Privacy Policy

Effective: 24 June 2026

1. Introduction & scope

Slashboard ("Slashboard", "the Service", "we", "us", or "our") is an AI cost-observability platform operated by SlashLLM. This Privacy Policy explains what personal data we collect, how and why we process it, the legal bases on which we rely, and the choices and rights available to you.

This Policy applies to our marketing website, web application, and ingest API (collectively, the "Service"). It does not apply to third-party products, websites, or services that we do not own or control, even where they are linked from or integrate with the Service. By accessing or using the Service, you acknowledge that you have read and understood this Policy.

2. Data controller & contact

For the purposes of the EU/UK General Data Protection Regulation ("GDPR") and similar laws, SlashLLM is the data controller for personal data processed about account holders and visitors, and a data processor in respect of telemetry you transmit to us on behalf of your end users.

You can reach our privacy team at privacy@slashllm.com. If you are in the EEA or UK and believe we have not adequately addressed a concern, you also have the right to lodge a complaint with your local supervisory authority.

3. Information we collect

Account & identity data: name, work email address, hashed password, organisation name, role, and — where you sign in with a third-party identity provider — the basic profile information that provider returns (see Section 5).

Ingest telemetry (transmitted by your application): model identifier, provider, token counts, computed or submitted cost, latency, request status, and optional attribution tags (for example team, feature, or an opaque user identifier). We do NOT store prompt or response bodies by default. Such bodies are stored only if you, as the customer, explicitly enable body capture in Settings, and you are solely responsible for ensuring that content you choose to transmit is lawful and free of unnecessary personal data.

Usage & technical data: API-key activity timestamps, dashboard interaction events, device and browser type, IP address, approximate location derived from IP, and diagnostic logs.

Communications: records of correspondence when you contact support, sales, or legal.

4. How and why we use your data

We process personal data to: (a) provide, operate, secure, and maintain the Service; (b) authenticate users and protect accounts; (c) populate dashboards and compute cost analytics; (d) send transactional messages such as email verification, password resets, and budget alerts; (e) provide customer support; (f) detect, investigate, and prevent fraud, abuse, and security incidents; (g) comply with legal obligations and enforce our agreements; and (h) improve and develop the Service in aggregate, de-identified form.

We rely on the following legal bases where GDPR applies: performance of a contract, our legitimate interests (operating and securing the Service), compliance with legal obligations, and, where required, your consent.

We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising as those terms are defined under applicable U.S. state privacy laws. We do not use your LLM telemetry, prompts, or responses to train, fine-tune, or evaluate any machine-learning or AI model.

5. Google Sign-In & Google API Limited Use

If you choose to sign in with Google, we receive from Google only the basic profile information necessary to create and authenticate your account — typically your name, email address, language preference, and profile picture. We request the minimum scopes required for authentication and do not request access to your Gmail, Drive, Calendar, contacts, or other Google services.

Slashboard's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the sign-in and account features you request; we do not transfer or sell it to third parties except as necessary to provide the Service, comply with applicable law, or as part of a merger or acquisition; we do not use it for advertising; and we do not allow humans to read it unless we have your affirmative consent, it is necessary for security or to comply with law, or the data has been aggregated and de-identified. You can revoke Slashboard's access at any time via your Google Account permissions page.

6. Data retention

Raw event logs (llm_requests) are retained for 30 days from ingestion and then automatically purged. Aggregated cost rollups, which contain no personal data, are retained to support long-range analytics. Account and identity data are retained for the life of your account and for a limited period afterwards as necessary to comply with legal, tax, accounting, and dispute-resolution obligations, after which they are deleted or irreversibly anonymised.

7. Sub-processors & international transfers

We engage a limited set of vetted sub-processors to operate the Service, including providers of database, queue, object-storage, cloud-hosting, email-delivery, and analytics infrastructure. Each sub-processor is bound by a written agreement requiring confidentiality and data-protection commitments no less protective than those in this Policy. A current list of sub-processors is available on request at privacy@slashllm.com.

Where personal data is transferred outside your jurisdiction, including to the United States, we implement appropriate safeguards such as the European Commission's Standard Contractual Clauses or an equivalent lawful transfer mechanism.

8. How we protect your data

We maintain administrative, technical, and organisational safeguards designed to protect personal data. All data in transit is encrypted using TLS. API keys are stored as SHA-256 hashes; passwords are hashed using bcrypt. We enforce per-organisation data isolation at the application layer, apply least-privilege access controls, and test for cross-tenant leakage. No method of transmission or storage is completely secure, and while we strive to protect your data we cannot guarantee absolute security.

9. Your rights & choices

Depending on your location, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent. You may exercise these rights from your account settings or by emailing privacy@slashllm.com, and we will respond within the timeframe required by applicable law (generally 30 days). We will not discriminate against you for exercising any privacy right. We may need to verify your identity before fulfilling a request.

10. Cookies & similar technologies

We use a single, strictly necessary httpOnly session cookie to keep you signed in. We may use privacy-respecting, aggregate analytics to understand product usage. We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings, though disabling the session cookie will prevent you from signing in.

11. Children's privacy

The Service is intended for businesses and is not directed to individuals under the age of 16 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@slashllm.com and we will delete it.

12. Changes to this Policy

We may update this Policy from time to time. For material changes, we will provide notice by email or in-product at least 14 days before the change takes effect, unless an earlier change is required by law. The "Effective" date above indicates when this Policy was last revised, and your continued use of the Service after the effective date constitutes acceptance of the revised Policy.

13. Contact us

Questions, concerns, or requests regarding this Policy or your personal data can be sent to privacy@slashllm.com.

See also our Terms of Service.