Privacy Policy
Last updated: July 19, 2026
Introduction
This Privacy Policy explains how Deckary ("we", "us", "our") collects, uses, and shares information when you use the Deckary add‑ins and supporting services such as deckary.com (collectively, the "Services"). We are based in the Netherlands and process personal data in accordance with the EU General Data Protection Regulation (GDPR).
Scope and Service Description
Deckary provides add‑ins for Microsoft PowerPoint (Microsoft 365) and Google Slides (Google Workspace). Your slide content stays within your Microsoft or Google environment — we don't access or store the slides themselves. The add‑ins communicate with our services only for authentication, subscription validation, AI features (when used), and optional features like Excel linking, slide library, and Google Slides chart backing. The website provides account management, billing, and support.
Policies on Personal Information
Personal information is only collected for clearly defined purposes, stored using industry‑standard security practices, and deleted or anonymized when it is no longer required. We do not use personal information for advertising or sell it to third parties. Access to production data is restricted to staff who need it to operate Deckary or billing systems, and all processors are bound by written agreements.
Who We Are
Deckary is a productivity suite for consultants. For questions about this policy or your data, please contact us via the contact form at deckary.com/contact or email [email protected].
What We Collect
We collect information in the following contexts:
Website
- Contact details you submit via forms (e.g., name, email, message).
- Usage data such as pages viewed, device/browser information, and approximate location derived from IP address.
- Cookies and similar technologies to remember preferences and improve performance.
Add‑in
- Account identifiers to authenticate and authorize your access.
- Subscription status to determine feature access.
- Content-free product events such as a successful chart insertion or completed AI action, and separate operational error logs.
- AI prompts and instructions you provide when using AI features (not stored by Deckary — see AI Features section).
- Selected Excel cell data when using Excel linking (optional, 24‑hour retention — see Excel Linking section).
- Saved slide content when using the slide library (optional — see Slide Library section).
Helper Application
- The helper is a desktop app that registers keyboard shortcuts. It communicates with the add‑in via a WebSocket relay.
- Account identifiers for authentication.
- Diagnostics and error logs to maintain reliability and security.
Data Retention
| Data | Retention |
|---|---|
| Email address, subscription status | Duration of account |
| Basic usage analytics | 2 years |
| Saved slides (optional) | Duration of account |
| Excel link data (optional) | 24 hours (auto‑deleted) |
| Google Slides chart backing file (optional) | Stored in your Google Drive under your account; persists until you delete it |
| AI prompts | Not stored by Deckary. Routed through OpenRouter; downstream model-provider retention depends on the selected endpoint's published policy |
AI Features
If you use AI features, your prompts and requested source material are sent through OpenRouter over an encrypted connection to the model provider selected for that feature. We do not store prompts or responses.
- Training restriction: For text, vision, and research requests, Deckary asks OpenRouter to route only to endpoints whose published data policy denies data collection. Image-generation retention follows the selected endpoint's published policy.
- OpenRouter prompt logging: Deckary does not opt in to OpenRouter input/output logging.
- Model providers: The selected provider processes the request for inference and its endpoint-specific retention policy applies.
AI image generation uses the same OpenRouter path. Only the text description and image options you provide are sent for a new image; slide content is not added unless it is part of that description.
Excel Linking (Optional)
If you use Excel‑to‑PowerPoint chart linking:
- Selected cell data is temporarily stored on our servers to sync between Excel and PowerPoint.
- Data is encrypted in transit (TLS) and at rest (AES‑256).
- Expires and becomes inaccessible after 24 hours.
- Only accessible to your account.
If your data policies prohibit this, you can use Deckary without Excel linking — charts can be created with manual data entry instead.
Slide Library (Optional)
Users can save slides to a personal library for reuse across presentations. If you use this feature:
- Slide content (shapes, text, images) is stored on our servers linked to your account.
- Data is encrypted in transit (TLS) and at rest (AES‑256).
- Only accessible to your account.
If your data policies prohibit this, the slide library feature can be disabled. All other Deckary features work without it.
Google API Services User Data Policy
Deckary's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Google Slides Charts (Optional)
If you use the Deckary Google Slides add‑in to insert or edit charts:
- Deckary creates a single private Google Sheets file in your Google Drive (using the
drive.filescope) to hold the chart's data ranges and chart specification. The file stays in your Drive under your account. - Deckary writes chart data and configuration to that Sheets file (using the
spreadsheetsscope) so the chart embedded in your slide stays linked and editable. - Deckary only accesses the Sheets file it creates. It does not read, modify, or list any other Sheets, Docs, or Drive files in your account.
- You can delete the backing file at any time. Charts that depended on it will display their last‑rendered state.
- Chart data values you include in AI prompts (e.g., "Jan 100, Feb 120") are also processed by the selected model provider through OpenRouter as part of the prompt — see the AI Features section.
Purposes of Processing
- Provide, operate, and improve the Services.
- Authenticate users and secure accounts.
- Process payments and manage subscriptions.
- Deliver AI‑powered features you request.
- Communicate with you, including support and service notices.
- Analyze usage to improve performance and usability.
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Comply with legal obligations.
Legal Bases (GDPR)
- Performance of a contract (to provide the Services you request).
- Legitimate interests (to secure, improve, and market our Services in a proportionate manner).
- Consent (for optional cookies/analytics or certain AI processing where required).
- Legal obligation (to meet compliance and tax requirements).
Cookies
We use necessary cookies to operate the site and, where consented, optional cookies for analytics and performance. You can manage cookie settings in your browser and, where applicable, in our cookie banner.
Analytics
With your consent, we use PostHog Cloud EU for pseudonymous website and product analytics. We record bounded page, acquisition, product-entry, and successful-value events under an account identifier; we do not send email addresses, prompts, document content, filenames, local paths, or raw errors. Session replay, broad click autocapture, and stored IP addresses are disabled.
Current analytics preference: disabled
Data Sharing and Subprocessors
We share data with trusted service providers who process data on our behalf:
| Provider | Purpose | Data processed |
|---|---|---|
| PostHog Cloud EU | Consented web and product analytics | Pseudonymous account and event identifiers, page paths, campaign fields, bounded product events |
| Auth0 (Okta) | Authentication | Email, login credentials |
| Supabase | Database and file storage | Account data, subscriptions, saved slides, Excel link data |
| Vercel | Website and API hosting | Request data, server logs |
| Stripe | Payment processing | Payment details, billing info |
| OpenRouter and selected model providers | AI text, vision, research, and image processing | Prompts, requested source material, and images when AI features are used |
| Railway | WebSocket relay and slide-rendering hosting | Auth tokens, relay messages, presentation content, rendered slide images |
| Sender | Transactional email | Email address |
These providers are engaged under data processing agreements and are obligated to handle data securely and only according to our instructions. We do not sell your personal data.
International Transfers
Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and implement additional measures where necessary.
Your Rights (GDPR)
- Access your personal data and obtain a copy.
- Rectify inaccurate or incomplete data.
- Erase data (right to be forgotten) where applicable.
- Restrict or object to certain processing.
- Data portability.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a supervisory authority, including the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
To exercise your rights, contact us via the form at deckary.com/contact or email [email protected]. We may need to verify your identity before responding to your request.
Security
We implement technical and organizational measures designed to protect personal data, including encryption in transit (TLS 1.2+) and at rest (AES‑256), OAuth 2.0 authentication, and access controls based on the principle of least privilege. A full security brief is available on request — email [email protected].
Children
Our Services are not directed to children under 16. If you believe a child has provided personal data to us, please contact us to request deletion.
Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via the website or by email where appropriate.
Contact
Questions or requests? Contact us via the form at deckary.com/contact or email [email protected].