// Privacy notice · DRAFT · 2026-05-20

What we keep. What we don't.

A plain-language description of the data SLASHED handles when you route requests through api.slashed.pro. This page is a working draft published for transparency while a privacy counsel review is in progress.

DRAFT — not yet a binding privacy notice

This document describes our intended posture and current data-handling practice. It has not been reviewed by external privacy counsel. Specific representations about jurisdiction, regulatory basis, statutory rights, and remedies will be added — and may change — after that review.

Material changes will be dated and reflected in the changelog at the foot of this page. If you need a counsel-grade representation before that review completes, write to hi@slashed.pro and a founder will respond directly.

Version 0.1-DRAFT Last updated 2026-05-20 Status pre-counsel
— 01 · What SLASHED collects

Account, billing, request metadata. Not prompt content.

SLASHED is a single-hop OpenAI-compatible gateway across eleven frontier models from Anthropic, Google, and OpenAI. The data we handle falls into four categories: account data, credentials, billing data, and request metadata. Prompts and completions traverse the gateway but are not persisted as a default behaviour.

Account data
Email address, organisation name, account-level configuration. Captured when you sign up at dashboard.slashed.pro. Stored in our first-party PostgreSQL instance for the lifetime of the account.
API credentials
SLASHED-issued sl- keys, and — if you opt into key import — provider credentials (sk-, qua-, or-) which sit encrypted at rest. Credentials are scoped to your account and never exposed in logs or telemetry.
Billing data
Payment-method metadata for invoice generation (last 4 digits of card, billing address, VAT identifier where applicable). Card primary-account-numbers are not stored on SLASHED systems — that handling is delegated to the payment processor named on the sub-processors page.
Request metadata
Per-request: model ID, token counts (prompt + completion), latency, HTTP status, region, API-key reference (hashed). What we do not store: prompt text, completion text, tool-call arguments, attached files, or any other request body content — unless you have explicitly opted into payload logging for your own debugging via the dashboard.
Dashboard telemetry
Authenticated page views, feature use, and error events from dashboard.slashed.pro. Limited to UI events; never includes customer prompt content. Vendor selection for this telemetry is in flight — see the sub-processors page for the current candidate set.
// Plain statement: Unless you explicitly opt into payload logging on a per-key basis from the dashboard, SLASHED does not write your prompts or completions to any first-party store. They exist only for the lifetime of the request that produced them. That is the default and the only default.
— 02 · Sub-processors and where data flows

Three model providers. One named edge. One first-party store.

Every request to api.slashed.pro is forwarded to exactly one named upstream model provider — OpenAI, Anthropic, or Google AI Studio — depending on the model you select. There is no proxy chaining, no unnamed fourth-party, no customer-prompt write-back to any third-party telemetry sink.

The full sub-processor map, including support services for billing, transactional email, edge TLS, and product analytics, is published at /sub-processors. That page is the canonical list and is governed by a 30-day advance-notice commitment for any new entries.

  • Model inference OpenAI, Anthropic, Google AI Studio. When you select a model, the corresponding provider receives the prompt and returns the completion. SLASHED routes pass-through. We configure provider-side accounts with the no-training / data-opt-out options each provider offers; ultimate enforcement of those opt-outs sits with the provider under their own published policy.
  • Edge / TLS Cloudflare (illustrative). Terminates TLS, performs DDoS mitigation, serves DNS for slashed.pro. Sees headers and request envelope; treated as a sub-processor and listed on the canonical page.
  • First-party store SLASHED-operated PostgreSQL. Holds account, key, and usage metadata. Co-located with the origin host. Customer prompts and completions are not persisted here.
  • Billing & mail Payment processor + transactional email vendor (illustrative). Final vendor selection in flight; named on the sub-processors page before activation.
  • Our intended posture: if a name is not on the sub-processors page, your prompt is not routed to it. See the four commitments published at /sub-processors#commitments — including 30-day advance notice for new entries. Counsel review will set out the precise contractual representation here.

    — 03 · Retention

    Only what billing and audit require. The rest disappears.

    Retention is bounded by purpose. Prompts and completions are not retained as a default behaviour. Other data classes are kept for the minimum interval that supports billing reconciliation, security audit, and statutory record-keeping.

    Prompt + completion content
    Short-lived by default. Exists only for the duration of the request. Not written to a first-party persistence store. Not shipped to any analytics or telemetry sink. The exception is per-key opt-in payload logging for customer-initiated debugging, which is retained for a short bounded window (target: 7 days) and then purged.
    Request metadata
    Target: 30 days. Token counts, latency, HTTP status, model ID, hashed key reference. Used for dashboard charts, anomaly detection, and billing reconciliation. Aggregated to monthly totals after the retained window; raw rows purged. Specific window may be tuned during the pre-counsel period and will be reflected here with an updated date.
    Aggregated billing records
    Long-term, per applicable accounting / tax record-keeping obligations. Includes monthly token totals per model, invoice line items, and payment receipts. The specific retention duration is jurisdiction-dependent and will be set out concretely after counsel review.
    Account data
    Lifetime of the account. Deleted within a target of 30 days of a confirmed account-closure request, except where the data is reflected in retained billing records (see above).
    Security audit logs
    Target: 90 days. Authentication events, key rotation events, admin-console activity. Used for incident investigation; not used for product analytics.
    Status / incident records
    Public history. Posted at status.slashed.pro. Timestamps and component health only; no customer-identifying content.

    Specific retention values above are configurable on a per-engagement basis for the self-hosted edition, where the customer controls the underlying storage entirely. For the hosted gateway, retention values are set globally and changes will be reflected here with an updated date.

    — 04 · Your rights and how to exercise them

    Access. Export. Delete. From the dashboard or by email.

    You can exercise the following rights over data SLASHED holds about your account. Most are available as self-serve actions inside the dashboard; the remainder are handled by email and acknowledged within a reasonable working interval (target: 5 business days).

    // How to ask: Most actions live in dashboard.slashed.pro under Account → Privacy. For anything not self-serve, write to hi@slashed.pro with the action and the affected account email. A founder acknowledges within 5 business days.
    — 05 · Security posture

    Industry-standard encryption. Isolation. No claimed certifications.

    SLASHED uses industry-standard encryption (TLS 1.3 in transit; strong symmetric encryption at rest, currently AES-256-class where the underlying storage layer supports it). Per-key rate limits, per-key audit logs, and key separation isolate one customer's activity from another's. SLASHED does not use customer prompts or completions to train any model on its side; provider-side training opt-outs are configured per the policy each sub-processor publishes.

    What we do not yet claim: SOC 2 Type II certification, ISO 27001, HIPAA conformance, or PCI-DSS scope. A SOC 2 Type II audit is in progress with a target completion in Q4 2026; that status is repeated on the landing page and the sub-processors page and will be updated here once the report is issued.

    GDPR posture (lawful basis, DPA availability, EU representative, supervisory authority) will be set out specifically once counsel review concludes. The current direction is to make a DPA available on request and to honour the rights enumerated above; the binding text will appear here in a later revision.

    Questions about data handling? A founder replies.

    Email hi@slashed.pro for privacy questions, DPA requests, or anything raised by a procurement controls matrix. Not a queue — a working founder. Acknowledged within 5 business days.

    Read the terms →