Privacy and your data
What stays on your computer, what Slashspace sends elsewhere and when, and how to keep sensitive work local.
Slashspace is local-first: your canvases are ordinary files on your computer, and Slashspace doesn't sync or back them up to its servers. Many features still need a server, though, and some send more than you might expect.
Long-context work often involves unpublished drafts and sensitive sources, so it helps to know exactly where each piece goes. The privacy policy is the formal version and names every service provider involved.
What stays on your computer
- Canvases. Each canvas is a folder inside
SlashspaceOSin your home folder, holding its chats, notes, connections, captured text and generated images. See where canvases live on disk. - Prompts and skills. Your prompt library is in
~/SlashspaceOS/.promptsand installed skills are in~/.agents/skills. Personas and settings are in the app's data folder. - API keys. Keys are encrypted with your operating system's secure storage (the Keychain on a Mac) and don't sync. Each key goes only to its own provider, except with the OpenRouter image option below. Custom connector sign-ins are encrypted too, but environment variables for connectors that run on this computer are saved unencrypted.
- Local model runs. Chats with an Ollama model run on your computer. Chat titles, analytics and sign-in checks still use the network.
- Update backups. When the app downloads an update, it copies your
SlashspaceOSfolder into abackupsfolder in the app's data folder, keeping the last few copies.
What leaves your computer
"Slashspace's servers" means Slashspace's own backend, which passes requests on to the providers named in the privacy policy.
| Feature | What is sent | Where it goes | When |
|---|---|---|---|
| Chats on a Slashspace model, including Auto | Your message, earlier turns, the chat's context (connected nodes, or a summary of the canvas when nothing is connected), attachments and tool results | Slashspace's servers, then through Vercel AI Gateway to the model's maker, such as Anthropic or OpenAI. Auto also sends the start of your message to a small model that picks one. | Every send |
| Chats on your own API key or a custom provider | The same | Straight to that provider or endpoint. With Qolaba, attached files are first uploaded to Slashspace's storage and Qolaba gets a link. | Every send |
| Claude Code, Codex, Cursor | Your messages, canvas context and the tools Slashspace gives them | Anthropic, OpenAI or Cursor, under your own account | Every send |
| Chat titles | The first message of each new chat | By default, Slashspace's servers and an OpenAI model, whatever model the chat uses | Each new chat |
| Image descriptions | An image you add with Add From Computer | Your default chat model, when it runs on one of your API keys | When you add it |
| Orchestrator mode | Your request, a summary of the whole canvas (including where your documents are on your computer), nodes it opens and the earlier conversation | Slashspace's cloud, which runs it on an Anthropic model | Every message, whatever is connected |
| Image generation | Prompt, settings and reference images | Slashspace's servers and storage, then OpenRouter. The result is stored there and copied to your computer. Use my OpenRouter key for image generation also sends your OpenRouter key. | Each generation |
| Web node | The page address | Slashspace's servers, which fetch the page through a scraping service. That service hosts the screenshot. | When you capture a page |
| Post node | The post link | Slashspace's servers and third-party transcription services | When you add the link |
| Document node | The whole file | Slashspace's storage, a third-party parser, and a vector database of search embeddings. Open Markdown and Open PDF are public links: anyone who has one can open the converted file. | When you add it |
| AI Search | Text of new or changed nodes on the canvas, and your searches | Slashspace's servers, kept in a search index for your account | Each time you switch to AI Search |
| Voice input | The recording | Slashspace's servers, then Groq. With your own Groq key, straight to Groq. | When you finish recording |
| Connectors | Tool requests and results | Included connectors: Composio, set up through Slashspace's servers. Custom connectors: the server you added. | When a tool runs |
| Agent skills | Browse and install requests | skills.sh | When you browse or install |
| Sign-in and devices | Your email, a device ID, your computer's name and operating system, the app version | Slashspace's servers | At sign-in and in account checks |
| Update checks | Your IP address, app version and platform | slashspace.download | At launch and when you check |
| Bug / Feedback | Your message, attachments and the app's log, with file paths and email addresses removed | Slashspace's support team | When you send |
Two things are easy to miss. Choosing Orchestrator mode is your go-ahead to send canvas context to Slashspace's cloud, and no notice appears when you switch to it yourself. And Claude Code and Codex can read any node on the canvas with a tool, even when the chat is set to Isolated context.
Analytics and error reports
Usage analytics go to PostHog, and they are not all off by default:
- AI usage, for every chat on every model, including your own keys and Ollama: the model, provider, token counts, timings, tool names and any error. Never the text of your prompts or the replies. Always sent.
- Feature usage: app launches, screens, clicks and feature events. A click can record the text you clicked, such as a canvas name. Sent before you sign in; after that, only while the analytics opt-in is on.
Error reports go to Sentry and can include your IP address and any file path or canvas name in the error. About 1 in 10 sessions, and any session with an error, also send a screen replay with text, form fields and images masked.
Once you sign in, analytics are linked to your account. No setting turns off AI usage analytics or error reports.
Privacy settings
Privacy Settings, at the bottom of Settings > Account, lists opt-ins, each with an Enable or Disable button. The list comes from Slashspace's servers, so it appears only while you're signed in and its wording can change. It currently has two:
- Cloud indexing, the cloud vector database behind AI Search. With it off, AI Search shows "You have not opted in for cloud indexing!" instead of results. Switching to AI Search starts sending canvas text for indexing either way, and turning the opt-in off doesn't delete text already indexed.
- Analytics, which covers the feature-usage analytics above.
Both are off for a new account. Accounts that date from Rabbitholes keep the choices made there. Neither setting affects the rest of the table, AI usage analytics or error reports.
Keeping sensitive work local
- Chat on Ollama or your own API keys, not Slashspace models.
- In Settings > Default Models, set Title Generation Model to a model on your own API key, so new chats aren't titled through Slashspace.
- Keep sensitive material on its own canvas, and don't use AI Search or Orchestrator mode there.
- Paste the passages you need into a Text node instead of adding a Document, Web or Post node.
- Connect only what a chat needs. A chat with nothing connected gets a summary of every node on the canvas. Isolated context turns that off, though Claude Code and Codex can still read nodes. See context modes.
- If you dictate, save a Groq key so recordings skip Slashspace's servers.
- Don't share Open Markdown or Open PDF links.
Deleting your data
On your computer. Delete a canvas from the sidebar (this is permanent), or delete the whole SlashspaceOS folder. Update backups stay in ~/Library/Application Support/Slashspace/backups on a Mac and %APPDATA%\Slashspace\backups on Windows. If you moved from Rabbitholes, the old ~/rabbitholes folder is still there too.
On Slashspace's servers. Deleting a canvas doesn't remove copies already uploaded: documents, the AI Search index, and generated and reference images. To have your hosted data and your account deleted, email support@slashspace.ai from the address you sign in with.