PRIVACY
What Slippy Labs collects, what it doesn't, and where it goes. Effective 27 August 2026.
Slippy Labs is a hobby project run by one person on one server. There are no ads, no analytics, no tracking pixels and no third-party trackers on any page here — not on this site, and not on any slippylabs.com subdomain. Nothing collected here is sold, rented or shared for marketing. This page covers the whole estate: the hub, every tool, every game, and every logged-in service.
The short version
- No analytics and no advertising anywhere. The only cookies are the one that keeps you signed in, the one that remembers your accessibility settings, and, if you use the floating player, two that remember how you left it.
- Every page sends
Permissions-Policy: interest-cohort=(), opting you out of Google's ad-topic profiling. - Web server logs record your IP address for about 14 days. On a plain visit, that is essentially all of it.
- Send a message, file a report, make an account, upload a file or post a score, and that gets stored. The sections below say exactly what, and exactly where.
- Want something deleted? Ask, and it gets deleted.
What a plain visit leaves behind
Server logs. The web server writes one line per request: your IP address, the time, the page requested, the response status, your browser's user-agent string, and the referring page if your browser sent one. These rotate daily and are kept for roughly two weeks before being deleted. They are used for debugging and for spotting abuse. Nothing else.
Cloudflare. DNS and HTTPS for this domain are proxied through Cloudflare, so Cloudflare sees every request before this server does, and applies its own bot protection. That part is governed by Cloudflare's privacy policy, not this one.
Google Fonts. Every page loads the "Press Start 2P" pixel typeface from fonts.googleapis.com. That request goes to Google and carries your IP address and user-agent. It is the one unavoidable third-party asset request on this site, and blocking it costs you nothing but the retro font.
The login check. Every page here quietly asks admin.slippylabs.com whether you are signed in, so it knows whether to show the login-only panels. That request carries the login cookie described below. If you have never signed in there is no cookie to carry, and the answer is simply "no".
The home-page strip. When you are signed in, the top of slippylabs.com shows the current temperature and your next few calendar events. It reads your saved weather location and, if you have switched calendar sync on, your calendar, both from your account; then it asks weather.slippylabs.com for that location's forecast, without sending anything about your account. It refreshes about every ten minutes while the tab is open and stops while the tab is in the background. Signed out, none of it runs and nothing is requested.
Accounts
Accounts live at admin.slippylabs.com and unlock the gated corners of the site — cloud storage, the jukebox, the channel deck, the game library, the server bay. Registration is invite-code only.
An account stores your username, a hash of your password (never the password itself), the date you registered, which services you have been granted, and the invite code you used.
Email is optional. You may add an address — at sign-up, or later from your account page — and it is used for exactly one thing: mailing you a link to reset your password if you forget it. It is never used for anything else, and it is not required. Leave it blank and none is stored. Add one and you can clear it again at any time from the same page. A reset link is relayed through Gmail's SMTP servers, so Google handles that message in transit.
If you enable two-factor authentication, the account additionally stores the TOTP secret needed to verify your codes, plus hashed one-time recovery codes.
Password recovery works the same way: any recovery codes you generate, and any reset code an admin issues you, are stored only as hashes and expire once used. Changing your password discards every outstanding reset code for the account.
The login cookie. Signing in sets a single cookie scoped to .slippylabs.com, so one session works across every subdomain. It lasts 7 days, is marked Secure, HttpOnly and SameSite=Lax, and carries only your username, whether you are an admin, and which services you may reach. It is strictly functional and is not used to track you. The only other cookies on this site are the accessibility one and the floating player's two, both described below.
Accessibility settings
Every game on gambling.slippylabs.com carries an Access button that opens a settings panel: text size, card and board size, a high-contrast mode, and colour-blind card decks. Nothing there is on unless you turn it on.
Because every game sits on its own subdomain, the choice is kept in one cookie scoped to .slippylabs.com so you only have to make it once. sl_a11y holds nothing but those four settings — something like t130.c115.h1.cb2 — and no identifier of any kind. It lasts a year, is marked Secure and SameSite=Lax, and is readable by pages on this site so they can apply your settings before the page draws. It is never sent anywhere else, it is set whether or not you are signed in, and it is not used to track you. Clearing your cookies resets the panel to its defaults and nothing else.
The floating player
Signed in, a small player rides along in the corner of every page so music or TV carries on while you move around the site. It appears only for accounts that hold the jukebox or Slippy TV grant; signed out, it is never loaded at all.
To survive a page change it remembers two things in cookies scoped to .slippylabs.com. slippydeck holds how you left it — which corner, open or collapsed, which tab, and whether something was playing so the next page knows to pick it back up. If you send the player into its own window, slippydeckwin holds a timestamp plus the title of what is playing, which is how the pill on every other page can show it. That one expires within a minute of the window closing. Both are readable by pages on this site, unlike the login cookie; neither is sent anywhere else, and neither is used to track you.
What you were actually listening to — the queue, the track, how far into it you were, the channel, the volume — is kept in your browser's own local storage on jukebox.slippylabs.com and slippy-tv.slippylabs.com. It is not stored on the server, and clearing your site data erases it.
The contact form
Sending a transmission delivers an email to the site owner containing your callsign, your email address, your message and your IP address. Your email address is set as the reply-to so that a reply is possible.
That message is not written to any database on this server — it exists only as email. It is relayed through Gmail's SMTP servers, so Google handles it in transit, and it then sits in an ordinary Gmail inbox for as long as it stays useful.
The report-an-issue form
Filing a bug or an idea creates an issue in a private GitHub repository. Worth reading closely: the issue body includes the email address you optionally supplied and your IP address, alongside your title and description. GitHub therefore stores both, under GitHub's own privacy policy. If you would rather it didn't, leave the email field blank — the IP address is still recorded either way, because it is what stops report spam.
If GitHub cannot be reached, the identical report — email address and IP address included — is emailed to the site owner instead.
The tracker is private, so nobody else can read your report.
Games, scores and leaderboards
Leaderboards. When you post a score you choose the name that appears beside it. That name and that score are public on the high-score tables. Your IP address is not stored: it is put through a salted one-way hash first, and only the hash is kept, purely to rate-limit score spam. Pick a nickname rather than your real name if that matters to you.
Multiplayer games. In any game with other players — the casino tables, the MMOs, the fighters, the social-deduction rooms — the display name you choose and anything you type in chat are visible to everyone else in that room.
The casino. Luck Games records your username, your play-money balance, a ledger of your play-money transactions, your per-game rating and win/loss record, and any cosmetic skins you have unlocked. No real money is involved anywhere on this site. There are no payments, no card details are ever requested, and the chips are worth precisely nothing. Bans, where issued, are recorded against a username with a reason and a timestamp. If you host or enter a tournament, the event you created or entered, your finishing place, and the play-money buy-in and prize attached to it are recorded against your username and shown publicly on that event’s page.
The jukebox. Playlists are stored on the server against your account: the name, the description, which tracks are in it and in what order. A playlist you mark as shared is visible to — and playable by — every other signed-in account that has jukebox access, listed under your username as its owner; a private one is visible only to you and to an admin. Tracks you star, and how often a track has been played, are recorded against your account in the same way. Deleting a playlist removes it from the server.
Single-player tools. Most of the tools on projects.slippylabs.com run entirely inside your browser. Files you drop into an image converter, a PDF editor, an emulator or similar are processed locally and are not uploaded, unless that tool's own page says otherwise. Weather Outlook is the exception — it needs a server to reach the forecast services, and it is described in its own section below.
SlipDJ. A track you drag onto a deck from your own machine is decoded in the tab and never uploaded — that part works signed out and leaves nothing behind. Signed in, three other things are stored. Tracks you upload to My Crate live on this server's disk with their filename, size and upload time, and are visible only to you. A mix you record is the master output of your session, saved to this server as an audio file alongside its length and an automatic tracklist of what was playing and when; mixes are private, and you can delete one at any time. If you press Share on a mix, an unguessable link is created that lets anyone holding it play that mix without signing in — the page is marked not to be indexed by search engines, and revoking the link stops it working immediately. Saving a session records what was loaded on each deck, your cue points, loops and knob positions — settings, not audio.
SlipDJ also keeps a shared beatgrid cache: the detected tempo and waveform shape of a track, stored against the track rather than against you. A track's tempo is the same for everybody, so analysing one once saves everyone else the wait. It records nothing about who played what.
Tools that listen. The Milkdrop visualizer, the spectrum analyzer and the karaoke app read live audio — from your microphone, from an audio file you pick, or, in the visualizer, from a browser tab you choose to share. Your browser will always ask before any of that starts, and it is never automatic. That audio is analysed in the tab and never leaves it: it is not recorded, not saved and not uploaded, and microphone and shared-tab audio are deliberately not routed back to your speakers so they cannot feed back. Nothing about what you played is stored.
Files you upload
The cloud storage bay, the jukebox and SlipDJ's crate sit behind the login. For each file they record the original filename, the file type, the size and the upload time — and, of course, the file itself, on this server's disk. Ask, and it will be deleted.
Voice, screenshare and watch party
SlipCord and Voice Chat connect callers directly to one another wherever the network allows. When a restrictive NAT blocks a direct connection, audio and video are relayed through Cloudflare's TURN service instead. Either way, calls are not recorded and not stored on this server. Room names and passwords exist only for as long as the room does.
Weather Outlook
weather.slippylabs.com is the one tool here with a back end, because the forecast services it reads cannot be called from a browser — some send no cross-origin headers, and one refuses any request that does not look like a desktop browser.
What is sent. Searching a place sends what you type to this server, which passes it to Open-Meteo's geocoder. Loading a forecast sends the chosen coordinates, and this server then queries the nine forecast sources on your behalf. Those services see this server's address, not yours — unlike Slippy TV, nothing on the page talks to them directly.
Using your location is optional and never automatic. The “My location” button asks your browser for a fix, which your browser will prompt you to allow. If you allow it, those coordinates are sent to this server, which asks BigDataCloud what the nearest place is called and then collects the forecast as above. Decline it, or simply never press it, and no location of yours is ever requested — search works perfectly well instead.
What is stored. Collected forecasts are cached on this server for a few hours, keyed by coordinates rounded to about a kilometre and holding nothing but weather. That cache has no account, no session and no identifier in it, and a place you looked at is indistinguishable from the same place looked at by anyone else. The places you have searched, your °C/°F choice and any event window you set are kept in your browser's local storage and are not sent to this server. The usual web-server log line applies, as on every page.
Kept in your browser, not on the server
Several pages use your browser's local storage for preferences that never leave your machine: the visual-effects setting, the callsign you last used on a leaderboard, per-game options, some local best times, and the floating player's queue and position described above. Clearing your browser's site data for this domain erases all of it.
The calendar. calendar.slippylabs.com keeps every event you enter — its title, notes, times and repeat rule — in that same browser storage. By default that is the whole story: the events are never sent to this server, so they exist only in the browser you typed them into, and clearing that browser's site data deletes them for good. Importing an .ics file reads it in your browser, and exporting one writes the file straight to your downloads; neither passes through the server.
The calendar's extra calendars. The same page can draw public holidays, observances, seasons, moon phases and religious days beside your own events. These are worked out in your browser from the date rules themselves — nothing is requested and nothing is stored. The one exception is the Space launches layer: while it is switched on, the page fetches the upcoming launch schedule from mission.slippylabs.com, roughly twice an hour. That is a plain request for a public list, identical for everybody; nothing about you or your calendar is sent with it. Which of these layers you have switched on is remembered in your browser, and travels with your account only if you have also turned calendar sync on. Generated days are never written into your .ics export and never uploaded.
Calendar sync, if you switch it on. There is a "Sync my calendar to my account" switch near the bottom of that page. It is off unless you turn it on, and it does nothing at all unless you are signed in. Turned on, a copy of your events — and a flattened list of the next ninety days, which is what lets the home page show your next few — is stored against your account on this server, so the same calendar follows you to another device. Turning the switch back off deletes that stored copy; it does not merely stop using it. Only you and an administrator of this server can read it, and it is included in the server backups described below.
Your weather location. If you are signed in and pick a place on weather.slippylabs.com, that place — its name and coordinates, nothing else — is stored against your account so the home page knows where to show the temperature for. The page tells you so while you are signed in. Signed out, your recent places stay in your browser as before. The forecast request itself carries no account information.
Third parties actually involved
The complete list. There are no others:
- Cloudflare — DNS, HTTPS and bot protection for every page, plus the TURN relay for calls.
- Google Fonts — the pixel typeface loaded on every page.
- Google / Gmail — relays contact-form mail and fallback report mail.
- GitHub — stores issue reports in a private repository.
- Third-party stream hosts — Slippy TV plays public streams listed by the iptv-org index, fetched directly from whoever publishes them. Those hosts see your IP address, exactly as they would for any video you watch on the web.
- Forecast services — Weather Outlook reads Open-Meteo, The Weather Channel, AccuWeather, the US National Weather Service, MET Norway and BigDataCloud. This server queries all of them on your behalf, so they see this server's address rather than yours, and they receive the place you asked about but nothing about you.
How long things are kept, and how to have them deleted
- Server logs: about 14 days, then gone automatically.
- Accounts, uploads, leaderboard entries and casino records: kept until you ask for them to go.
- Contact messages and issue reports: kept for as long as they stay useful — in an inbox and a private tracker respectively.
To close an account, remove a leaderboard entry, delete uploads or take down a report, email [email protected] or use the contact form. Say what you want gone. There is no process to fight through — it is one person and a delete key.
Children
This site is not directed at children under 13, and no account is knowingly created for one. If you believe a child has supplied personal information here, get in touch and it will be removed.
Security, stated honestly
Everything is served over HTTPS with HSTS. Passwords are hashed and never stored in the clear, and two-factor authentication is available. Login-gated services are gated at the web server itself, not merely inside the app.
That said: this is a personal hobby server run by one person, not a company with a security team. It is looked after carefully, but no guarantee is offered. Don't store anything here you couldn't stand to lose or to have exposed, and use a password you don't use anywhere else.
Changes to this page
If what the site collects changes, this page changes with it and the date at the top is updated. There is no mailing list to notify you — check back here.
Questions
Ask. [email protected], or the contact form.
"No ads, no trackers, no funny business. Read it if you like."