SlipNote

Privacy

Last updated July 2, 2026

SlipNote is built to need as little of your data as possible. There are no accounts, no profile fields, and no third-party trackers.

What we store

  • The files you upload and their original filenames, kept on our server until someone deletes them.
  • The workspace name you typed and the slug derived from it.
  • The course code and title the owner created.
  • An uploader name if you typed one (optional, free text).
  • A content fingerprint (SHA-256 hash) of each file, used to skip duplicate uploads and to stop files the operator removed from being re-uploaded. Fingerprints of operator-removed files are kept after the file itself is gone; a fingerprint can't be turned back into the file.
  • If you report a file: the report reason and your IP address, used only to review the report.
  • The board's owner secret, and an upload passphrase if the owner sets one — both stored only as one-way hashes, so we can't read them back.
  • An optional recovery email if the owner opts in. It is stored encrypted at rest and used only to send a fresh owner link when requested.
  • Standard server logs (IP address, request path, timestamp), used for security and debugging, not analytics.
  • A session cookie to remember owner-mode unlocks and passphrase entries within a single visit.
  • A small browser-side recent boards cookie if you open a board in owner mode, so this browser can show shortcuts back to boards you've recently managed.
  • A browser-side theme preference (light, dark, or system) stored locally on this device only.

How long we keep it

SlipNote does not auto-delete anything. Files, workspaces, and course details are kept until someone removes them — an uploader deleting their own file, the owner deleting files, or the operator removing content. A board that is never touched stays indefinitely. Report details, including the reporter's IP address, are retained only for as long as needed to review the report and are not used for anything else.

Age

SlipNote is intended for students in higher or further education and is not directed at children under 13. We don't knowingly collect personal information from children under 13. If you believe a child has uploaded personal information, report the file or contact the operator and it will be removed.

Your rights

Depending on where you live (for example under GDPR or CCPA), you may have the right to access, correct, or delete personal information about you, or to object to its processing. Because SlipNote holds so little — no accounts, no profiles — most of this is self-service: delete your own file with its delete link, or ask the workspace owner or site operator. For anything else, contact the operator of the specific site.

What we don't do

  • No analytics, no advertising, no profile building.
  • No selling or sharing of data with third parties.
  • No account, password, or email is required to browse, create a board, or upload files.

Email delivery

If the operator enables recovery, recovery emails are sent through the site's configured mail provider. That provider may process message metadata needed to deliver the email. SlipNote itself does not use recovery emails for marketing or mailing lists.

Telegram notifications (optional)

If the site operator has configured Telegram, a one-line notice (course, section, filename, link) is posted to the configured channel on every new upload. This is set by the operator, not per workspace.

Deleting your data

An uploader can remove their own file via the one-time delete link shown after upload. The workspace owner can delete any file in their workspace and can add, change, or remove the workspace's recovery email. There is currently no UI to delete an entire workspace. If you need this, contact the site operator.

Contact

SlipNote is open source. The code is at github.com/otatechie/slipnote. For privacy questions on a specific deployment, contact the operator of that site.