Your information.
Our responsibility.
Last updated June 23, 2026. This policy explains what we collect, why, how long we keep it, who we share it with, and the rights you have over it.
1. Scope of this policy
This Privacy Policy describes how SlashBlogs ("we," "us," or "our") collects, uses, retains, and discloses personal information when you use the SlashBlogs platform, including the dashboard, the APIs, and the supporting Appwrite backend (the "Service").
It applies to information we collect through the Service, by email, and through other interactions you have with us in connection with the Service.
It does not apply to information collected by third parties that we do not own or control, including our hosting provider (Appwrite Cloud) or any third-party sites or services that are linked to from the Service.
2. Information we collect
We collect information in three ways: information you give us directly, information collected automatically as you use the Service, and information from third-party integrations you connect.
Account information. When you create an account, we collect your name, email address, organization name, and the password you choose (stored as a one-way hash by Appwrite).
Content. We store the posts, pages, taxonomies, media, SEO metadata, comments, and any other content you create or upload through the Service.
Usage information. We log requests made to the Service, including IP address, user agent, timestamps, and the action performed. We use this for security, abuse prevention, debugging, and aggregate analytics.
Billing information. None. The Service is free during early access, so we do not collect, process, or store payment details of any kind.
Integration data. If you connect Google Search Console or another supported third-party service, we store the OAuth tokens needed to read data on your behalf and we cache the data those services return to us. Google Analytics integration is coming soon.
3. How we use information
We use the information we collect to:
(a) provide, operate, secure, and improve the Service;
(b) authenticate you and protect your account;
(c) detect and prevent fraud and abuse;
(d) respond to your support requests and other communications;
(e) send you service-related notices (security alerts, material changes to these Terms or this Policy);
(f) detect, prevent, and address abuse, security incidents, and violations of our Terms;
(g) comply with our legal obligations.
We do not use Your Content to train any machine-learning model. We do not sell personal information to third parties.
4. Legal bases for processing (EEA / UK)
If you are in the European Economic Area, the United Kingdom, or a similar jurisdiction, our legal bases for processing your personal information include:
Performance of a contract — to provide the Service you have signed up for.
Legitimate interests — to secure the Service, prevent abuse, and improve our product, where our interests are not overridden by your rights.
Compliance with legal obligations — where we are required to retain or disclose information by law.
Consent — for optional features like analytics cookies and marketing communications, which you can withdraw at any time.
5. How we share information
We share personal information only as described below:
Service providers. We share information with vendors that help us operate the Service — Appwrite (authentication, database, storage, functions), our hosting and email providers. Each is contractually obligated to protect the information.
Team members. If you join a workspace, the workspace owner and admins can see your name, email, role, and the actions you take in that workspace.
Legal. We may disclose information if we believe in good faith that we are required to do so by law, a valid subpoena, or a court order, or to protect our rights, your safety, or the safety of others.
Business transfers. If we are acquired, merge, or sell substantially all of our assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
Aggregated or de-identified information. We may share aggregate or de-identified statistics about the Service with third parties (for example, "X workspaces created in Q3"). Such statistics cannot be used to identify you.
We do not sell personal information. We do not share personal information with third parties for their own marketing purposes.
6. Data retention
We retain personal information for as long as your account is active or as needed to provide the Service.
If you cancel your account, we delete Your Content from production systems within 30 days. Encrypted backups are rotated out within 90 days. We retain billing records for the period required by tax and accounting law (typically 7 years).
We retain audit logs for 12 months unless a longer period is required to resolve a security incident or legal dispute.
7. Your rights
Depending on where you live, you may have some or all of the following rights:
Access — request a copy of the personal information we hold about you.
Correction — ask us to correct information that is inaccurate or incomplete.
Deletion — ask us to delete your personal information, subject to our legal retention obligations.
Portability — receive your information in a structured, machine-readable format.
Restriction or objection — ask us to restrict or stop processing your information in certain circumstances.
Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
Complain — lodge a complaint with your local data-protection authority.
To exercise any of these rights, email privacy@slashblogs.com. We respond within 30 days. We may need to verify your identity before acting on the request.
8. Cookies and similar technologies
We use a small number of cookies and local storage entries to operate the Service. See our Cookie Policy for details on what we use, why, and how to control them.
9. International transfers
We are based in India and use infrastructure providers that may store data in other countries (including the United States and the European Union). When we transfer personal information across borders, we rely on the European Commission's Standard Contractual Clauses (or equivalent UK or Swiss mechanisms) and on the safeguards offered by our infrastructure providers.
If you would like a copy of the safeguards applicable to your data, contact privacy@slashblogs.com.
10. Security
We protect personal information with industry-standard technical and organizational measures, including encryption in transit (HTTPS / TLS 1.3) and at rest, per-workspace access controls, audit logging of sensitive actions, and least-privilege access for our own staff.
No system is perfectly secure. If we become aware of a personal-data breach that affects you, we will notify you and the relevant authorities in accordance with applicable law.
Security disclosures can be sent to security@slashblogs.com. We maintain a responsible-disclosure program and a published security.txt at /.well-known/security.txt.
11. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact privacy@slashblogs.com and we will delete it.
12. Changes to this policy
We may update this Policy from time to time. If we make a material change, we will give you notice by email or through the Service at least 14 days before the change takes effect. The updated Policy will be posted on this page with a revised "Last updated" date.
13. Contact
For privacy questions, data-subject requests, or to exercise your rights, email privacy@slashblogs.com.
Our designated contact for data-protection matters is the privacy team, reachable at the same address.