Privacy Policy

Last updated: September 9, 2026

Introduction

This Privacy Policy explains how Deckary ("we", "us", "our") collects, uses, and shares information when you use the Deckary add‑ins and supporting services such as deckary.com (collectively, the "Services"). We are based in the Netherlands and process personal data in accordance with the EU General Data Protection Regulation (GDPR).

Scope and Service Description

Deckary provides add‑ins for Microsoft PowerPoint (Microsoft 365) and Google Slides (Google Workspace), a browser-based presentation builder, and an MCP connector for external AI agents. Content in an Office or Google file remains in that environment unless you use a feature that sends selected content to Deckary or another provider. Saved Web Builder presentations and slide-library content are stored by Deckary. When you explicitly share a live PowerPoint presentation through MCP, presentation state and rendered slide images pass through Deckary's services for the active session. The website also provides account management, billing, and support.

Policies on Personal Information

Personal information is only collected for clearly defined purposes, stored using industry‑standard security practices, and deleted or anonymized when it is no longer required. We do not use personal information for advertising or sell it to third parties. Access to production data is restricted to staff who need it to operate Deckary or billing systems, and all processors are bound by written agreements.

Who We Are

Deckary is a productivity suite for consultants. For questions about this policy or your data, please contact us via the contact form at deckary.com/contact or email [email protected].

What We Collect

We collect information in the following contexts:

Website

Add‑in

Helper Application

Web Builder and MCP Connector

Data Retention

DataRetention
Email address, subscription statusDuration of account
Basic usage analytics2 years
Saved slides (optional)Duration of account
Saved Web Builder presentations, assets, restore points, and artifactsDuration of account; deleting a presentation removes it from active use. Associated account data is purged within 30 days after account deletion
Live PowerPoint MCP presentation content and rendersProcessed in memory for the active connection and request; not persisted by the MCP connector as a saved Deckary presentation
MCP product analytics2 years, when analytics consent applies
Excel link data (optional)No automatic expiry. Deleting a link disables it; stored source details and cell data are not automatically erased by that action. Contact us to request deletion of stored data.
Google Slides chart backing file (optional)Stored in your Google Drive under your account; persists until you delete it
AI promptsNot stored by Deckary. Routed through OpenRouter; downstream model-provider retention depends on the selected endpoint's published policy

MCP Connector Data Handling and Retention

Deckary's MCP connector lets an external AI agent you choose work with presentations in your Deckary account. The connector receives only the tool calls that the agent sends to Deckary; it does not receive the agent's unrelated conversation history, memory, or files. The external agent receives the presentation data and images returned by the tools you authorize, and that provider's privacy and retention terms apply to its copy of that data. Deckary's MCP server does not select or invoke an AI model for these tool calls.

Saved Web Builder presentations

MCP can read, render, and edit owner-scoped Web Builder presentations. Their slide content, themes, assets, restore points, and generated artifacts are stored with your Deckary account. Changes made through MCP are saved in the same way as changes made in the Web Builder and remain available for the duration of the account. Deleting a presentation removes it from active use; all associated account data is purged within 30 days after account deletion.

Live PowerPoint presentations

Live PowerPoint tools work only after you sign in to the Deckary add‑in, turn on MCP sharing, and keep the sharing session connected. Deckary relays the requested presentation state, editable object data, commands, and slide renders between the external agent and the add‑in. The relay holds live-session and pending-command state in memory and removes it when the connection ends. The MCP connector does not persist this live presentation content or its renders as a saved Web Builder presentation.

MCP analytics

When analytics consent applies, Deckary records a bounded product event for an MCP tool call: the tool name, duration, outcome, bounded error code, result byte counts, and image counts. These events do not include deck identifiers, presentation titles, prompts, authoring programs, slide content, rendered images, or raw errors.

AI Features

If you use AI features, your prompts and requested source material are sent through OpenRouter over an encrypted connection to the model provider selected for that feature. We do not store prompts or responses.

AI image generation uses the same OpenRouter path. Only the text description and image options you provide are sent for a new image; slide content is not added unless it is part of that description.

Excel Linking (Optional)

If you use Excel‑to‑PowerPoint chart linking:

If your data policies prohibit this, you can use Deckary without Excel linking — charts can be created with manual data entry instead.

Slide Library (Optional)

Users can save slides to a personal library for reuse across presentations. If you use this feature:

If your data policies prohibit this, the slide library feature can be disabled. All other Deckary features work without it.

Google API Services User Data Policy

Deckary's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Google Slides Charts (Optional)

If you use the Deckary Google Slides add‑in to insert or edit charts:

Purposes of Processing

Legal Bases (GDPR)

Cookies

We use necessary cookies to operate the site and, where consented, optional cookies for analytics and performance. You can manage cookie settings in your browser and, where applicable, in our cookie banner.

Analytics

With your consent, we use PostHog Cloud EU for pseudonymous website and product analytics. We record bounded page, acquisition, product-entry, and successful-value events under an account identifier; we do not send email addresses, prompts, document content, filenames, local paths, or raw errors. Session replay, broad click autocapture, and stored IP addresses are disabled.

Current analytics preference: disabled

Data Sharing and Subprocessors

We share data with trusted service providers who process data on our behalf:

ProviderPurposeData processed
PostHog Cloud EUConsented web and product analyticsPseudonymous account and event identifiers, page paths, campaign fields, bounded product events
Auth0 (Okta)AuthenticationEmail, login credentials
SupabaseDatabase and file storageAccount data, subscriptions, saved slides, saved Web Builder presentations and assets, Excel link data
VercelWebsite and API hostingRequest data, MCP tool arguments and results, server logs
StripePayment processingPayment details, billing info
OpenRouter and selected model providersAI text, vision, research, and image processingPrompts, requested source material, and images when AI features are used
RailwayWebSocket relay and slide-rendering hostingAuth tokens, relay messages, presentation content, rendered slide images
SenderTransactional emailEmail address

These providers are engaged under data processing agreements and are obligated to handle data securely and only according to our instructions. We do not sell your personal data.

International Transfers

Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and implement additional measures where necessary.

Your Rights (GDPR)

To exercise your rights, contact us via the form at deckary.com/contact or email [email protected]. We may need to verify your identity before responding to your request.

Security

We implement technical and organizational measures designed to protect personal data, including encryption in transit (TLS 1.2+) and at rest (AES‑256), OAuth 2.0 authentication, and access controls based on the principle of least privilege. A full security brief is available on request — email [email protected].

Children

Our Services are not directed to children under 16. If you believe a child has provided personal data to us, please contact us to request deletion.

Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via the website or by email where appropriate.

Contact

Questions or requests? Contact us via the form at deckary.com/contact or email [email protected].