumeration reports without material impact
- Vulnerabilities in third party software or services we use but do not control
- Denial of service, volumetric, or resource exhaustion attacks
- Reports generated solely by automated scanners
Safe harbor
We will not pursue legal action against researchers who act in good faith, comply with this policy, and make a reasonable effort to avoid privacy violations, data destruction, or service disruption. If you are unsure whether specific testing is authorized, contact us at security@slashy.com before proceeding.
Your data control
What control do I have over my data?
You can request access to, export of, or deletion of personal data associated with your Slashy account:
- Access or export: request a copy of the personal data we hold about you
- Delete: submit a deletion request using the methods described below
- Revoke access: disconnect your account instantly through Google Account settings or within Slashy
- Manage preferences: update the controls available in Slashy settings
How do you handle privacy?
We follow established privacy principles in everything we build:
- Purpose limitation: customer content is used to deliver requested features. Account and usage data may also be used to operate, secure, and improve the service as described in our Privacy Policy
- Privacy by design: privacy considerations are built into every feature from the start
- Transparency: we're clear about what data we collect and why
- No selling of data: we never sell your personal data to third parties
To exercise any data rights, contact privacy@slashy.com. We respond to all requests within 30 days.
Do you offer a Data Processing Agreement (DPA)?
Yes. We provide a DPA for enterprise customers that outlines our data handling obligations. It's available on our DPA page or by contacting privacy@slashy.com.
Data management
Deletion of customer data
You can delete all your data at any time. Upon account disconnection or deletion request, we follow this timeline:
Account access revoked, OAuth tokens invalidated, sync stopped
Hard delete from production systems (email and calendar data, AI memories, embeddings)
Backups destroyed (up to 14 days during active incident investigations)
Data required by law (billing records) may be retained longer. Request immediate deletion at privacy@slashy.com.
Subprocessors
Slashy uses the following third party service providers that may process customer data. All subprocessors are bound by data processing agreements and are contractually obligated to maintain appropriate security measures.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure hosting | United States |
| Supabase, Inc. | Database and authentication | United States |
| Vercel | Frontend hosting and edge network | United States |
| Provider | Purpose | Location |
|---|---|---|
| OpenAI | AI inference (GPT) | United States |
| Anthropic | AI inference (Claude) | United States |
| AI inference (Gemini) | United States |
| Provider | Purpose | Location |
|---|---|---|
| Groq | Low latency AI inference | United States |
| Fireworks AI | AI inference | United States |
| Novita AI | AI inference | United States |
| OpenRouter | AI inference routing | United States |
| Concentrate | AI inference routing | United States |
| Provider | Purpose | Location |
|---|---|---|
| Cartesia | Voice AI (text-to-speech) | United States |
| LiveKit | Real-time voice and video infrastructure | United States |
| Deepgram | Speech-to-text | United States |
| Provider | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | United States |
| PostHog | Product analytics | United States |
| Sentry | Error monitoring | United States |
| Temporal Technologies | Workflow orchestration | United States |
| Resend | Customer communications | United States |
| CloudConvert | File conversion | Germany |
| HTML/CSS to Image | Image rendering | United States |
| Photon | Agent messaging integration (iMessage) | United States |
| Composio | Agent tool integrations (Slack, Zoom) | United States |
| Reducto | Document parsing (OCR) | United States |
Resources
Our security team can help with compliance documentation, enterprise requirements, or questions about our practices.