Privacy Policy

Effective July 21, 2026

DeckCP ("DeckCP", "we", "us") provides a deck-editing application at deckcp.com. This policy explains what data we collect from people who use our site and application, how we use it, and the choices you have.

1. Information we collect

Account information. When you sign in with Google or a magic-link email, we receive your name, email address, and profile photo (if provided by Google). We use Supabase Auth to manage sign-in and store session data.

Content you create. Decks, slides, uploaded images, and other content you create or upload in the editor are stored so the product can function.

Usage data. On our production site we use two analytics services. Google Analytics gives us aggregate traffic data (pages visited, referrers, device type). PostHog gives us product analytics: it automatically records page views and interactions such as clicks ("autocapture") and builds a per-visitor profile so we can understand how the product is used — including for visitors who view a shared deck without signing in. Neither service is enabled in local development, and we do not use either for advertising.

Deck view analytics. When you open a deck that someone shared with you, we record that the deck was viewed — including time spent per slide — and show this to the deck's owner so they can see how their deck is performing. If you arrived through a personalized share link, the view may be attributed to that link.

Cross-site visits (the site tag). Deck owners can install a small DeckCP script (the "site tag") on websites they own. When you visit a site running the tag, it records the pages you viewed there — using a first-party cookie identifier set by that site — and sends them to DeckCP on that owner's behalf. If the owner already knows who you are — for example because you entered your email at one of their decks' email gates, or you clicked from their deck to their site (or from their site to their deck) — those visits may be linked to you and shown to the owner alongside your deck-viewing activity. If the site also uses the PostHog analytics tool, the tag may read that tool's visitor identifier for the same linking purpose. The owner's own privacy policy governs their site; DeckCP processes this data as their service provider. We also run the tag on our own websites. The tag is never used for advertising, and this data is never sold or shared with anyone other than the site's owner.

Waitlist / contact information. If you join our waitlist or email support, we store the email address and message you provide.

2. How we use information

3. Uploaded originals and AI training

Import originals. When you import a file (for example a PowerPoint or PDF), we retain the original you uploaded, encrypted at rest (AES-256-GCM) in a private storage bucket. We keep it so we can replay a failed import and debug and improve the import pipeline. All content you upload is encrypted at rest, on every plan.

AI training. As of July 21, 2026 — and only for content uploaded after you accept terms that say so — content on Free and Pro plans may be used to improve and train DeckCP's AI. Content in Team workspaces is never used for training, and decks protected by a password or email gate are excluded on every plan. Nothing uploaded before that date, under earlier terms, is used for training.

Deletion. Deleting a deck removes it from any future training runs. To be honest about the limits of that: models that were already trained before you deleted are not retrained retroactively, so information a model has already learned may persist in that model even after the source deck is gone.

4. Third-party services

We rely on the following processors to operate DeckCP:

Each of these providers processes data under its own privacy policy and only to the extent necessary to provide their service to us.

5. Gmail and Google user data

Some workspace features can connect a Gmail account. We ask for each permission only when you first use the feature that needs it:

DeckCP's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, do not sell it, do not transfer it to third parties except as necessary to provide the feature (or for security or legal compliance), and do not allow humans to read it except with your explicit permission, for security purposes, or to comply with law.

You can disconnect DeckCP's access at any time from your Google Account's third-party connections page; we will also delete stored tokens on request.

6. Cookies

We use a session cookie to keep you signed in, managed by Supabase Auth. Our production site also sets analytics cookies and similar local-storage identifiers via Google Analytics and PostHog; these let the analytics tools recognize a returning browser. Websites running the DeckCP site tag (see "Cross-site visits" above) set a first-party dcp_vid cookie on that site so returning visits can be recognized. We do not use cookies for third-party advertising.

7. Data retention

We retain account and content data for as long as your account is active. You may request deletion of your account and associated data at any time by contacting us (below); we will delete it within a reasonable period, except where retention is required by law.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to withdraw consent to processing. To exercise any of these rights, contact us at the email below.

9. Security

We use industry-standard measures — encrypted transport (HTTPS), access-controlled databases, and secure session cookies — to protect your data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Children

DeckCP is not directed at children under 13, and we do not knowingly collect personal information from them.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the effective date above.

12. Contact

Questions about this policy or your data? Email support@deckcp.com.