Privacy Policy

Last updated: August 27, 2026

This privacy policy explains what personal data slim-down collects, why, and what choices and rights you have. slim-down is a personally run project (not a registered company); its administrator is the data controller for your data under the GDPR.

Who is responsible for your data?

slim-down is run as a personal project, without a company registration. For any questions about this privacy policy or your data, you can reach the administrator at info@slim-down.nl.

What data do we collect?

Depending on how you use slim-down, we process the following data:

  • Account data: your email address and a bcrypt-hashed password (never stored in readable form) when you create an account.
  • Google sign-in: if you choose to sign in with Google, we receive your email address and name as provided by Google's OAuth service.
  • Session and security data: a session cookie (session_token) to keep you logged in, and a csrf_token cookie to protect against cross-site request forgery.
  • Preferences: cookies for your language (lang) and theme (theme) setting, so they persist between visits.
  • Anonymous users: to enforce the free quota (3 conversions per day), we use a machine fingerprint (a technical hash based on your browser/screen characteristics, stored in an fp cookie) together with your IP address. This data is not linked to an account.
  • Document content: the text or files you paste or upload for conversion. If you're logged in, you can choose to save documents so you can find them across devices; you can delete these yourself at any time.

What do we use your data for?

  • To deliver the conversion service, manage your account, and let you log in (performance of a contract, GDPR Art. 6(1)(b)).
  • To prevent abuse (rate limiting via fingerprinting) and secure the service, e.g. against CSRF attacks (legitimate interest, GDPR Art. 6(1)(f)).
  • To let you sign in with Google, based on your active choice to do so (consent, GDPR Art. 6(1)(a)).

No advertising or tracking cookies

slim-down does not use third-party analytics, advertising, or tracking cookies. The only cookies we set are functional: for session management, security (CSRF), preferences, and the free quota for anonymous users.

Do we share data with third parties?

We don't share data for marketing purposes. Data is only shared with: Google, when you choose to sign in with Google (Google acts as its own data controller for the sign-in process); and our hosting provider, which operates the servers and database slim-down runs on, acting as a processor.

How long do we keep your data?

We keep account data and saved documents for as long as your account exists, or until you delete them yourself. Fingerprint and request data for the anonymous free quota is kept only briefly (typically expiring automatically within a few days). Session cookies are valid for a maximum of 30 days.

How do we secure your data?

We transmit all traffic over HTTPS, hash passwords with bcrypt, use HttpOnly cookies for sessions, apply CSRF protection, and send strict security headers (such as Content-Security-Policy and X-Frame-Options).

What rights do you have?

Under the GDPR you have the right to access, rectify, erase, restrict processing of, port, and object to the processing of your data. You can also file a complaint with your national data protection authority at any time. To exercise any of these rights, contact us at info@slim-down.nl.

Changes to this policy

We may update this privacy policy from time to time, for example when slim-down's functionality changes. The date at the top of this page shows when the policy was last updated.

Contact

Questions about this privacy policy or how we handle your data? Email info@slim-down.nl.