SlimeLog

Privacy Policy

Last updated: August 5, 2026

This policy covers the SlimeLog website at slimelog.com and the SlimeLog app for iPhone. Both are the same product: the iPhone app loads slimelog.com inside a native shell, so everything described here applies whether you are signed in on the web or on your phone.

SlimeLog is an independent project operated from Connecticut in the United States. You can reach us any time at support@slimelog.com. For privacy questions, put PRIVACY in the subject line and we will route it accordingly.

What We Collect

The categories below are the same ones listed on the SlimeLog App Store product page. Nothing is collected that is not on this list.

Email address

Your sign-in email, and the email you give us if you join the waitlist without creating an account. If you sign in with Apple using Hide My Email, we only ever see the private relay address Apple gives us.

Photos or videos

Photos you attach to a slime log, and your profile photo. On iPhone we ask for camera and photo library access only at the moment you tap to add a photo. We do not scan or index your photo library, and we only receive the specific images you pick.

Other user content

Everything you write and record in the app: slime names, your six ratings per slime, notes, collection names, comments, brand suggestions, brand claims, reviews, reports you file, and your profile bio and username. Some of this is public by design. Your shelf, your logs, and your ratings are visible to other users unless you mark them private.

User ID

Your SlimeLog account ID, and the account identifier your sign-in provider gives us when you use Sign in with Apple or Google. We attach your user ID to analytics and crash reports so we can tell one person's session apart from another and answer support requests.

Device ID

A per-install identifier used by our analytics and crash tools, plus your push notification token if you turn notifications on. The push token is a routing address for your specific install. It is stored so we can send you the notifications you asked for, and it is deleted with your account. This is not an advertising identifier. SlimeLog does not request the iOS advertising identifier and does not ask for App Tracking Transparency permission, because we do not track you across other companies' apps or websites.

Purchase history

Whether you have a SlimeLog Pro or Brand Verification subscription, when it started, when it renews, and whether it is active. On iPhone this comes from your App Store transaction receipt. On the web it comes from Stripe. We never see or store your card number.

Product interaction

Which screens you open, which features you use, and how you move through flows like logging a slime or completing onboarding. We use this to find the parts of the app that are confusing or broken.

Crash data

When something crashes or throws an error, we receive a stack trace and basic device and browser information. When an error fires, our crash tool also records a replay of that session so we can see what led up to it. Text on screen is masked and images and video are blocked in those replays by default, but we are telling you about it because it is a recording of your session either way. Crash data is not linked to your identity on the App Store label, but a crash report can carry your user ID if you were signed in.

Performance data

Page load timings, slow requests, and error rates, sampled rather than captured on every visit.

Date of birth

We ask for your date of birth once, at sign-up, to confirm you are 13 or older. We store the date so we do not have to ask again and so we can enforce the age limit. It is not used for advertising, segmentation, or anything else, and it is never shown on your public profile.

How We Use It

  • To run your account and the app: signing you in, saving your logs and photos, showing your shelf, powering follows, comments, and notifications.
  • To operate the community features: leaderboards, the brand catalog, the guide, and the discover feed all read from content users have chosen to publish.
  • To keep the app safe: running user-authored text through moderation, handling reports, and acting on abuse.
  • To fix problems: crash reports, performance data, and error session replays.
  • To understand what to build next: aggregate product analytics.
  • To manage subscriptions: unlocking Pro features and handling billing state.
  • To send you email you asked for: account email like password resets and verification, plus marketing email only if you explicitly opted in. Every marketing email has an unsubscribe link.

What We Do Not Do

  • We do not sell your personal information. We never have.
  • We do not share your personal information for cross-context behavioral advertising.
  • We do not track you across other companies' apps or websites. There is no advertising SDK in the SlimeLog app.
  • We do not sell or license your photos or your logs.
  • We do not buy contact lists or add anyone to marketing email who did not opt in.

Companies That Process Your Data

SlimeLog is a small project, so we rely on established vendors rather than running our own infrastructure. Each one below receives only what it needs for its job, and each is bound by its own agreement with us to use that data only to provide the service.

SupabasePrivacy policy

Our database, authentication, and photo storage. This is where your account and everything you log actually lives.

Receives: Email address, user ID, date of birth, profile information, slime logs, ratings, notes, comments, photos, notifications, and all other user content.
Processed in: United States

VercelPrivacy policy

Hosting. Every request to slimelog.com passes through Vercel, including requests from inside the iPhone app.

Receives: IP address, request URLs, and standard server log data.
Processed in: United States

ApplePrivacy policy

Sign in with Apple, in-app purchases, and push notification delivery for the iPhone app.

Receives: Your Apple account identifier, your email or Apple private relay address if you choose to share it, in-app purchase transactions, and your push token for delivery.
Processed in: Handled under Apple's own privacy policy

GooglePrivacy policy

Sign in with Google, if you choose that sign-in method.

Receives: Your Google account identifier, email address, and name if you share it.
Processed in: Handled under Google's own privacy policy

RevenueCatPrivacy policy

Manages your subscription entitlement on iPhone, so the app knows whether Pro is active.

Receives: Your SlimeLog user ID, App Store transaction receipts, purchase history, and a device identifier.
Processed in: United States

StripePrivacy policy

Billing for subscriptions bought on the web. Stripe handles card data end to end under PCI compliance, so SlimeLog never sees or stores your card number.

Receives: Payment details you enter on Stripe's form, your email address, and your subscription state.
Processed in: United States and European Union

SentryPrivacy policy

Crash and performance monitoring, including the error session replays described above.

Receives: Crash stack traces, performance metrics, device and browser information, your user ID when you are signed in, and a device identifier.
Processed in: United States

PostHogPrivacy policy

Product analytics. Tells us which features get used and where people get stuck.

Receives: Page views, feature interaction events, a device identifier, and, once you sign in, your user ID, email address, username, and subscription tier.
Processed in: United States

BrevoPrivacy policy

Waitlist and marketing email.

Receives: Your email address, first name if you gave one, your marketing opt-in state, and how you heard about SlimeLog.
Processed in: European Union

ResendPrivacy policy

Transactional email for brand claim verification and moderation alerts.

Receives: The recipient email address and the contents of that specific message.
Processed in: United States

If we add a processor, this list gets updated before the change ships.

How Long We Keep It

  • Your account and everything in it is kept until you delete your account. There is no inactivity purge.
  • Deleted content is removed from the live app immediately and drops out of encrypted infrastructure backups within 30 days.
  • Product analytics is retained for 12 months, then aged out.
  • Crash reports and session replaysfollow our crash tool's standard retention, which is 90 days or less.
  • Billing records are kept as long as tax and accounting law requires, which is generally seven years. This is transaction data, not card numbers.
  • Moderation reports are kept after they are resolved so repeat abuse can be recognized.
  • Waitlist entries from people who never created an account are kept until you unsubscribe or ask us to remove you. Deleting a SlimeLog account does not automatically clear a waitlist entry, so email us if you signed up for both.

Your Controls

  • Get a copy of your data. Settings has a download link that exports everything tied to your account as a JSON file.
  • Fix something wrong. Your profile, username, email, and every log you have written are editable in the app.
  • Delete your account. Settings has a Delete Account option. If you signed up with an email and password, you confirm with your password. If you signed in with Apple or Google, you confirm by typing DELETE, because those accounts do not have a SlimeLog password. Either way it permanently removes your logs, your uploaded photos, your ratings, comments, profile, and push token. This is not reversible and we cannot restore an account after deletion.
  • Turn off notifications. Notification preferences are in Settings, and iPhone notifications can also be turned off in the iOS Settings app.
  • Stop marketing email. Use the unsubscribe link in any marketing email, or the toggle in Settings.
  • Ask us directly. Anything you cannot do in the app, email support@slimelog.com and we will handle it.

Your California Privacy Rights

If you live in California, the California Consumer Privacy Act as amended by the CPRA gives you the following rights. We honor them for everyone, not just California residents.

  • The right to know what personal information we collect, why we collect it, and who we share it with. That is the What We Collect and Companies That Process Your Data sections above.
  • The right to know whether it is sold or shared. SlimeLog does not sell your personal information and does not share it for cross-context behavioral advertising, as those terms are defined by the CCPA. We have not done so in the preceding 12 months.
  • The right to opt out of sale or sharing. Because we do not sell or share your personal information, there is nothing to opt out of. If that ever changes, we will add a Do Not Sell or Share My Personal Information link before the change takes effect.
  • The right to access the specific pieces of personal information we hold about you. Use the data export in Settings, or email us.
  • The right to delete your personal information. Use Delete Account in Settings, or email us.
  • The right to correct inaccurate personal information.
  • The right to limit use of sensitive personal information. We do not use sensitive personal information for any purpose beyond running the app.
  • The right to equal service and price. We will never deny you service, charge you a different price, or give you a worse experience because you exercised a privacy right.

To make a request, email support@slimelog.com. We will verify that the request came from you, usually by asking you to send it from the address on the account, and respond within 45 days. An authorized agent may act for you with written permission.

European Union and United Kingdom Users (GDPR)

If you are in the EU, the EEA, Switzerland, or the UK, SlimeLog is the data controller for the information described in this policy.

Legal basis for processing

  • Performance of a contract. Running your account, storing your logs and photos, delivering the community features, and managing your subscription. Without this we cannot provide the app.
  • Legitimate interests. Product analytics, crash and performance monitoring, moderation, and fraud and abuse prevention. Our interest is keeping the app working and safe, balanced against your interest in not being over-monitored, which is why analytics is aggregate and replays only fire on errors.
  • Consent. Marketing email, camera and photo library access, and push notifications. You can withdraw consent at any time without affecting processing that already happened.
  • Legal obligation. Keeping billing and tax records.

Your rights

You have the right to access your data, to have inaccurate data corrected, to have your data erased, to restrict processing, to data portability in a machine-readable format, to object to processing based on legitimate interests, and to withdraw consent. The export and delete tools in Settings cover access, portability, and erasure directly. For anything else, email support@slimelog.com and we will respond within one month.

International transfers

SlimeLog is operated from the United States and most of our processors are based there, so your data is transferred to and stored in the United States. Where a transfer out of the EEA or UK is involved, it relies on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which are part of our agreements with those processors. You can ask us for more detail about a specific transfer.

Data protection officer

SlimeLog is not required to appoint a Data Protection Officer under Article 37. We are not a public authority, our core activity is not large-scale systematic monitoring, and we do not process special category data at scale. Privacy questions go to support@slimelog.com.

Complaints

If you think we have handled your data badly, please tell us first so we can fix it. You also have the right to complain to your local supervisory authority, which for UK users is the Information Commissioner's Office, without contacting us at all.

Children's Privacy

SlimeLog is rated 13+ and you must be 13 or older to create an account. We ask for your date of birth at sign-up and block accounts that do not meet the age limit.

We do not knowingly collect personal information from children under 13. If we learn that an account belongs to someone under 13, we delete it and the data attached to it. If you are a parent or guardian and believe your child under 13 has created a SlimeLog account, email support@slimelog.com with the username or email address and we will remove the account and confirm back to you. You do not need an account of your own to make that request.

The App Store Privacy Label

The SlimeLog product page in the App Store carries Apple's machine-readable privacy label, which summarizes the same data collection this policy describes. The categories declared there are email address, photos or videos, other user content, user ID, device ID, purchase history, product interaction, crash data, and performance data. Crash data and performance data are declared as not linked to your identity. The rest are linked, because SlimeLog is an account based app. Tracking is declared as No, and third-party advertising is declared as No.

The app also ships a privacy manifest inside the binary that declares the same set. If you ever find the label, the manifest, and this page disagreeing, this page is the one we maintain by hand, so tell us and we will reconcile all three.

Security

Traffic to SlimeLog is encrypted in transit. Database access is governed by row level security policies, so one account cannot read another account's private data even if a query goes wrong. Sensitive keys stay server side and are never shipped to your browser or your phone. No system is perfectly secure, and we are not going to claim otherwise. If you find a vulnerability, email support@slimelog.com and we will work with you on it.

Changes To This Policy

When this policy changes we update the date at the top. If a change is material, meaning it affects what we collect, why we collect it, or who we share it with, we will tell you by email or with an in-app notice before it takes effect. Past versions are available on request.

Contact

support@slimelog.com

Effective date: August 5, 2026

Read our Terms of Service