Last updated: October 3, 2026
Slashspace, formerly RabbitHoles AI, is a product of Lokus LLC ("we", "us", or "our"). We are committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and who we share it with when you use the Slashspace desktop app, our website at slashspace.ai, and the online services behind them.
Slashspace is local-first. Your canvases, chats, and files are saved on your computer. Some features need to send data off your computer to work. Section 3 explains what each of them sends and where it goes.
Account Details: You need an account to use Slashspace's AI features and to buy a plan. Sign-in is handled by Clerk. We receive your name, email address, and profile picture (if your sign-in method provides one), and we keep an account record in our database (Convex). Some older accounts also have a record in a legacy database (Supabase) that holds the email address, license details, and feature preferences.
Device Information: When you sign in to the desktop app, it registers your computer with our servers. It sends a device ID derived from your computer's machine ID, your computer's name as set in your operating system (which often includes your own name), and your operating system type. We use this to enforce device limits, list your devices on your account page, and allow one free trial per device. Requests from the app to our servers also include the app version.
Payment Information: Purchases and subscriptions are processed by Stripe through our billing provider, Autumn. You enter card details on pages hosted by Stripe, and we do not receive your full card number. We and Autumn keep your name, email address, account ID, device ID, and the status of your purchases and subscriptions. We also record your AI credit usage (the model used, token counts, and cost) so we can show your balance and transactions.
Canvases, Chats, and Files: Your canvases, nodes, chats, and attachments are saved on your computer in the SlashspaceOS folder in your home directory. App settings are saved in the app's data folder on your computer. When the app installs an update, it also keeps a backup copy of your SlashspaceOS folder on your computer. This content is not sent to us unless you use a feature that needs it, as described in Section 3.
Data From RabbitHoles AI: If you used RabbitHoles AI, the app copies your data from the old ~/rabbitholes folder into the new location. The old folder is left on your computer.
API Keys: You can add your own API keys for AI providers such as OpenAI, Anthropic, Google, OpenRouter, xAI, DeepSeek, Perplexity, Groq, Qolaba, and Fal. Your keys are stored on your computer, encrypted with your operating system's secure storage. A key is sent only to the provider it belongs to, with one exception: if you turn on image generation with your own OpenRouter key, the key is sent to our servers so our image service can call OpenRouter for you. It is encrypted before it is passed to our background job service.
Connector Credentials: Header values and sign-in tokens for MCP servers you add are stored on your computer and encrypted where your operating system supports it. Environment variables you set for MCP servers that run on your computer are stored unencrypted in the app's settings.
We use PostHog to understand how Slashspace is used.
AI Usage in the Desktop App: For each AI chat request, the app sends PostHog the model and provider, token counts, timing, the reason the response ended, the names of any tools used, and an error message if the request failed. This applies to every model, including your own keys and local models. It is linked to your account ID, or to a random ID for this installation if you are not signed in. The text of your prompts and of the AI's responses is not included. This cannot currently be turned off in the app.
Feature Usage in the Desktop App: The app records how its features are used. Examples are launching the app, sending a chat (without its text), creating or deleting nodes, opening a canvas, connecting a provider or connector, and seeing an upgrade screen. It also records clicks and screen views automatically, which can include the text of a button or link you click, such as a canvas name. Before you sign in, these events are sent without an account link. When you sign in, the app links them to your account ID, email address, plan, and device ID, and from then on sends them only if analytics is turned on for your account.
Our Website: Our website sends PostHog page views, clicks, and similar events. These are not linked to your account. See Section 5 for the cookies involved.
Sentry: The desktop app sends error and crash reports to Sentry. A report can include the error message, technical details about your computer and the app, your IP address, and any file path or canvas name that appears in the error. For about 1 in 10 sessions, and for any session where an error occurs, the app also sends Sentry a replay of what happened on screen. With the settings we use, text, form fields, and images are masked in these replays. Error reports cannot currently be turned off in the app. Our servers also report errors to Sentry, and those reports can include details of the request that failed, such as your account ID or email address and the app version.
Support Form: When you send a support request or feedback from the app, we receive your message, any screenshots or videos you attach, the app's log file, your account email address, and your device ID. These are delivered to our team through Discord, and attachments are kept in our file storage. If you email us, we receive your message and anything you include.
Microphone Access: The app uses your microphone only when you press the microphone button for voice input. Section 3 explains where the recording goes.
File System Access: The app accesses files and folders you choose, such as in your Documents and Downloads folders, so you can open, attach, and save files.
Camera Access: The app's system settings list camera access, but the app does not currently use your camera.
Providing Services: To run the features you use, such as hosted AI models, document and link processing, voice input, image generation, search, and connectors.
Accounts and Billing: To sign you in, manage your plan and credits, enforce device limits, and allow one free trial per device.
Emails: To send account and purchase emails, such as welcome, purchase, and team invitation emails, through Resend. We may also add your email address, name, plan, and number of devices to Loops, which we use for product emails.
Support: To answer your questions and fix problems you report.
Improving Slashspace: To understand how features are used and to find and fix errors, using the analytics and error reports described above.
Security and Abuse Prevention: To block abusive traffic by IP address or user agent, limit repeated sign-in attempts, and stop the same device from starting more than one free trial.
Marketing Measurement: To measure our LinkedIn ads and credit referrals on our website, as described in Section 5.
Your content stays on your computer unless you use a feature that needs a server. This section lists what each feature sends and where.
Local Models (Ollama): Chats with a local model run on your computer through Ollama, and your messages stay on your device. Chat titles and voice input can still use our servers (see below), and AI usage details go to PostHog (see Section 1.3).
Your Own API Keys: Chats go directly from your computer to the provider you chose, such as OpenAI, Anthropic, or Google, and we do not receive their content. The provider's own terms and privacy policy apply. If you use Qolaba, files you attach are first uploaded to our file storage, and a link to them is sent to Qolaba. When you add an image to a canvas, the app may send it to your default model to write a description of it.
Slashspace Hosted Models: When you use a Slashspace model, which uses your credits, the app sends our servers your messages, the canvas content the chat uses (its connected nodes, or a short summary of the canvas if the chat has no connections), attached images and documents, and tool results. Our servers pass the request through Vercel AI Gateway to Anthropic, OpenAI, or Amazon Bedrock. When the model is set to Auto, the start of your latest message is also sent to a small OpenAI model that picks which model answers. We do not save hosted chat conversations in our database. We keep a billing record of each request with the model used, token counts, and cost.
AI Training and Provider Data Policies: We do not use your content to train AI models. Every AI model is run by a provider with its own data terms, including whether it keeps your requests or uses them for training. For Slashspace hosted models, we prioritize providers and models that do not train on your requests and that offer zero data retention, but their own terms still apply. When you use your own keys, subscriptions, or other providers, choose ones whose terms suit you, such as ones that offer zero data retention and no training.
Canvas Orchestrator: When you use Orchestrator mode, the conversation runs on our servers as a background job on Trigger.dev, using an Anthropic model through Vercel AI Gateway. Each turn sends the canvas name, the canvas content, and recent conversation. Trigger.dev keeps each job's inputs and outputs in its run history.
Chat Titles: By default, the first message of each new chat is sent to our servers to generate a title with an OpenAI model through Vercel AI Gateway. This happens even when you chat with your own key or a local model. You can change the title model in Settings.
Claude Code, Codex, and Cursor: These run through the command-line tool or SDK you installed and signed in to. Your messages, canvas content, and the tools the app gives them are sent to Anthropic, OpenAI, or Cursor under your own account with them.
Documents: When you add a document, such as a PDF, to a canvas while signed in, the app automatically uploads it to our file storage. A background job on Trigger.dev converts it to text with a document parsing service (PDFVector, LlamaParse, or Firecrawl), creates search embeddings with Google's Gemini embedding model, and stores the text and embeddings in Turbopuffer, our search database.
AI Search: When you open AI Search, the app sends the text of the current canvas to our servers to be indexed the same way. This includes chats, notes, web page and video transcripts, and image descriptions. Your search queries are also sent to our servers, and Cohere ranks the results.
Web Pages: When you add a web page to a canvas, its address is sent to our servers, which fetch the page with Firecrawl.
Videos and Posts: When you add a video or social media link, such as a YouTube link, its address is sent to our servers. We fetch the transcript through Scrape Creators or Supadata, or by downloading the audio and transcribing it with Groq. Audio downloaded this way is kept in our file storage. Video and post nodes also show embedded players from sites such as YouTube, Instagram, TikTok, and X, which load content from those sites.
Voice Input: If you have added a Groq API key, your recording goes directly to Groq for transcription. Otherwise it goes to our servers, which send it to Groq.
Image Generation: Your prompt, settings, and any reference images are sent to our servers, and reference images are uploaded to our file storage. A background job on Trigger.dev sends the request to OpenRouter and saves the generated image in our file storage, and the app then saves a copy on your computer.
Connectors: For included connectors, our servers set up a session with Composio linked to your account ID, and the app then sends tool requests to Composio and receives the results directly. When you connect a service such as Gmail or Notion, you sign in through Composio, which keeps that access. MCP servers you add yourself are contacted directly from your computer, and we do not receive that traffic.
Skills: When you browse or install skills, the app contacts skills.sh.
App Updates: The app checks slashspace.download for updates when it starts and when you check manually. The update server sees your IP address, app version, and platform, but no account information.
Service Providers: We share information with the service providers below only as needed to run Slashspace.
| Service provider | What it receives | Why |
|---|---|---|
| Clerk | Name, email address, profile picture, sign-in details | Account sign-in |
| Convex | Account, device, license, and credit usage records | Our main database |
| Supabase | Email address, license details, and preferences for older accounts | Legacy account database |
| Render and Cloudflare | Requests to our servers, including IP address | Hosting our servers |
| Vercel | Website visits, including IP address, and hosted AI requests | Hosting our website and routing hosted AI requests |
| Anthropic, OpenAI, and Amazon Bedrock | Hosted AI requests | Answering chats that use Slashspace models |
| OpenRouter | Image prompts and reference images | Image generation |
| Groq | Voice recordings and downloaded video audio | Transcription |
| Document and canvas text | Creating search embeddings | |
| Cohere | Search queries and matching text | Ranking search results |
| Turbopuffer | Indexed text and embeddings, stored per account | Search database |
| Trigger.dev | Inputs and outputs of background jobs, such as documents, image prompts, transcripts, and Orchestrator conversations | Running background jobs |
| Amazon Web Services | Uploaded documents, reference and generated images, support attachments, and downloaded video audio | File storage |
| Firecrawl, PDFVector, and LlamaParse | Web page addresses and documents | Extracting text |
| Scrape Creators and Supadata | Video and post addresses | Fetching transcripts |
| Composio | Account ID and connector tool requests | Connectors |
| Autumn and Stripe | Name, email address, account ID, device ID and name, purchases | Billing and payments |
| Upstash | Short-lived billing records for hosted AI requests, without their content | Holding credits while a request runs |
| Resend | Email address and name | Account and purchase emails |
| Loops | Email address, name, plan, and number of devices | Product emails |
| PostHog | The analytics described in Section 1.3 | Product analytics |
| Sentry | The error reports and replays described in Section 1.4 | Error monitoring |
| Discord | Support requests described in Section 1.5 | Delivering support requests to our team |
| LinkedIn, Dub, and DataFast | Website visit data described in Section 5 | Ad measurement, referral tracking, and website analytics |
Providers You Choose: When you use your own API key, Claude Code, Codex, Cursor, or an MCP server you added, that provider receives data under your own account and its own terms and privacy policy.
Legal Requirements: If required by law, we will comply with legal obligations to disclose information.
Our website uses the cookies, browser storage, and tracking scripts below. They load when you visit the site, and we do not currently show a cookie consent banner. You can block or delete cookies in your browser settings.
Sign-in (Clerk): Cookies that keep you signed in.
Analytics (PostHog): A cookie and a browser storage entry, kept for up to a year, used to count visits and record page views and clicks.
Analytics (DataFast): A script that records visits to our website.
Ads (LinkedIn Insight Tag): A script from LinkedIn that measures the results of our LinkedIn ads. LinkedIn may set its own cookies.
Referrals (Dub): A dub_id cookie, kept for 90 days, that records which referral link brought you to our site. If you then buy, the referral is attached to your checkout so it can be credited.
Preferences: Your light or dark theme choice, saved in your browser.
Local Data Storage: Your content is stored on your computer, and your API keys are encrypted with your operating system's secure storage. We recommend that you secure your device with appropriate measures to prevent unauthorized access.
Data in Transit: The app and our website connect to our servers over encrypted connections (HTTPS).
Keep Chats Off Our Servers: Use your own API keys, Claude Code, Codex, Cursor, or a local model instead of Slashspace models, and choose a title model other than the Slashspace default in Settings.
Analytics: When signed in, feature usage analytics in the desktop app are sent only if analytics is turned on for your account.
Devices: You can remove devices from your account page.
Local Data: You can delete your canvases and chats by deleting them in the app or by deleting the SlashspaceOS folder.
Cookies: You can block or delete cookies in your browser settings.
Age Restriction: Our application is not intended for children under the age of 13. We do not knowingly collect personal information from anyone under 13 years of age.
Policy Updates: We may update our Privacy Policy from time to time. Changes will be effective immediately upon being posted on this page.
If you have any questions or concerns about this Privacy Policy or your information, please contact us at support@slashspace.ai.
Lokus LLC
447 Broadway, New York, 10013