What's stored, and where.
The short version: this website sets no cookies and runs no tracking script, your platform data lives on servers in Germany, and the only processor outside the EU is GitHub — which is only involved if you choose to connect a repository.
This website
slew.sh sets no cookies and loads no analytics script, so there is no consent banner because there is nothing to consent to. Visitor numbers come from the CDN's own request logs, aggregated server-side into counts of pages, referrers and countries. No profile is built, nothing is shared with an advertising network, and you are not identifiable in the result.
If you create an account
Accounts are created by signing in with GitHub. That gives slew your GitHub username, your account ID, your avatar URL and the email address on your GitHub account — used to identify you, to contact you about your account, and for nothing else. Signing in with GitHub does not grant access to your repositories; connecting a repository is a separate, explicit step.
What you put on the platform
Project source, build output, environment variables, deploy logs and custom domain configuration. This is your content — it is processed to build and serve your sites and is not read, mined or used to train anything. Environment variables are stored encrypted.
Requests to sites you host generate log entries at the edge, which are aggregated into the traffic statistics you see in the dashboard. These statistics are cookieless and are not used to identify individual visitors to your sites.
Subprocessors
Everyone who touches data on slew's behalf, and what for:
- Hetzner (Germany)
- Servers, databases, build machines and encrypted off-site backups. This is where your source, builds and platform data physically live.
- Bunny (Slovenia)
- CDN, DNS and TLS termination. Serves your sites and produces the request logs that traffic statistics are derived from.
- GitHub (United States)
- Sign-in and repository access, only if you connect a repository. This is the one processor outside the EU, and it is one you already use — nothing is sent to GitHub that did not come from there.
- EU model providers
- Only when you call the AI gateway: Mistral and Scaleway and OVHcloud in France, IONOS in Germany. Prompts are routed to EU-hosted models only and are not used for training.
Email delivery and payment processing each involve one further provider. Ask me for the current list and I will send it in writing.
Data processing agreement
For anything you host on slew, you are the controller and slew is the processor. If you need a signed data processing agreement — because a client asked, or because you're answering a tender — email hello@slew.sh and you'll get one as a document, along with the subprocessor list above in a form you can attach.
Because everything runs on EU-operated infrastructure under EU jurisdiction, there is no transfer mechanism to argue about for the platform itself. The GitHub connection is the one US element, and it is optional and initiated by you.
Your rights
You can ask for a copy of what's held about you, ask for it to be corrected, or ask for your account and its data to be deleted. Deleting your account removes your projects, deploys and traffic data. Email hello@slew.sh and it gets handled by the person who has the database access to actually do it.
Encrypted backups roll over on a schedule, so deleted data can persist in backups for a short period after account deletion before ageing out.
Getting in touch
Questions about any of this go to hello@slew.sh. You also have the right to complain to your national data protection authority; in the Netherlands that's the Autoriteit Persoonsgegevens.