← Back

Privacy Policy

Effective Date: March 30, 2026

1. Introduction

DamnSlides ("Company", "we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect information when you use the DamnSlides platform at damnslides.com ("Service"). It also describes your rights regarding your personal data and how to exercise them. This policy applies to all users of the Service, regardless of location.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your email address and authentication credentials. If you sign in via Google OAuth, we receive your name, email address, and profile picture from Google. We do not receive or store your Google password.

2.2 User-Generated Content

We store the topics, instructions, outlines, and presentation content you create or upload using the Service ("User Content"). We also store the AI-generated presentations, slides, and review results ("AI Output"). This data is associated with your account and is necessary to provide the Service.

2.3 Usage and Transaction Data

We collect information about how you interact with the Service, including: features used, pages visited, generation history, credit consumption, transaction records, timestamps of actions, and session duration. This data helps us operate, maintain, and improve the Service.

2.4 Technical and Device Data

We automatically collect technical information including: IP address, browser type and version, operating system, device type, screen resolution, referring URL, and page load performance metrics. This data is collected through Vercel Web Analytics, which is a first-party, privacy-friendly analytics solution that does not use cookies or track users across sites.

2.5 Payment Information

If you subscribe to a paid plan, payment details (credit card number, billing address) are collected and processed directly by our third-party payment processor. We do not receive, access, or store your full payment card number. We may receive limited information such as the card's last four digits, expiration date, and billing country for record-keeping and support purposes.

2.6 Communications

When you contact us via email or through the Service, we collect the content of your messages, your email address, and any attachments you provide. We use this information to respond to your inquiries and improve our support.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: Process your input, generate presentations, manage your account, allocate and track credits, and deliver the core functionality of the Service.
  • Service Improvement: Analyze usage patterns, identify bugs, optimize performance, and develop new features. We use aggregate, anonymized data for these purposes whenever possible.
  • Billing and Administration: Process payments, manage subscriptions, send billing notifications, and maintain transaction records.
  • Security and Fraud Prevention: Detect, investigate, and prevent unauthorized access, fraud, abuse, and violations of our Terms of Service.
  • Communication: Send account-related notifications (password resets, billing alerts, security notices, service updates). We do not send marketing or promotional emails without your explicit opt-in consent.
  • Legal Compliance: Comply with applicable laws, regulations, legal processes, and governmental requests.

4. Legal Bases for Processing (EEA/UK Users)

If you are located in the European Economic Area or United Kingdom, we process your personal data on the following legal bases under GDPR:

  • Contractual Necessity (Art. 6(1)(b)): Processing necessary to provide the Service, manage your account, and fulfill your subscription.
  • Legitimate Interests (Art. 6(1)(f)): Processing for security, fraud prevention, service improvement, and analytics, where our interests do not override your rights.
  • Consent (Art. 6(1)(a)): Where you have given explicit consent, such as for marketing communications. You may withdraw consent at any time.
  • Legal Obligation (Art. 6(1)(c)): Processing necessary to comply with legal requirements (e.g., tax records, regulatory requests).

5. AI-Specific Data Practices

5.1 How AI Processing Works

When you use AI features, your User Content (topics, instructions, outline text) is sent to third-party AI model providers via API for real-time processing. The AI provider generates a response, which is returned to you through our Service.

5.2 What We Send to AI Providers

We send only the content necessary to generate your presentation: your topic text, style preferences, outline content, and slide HTML for regeneration. We do not send your personal information (name, email, account ID, payment details) to AI providers.

5.3 AI Provider Data Retention

Our AI provider agreements stipulate that input data is processed in real-time and is not retained or used for model training purposes. However, AI providers may temporarily log API requests for abuse monitoring and debugging, subject to their own privacy policies and data retention schedules.

5.4 No Training on Your Data

We do not use your User Content or AI Output to train, fine-tune, or improve AI models. Your content is processed solely to deliver the requested output to you.

6. Cookies and Tracking Technologies

6.1 Essential Cookies

We use strictly necessary cookies for authentication session management. These cookies are required for the Service to function and cannot be disabled. They do not track you across websites.

6.2 Analytics

We use Vercel Web Analytics, a privacy-friendly analytics tool that does not use cookies, does not collect personally identifiable information, and does not track users across sites. It provides aggregate metrics such as page views, visitor counts, and performance data.

6.3 No Advertising Cookies

We do not use advertising cookies, retargeting pixels, social media tracking scripts, or any third-party tracking technologies for advertising purposes.

6.4 Do Not Track

Our Service respects "Do Not Track" (DNT) browser signals. Since we do not engage in cross-site tracking, DNT signals do not change how the Service operates.

7. How We Share Information

We do not sell your personal data. We share information only in the following circumstances:

7.1 Service Providers

We share data with trusted third-party service providers who assist us in operating the Service, subject to data processing agreements:

  • Vercel: Hosting, deployment, and edge delivery of the Service.
  • Supabase: Database storage, authentication, and real-time infrastructure.
  • AI Providers: Content generation via API (see Section 5).
  • Payment Processors: Subscription billing and payment handling.

7.2 Legal Requirements

We may disclose your information if required by law, subpoena, court order, or governmental request, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a government request.

7.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your personal data may be transferred as part of the transaction. We will notify you via email or prominent notice on the Service before your data is transferred and becomes subject to a different privacy policy.

8. Data Retention

  • Account data and presentations: Retained as long as your account is active. Deleted within 30 days of account deletion request.
  • Credit transaction history: Retained for 12 months for billing, audit, and dispute resolution purposes.
  • Technical logs: Retained for up to 90 days for security and debugging purposes.
  • Payment records: Retained as required by applicable tax and financial regulations (typically 7 years).
  • Support correspondence: Retained for up to 24 months after ticket resolution.

9. Data Security

We implement industry-standard technical and organizational security measures, including:

  • Encryption in transit (TLS 1.2+) and at rest for all stored data.
  • Row-level security (RLS) in our database, ensuring users can only access their own data.
  • Server-side authentication and authorization for all API endpoints.
  • No storage of payment card details on our servers (handled by PCI-compliant processors).
  • Regular security reviews and dependency updates.
  • Access controls limiting employee access to personal data on a need-to-know basis.

While we strive to protect your data, no method of transmission or storage is 100% secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant authorities within 72 hours as required by applicable law.

10. International Data Transfers

The Service is hosted on Vercel's global edge network with primary data processing in the United States. Your data may be transferred to, stored, and processed in the United States and other countries where our service providers operate. These countries may have different data protection laws than your jurisdiction.

For transfers from the EEA/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or other appropriate safeguards as required by GDPR. By using the Service, you acknowledge and consent to the transfer of your information as described in this section.

11. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If we become aware that a child under 16 has provided us with personal data without parental consent, we will take steps to delete that information. If you believe a child has provided us with personal data, please contact us at privacy@damnslides.com.

12. Your Rights

12.1 General Rights

Regardless of your location, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your account and associated personal data.
  • Export: Export your presentations via the PPTX export feature.

12.2 EEA/UK Rights (GDPR)

If you are in the EEA or UK, you additionally have the right to:

  • Data Portability: Receive your data in a structured, commonly used, machine-readable format.
  • Restriction: Request restriction of processing in certain circumstances.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent.
  • Lodge a Complaint: File a complaint with your local data protection authority.

12.3 California Rights (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know: Request disclosure of the categories and specific pieces of personal information collected.
  • Delete: Request deletion of personal information we have collected.
  • Opt-Out of Sale: We do not sell personal information. No opt-out action is required.
  • Non-Discrimination: We will not discriminate against you for exercising your rights.

12.4 Exercising Your Rights

To exercise any of these rights, contact us at privacy@damnslides.com. We will verify your identity before processing your request. We aim to respond within 15 business days (or within the timeframe required by applicable law). If we need additional time, we will inform you of the reason and extension period.

13. Marketing Communications

We only send marketing or promotional emails with your explicit opt-in consent. You may opt out at any time by clicking the "unsubscribe" link in any marketing email or by contacting us. Opting out of marketing emails does not affect transactional communications (billing, security, account notifications).

14. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices or content of those third parties. We encourage you to review their privacy policies before providing any personal data.

15. Sensitive Data

We do not intentionally collect sensitive personal data, including racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, or criminal history. Please do not submit such data as User Content. If sensitive data is inadvertently collected, we will delete it upon discovery or request.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. For material changes, we will provide at least 14 days advance notice via email or in-app notification. The "Effective Date" at the top of this page indicates when the policy was last revised. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

17. Contact Us

For privacy-related questions, data requests, or complaints, contact our privacy team: