Privacy Policy
Effective date: May 13, 2026
This Privacy Policy explains how Slate HQ ("we", "us", "our") collects, uses, and shares personal data when you visit our website or use our service to generate AI UGC ad videos with our AI video engine.
1. Data controller
The data controller responsible for your personal data is Slate HQ. You can reach us at hello@slatehq.org. For privacy-specific requests, see Section 9 below.
2. Data we collect
- Account data. Email address (required) and a display name (optional) that you provide when you sign up.
- User-generated content. Product images you upload, the one-line product descriptions you enter, and the video outputs our AI video engine generates from those inputs.
- Billing data. Payments are handled by Lemon Squeezy as Merchant of Record. We do not see or store your full card number. We receive your billing email, card last four digits, and invoice records via the Lemon Squeezy API.
- Usage data. Aggregated page views and feature interactions collected through Vercel Analytics, which is cookieless and privacy-friendly. IP addresses are truncated before storage.
- Communications data. When we send you transactional or waitlist emails via Resend, we receive delivery metadata such as message IDs, opens, and link clicks.
3. Purposes and legal bases (GDPR Art. 6)
- Providing the service (creating your account, generating videos, storing your outputs) — performance of a contract.
- Sending confirmation and status emails related to your account, generations, or purchases — performance of a contract.
- Marketing waitlist emails. Signing up to our waitlist constitutes your consent to receive related product updates. You can withdraw consent at any time via the unsubscribe link in any email.
- Analytics. Cookieless, aggregated analytics — legitimate interest in understanding and improving our service.
- Legal and tax compliance (e.g. retaining invoices) — legal obligation.
4. Sub-processors
We share personal data with the following sub-processors strictly to provide the service. Each is bound by a data processing agreement.
| Processor | Role | Data | Location |
|---|---|---|---|
| Vercel | Hosting & analytics | Page metadata, truncated IP addresses | US |
| Supabase | Authentication, database, storage | Account email, uploaded images, generation metadata | US (EU region available on request) |
| Resend | Transactional & waitlist email | Email address, message IDs, opens / clicks | US |
| Lemon Squeezy | Payments (Merchant of Record) | Name, billing email, card last 4 (never full card number), invoices | US |
| fal.ai | AI video generation infrastructure | Product image and prompt (transient processing only) | US |
5. International transfers
Our sub-processors are primarily located in the United States. When we transfer personal data from the European Economic Area, United Kingdom, or Switzerland to the United States, we rely on the EU Standard Contractual Clauses (SCCs) and, where applicable, on the EU-US Data Privacy Framework and its UK and Swiss extensions.
6. Data retention
- Account data: retained until you delete your account, plus 30 days for backup expiry.
- Uploaded product images: automatically deleted 90 days after generation, or sooner on your request.
- Generated videos: stored until you delete them or close your account, plus 30 days for backup expiry.
- Billing records: retained for 7 years to comply with tax and accounting obligations.
- Analytics: aggregated metrics retained indefinitely; raw events deleted after 30 days.
7. Your rights (GDPR Art. 15–22)
If you are located in the EEA, UK, or Switzerland, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion (“right to be forgotten”);
- request restriction of processing;
- data portability in a structured, machine-readable format;
- object to processing based on legitimate interests, including profiling;
- opt out of solely automated decisions that produce legal or similarly significant effects.
To exercise any of these rights, email privacy@slatehq.org. You also have the right to lodge a complaint with your local supervisory authority.
9. Children
Slate HQ is not directed at users under 18, and we do not knowingly collect personal data from children. The service is not intended for children under 13 in the United States; if you believe a child has provided us with personal data, please contact us so we can delete it.
10. Security
We protect your data with TLS encryption in transit and encryption at rest for storage and databases. Passwords are hashed by Supabase (we never see plaintext passwords). In the event of a personal data breach affecting EEA users, we will notify the relevant supervisory authority within 72 hours of becoming aware, in line with GDPR Art. 33, and notify affected users without undue delay where required.
11. California residents (CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request deletion or correction of your personal information, and to opt out of the “sale” or “sharing” of your personal information. We do not sell or share your personal information for cross-context behavioral advertising. To exercise these rights, email privacy@slatehq.org. We will not discriminate against you for exercising any of these rights.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and notify registered users by email or in-product notice at least 7 days before the changes take effect.
13. Contact
General questions: hello@slatehq.org.
Data Protection Officer / privacy requests: privacy@slatehq.org (placeholder address — to be confirmed).
See also our Terms of Service.