The top half is the plain-language version. The bottom half is the part a careful reader checks — legal bases, retention periods, where the machines are, and who can see what.
Version 2026-09. We keep every previous version at version history.
Your writing is private. We do not use it to train writing models, and we do not show it to anyone unless you ask us to. It powers your own project and nothing else. Two narrow exceptions exist on our side, and rather than leave them for you to discover, they are written out below under staff access.
Three different things, which are worth keeping apart because they are treated differently.
Account data — your email address, and billing records if you subscribe. What you write — your manuscripts, notes, characters and everything else you create. Usage and device data — which features you open, when, and enough technical detail to keep the service running and to investigate faults.
The second of those is the one people worry about, so to be explicit: your manuscripts are stored so we can give them back to you, and processed only to run the features you ask for.
There is now a fourth, and it is small: if you apply for the Team closed beta, we keep the work email address, team name, size and type you chose, anything you typed in the note field, which language page you applied from, and the page on our site you came from. That is the whole record. We use it to reply to you and to decide the order we onboard teams in.
Under the GDPR each purpose needs a legal basis, and they are not interchangeable.
Running your account and the service — performance of our contract with you. Keeping the service secure and preventing abuse — our legitimate interests. Analytics and advertising — your consent, which you give or refuse in the cookie banner and can change at any time. Billing records — a legal obligation, which is why invoices outlive a deleted account.
The Team closed-beta form — your consent, given by submitting it. You can withdraw it by writing to service@slima.ai, and there is no consequence: withdrawing removes you from the beta list, not from Slima.
When you ask the coach a question, run a Beta Reader report or check continuity, the relevant part of your manuscript is sent to a model provider. Passages, not the whole book — only what the request actually needs.
Three things never happen: your work is not used to train anyone's models, it is not shared with other users, and it is not read by us for any purpose other than a fault you have reported. Providers hold the passage briefly for their own abuse detection and then discard it.
Models that run on our own infrastructure do not leave our systems at all. Which providers we use is listed by category on the subprocessor page, and by name if you write and ask.
Application servers and the primary database are in Tokyo, Japan. Media files and encrypted backups are in Cloudflare R2. The web application itself is served from a global CDN — static files only, never manuscript content.
Deletion is not instant, and the reason is worth stating plainly rather than hiding in a clause.
| What you did | When it is really gone |
|---|---|
| Emptied a single work from the trash | Removed from the database immediately; media files deleted by the cleanup job; gone from encrypted backups within 35 days as they rotate |
| Deleted your account | 30-day grace period, cancelled by signing back in. Then a hard delete of the account, every work, and every AI conversation. Worst case including backups: 65 days |
| Applied for the Team closed beta | Kept until the beta closes, or until you ask us to delete it — whichever comes first. Deleted on request within 30 days |
| Encrypted database backups | 35-day rotation, destroyed automatically when they expire |
That 35-day window exists so your work can be recovered after a hardware failure or an attack. It is a trade between protecting your data and forgetting it immediately, and we have made it as short as we sensibly can. Everything in it is encrypted.
Tokyo is where the machines are. That is a fact about geography, not a legal basis.
The data controller is Slima, Inc., a company in the United States, so as a matter of law your data is transferred to a US entity regardless of where it is stored. The lawful basis for that transfer, and for the transfers to each of our providers, is the Standard Contractual Clauses (SCCs) together with a data processing agreement signed with each of them.
If you are in the EU, EEA or UK these are rights rather than features, and the same buttons serve everyone.
We answer within one month. If a request is unusually complex we will tell you why before that month is up, rather than after.
You may also complain to the data protection authority in the country where you live — in Spain, the Agencia Española de Protección de Datos (AEPD). You do not have to raise it with us first.
There is no interface, dashboard or internal tool that displays the contents of a manuscript. The admin backend shows metadata only — title, word count, when it was last touched. Internally, Beta Reader work shows aggregate statistics, not report contents.
Two exceptions, disclosed here rather than left to be found. First, when someone reports that the AI invented something that is not in their book, there is a read-only view of that book's AI memory entries so the fault can be traced. Those are AI-generated summaries rather than your prose, and you can clear them yourself. Second, a small number of engineers hold direct access to the production database. That access is least-privilege, logged, used only to investigate reported problems, and prohibited by internal policy from being used to read anyone's work.
Two cookies are always set because the site cannot work without them: a session cookie, and the one that remembers your answer to the cookie banner. Neither is used to track you.
Everything else — Google Analytics, and the Meta and Reddit advertising pixels — loads only after you allow it, and not at all until then. Be clear about what analytics does see: the events carry a random account identifier and a random work identifier, so one session can be told from another. That is a real identifier, not an aggregate. What the events do not carry is anything you wrote — analytics has no access to manuscript content, and the URLs it records hold random identifiers rather than titles or filenames.
You can change or withdraw that choice from the cookie settings link in the footer. Withdrawing also deletes the cookies those trackers set for themselves.
Slima is for people aged 16 and over, or the higher minimum age set by your country's law if there is one.
Material changes are announced by email before they take effect, and every previous version stays available at version history. We would rather you could check what changed than take our word for it.
Questions about privacy, or a request under any of the rights above? Email service@slima.ai and a person will answer.
Slima · service@slima.ai
Before we count anything
Analytics and advertising cookies stay off until you turn them on. The ones that keep the site working, and the one that remembers this choice, are always on. The detail is in the Privacy Policy.