Legal

Privacy

Slideable is a deck editor. It is designed so that the least possible amount of your work leaves your own browser, and so that everything which does leave it does so because you asked for something that requires it. This page describes exactly what is stored, where, and for how long. It is written to be checked rather than to be reassuring.

Last updated Aug 12, 2026

What we do not do

There is no analytics package on this site or in the editor. No advertising network, no session recorder, no heatmap tool, no cross-site tracking pixel, and no third-party tag manager that could add one later without a code change. We do not sell personal data, we do not share it with advertisers or data brokers, and we do not build behavioural profiles. There is no cookie consent banner on this site because there is nothing on it that would require one.

We also do not use the contents of your decks to train machine learning models — not ours, and not anybody else’s.

Using Slideable without an account

You can open the editor and build a deck without signing up. When you do, your decks are stored in your own browser, in IndexedDB, and your interface preferences are stored in localStorage. That data stays on the device. We cannot read it, we cannot recover it for you, and clearing your browser storage deletes it permanently. If a deck you have not signed in to save matters to you, export it.

What we store when you create an account

Creating an account means we hold the data needed to have an account and to keep your decks:

  • Your email address, and a password stored only as a salted hash — we never hold the password itself and cannot tell you what it is.
  • A profile record: a display name, and an avatar if you set one.
  • Your decks, and the images and files you upload into them.
  • Version history: branches, commits, snapshots, revisions, merge requests and reviews. This is the feature that lets a team see what changed and who changed it, and it means older states of a deck are retained until the deck is deleted.
  • Membership and sharing records — which decks you can see, and who else can see them.
  • Operational logs, including access records and standard server logs containing IP address, timestamp and user agent, kept for security and abuse investigation.

Authentication and storage are provided by Supabase, which processes this data on our behalf as a sub-processor.

What happens when you share or publish a deck

Publishing a deck creates a link that serves that deck to whoever holds it. A share link is not a password: anyone who has the URL can open the deck, and anyone who has opened it can pass it on. Re-publishing keeps the same URL, which is convenient and also means an old link keeps working against the updated deck. Unpublish a deck when you no longer want it reachable, and treat anything you have published as public.

What happens when you connect an AI agent

Slideable runs an MCP server so that an AI client — Claude, Claude Code, Cursor, Codex, Gemini CLI, VS Code and others — can work on your decks. Connecting one runs an OAuth flow: you sign in, the client is issued an access token, and we store the client registration, the authorisation code and the token. That token lets the client act as you, within the scope you granted, until you revoke it.

The consequence is worth stating plainly, because it is the part people miss. Once you connect an agent, the contents of the decks it reads are sent to whichever AI provider runs that client, and are then subject to that provider’s privacy policy and retention rules rather than ours. We do not control what Anthropic, OpenAI, Google, Microsoft or anyone else does with a prompt their own client constructed. If a deck should not be read by a third-party model, do not connect an agent to it.

Third parties that receive data, and why

  • Supabase — authentication, database and file storage for accounts and cloud decks.
  • Vercel — hosting for this site, the editor and the MCP endpoints. Receives the request data any web host receives, including IP address.
  • Unsplash — only when you search for a stock image. Your search term is sent to Unsplash, and images you insert are loaded from Unsplash servers, which therefore see the request.
  • Google Fonts — this marketing site loads two typefaces from Google’s font CDN, which means Google receives the IP address of visitors to these pages.
  • Your chosen AI provider — only if you connect an agent, as described above.

How long things are kept

Decks, assets and their version history are kept until you delete them or delete your account. Deleting a deck moves it to trash first; emptying trash removes it. Deleting your account removes your profile, your decks and their history within 30 days, except where we are required to keep a record for legal or accounting reasons. Server and access logs are kept for a rolling 90 days.

Your rights and how to use them

You can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to a particular use. Write to privacy@slideable.ai from the address on the account and we will respond within 30 days. Depending on where you live you may also have the right to complain to a data protection authority, and nothing here is intended to limit that.

Children

Slideable is not intended for children under 16, and we do not knowingly create accounts for them. If you believe a child has an account, write to us and we will remove it.

Changes to this policy

We will change this page when the software changes, and the date at the top is the date of the last change. If a change materially affects what happens to data we already hold, we will tell account holders by email rather than relying on you to re-read the page. Questions go to privacy@slideable.ai.