Privacy Policy
Last updated August 2026. What SlayTab collects, why, who else sees it, and how to get it deleted.
SlayTab is a personal workspace: your documents, links, calendar, notes and tasks in one browser tab. This page explains exactly what we store, why, who else can see it, and how to get it back or deleted. It covers the SlayTab web app at slaytab.com and the SlayTab browser extension.
By using SlayTab you agree to your information being handled as described here. If you do not agree, please do not use it.
The short version. We store what you put into SlayTab so we can show it back to you. We do not sell it, we do not advertise against it, and we run no analytics or tracking scripts. A handful of services see parts of it because features depend on them: our AI provider (only when you use the assistant), Google (only if you connect a calendar), Razorpay (only if you subscribe), and a geolocation service (only if we have switched sign-in geolocation on, which we tell you about below).
1. Who we are
SlayTab is operated by Gamatics India Pvt Ltd (“Gamatics”), India. For anything in this policy, write to privacy@slaytab.com.
2. What we collect
Account details
Your name, email address and a password. Passwords are stored only as a bcrypt hash — we cannot read yours, and nobody at Gamatics can tell you what it is. We also record when you last used the app, so we can tell an active account from a dormant one.
The things you put in
- Files you upload, stored on our server as you sent them
- Links you save — the address, title, icon and category
- Notes and tasks you write, including due dates and reminders
- Calendar events pulled from any calendar you connect
- Assistant conversations — your messages and the assistant's replies
From the browser extension
The extension reads a tab's address and title only when you ask it to save that tab — by clicking the toolbar button, using the right-click menu, or pressing the keyboard shortcut. It does not watch your browsing, run in the background, or read page content. It stores your SlayTab address and access token locally in the browser so you do not have to type them again.
Payment details
If you subscribe, Razorpay processes the payment. Card numbers never reach our servers. We keep the subscription status, the invoice records Razorpay sends us, and the payment identifiers needed to match a payment to your account.
Collected automatically
Like any web server, ours records requests: your IP address, browser and operating system, the page requested and the time. These logs keep the service running and let us investigate errors and abuse. They are not used to build a profile of you, and are not shared.
Separately, we keep a record of each sign-up, sign-in and failed sign-in attempt — the time, the IP address it came from, and your browser. This is how we notice someone trying to break into an account, and it is how we know roughly where our users are. It is kept with your account and deleted when your account is.
If sign-in geolocation is switched on for this deployment, that IP address is sent to ipwho.is to be turned into an approximate country, region and city, which we store alongside the sign-in. Nothing else is sent — not your name, not your email, not anything you have saved — and the request is made from our server over an encrypted connection, not from your browser. The feature is off unless we have enabled it; the table in section 4 says so too.
What we do not collect
No advertising or analytics cookies, no third-party trackers, no session recording, no device fingerprinting, no location data. The only cookie we set is the one that keeps you signed in.
3. Why we hold it
| Purpose | What it uses |
|---|---|
| Running the product | Account details and everything you save |
| Signing you in and keeping the session | Email, password hash, session cookie |
| Billing and invoicing | Email, subscription and payment records |
| Service email — receipts, password and account notices | Name, email |
| Product email you can switch off | Name, email, usage summary |
| Keeping the service working and secure | Server logs, error logs |
4. Who else sees it
We use a small number of processors. Each one sees only what its feature needs.
| Service | What it receives | When |
|---|---|---|
| OpenAI or Anthropic, whichever powers the assistant on this deployment | Your message to the assistant, plus the parts of your workspace it searches to answer — titles, note text, task and event details | Only when you send a message to the assistant |
| Read and write access to the calendars you choose, using a token you grant and can revoke | Only if you connect Google Calendar | |
| Razorpay | Your email and payment details, handled entirely by them | Only if you subscribe |
| Our email provider | Your name, email and the contents of the message being sent | When we send you email |
| DuckDuckGo icon service | The domain names of links you save, so we can show their site icons — never the full address, and never your identity | When a page showing your links loads |
| jsDelivr | Your IP address and browser, as with any file loaded from a CDN — it serves our icon font | On page load |
| ipwho.is | The IP address a sign-in or sign-up came from, and nothing else — not your name, not your email, not anything you have saved. It returns an approximate country, region and city, which we store against that sign-in so we can see roughly where our users are. The lookup is made from our server over an encrypted connection, never from your browser. | Only if sign-in geolocation is switched on for this deployment. It is off unless we have enabled it. |
About the assistant. It is powered by a third-party AI provider — OpenAI or Anthropic, depending on which is configured for this deployment. When you use it, your message and the matching parts of your workspace are sent to that provider to produce a reply. If you have material you would rather no third party processed, do not put it through the assistant — everything else in SlayTab works without it, and the assistant can be left unused entirely.
We do not sell your data, share it with advertisers, or use it to train anyone's models. We will disclose data if the law requires it, and would tell you unless legally prevented.
5. Where it lives, and for how long
Data is held on our servers and with the processors above. We keep what you save for as long as your account exists.
- Deleting inside the app archives first. Items, notes and tasks move to an archive you can restore from. Notes and tasks can then be deleted permanently from Manage → Archive.
- Cancelling a subscription deletes nothing. The assistant switches off; everything else keeps working on the free plan.
- Closing your account removes your account, files and content from our live systems within 30 days. Invoices and payment records are kept as long as tax and accounting law requires.
- Backups roll off on their own schedule, normally within 30 days.
6. Where your data is processed
SlayTab is operated from India, and our processors operate elsewhere: our AI provider (OpenAI or Anthropic) and our email provider in the United States, Google internationally, Razorpay in India, and ipwho.is internationally. Using the assistant, connecting a Google calendar, subscribing, receiving email, or signing in while geolocation is enabled therefore involves your data crossing borders. We only send each processor what its feature needs, under their own terms and safeguards. If that is not acceptable to you, those features can be left unused and the rest of SlayTab still works.
7. Your choices
- See it — everything we hold about you is visible in the app.
- Correct it — edit anything, including your name and email, in Account.
- Export it — ask us and we will send your content in a machine-readable form.
- Delete it — email privacy@slaytab.com from your account address and we will close the account and remove your data. There is no self-service delete button yet; we do it by hand, within 30 days.
- Stop the email — untick product emails in Account, or use the unsubscribe link in any of them. Receipts and account notices continue, as they must.
- Cut off Google — disconnect the calendar in SlayTab, or revoke access at your Google account permissions.
- Cut off the extension — revoke its token in Account → Browser extension, which stops it working immediately, or uninstall it.
Depending on where you live you may also have rights under the Indian DPDP Act, the GDPR or similar law — to object, to restrict processing, or to complain to a regulator. Write to us and we will act on any of them.
8. Security
Passwords are hashed, never stored in readable form. Extension tokens are stored as hashes and shown only once. Every request is checked against the signed-in account, so one user's data cannot be reached from another's session. Uploaded files are served only to the account that uploaded them, and the upload folder cannot execute code.
No system is perfectly secure. If we discover a breach affecting your data, we will tell you and the relevant authority as the law requires.
9. Children
SlayTab is not intended for anyone under 18, and we do not knowingly collect their data. India's Digital Personal Data Protection Act treats under-18s as children and requires verifiable parental consent, which we are not set up to obtain. If you believe a child has an account, tell us and we will remove it.
10. Changes
We will update this page when what we do changes, and move the date at the top. If a change materially affects how your data is handled, we will email you before it takes effect.