Sloe Laboratory · SLOE Labs Inc.
Last updated: 3 August 2026 · Supersedes the version published 1 July 2026
This policy explains how SLOE Labs Inc. ("we", "us"), a corporation incorporated under the Canada Business Corporations Act and registered in Ontario, collects, uses, shares, and protects information when you use Sloe Laboratory (the "Service") at sloelabs.com and its subdomains.
1. Two different roles — read this first#
Sloe Laboratory does two things, and our responsibilities differ between them.
When you use the Service for your own account, we are the controller of your account information. This policy governs that.
**When you build an operating system that holds data about your customers, staff, or contacts**, you are the controller of that data and we are your processor. We handle it on your instructions, for your purposes, under our Data Processing Addendum — not under this policy. If you are an individual whose data was put into someone else's Sloe Laboratory operating system, that organisation is responsible for it and is who you should contact; we will refer your request to them.
2. What we collect#
Account data — your email address and password. Passwords are stored only as salted hashes; we never hold them in plaintext.
Content you create or import — the operating systems, records, documents, and data you build or bring into the Service.
Connected-service data — data you explicitly authorise us to access through integrations, limited to the scopes you grant. See section 4.
Agent interaction data — prompts, responses, and the actions the agent takes on your behalf, including an audit log of those actions.
Memory — to make the agent useful across sessions, we generate and store mathematical representations (vector embeddings) of your content, together with extracted facts and summaries. This is derived from your content and is deleted with it.
Usage data — product-level telemetry (for example, which screens are used) to operate and improve the Service.
Technical data — IP address, browser and device information, and error diagnostics, used for security, abuse prevention, and debugging.
3. Artificial intelligence — how your data is used#
This is the section most people are looking for, so it is explicit.
We do not train on your data. We do not use your content to train or improve our own models, to build features or benchmarks for other customers, or for advertising. We do not sell it.
Model providers. Your prompts and the context needed to answer them are sent to the AI providers listed in section 6. We procure these on commercial terms under which the provider is contractually barred from using submitted content to train or improve its models, and from human review of that content, except where strictly necessary for security or legal compliance. We publish which providers we use, and on what terms, at https://sloelabs.com/subprocessors — so you can verify this rather than take our word for it.
What the agent can do. The Service is agentic: it can take actions — sending an email, updating a record — not only answer questions. Those actions occur on services you have connected and within the permissions you granted. Every action is logged and attributable, an independent verifier checks the agent's claims against what actually happened, and outbound email requires your confirmation and sends only from a domain you have verified.
Accuracy. AI output can be wrong. Review anything carrying legal, financial, or safety consequences before relying on it.
4. Connected services and Google user data#
When you connect a third-party account we never receive or store your password. A scoped access grant is created instead.
Who holds that grant. For most integrations the grant is held by our connector provider, Composio, which brokers the connection and executes actions against it on your instruction. We store a reference to the connection, not your credentials. Composio is listed at https://sloelabs.com/subprocessors with what it can see. Where we hold a credential directly — some specialist data connectors work this way — it is encrypted at rest with AES-256-GCM using a purpose-derived key and a per-token random value.
You can disconnect at any time from your integration settings, which revokes access.
We request the narrowest scopes that make a feature work. For Google integrations the scopes are limited to what the feature needs:
- Sending email — we send at your explicit direction. We do not read, search, or store the contents of your inbox.
- Spreadsheets — we read only the specific sheets you explicitly connect, and only to import the rows you ask us to. We do not browse your Drive or access other files.
You approve the exact permissions at Google's own consent screen before anything is connected, and you can review or revoke them at any time in your Google account.
Google API Services User Data Policy — Limited Use. Where Sloe Laboratory receives information from Google APIs, its use and transfer of that information adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide or improve user-facing features that are prominent in the Service; is not transferred or sold to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition; is not used for advertising; is not used to develop, improve, or train generalised AI or ML models; and is not read by humans unless we have your explicit consent, it is necessary for security or to comply with applicable law, or the data is aggregated and anonymised.
5. How we use information#
To provide, secure, maintain, and improve the Service; to authenticate you; to operate the agent and its memory at your direction; to process payments; to send transactional messages; to detect and prevent abuse; and to comply with legal obligations.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
6. Who else processes your data#
We share data with service providers strictly to operate the Service. The complete, current list — with what each does and where it runs — is published at https://sloelabs.com/subprocessors and mirrored at sub-processors.md. It includes our database, hosting, and infrastructure providers; our AI providers; our connector, email, payment, and error-monitoring providers.
We update that list before a new provider begins processing customer data.
We may also disclose information where required by law, to enforce our terms, to protect rights and safety, or in connection with a merger or acquisition — in which case we will give notice before your data becomes subject to a different policy.
7. International transfers#
We are Canadian; our providers are principally in the European Union and the United States. Your data will be processed outside your country and will be subject to the laws of those jurisdictions.
Where required, we rely on the EU Standard Contractual Clauses and the UK Addendum, and for South African customers on the contractual protections described in POPIA s72, as set out in Annex C of the Data Processing Addendum.
8. Retention#
We keep your data for as long as your account is active. After termination you may export it for 30 days, after which we delete it within 90 days, including from backups on their ordinary rotation, except where law requires us to keep it. Audit and action logs are retained for 24 months. Error-monitoring data is retained 90 days.
9. Your rights#
Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to processing of your personal information, and to withdraw consent. You may also have the right not to be discriminated against for exercising these rights.
Contact privacy@sloelabs.com. We respond within 30 days, or sooner where the law requires.
You may complain to your regulator — in South Africa the Information Regulator; in the EU/UK your supervisory authority or the ICO; in Canada the Office of the Privacy Commissioner. Contact us first and we will try to resolve it directly.
If your data is in an operating system operated by another organisation, see section 1 — contact them, and we will assist them in responding to you.
10. Security#
We describe our technical and organisational measures in the Security Overview and in Annex B of the DPA. Summarised: row-level ownership enforced in the database, encryption in transit and at rest, AES-256-GCM encryption of connector tokens, no AI provider credential ever exposed to the browser, and an audit log of every agent action.
No system is perfectly secure. If you believe you have found a vulnerability, report it to security@sloelabs.com — we will not pursue legal action against good-faith research that respects user privacy and avoids service disruption.
11. Children#
The Service is for business use and is not directed to children. We do not knowingly collect personal information from children under 16 (or the age set by local law). If you believe a child's data has been submitted, contact us and we will delete it.
12. Payments#
Paid plans are processed by Stripe, Inc. We do not collect or store full card numbers; Stripe handles them under its own security and compliance program. We retain only limited billing metadata — plan, status, and the last four digits of a card — needed to manage your subscription.
13. Changes#
We may update this policy. Material changes will be announced by updating the date above and, where the change is significant, by notifying you directly. If a change would materially reduce protection of data we already hold, we will seek your consent or give you a meaningful opportunity to object.
14. Contact#
SLOE Labs Inc. (Canada) Privacy: privacy@sloelabs.com · Security: security@sloelabs.com