Skip to content

Privacy Policy

Last updated: August 22, 2026

1. Who We Are

slide-deck.io is operated by Morton Technology Consulting LLC, a Florida limited liability company ("we," "us," or "our"). This Privacy Policy explains how we collect, use, and protect information when you use slide-deck.io (the "Service"). If you have questions, contact us at privacy@slide-deck.io.

2. Information We Collect

2.1 Account Information

When you register, we collect your email address, full name, and hashed password using the password-hashing scheme described on our Security page. If you sign in with Google, we receive your name, email, and profile picture URL from that provider. We do not receive or store your OAuth provider password.

2.2 Deck and Slide Content

The presentation content you create - slide text, speaker notes, layout choices, uploaded images, and associated data sources — is stored in our database and object storage on your behalf. This content is private to your account unless you explicitly create a share link. Share links are private-by-link rather than publicly listed.

2.3 Connected Data Sources

The available connected sources are CSV and HubSpot. CSV source contents are stored as plain text in the deck's database record, up to 512,000 characters. A HubSpot connection uses a private-app token supplied by you; that token is encrypted with AES-256-GCM before database storage and is not returned to the browser after storage. You choose contacts, companies, deals, or tickets. The service requests up to 100 records and reads a fixed set of common fields shown in the connection UI.

Source data is fetched when you refresh the source or generate from the deck. Up to 24,000 characters from each connected source may be included in an AI generation request. Removing a HubSpot source deletes our stored encrypted token but does not revoke the private-app token in HubSpot; revoke it separately in HubSpot settings.

2.4 Usage Analytics

We use PostHog for product analytics. Events can include page paths, feature use, account identifiers after sign-in, and error context. We do not intentionally include deck content in analytics events.

2.5 Operational Integrations

The application also contains separate Notion, Jira, Linear, ClickUp, Asana, Slack, and GitHub workflows. These are not selectable deck data sources in the connected-source panel. Their configured permissions are: Linear read; Jira read:jira-work; Slack incoming-webhook and commands; Asana default OAuth access; and the access granted by the user during the Notion or ClickUp authorization flow. GitHub uses a repository webhook secret rather than an OAuth access token.

These integrations store workspace, team, site, or repository identifiers and the credential needed for the selected workflow. Unlike HubSpot data-source tokens, their tokens and webhook values are not uniformly encrypted by the application before D1 storage. Selected project, task, issue, or page content can be sent to the configured AI provider when the user starts a generation workflow from that integration.

2.6 Billing Information

Payment card information is collected and stored by Stripe, our payment processor. We receive a customer ID and subscription status from Stripe, but we never see or store your full card number, CVV, or bank account details.

2.7 Log Data

Our servers automatically log your IP address, browser user agent, referring URL, and HTTP request metadata for security and debugging purposes. Log retention follows the infrastructure configuration operated for the Service; no shorter fixed deletion period is guaranteed by this application.

3. How We Use Your Information

  • Service delivery: generating, storing, and exporting your presentations; connecting to your data sources on your request.
  • Authentication: verifying your identity and maintaining your session.
  • Billing: processing subscription payments through Stripe and managing your plan tier.
  • Support: responding to your inquiries and diagnosing issues you report.
  • Security: detecting and preventing abuse, unauthorized access, and fraud.
  • Product improvement: analyzing anonymized usage patterns to prioritize features and fix bugs.

Presentation prompts, relevant uploaded-file excerpts, and connected-source data are sent to OpenAI's API for generation, or to Anthropic's API when it serves the request. We do not train our own models on this content. Provider retention and zero-data-retention eligibility depend on the provider account, endpoint, and contract configured by the Service operator; this application does not itself verify or guarantee zero-data retention.

4. Data Storage and Transfers

Your data is stored on Cloudflare infrastructure using D1 and R2. Data may be processed in locations permitted by Cloudflare and the AI providers under their applicable terms and our account configuration.

We do not currently publish a separate data-residency commitment. Contact us before using the Service where a specific processing region is required.

5. Data Sharing

We do not sell your personal data. We share data only:

  • With service providers: Stripe (payments), OpenAI and Anthropic (AI generation via API), Cloudflare (infrastructure), PostHog and Google when analytics or conversion measurement is configured, and our email delivery provider. Their own terms and retention practices also apply.
  • When required by law: in response to a valid court order, subpoena, or government request, or to protect the rights, property, or safety of slide-deck.io, our users, or the public.
  • In a corporate transaction: if slide-deck.io is acquired or merged, your data may transfer to the successor entity, subject to the same protections.

6. Roles and Data Processing Addendum

We determine the purposes of processing account, billing, support, security, and product analytics data. When an organization uploads personal data or connects HubSpot to create its presentations, that organization determines why the data is used and we process it to provide the requested service.

A Data Processing Addendum is not currently self-service or automatically incorporated into every subscription. If your organization requires a DPA, subprocessors, transfer terms, or a specific retention commitment, contact privacy@slide-deck.io and complete that review before uploading regulated or sensitive personal data.

7. Cookies and Local Storage

We use a single session cookie (sdi_session) to keep you logged in. It is HttpOnly, Secure, and SameSite=Lax. Local storage holds UI preferences and your cookie-banner choice. Optional Google Analytics 4 and PostHog load only after you click Accept analytics. Essential-only is the other choice. We do not load advertising pixels unless analytics is accepted.

8. Your Rights

  • Access: you may request a copy of your account data by emailing privacy@slide-deck.io.
  • Correction: you may update your name and email from your account settings at any time.
  • Deletion: deleting your account removes the account and associated database records synchronously and starts deletion of referenced exported files. Cleanup failures are logged for follow-up. Provider logs, billing records, and provider-managed backups follow the relevant provider's retention process.
  • Portability: signed-in users can download a JSON account export from GET /api/account/export, and can export decks as PPTX from the dashboard.
  • Analytics: choose Essential only or Accept analytics in the cookie banner. Essential only does not load Google Analytics or PostHog in the browser.

If you are in the European Economic Area or the United Kingdom, you have additional rights under the GDPR/UK-GDPR, including the right to lodge a complaint with your local supervisory authority.

9. Data Retention and Backups

Account, deck, CSV source, and encrypted HubSpot-token records are retained while the account or source remains active. Source removal deletes that source record. Account deletion removes application database records immediately and attempts object-storage cleanup. Stripe, Cloudflare, OpenAI, Anthropic, PostHog, Google, and email-provider records or backups follow their own retention and legal obligations. We have not verified a user-facing restore window for deleted data and do not promise that deleted sources can be restored.

10. Security

We implement technical and organizational measures to protect your data, including encryption at rest and in transit, rate limiting, and access controls. See our Security page for details. No system is perfectly secure; if you discover a vulnerability, please report it to security@slide-deck.io.

11. Children

The Service is not directed to children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us at privacy@slide-deck.io and we will delete it promptly.

12. Changes to This Policy

We may update this policy from time to time. We will notify you by email or by a prominent notice in the Service before material changes take effect. The "Last updated" date at the top reflects the most recent revision.

13. Contact

Morton Technology Consulting LLC
2241 N Monroe St #1309
Tallahassee, FL 32303
privacy@slide-deck.io