Privacy Policy
Last updated August 25, 2026
Slotted plans, generates and publishes marketing content on your behalf. Doing that means storing what you tell us about your business and sending it to AI providers for processing. This page sets out exactly what we collect, who receives it, and what you can and cannot currently do about it.
1. Who we are
Slotted is a marketing-calendar platform operated by Temerarii Media LLC (“Slotted”, “we”, “us”). This policy covers the Slotted web application at slotslot.xyz and its API. For anything in this policy, contact us at privacy@slotslot.xyz.
2. What we collect
Account information
Your email address, used to sign you in. Slotted signs you in with one-time codes rather than passwords, so we never store a password for your account. We record sign-in events.
Business and brand information you enter
Onboarding asks about your business so the system can generate a calendar for it: company name, website, industry, business description and model, value propositions, products and pricing, competitors, buyer personas, marketing-channel preferences, brand colours, typography and keywords, mission statement, content pillars, brand personality, voice guidance (words to use and avoid), and key dates. You choose what to enter.
Reference material you upload (“Sources”)
You may upload documents and media for the system to draw on — PDF, DOC, DOCX, TXT and Markdown up to 50MB; images up to 10MB; audio up to 100MB; video up to 200MB; or a URL for us to fetch. We extract the text, split it into passages, and compute numerical embeddings so the system can retrieve relevant passages when writing. Those embeddings are computed on our own servers by a model that runs in-process — no third party is involved in that step. The extracted text is stored alongside the original file, and is sent to AI providers as described in section 4.
Please do not upload material you lack the rights to use, and avoid uploading personal information about other people — we have no way to isolate it from the content sent to AI providers for processing.
Connected accounts
When you connect a platform, we store the credentials it issues to us — an OAuth access token and refresh token, or an API key — together with the account identifier and display name, so we can act on your behalf. Section 5 sets out what each permission is for.
Content and activity
The calendars, campaigns, drafts and scheduled posts you and the system create; the edits you make and when; and publishing attempts with their outcomes, including what was sent and what the platform returned.
Your own AI provider keys, if you supply them
Some features let you bring your own key for an external model, voice or avatar provider. Those keys are stored against your workspace and used only to make the calls you ask for.
Payment information
Payments are processed by Stripe. We receive your subscription status and plan. We never receive or store your card number.
Technical data
Server logs, and an audit log of security-relevant actions that records your IP address and browser user-agent alongside the action. Your IP address is also used, briefly, as a rate-limiting counter key. If you enable browser notifications we store the push subscription your browser issues.
4. How we use it, and the AI processing involved
We use your information to operate the service: to generate your calendar and content, to publish to the platforms you have connected, to bill you, to send you email, and to diagnose faults.
Generating content necessarily means sending your brand information, your uploaded reference material and your drafts to third-party AI providers for processing. This is core to how Slotted works and cannot be switched off while still using the product. Those providers process the content to return a result. We do not authorise them to use it to train their models, but you should not put anything into Slotted that you would not want processed by an external service.
We do not sell your personal information and we do not share it for advertising.
5. Connected platforms and what each permission is for
You choose which platforms to connect. We request the narrowest set of permissions that makes the feature work, and we ask for a write permission only where you have asked us to publish. Content reaches a platform only at your direction.
- Instagram — read your profile and media, and the Pages you manage, so we can show you the right account and give the AI context; publish the posts you schedule; read insights so we can report performance; read comments so we can surface engagement.
- Facebook — list the Pages you manage and read their engagement and content for context and reporting; create posts on the Pages you select.
- LinkedIn — identify you (OpenID and basic profile); post as you; read and post on the company pages you administer.
- TikTok — read your basic profile and stats to identify the account and report performance; upload and publish the videos you schedule; list your videos.
- X (Twitter) — read your profile and posts for context; publish the posts you schedule; keep a refresh token so scheduled posts still work when you are not present.
- Pinterest — read and create boards and pins for the content you schedule; read your account to identify it.
- Threads — read your basic profile, publish threads you schedule, and read insights and replies.
- YouTube — read your channel and analytics for reporting; upload the videos you schedule.
- Gmail — send only. We request permission to send mail and to read label names (used solely to confirm the connection works), plus your email address to identify the account. We deliberately do not request permission to read your mail or your drafts — nothing in the product reads the contents of your mailbox.
- Google Analytics and Search Console — read-only. We fetch reports so the AI can use your real performance data.
- WordPress, Webflow, Framer, Duda — read your site structure and existing content for context, and create or update the blog posts and images you publish through Slotted.
- Klaviyo, Mailchimp, Twilio, Attentive — read campaign, list and metric data for reporting, and create the campaigns and messages you ask us to.
- Zoom, GoToWebinar — read and create the events you schedule.
We do not read your private messages or your contacts on any of these platforms. You can disconnect at any time in Slotted, and you should also revoke Slotted’s access in the platform’s own settings.
6. Who else receives your information
We share information with providers that run the service on our behalf, and only as needed for their function. These receive data by default:
| Provider | What they do |
|---|---|
| Supabase | Database, sign-in, and file storage for everything you upload or create |
| Vercel | Application hosting — serves every page and API request |
| Anthropic | Primary AI text generation — calendars, campaigns, drafts, captions |
| OpenRouter | AI text generation routing for models not served directly by Anthropic |
| Hugging Face | Image generation, speech-to-text, and text-to-speech via the Inference API |
| Resend | Delivers your sign-in codes, service notices, and follow-up email |
| Upstash | Rate limiting and job coordination — stores your IP address briefly as a counter key |
| Sentry | Error monitoring and session replay (see section 8) |
| Stripe | Subscription billing — Stripe receives your card details directly, we never do |
These are contacted only when a key for them has been configured — by us for a specific feature, or by you when you bring your own key. If no key is configured, the feature degrades and no data reaches the provider:
| Provider | What they do |
|---|---|
| OpenAI | Alternative text model, image generation, and video caption transcription |
| Google (Gemini) | Alternative text model and image generation for blog automation |
| Perplexity | Live web research during onboarding — brand keywords, mission, channel benchmarks |
| Tavily | Web search during competitor and market research |
| Firecrawl | Fetches and extracts the text of a web page you ask us to read |
| DeepSeek | Alternative text model |
| AssemblyAI, Deepgram | Speech-to-text for audio and video you upload |
| ElevenLabs, HeyGen | Voice and avatar media, using a key you supply — we list the voices and avatars you already created there |
| fal.ai, Replicate, PiAPI, Kie, WaveSpeed, Ideogram, Stability, Leonardo, Recraft | Image and video generation models, selected by you and billed to your own key |
| Cloudinary, CloudConvert, Rendi | Media hosting, format conversion, and video rendering |
| Apify, Jina | Scraping and page-text extraction for research |
| Blotato | Third-party publishing relay for social platforms |
| Instantly | Outbound email sequencing, when you connect it |
| Twilio, Attentive | SMS messaging, when you connect it |
| Retell AI | Voice-agent calling, when you connect it with your own key |
| Cloudflare R2 | Object storage for generated media, once configured |
| Neo4j | Knowledge-graph store for uploaded reference material; falls back to in-memory when unconfigured |
We may also disclose information if required by law, or in connection with a merger or acquisition, in which case we will notify you.
7. Voice and avatar features
Slotted can use an AI voice or avatar in generated video. It does not record your face or your voice, and it does not create a clone from anything you give us. Instead, you supply your own HeyGen or ElevenLabs API key, and we list the avatars and voices that already exist in your account there so you can select one. The underlying likeness and voice data stays with that provider under your agreement with them.
8. Security, session replay, and current limitations
Data is transmitted over TLS and stored on infrastructure that encrypts data at rest. Access to your records is restricted at the database level so that one account cannot read another’s.
Session replay. Our error-monitoring provider, Sentry, records replays of user sessions — a sample of ordinary sessions and every session in which an error occurs — so we can see what led to a fault. Replay is configured to mask all text and block all media, so what is captured is the shape of the interaction rather than its contents. It is still a recording of your use of the app, and we would rather you knew that than discovered it.
Token storage. We want to be specific rather than reassuring: for most connected platforms the access tokens we hold are stored in our database without an additional application-layer encryption step, relying on the storage provider’s encryption at rest and on database access controls. Only the Facebook and X integrations currently encrypt their tokens at the application layer. We are moving the rest across. If this matters to your risk assessment, connect fewer accounts, or wait until this section says otherwise.
No system is perfectly secure. If you believe your account has been compromised, or you have found a vulnerability, contact privacy@slotslot.xyz.
9. How long we keep it
- Account, calendar, brand and source data is kept while your account is active, and is deleted when your account is deleted.
- Anonymous trial calendars created before sign-up are deleted after 30 days by a daily job.
- If you gave us your email during an anonymous trial and did not sign up, that email — with your company name and industry — is kept after the trial calendar is deleted, and is used to send you a short follow-up sequence. See section 10 for how to stop it.
- Calendar items you delete are first marked deleted and hidden from every view, then removed with the rest of your data on account deletion.
- Credentials for a platform are deleted when you disconnect it. You should also revoke Slotted’s access in that platform’s own settings.
- Billing records are retained as long as tax and accounting law requires.
10. Your choices and rights
You can view and edit the information you entered at any time in the app, and you can disconnect any platform at any time.
Deleting your account. We want to be straight with you about this: the deletion itself is implemented and thorough — it removes your calendars and entries, onboarding responses, connected-account credentials (attempting to revoke them at the provider first), uploaded sources and their extracted text, stored AI memory, publishing history, workspaces and your sign-in record. But there is not yet a button for it in the app. To delete your account today, email privacy@slotslot.xyz and we will run the deletion and confirm when it is done. We are adding a self-serve control; until this paragraph changes, please assume the email route is the only one.
Stopping follow-up email. Every follow-up email carries a one-click unsubscribe link, and we honour it immediately — the link works without signing in, and the suppression is permanent: it survives even if the original record is deleted, so starting a new trial will not resume the sequence. You can also email privacy@slotslot.xyz and we will remove you and delete the record.
Depending on where you live you may have additional rights — to access a copy of your data, to correct it, to have it deleted, to object to or restrict certain processing, and to lodge a complaint with your data-protection authority. Email privacy@slotslot.xyz and we will respond within 30 days. We will not discriminate against you for exercising these rights.
11. International transfers
We are based in the United States and our providers operate there and elsewhere. If you use Slotted from outside the United States, your information will be transferred to and processed in the United States, where privacy law differs from your own.
12. Children
Slotted is a business tool and is not directed to anyone under 18. We do not knowingly collect information from children. If you believe a child has provided us information, contact privacy@slotslot.xyz and we will delete it.
13. Changes
We will update this policy as the product changes, and will revise the date at the top of the page. For material changes affecting how we use information you have already given us, we will notify you by email before the change takes effect.
Contact
Questions about this policy, deletion requests, and data-rights requests all go to privacy@slotslot.xyz.
For counsel — complete before publication
- Legal entity
- Temerarii Media LLC
- Registered address
- [LEGAL ENTITY REGISTERED ADDRESS]
- Governing law
- State of Delaware, United States
- Privacy contact
- privacy@slotslot.xyz
- Support contact
- support@slotslot.xyz
Our Terms of Service govern your use of the service.