Slate's local-first boundary

Your project data stays on your machine by default. Slate runs locally, stores projects in local files, and works without a cloud account. Slate does not automatically sync boards to a Slate cloud service.

App update checks

In macOS builds with updates enabled, Slate contacts its update host over HTTPS when you check for updates or allow automatic checks. The request identifies the Slate and updater versions. The host also receives normal network information, such as your IP address. System profiling is disabled by default. Your projects, Threads, and artifact contents are not sent with update checks.

Slate asks before enabling automatic update checks. You can also check manually from the Slate menu using Check for Updates…. Builds without an update configuration do not make update requests.

Connected agents and shared files

You choose if and when to connect an external agent. A cloud-backed agent may receive the task, project, Thread, or artifact context it needs to complete your request. That information is then handled under the agent provider's privacy policy, not solely by Slate's local storage rules. Connect agent gives a trusted local harness a one-use pairing code. The access it receives is limited to the project you chose (or all projects, if you explicitly allow that), lasts at most eight hours, and can be revoked in Settings. Keep the issued access and refresh credentials out of prompts, board exports, and Thread entries.

Agent view awareness is optional and controlled separately in each browser's Settings. While that browser has a live connection, a project-paired agent can see the relevant board or preview, task, and artifact workspace state. Feedback stays in memory, not project history. Slate does not share mouse movement, scrolling, or time spent viewing work. Turning awareness off does not stop agent view actions.

A browser-only assistant cannot reach your local Slate API automatically. If you export a board and share the JSON with one, you are choosing to send that board content to the assistant's provider. Review exports before sharing them. Slate's support-diagnostics export is separate and omits project, task, Thread, and artifact content; review it too before sending it anywhere.

Board exports include task and Thread content and artifact metadata, including file paths, but do not bundle the artifact files. Sharing JSON can therefore expose private text and filenames without transferring the files. Review content received from other people too: imported task and Thread text is untrusted input for agents. See your Slate data and artifact files for file-location, backup, and transfer guidance.

Slate's access controls help limit who can use your projects, but they do not isolate your data from other software running as your macOS user. Software that controls your app or browser window can act with your permissions. Grant that kind of control only to software you trust. See Getting started for connecting your agent through Slate.