Privacy Policy

Slate · Effective 15 September 2026

Slate is a personal health app. It reads your body's data to tell you something useful about it. This page explains exactly what it collects, where each piece of it physically lives, and the one company besides Apple that ever sees any of it.

The short version

1. Who is responsible for your data

Slate is operated by MJ Largie. If you have a question about anything on this page, or want to exercise any of the rights described in section 9, write to slate.service.app@gmail.com and we will respond.

2. What Slate collects

Account information

When you create an account, Slate stores your email address and a securely hashed version of your password. We never store or have access to your password in readable form. Authentication is handled by Supabase (see section 5).

Profile and goals

During setup you provide details used to calculate your targets: your goal (lose, maintain, gain, general health), sex, date of birth, height, current and target weight, dietary style and any allergies or food restrictions you flag. Your calorie and macronutrient targets are stored alongside these.

Apple Health data

With your explicit permission — granted through Apple's own Health permission screen, and revocable at any time in the Health app — Slate reads the following from Apple Health:

Slate also writes the meals you log back to Apple Health as nutrition entries, so your food data is available to the other health apps you use. It writes nothing else.

Some of these readings require an Apple Watch or a comparable wearable. If you do not have one, Slate simply works with less and tells you so — it does not estimate heart data it cannot measure.

What you log yourself

Meals and drinks, your daily journal (things like alcohol, added sugar, mood, illness, travel, late meals, screens in bed, late caffeine), workouts and training templates, weight history, saved foods, and your conversations with Coach.

Photos

If you photograph a meal, the image is sent to Google's Gemini API to be identified and analysed (section 4). The photo itself is not uploaded to Slate's servers — it stays in your device's storage, and Slate saves only a reference to where that file sits on your own phone, so the picture can be shown again next to the meal. Slate does not read your photo library; it only ever receives an image you deliberately take or choose.

What Slate deliberately does not collect

No advertising identifiers. No location. No contacts. No browsing or cross-app activity. No device fingerprinting. No behavioural analytics of any kind. Slate has no analytics SDK, no crash-reporting SDK, and no advertising SDK installed.

3. Where your data physically lives

This distinction matters more than the list above, so it is set out explicitly:

DataWhere it is stored
Daily journal entriesYour device only
Workout logs and training templatesYour device only
Coach conversation historyYour device only
Weight historyYour device only
Body stats, diet style, allergiesYour device only
Saved foods and meal templatesYour device only
Meal photosYour device only
Apple Health readingsApple Health on your device; read as needed, not copied to our servers
Email address and password hashSlate's servers (Supabase)
Profile details and goalsSlate's servers (Supabase)
Logged meals and drinks (names, calories, macros, times)Slate's servers (Supabase)

Everything stored on Slate's servers is protected by row-level security keyed to your account, which means the database itself refuses to return one person's rows to another person — it is not merely a rule the app is trusted to follow.

4. AI processing, and exactly what is sent

Slate's food analysis, plan generation and Coach are powered by Google's Gemini API. These requests go directly from your device to Google. Here is precisely what is included, and when:

Google processes this under the Gemini API terms and the Google Privacy Policy. Slate sends only what a given request needs. Your full Apple Health history, your journal and your logged workouts are not sent to Google — only the specific current figures listed above.

If you would rather no health information reach Google at all, do not use Coach, the food camera, or plan generation. Every other part of Slate — logging, your scores, your trends, your journal and your patterns — is computed on your device and works without them.

5. Who else is involved

Slate relies on three service providers, and no others:

Slate does not share your data with anyone else. Slate does not sell your data, does not rent it, does not trade it, and does not use it to build advertising profiles. There is no data broker in this list, and there will not be one.

6. Apple Health data: specific commitments

Health data deserves stricter promises than everything else, and Apple requires them. Slate commits that data read from Apple Health (HealthKit) is:

You can review or revoke Slate's access to any individual Health category at any time in the Health app, under Sharing → Apps. Revoking it does not delete anything; Slate simply stops being able to read that category and will tell you what it can no longer show.

7. Notifications

If you turn on tracking reminders, Slate schedules them locally on your device. No push notification tokens are registered, no notification server is involved, and no reminder content leaves your phone.

8. How long data is kept

Data stored on your device remains until you delete it, sign out, or remove the app. Signing out clears your logged data from the device. Deleting the app removes everything stored on it.

Data stored on Slate's servers is kept while your account exists. When you ask us to delete your account, your account record and every row associated with it — profile, goals, meals, hydration — are permanently deleted. Deletion is irreversible and we do not retain a shadow copy.

9. Your rights and how to use them

Whatever jurisdiction you are in, Slate will honour the following on request:

To exercise any of these, email slate.service.app@gmail.com from the address on your account. We will respond within 30 days.

If you are in the UK or EU, our lawful basis for processing is your consent (for health data) and the performance of our contract with you (for account data and the features you request). You have the right to complain to your local data protection authority.

10. Children

Slate is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

11. Security

Traffic between the app and our servers is encrypted in transit (TLS). Passwords are hashed, never stored in readable form. Database access is constrained by row-level security tied to your authenticated account. New passwords are checked against known public breach corpora so an already-compromised password cannot be set.

No system is perfectly secure. If we ever discover a breach affecting your data, we will tell you and the relevant authorities promptly rather than quietly.

12. Changes to this policy

If this policy changes in a way that materially affects how your data is handled, we will update the effective date at the top and notify you in the app before the change takes effect. We will not quietly broaden what we collect.

13. Contact

slate.service.app@gmail.com