Slingshot Build — Privacy Policy
Last updated: June 22, 2026 Effective date: July 7, 2026
This Privacy Policy explains how Slingshot Labs LLC ("Slingshot," "we," "us," "our"), a Michigan limited liability company, collects, uses, shares, and protects personal information in connection with Slingshot Build and the website at slingshot.build (the "Service"). It is part of and incorporated into our Terms of Service.
By using the Service, you agree to this Policy. If you don't agree, don't use the Service.
Plain-language summary (not a substitute for the full Policy): We collect the minimum we need to run Slingshot — your GitHub identity and email, an encrypted token to access the repositories you connect, basic project and edit records, and (if you publish a paid site) billing details handled by Stripe. We use trusted providers (GitHub, Cloudflare, Stripe, Supabase) to operate the Service. We don't sell your personal information. Your code, content, and images stay in your own GitHub repository — we don't claim them. You have rights to access and delete your data.
1. Scope
This Policy covers personal information we process about:
- Users — people who create an account, connect a repository, or use the editor, deploy, and publishing features; and
- Visitors to slingshot.build — people who browse our marketing pages, the
/specpage, or submit an abuse report or early-access form.
It does not cover: information handled by third-party services governed by their own policies (your AI provider, your domain registrar, GitHub, and any analytics or embed you inject into your own site); or the personal information that your published websites collect from their visitors (see §2).
2. Two different roles: your data vs. your visitors' data
It's important to separate two things:
- When we handle data about you (a Slingshot user), Slingshot is the controller. This Policy applies.
- When your published website collects data from its own visitors, you are the controller of that data, not Slingshot. Slingshot routes traffic to your site through our deployment infrastructure, but the analytics, pixels, forms, and embeds on your site are your own injected snippets running under your own third-party accounts — we don't operate them, and we don't receive that data on your behalf. You are responsible for your site's own privacy notice, cookie consent, and compliance with applicable law (see the Acceptable Use Policy §4).
3. Information we collect
Information you provide or authorize:
- Account & identity (via GitHub OAuth): your GitHub username, account ID, email address, and avatar, as provided by GitHub when you sign in.
- GitHub access authorization: a GitHub access token that lets us read and write the repositories you connect. We store this token encrypted (AES-256-GCM) in an access-restricted database table; it is not readable by your browser or other users.
- Project & repository metadata: the repositories and branches you connect, project names, site slugs, custom domains, and related configuration.
- Content we process on your behalf: the contents of repositories you connect, the edits you make, and the build artifacts produced for deployment — processed only to provide the Service and at your direction. Your source of truth remains your GitHub repository.
- Billing information (paid plans): payments are processed by Stripe. We receive limited billing metadata (such as subscription status, the last four digits and brand of your card, and billing country) but we do not collect or store full payment card numbers — Stripe does, under its own terms and PCI compliance.
- Support, abuse reports, and forms: information you submit when you contact support, file an abuse report (URL, reason, your email), or sign up for early access (email and source).
Information we collect automatically:
- Usage & log data: IP address, browser/device and user-agent information, pages and features used, timestamps, and similar diagnostic data, including data used to rate-limit and prevent abuse.
- Cookies & similar technologies: essential cookies needed for authentication and session management (via Supabase) and for the Service to function. See §6.
- Deployment records: non-sensitive records of deployments and their status (per-project deploy tokens are stored only as a one-way hash).
We do not intentionally collect special categories of sensitive personal information, and you should not submit them through the Service.
4. How we use information
We use personal information to:
- Provide and operate the Service — authenticate you, connect repositories, run the editor, orchestrate builds and deployments, and serve preview and published sites;
- Process payments and manage subscriptions (through Stripe);
- Maintain security and prevent abuse — detect, investigate, and stop fraud, abuse, AUP violations, and threats to the Service or others, including rate-limiting and enforcement;
- Communicate with you — send service, transaction, security, and support messages, and (where permitted) product updates you can opt out of;
- Improve the Service — understand usage and fix problems; and
- Comply with law — meet legal obligations and respond to lawful requests.
5. Legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies, we process personal information on these bases: performance of a contract (to provide the Service you request), legitimate interests (to secure, maintain, and improve the Service and prevent abuse, balanced against your rights), consent (where required, e.g., certain communications — you may withdraw it), and legal obligation (to comply with law).
6. Cookies and similar technologies
The Slingshot Build application uses essential cookies for authentication and session management. We do not use the slingshot.build application to run third-party advertising or cross-site tracking cookies. Any analytics, pixels, or cookies present on your published site come from snippets you injected under your own accounts and are your responsibility, not ours. Where required by law, we will provide a cookie notice and any necessary controls for our own site.
7. How we share information
We share personal information only as described here. We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are defined under California law).
- Service providers / sub-processors who help us run the Service, under contracts limiting their use of the data, including (currently):
- GitHub — authentication and repository access/build runners;
- Cloudflare — deployment, routing, custom hostnames, and TLS;
- Stripe — payment processing;
- Supabase — authentication and database;
- Railway — running the deploy relay.
- Legal and safety — when we believe in good faith it's required by law or legal process, or necessary to protect the rights, property, or safety of Slingshot, our users, or the public (including responding to abuse reports and cooperating with law enforcement).
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
- With your direction or consent — for example, the third-party services you connect or inject.
A current list of sub-processors will be maintained here or on a linked page; we'll update it as providers change.
8. Data retention
We keep personal information for as long as your account is active and as needed to provide the Service, then for a commercially reasonable period afterward to comply with legal obligations, resolve disputes, prevent abuse, and enforce our agreements. When you delete your account, we delete or de-identify your personal information within a reasonable time, except where retention is required by law. Your code and content remain in your own GitHub repository regardless of what we retain or delete.
9. Security
We use technical and organizational measures designed to protect personal information, including encryption of your GitHub access token at rest (AES-256-GCM), one-way hashing of per-project deploy tokens, encryption in transit (TLS), and access controls that restrict sensitive data to service-role access. No method of transmission or storage is 100% secure, and we can't guarantee absolute security. You're responsible for safeguarding your GitHub credentials and the access you grant.
10. Your privacy rights
Depending on where you live, you may have some or all of the following rights regarding your personal information:
- Access / know — request a copy of the personal information we hold about you and how we use it;
- Correct — ask us to fix inaccurate information;
- Delete — ask us to delete your personal information;
- Portability — request a copy in a portable format;
- Object / restrict — object to or restrict certain processing (EEA/UK);
- Withdraw consent — where processing is based on consent;
- Opt out of sale/sharing — we don't sell or share personal information for cross-context behavioral advertising, so there's nothing to opt out of; and
- Non-discrimination — we won't discriminate against you for exercising these rights.
To exercise a right, email privacy@slingshot.build. We'll verify your request (typically via your account email) and respond within the time required by law. You may use an authorized agent where the law allows. If we deny a request, you may appeal by replying to our decision. EEA/UK users may also lodge a complaint with their data protection authority; California users may have an additional right to appeal.
California (CCPA/CPRA): In the past 12 months we have collected the categories described in §3 (identifiers, commercial information, internet/usage activity, and customer records). We disclose information to sub-processors as described in §7 for business purposes. We do not sell or share personal information. You have the rights listed above.
11. International data transfers
We are based in the United States and process information in the U.S. and wherever our sub-processors operate. If you access the Service from outside the U.S., you understand your information will be transferred to and processed in the U.S. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for transfers of EEA/UK personal information.
12. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you are under 18 (or the age of majority where you live), you may use the Service only with a parent's or guardian's consent and involvement, consistent with the Terms of Service §2. If you believe a child under 13 has provided us personal information, contact us at privacy@slingshot.build and we will delete it.
13. Third-party services and links
The Service interoperates with and may link to third-party services — your AI provider, GitHub, your domain registrar, and any analytics or embeds you inject. Those services have their own privacy policies, and this Policy does not apply to them. We encourage you to review them.
14. Changes to this Policy
We may update this Policy from time to time. We'll post the updated Policy with a new "Last updated" date and, for material changes, provide additional notice where required. Your continued use of the Service after changes take effect means you accept the updated Policy.
15. Contact us
Questions or privacy requests:
Slingshot Labs LLC Privacy: privacy@slingshot.build · General: hello@slingshot.build · Support: support@slingshot.build Mailing address: [MAILING ADDRESS PENDING]
Slingshot Build is a product of Slingshot Labs LLC. This document is a draft pending review by licensed counsel.