Who we are
Slatebook (“we”, “us”, “our”) operates the slatebook.in website and related services. We are based in India and the service is governed primarily by Indian law, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”).
The data fiduciary for the purposes of the DPDP Act is Slatebook. You can contact us about anything in this policy at support@slatebook.in.
What we collect
We only collect data we need to run the service. Categories, with the source of each:
- Account data — your name and email address. Provided by you at signup (email + password) or returned by Google when you sign in with Google. When you use Google sign-in we receive your email, profile name, and a unique Google user ID.
- Profile data — work experience, education, skills, projects, accomplishments, certifications, location, headline, summary, and (if you upload one) a profile picture. You provide this directly or by uploading a resume PDF that our AI parses into structured fields.
- Job preferences— target roles, locations, work-style preferences, target company stages and industries, salary expectations, “open to opportunities” status.
- Job interaction data — which jobs you save, apply to, or dismiss. We use this to improve your recommendations and to score future matches.
- Application data — when you apply through Slatebook to a role posted directly by an employer, we store the application content and share it with that employer (and only that employer).
- Messaging — direct messages, connection requests, vouches, and recruiter conversations on the platform. Stored encrypted at rest.
- Recruiter data — when you act as a verified recruiter, the employer you claim, your role on that team, your colleagues you invite, the jobs you post, and the candidates you unlock.
- Technical data — authentication session cookies, last-login timestamp, IP address (for rate-limiting and abuse investigation only), and minimal server logs (kept up to 30 days).
How we use AI
Slatebook is built around AI features. Here’s what data goes to which AI service and why:
- Candidate embeddings.A multi-facet representation of your profile (current role + recent work history + intent / preferences) is sent to Google’s Gemini Embedding API to produce a vector. We store the vector to power matching. The raw text is processed by Gemini in transit and not retained by Google for model training.
- Job embeddings. The same Gemini Embedding API turns each job description into a vector that lets us compare jobs to candidates.
- Job Insights (Pro).When a Pro user requests insights, we send their profile + the job description to Google’s Gemini Flash Lite API. The model returns a structured analysis we store on your row and show only to you.
- Tailored Resume (Pro). Same flow as Job Insights — profile + job + the prior insight result are sent to Gemini Flash Lite. The output is a per-role bullet rewrite stored on your row and shown only to you.
- Resume PDF import. When you upload a resume PDF on the Import page, the PDF is sent to Gemini Flash Lite for one-shot structured extraction into your profile fields. The PDF itself is not permanently stored after parsing.
- Resume bullet generation. Work-experience descriptions you save are sent to Gemini Flash Lite to generate resume-ready one-line bullets you can edit.
- Job description enrichment.Job listings we ingest from public feeds are sent to Groq’s openai/gpt-oss-20b API for structured-data extraction (years-of-experience parsing, must-have/nice-to-have classification). No candidate data is involved.
AI outputs can occasionally be wrong. You remain in control of any AI-generated text on your profile, resume, or messages and can edit or delete it at any time. We do not use your data to train any third-party model.
How we use your data
Your data exists to do four jobs:
- Match you with relevant roles. Your profile, preferences, embeddings, and dismissal history feed the recommendation engine that scores every active job against you. We use a hybrid of structured rules (skill overlap, experience range, country fit) and semantic similarity (Gemini embeddings) — see Section 3.
- Power Pro AI features. Job Insights and Tailored Resume use your profile + the target job to produce personalised analysis and resume edits.
- Operate the platform’s social features. Connections, vouches, messages, recruiter conversations, and the public profile / Slate you choose to publish.
- Run the service. Authentication, account recovery, transactional email (e.g. connection requests, application receipts), abuse prevention, and billing if you upgrade to Pro.
Third-party services we use
We use a small set of third-party services (“subprocessors”) to run the platform. Each is bound by their own DPA / privacy commitments. None retain your data for their own purposes, and none of them advertises to you. This list is current as of June 22, 2026 — if it changes materially we’ll update this page and notify active users.
Supabase
Their privacy policy →Postgres database + authentication + file storage
- Region
- AWS Mumbai (ap-south-1)
- Data shared
- All structured user data (profile, work history, skills, messages, applications, embeddings, AI-generated insights). Auth handles email + password / OAuth tokens.
Vercel
Their privacy policy →Hosting + edge functions + CDN
- Region
- Global (predominantly serverless)
- Data shared
- Request metadata (IP, user-agent, URL path) needed to route requests. Page content. Vercel sees the data passing through but does not have access to the database.
Google (Gemini API)
Their privacy policy →AI inference — embeddings, Job Insights, Tailored Resume, resume parsing, resume bullets
- Region
- Google Cloud (global)
- Data shared
- Candidate profile snippets, job descriptions, prior AI outputs — sent at the time of each request. Google does not retain prompts or outputs for model training. See Gemini API privacy commitments.
Google (Workspace + OAuth)
Their privacy policy →Sign in with Google + Gmail outbound email (transactional notifications from Slatebook to you)
- Region
- Google Cloud (global)
- Data shared
- Email address + name from your Google account when you use Google sign-in. The Gmail-send scope is used to send Slatebook-branded transactional emails from our domain. We never read your inbox.
AI inference — fast structured extraction from job descriptions (no candidate data involved)
- Region
- US data centers
- Data shared
- Public job descriptions ingested from feeds. No candidate or recruiter data is sent to Groq.
Razorpay / Stripe (future)
Their privacy policy →Payment processing for Pro subscriptions and recruiter credits
- Region
- India / Global
- Data shared
- Payment card data flows directly to the processor — Slatebook never sees or stores card details. We receive only the transaction reference + status.
We will add additional subprocessors only when needed and with prior notice via this page.
International data transfers
Your data is stored in India (Supabase ap-south-1, AWS Mumbai). Some processing — AI inference via Gemini and Groq, hosting via Vercel, payments via Razorpay/Stripe — involves transfer to servers outside India. These transfers happen via secure TLS connections and are governed by the subprocessors’ own data-protection commitments.
Under the DPDP Act, cross-border transfer to countries not blacklisted by the Indian government is permitted. At present no countries we transfer to are blacklisted; we will revisit this page if that changes.
What’s public vs. private
By default, your profile is private. The exceptions, all opt-in by you:
- Your public profile at
slatebook.in/u/<your-username>— only accessible after you choose a username. - Your Slate at
slatebook.in/u/<your-username>/slate— same gating. - Slatebook connections you accept can see your full profile within the platform.
- Recruiters you accept an Unlock request from get your full identity revealed (until accept, they see an anonymised summary only).
Even on the public surfaces, we never display compensation expectations, dealbreakers, or private preferences.
Your rights
You have the following rights over your data. The DPDP Act entitles you to most of these as a matter of law; the others are commitments we make on top.
- Access and correction. Edit any field on your profile in real time from /profile.
- Data portability. Download all your data as a JSON file from Settings.
- Erasure. Delete your account and everything associated with it from Settings. Immediate and irreversible, with minor exceptions for abuse logs.
- Withdraw consent. Opt out of email digests (all opt-in by default) and disable the AI Pro features at any time.
- Hide from recruiters.Set your status to “Not looking right now” in Job Preferences and recruiters no longer see you in anonymised search.
- Lodge a grievance. Write to support@slatebook.in with any concern. We aim to respond within 7 days. If you’re not satisfied, you may escalate to the Data Protection Board of India.
Retention
We retain your data while your account exists. On deletion:
- Profile, preferences, applications, messages, embeddings, and AI-generated insights are removed immediately from our primary database.
- Anonymised abuse-investigation logs and a hashed fingerprint of your account (to prevent re-creation by a banned actor) may be kept for up to 90 days.
- Backups are retained for up to 30 days then overwritten; your data will not be restored from those backups except in a disaster-recovery scenario.
Security
All traffic to slatebook.in is encrypted in transit via TLS 1.2+ and HSTS. Database access is restricted via row-level security on every table so users can read only their own data. Service-role credentials are server-side only. We don’t store payment card data — that flows directly to the regulated payment processor.
Full security posture, encryption details, and our responsible-disclosure programme are on the Security page.
Children
Slatebook is for working professionals and is not directed at users under 18 years old. We don’t knowingly collect data from children. If you believe a child has registered, please write to us at support@slatebook.in and we’ll delete the account.
Changes to this policy
If we make substantive changes (a new subprocessor, a new data category, a change in retention, etc.) we’ll update the “Last updated” date above and notify active users by email at least seven days before the change takes effect.
Contact
Questions, concerns, or data-rights requests:
support@slatebook.inWe aim to respond within 7 days. For security vulnerabilities, please use support@slatebook.in — see the Security page.