Privacy Policy
Effective July 19, 2026
What we store on our servers
- Account details: email, hashed password, optional name.
- Billing metadata (Stripe customer id, subscription status, credit ledger). No card numbers — Stripe holds those.
- Chat threads and messages, so you can resume a conversation across devices.
- Skills you've authored, so they follow you across devices.
- Attachment metadata (filename, size, media type). The file bytes themselves are held only by OpenAI, with temporary retention — see “Model providers” below.
- Server-side logs for security, billing, and debugging. We aim to keep message content out of these logs.
What stays on your device
Deck snapshots (used for per-message undo) live in the PowerSlide add-in's local cache and are not uploaded to our servers. Chat transcripts are persisted server-side so you can resume yesterday's conversation — the deck bytes themselves are not.
Model providers
Agent turns — your prompts and the slide text needed for a request — are sent to our LLM provider (currently OpenAI) for inference. OpenAI states that it does not use data sent through its API to train its models.
Files you attach are handled by OpenAI with temporary retention rather than permanent storage:
- Uploaded file bytes go to OpenAI's Files API and are currently set to expire about a day after upload.
- For searchable formats, an indexed copy may be kept in a per-user OpenAI vector store, currently set to expire about a day after your last activity.
- Files used for in-agent computation run in a sandboxed container that is discarded shortly after it goes idle.
OpenAI may also retain the request and response data from an agent turn for up to 30 days for abuse monitoring, after which it is deleted.
Third parties we rely on
- Fly.io — application hosting; runs our web and add-in servers.
- Neon — managed PostgreSQL database; account and billing data at rest.
- OpenAI — model inference and temporary file storage (see “Model providers”).
- Stripe — payments and subscription management.
- Resend — transactional email (sign-in, verification, password reset).
- Cloudflare — DNS, and the Turnstile challenge that protects sign-up from abuse (no cookies set on the PowerSlide origin).
- Google and Apple — single sign-on, only if you choose to sign in with them.
Your rights
You can delete your account at any time from the account page. To access, correct, or export the personal data we hold about you, email hello@getpowerslide.com and we'll respond within the timeframe required by applicable law. EU/UK residents can lodge a complaint with their local data-protection authority.
Retention
We keep personal data for as long as your account is active, and after that only as long as needed for the purposes described here or to meet legal, tax, and accounting obligations. Local device data is kept until you clear it.
Changes
We may update this Policy from time to time. The current version is always posted here with its effective date; where a change materially affects how we use your personal data, we'll take reasonable steps to let you know before it takes effect.
Contact
The data controller is TODO: your name or registered company name (PowerSlide); full provider details are in our legal notice. Data-protection questions? hello@getpowerslide.com.