Privacy Policy
This English version is a convenience translation of the German privacy policy (Datenschutzerklärung). If the two differ, the German version is the legally binding one.
This Privacy Policy informs you, in accordance with Art. 13 and Art. 14 GDPR (DSGVO), which personal data we process when operating the website slaide.de and the web app app.slaide.de (together "Slaide", the "Service"), for which purposes and on which legal basis, and which rights you have.
As of: October 2026
1. Controller
The controller within the meaning of the GDPR is:
Nathalie Scholl (sole proprietorship) Im Zukunftspark 4 74076 Heilbronn Germany
E-mail: info@slaide.de
Nathalie Scholl (address as above) is responsible for journalistic and editorial content under § 18 (2) of the German State Media Treaty (MStV).
We have not appointed a data protection officer because there is no legal obligation to do so.
2. Contact for data protection matters
For questions about data protection or to exercise your rights, you can reach us at the address above and by e-mail at info@slaide.de.
3. General principles and legal bases
We process personal data only to the extent necessary to provide a working Service or where another legal basis exists. The relevant legal bases under Art. 6 (1) GDPR are:
- point (b), processing to perform the contract for the use of the Service or to take steps prior to entering into it,
- point (f), processing based on our legitimate interest (in particular in a secure, stable Service free of abuse),
- point (c), processing to comply with a legal obligation (for example commercial and tax retention duties),
- point (a), processing based on consent you have given, where consent is obtained.
We and our service providers do not use your content to train AI models (see Section 9; for AI assistants that you connect to your account yourself, see Section 13).
4. Visiting the website and server logs
When you visit the website and the app, technical access data that your browser transmits is processed automatically, in particular IP address, date and time of access, the requested resource, the HTTP status code, the amount of data transferred, the referrer, and information about your browser and operating system (user agent). This data is technically necessary to deliver the content, to ensure the stability and security of the Service and to defend against abuse (for example attacks or overload).
The legal basis is Art. 6 (1) point (f) GDPR (legitimate interest in secure and trouble-free operation). Delivery is handled by our hosting and CDN provider Vercel (see Section 12).
5. Protection against abuse and overload (rate limiting)
To protect our Service against abuse, automated attacks, brute-force login attempts and excessive use of the cost-intensive AI and generation functions, we limit how often certain requests may be made per user or per access. For this purpose we process your IP address or, where you are signed in, your account identifier. These attributes are stored only as an irreversible hash value, so the original IP address cannot be reconstructed from the stored counter; the counters are removed again when the respective time window ends.
A document can only be generated after sign-in; the IP and account limits protect the authenticated generation and authentication functions as well as the free PDF conversion without sign-in (Section 8) against abuse.
The legal basis is Art. 6 (1) point (f) GDPR (legitimate interest in a secure, stable Service free of abuse).
6. Registration, account and profile
To use the Service on an ongoing basis, you create an account. We process:
- your e-mail address,
- a password stored in encrypted form (password hash; we do not store your plain-text password), if you register with e-mail and password,
- optionally a name and voluntary information you give during onboarding (for example intended use or preferences).
To confirm your e-mail address we send a verification e-mail; the free document allowance is only unlocked after successful verification.
The legal basis is Art. 6 (1) point (b) GDPR (performance of the contract). Authentication, user management and data storage are handled by our service provider Supabase (see Section 12).
7. Signing in with Google or Apple (OAuth)
Optionally you can sign in with your Google or Apple account instead of e-mail and password. If you choose this, you are redirected to the respective provider and sign in there. The provider then transmits the identification data needed to match your account (in particular your e-mail address and a user identifier) to us or to our authentication service Supabase. We do not receive your Google or Apple credentials.
The legal basis is Art. 6 (1) point (b) GDPR (performance of the contract) or Art. 6 (1) point (a) GDPR where the provider obtains consent. The respective privacy notices of Google or Apple apply to processing by Google or Apple themselves. You can remove an existing link in the account settings.
8. Orders, uploaded content and created documents
From an order that you type in, Slaide creates documents with the help of AI (for example presentations or slides, reports, PDFs, spreadsheets). Optionally you can upload your own files (for example PDF, Word or Excel files or images) as context. A web research function is also available, in which the AI model retrieves publicly accessible web pages.
You can enter an order on the website, but the creation of a document is only triggered after sign-in. As with signed-in use, the order is then transmitted to our AI service providers for creation (see Section 9).
Free tools on the website: The tools "Shrink PowerPoint", "Extract images from PowerPoint", "Export PowerPoint notes", "Remove PowerPoint notes", "Extract PowerPoint slides" and "Replace PowerPoint fonts" run entirely in your browser without an account; the file is not transmitted to us. For the tools "PDF to PowerPoint" and "Word to PowerPoint", by contrast, you upload the file to our file storage (Supabase, EU); it is only converted after you have created a free account or signed in. The file is then converted on our servers (Vercel, EU region) into a document in your library and remains stored as its source file until you delete the document or the file (see below, signed-in use). If you do not create an account, an automatic clean-up run deletes the uploaded file after seven hours at the latest. Word files and PDF pages with a text layer are converted without an AI service. If a PDF page has no text layer (for example a scan or a PDF saved as an image), we transmit an image of that page for text and layout recognition to our AI service provider OpenRouter (USA) and the model used there (see Section 9); the result serves only this conversion. To protect against abuse we limit the number of uploads per IP address (see Section 5). The legal basis is Art. 6 (1) point (b) GDPR (performing the conversion you requested).
When you are signed in, we process and store:
- the orders and inputs you formulate,
- the files you upload and their contents; these may contain confidential information, so upload only content that you are entitled to have processed,
- the documents generated from them, so that they remain available in your library, can be edited and can be exported as PDF.
If you share a document, a publicly accessible sharing link with a random identifier is created for it; the document can then be reached by anyone who knows this link. Sharing only happens at your instigation.
The legal basis is Art. 6 (1) point (b) GDPR (performance of the contract). You can delete documents and uploaded files yourself at any time; you can deactivate sharing links. For generation, orders and relevant uploaded content are transmitted to AI service providers, including in the USA (see Section 9 and Section 12).
9. Processing by AI services (transfer to the USA)
Important notice: To create your documents, we transmit your order and the uploaded content relevant to it to our AI routing service provider OpenRouter (USA). Through it, the content is forwarded to the language-model providers selected in each case, which carry out the generation. The content transmitted for generation therefore leaves the European Economic Area and is processed in a third country (USA).
For the optional image generation, OpenAI (USA) is additionally involved; the respective image description is transmitted.
This processing takes place on our behalf and solely to provide the service you requested (Art. 6 (1) point (b) GDPR). The providers are contractually barred from using your content for their own purposes or for training AI models; we work towards processing without lasting storage of the transmitted content at the provider. For the basis of the third-country transfer, see Section 12.
Note on AI results: Content generated by AI can contain errors, inaccuracies or invented statements ("hallucinations"). It does not replace professional, legal, tax or medical advice. Please check all results yourself before using them.
10. Payment processing via Stripe
For paid subscriptions (Slaide Plus, Slaide Pro and Slaide Max) and usage-based pay-as-you-go billing we use the payment service provider Stripe (Stripe Payments Europe Ltd., Ireland; Stripe, Inc., USA). You enter your payment data (for example card data) directly with Stripe. We ourselves do not receive complete payment-instrument data, only the payment status, a customer reference and the information needed for contract and invoice handling.
You manage your subscription (for example cancellation, payment method) through the Stripe customer portal, which you can reach from the settings. Invoices and receipts are provided through Stripe.
The legal basis is Art. 6 (1) point (b) GDPR (performance of the contract) and Art. 6 (1) point (c) GDPR (compliance with commercial and tax obligations). Stripe's privacy notices apply in addition.
11. E-mail delivery and error monitoring
Transactional e-mails: To confirm your e-mail address, to reset your password and for account and security messages, we send e-mails through the service provider Resend (USA). Your e-mail address and the content of the respective message are processed for delivery. The legal basis is Art. 6 (1) points (b) and (f) GDPR.
Error and stability monitoring: To detect and fix technical errors we use Sentry. Technical diagnostic data is processed (for example error messages, browser and device information and, to a limited extent, technical connection data). Sentry is configured so that the transmission of standard personal data (in particular IP addresses) is disabled and none of the content you enter is transmitted. To a limited extent, a recording of the session flow (session replay) may be made for error analysis; all displayed texts as well as image and media content are automatically masked or hidden, so that your inputs and document contents are not captured, only the layout and the rough flow of interaction. According to our configuration, processing takes place primarily in the EU (Sentry region Germany). The legal basis is our legitimate interest in a stable and secure Service (Art. 6 (1) point (f) GDPR).
Privacy-friendly usage and performance measurement: To measure technically relevant page views, load times and rough funnel events, we use Vercel Web Analytics and Speed Insights. The measurement uses no analytics cookies and does not transmit document contents, orders or file names. Page views in the library, editor and settings as well as public share and referral links are discarded; product-related events are only transmitted with a neutral /app address. The legal basis is our legitimate interest in improving stability and user guidance (Art. 6 (1) point (f) GDPR).
When you use the optional Chrome extension, only rough, content-free product events are transmitted to the same service, such as opening the extension, the number of sources added, the start of an outline or a technical error. Web page contents, highlighted passages, URLs, titles, search terms and presentation contents are not transmitted as analytics events. The extension only sends content to Slaide when you explicitly add a source and request an outline or presentation.
Chrome Web Store – Limited Use: Data that the extension receives from a web page you explicitly selected is used exclusively to provide, secure and technically improve the described research, outline and presentation function. This data is not sold and is not used for personalized, behavioral or interest-based advertising. It is only passed on where necessary for this function, for secure operation or for legal obligations, and only for the described purpose.
12. Recipients and processors; third-country transfers
We use carefully selected service providers that process personal data on our behalf or as independent recipients. We have data processing agreements under Art. 28 GDPR with processors. The following overview names the service providers, their purpose and the place of processing:
| Service provider | Purpose | Place of processing |
|---|---|---|
| Vercel | Hosting, delivery, execution of document creation and rendering, and privacy-friendly usage and performance measurement | USA / EU |
| Supabase | Database, authentication, file storage | EU |
| OpenRouter | Routing of the AI models (transmission of order and content) and the language-model providers behind it | USA |
| OpenAI | Image generation (optional feature) | USA |
| Resend | Sending transactional e-mails | USA |
| Sentry | Error and stability monitoring (without content PII; session replay masked) | EU (region Germany) / USA |
| Stripe | Payment processing and invoices | Ireland / USA |
| Pexels | Stock photo search | USA |
| Brandfetch | Logo search | USA |
| Google / Apple | Optional sign-in (OAuth) | USA |
| AI assistants that you connect yourself (for example OpenAI, Anthropic, xAI) | Use of your Slaide account in the assistant, only after your consent and within the scope of your approval; independent controllers (see Section 13) | USA or depending on the provider |
Transfers to third countries: Where service providers process data (also) in the USA or other third countries, we base the transfer on the requirements of Art. 44 et seq. GDPR. We primarily rely on providers certified under the EU-US Data Privacy Framework (DPF) (adequacy decision of the European Commission); otherwise on the standard contractual clauses of the European Commission (Art. 46 (2) point (c) GDPR) together with supplementary safeguards. Despite these measures, third countries such as the USA may have a level of data protection that does not correspond to that of the EU in every respect; in particular, access by authorities there cannot be completely ruled out.
13. Connecting AI assistants (Model Context Protocol)
You can connect your Slaide account to an AI assistant from a third-party provider, for example ChatGPT (OpenAI), Claude (Anthropic) or Grok (xAI), or any other assistant that supports the Model Context Protocol (MCP). On your behalf, the assistant can then search, read, create, change and export documents in your library. The connection only comes about if you establish it yourself: you sign in to Slaide and expressly grant, on our consent page, the permissions shown there (read, write, export). Without this consent, an assistant gets no access to your account.
Which data is processed in the process:
- Connection data: the name of the application you connect (for example "ChatGPT"), the permissions granted, the time of consent and of last use, and technical identifiers of the connection. We store the access and refresh tokens exclusively as irreversible hash values.
- What the assistant receives from us when it asks: title, format, page count and time of last change of your own documents; where needed, the text, speaker notes and spreadsheet cells of a document it is to read; the status of the jobs it has started; and, for exports it requests, a private download link that is valid for 15 minutes. Not transmitted are your e-mail address, payment and invoice data, details of your plan or credit balance, and documents of other people.
- What the assistant hands to us: the order (instruction, any text provided and source addresses) and up to three file attachments per order, which it makes available to us through a time-limited download link. We process them like any other order and upload (Sections 8 and 9); we store attachments privately in the newly created document, and they are deleted together with the document.
- Images for display in the chat: If the assistant shows a card with the progress of a job, a page strip, a full-screen page view or an overview of your documents, your browser retrieves preview images of your own documents from us through the chat interface: the first pages side by side, individual pages at reading size, or the first page of a document. Each retrieval uses a signed link that is valid for 15 minutes and releases only this image. We generate the images on request, keep them only transiently in the working memory of our servers (reuse for 15 minutes at most) and create no permanent copy. Your browser may cache an image for up to five minutes.
- The way back into Slaide: If you click "Open in Slaide" in a card, we redirect you through an address of ours to your document. In doing so we count the click as part of the privacy-friendly usage measurement (Section 11), and only with the information where the button was and whether the card came from ChatGPT or another assistant, without a document identifier and without an account identifier. We append a source indication (
utm_source) to the destination address, which feeds into the rough source attribution under Section 15. - Operating data: server logs (Section 4), the limitation of request frequency per connection or per hashed IP address (Section 5), error reports in Sentry with tool and application name but without orders, document contents and tokens (Section 11), and event counters (tool, name of the application, duration, error class, whether a connection is new) in our privacy-friendly usage measurement (Section 11). Orders, document titles, page contents, tokens and e-mail addresses never belong in these counters.
Purposes and legal bases: We process this data to enable you to search for, create, edit and output your documents in the assistant, to secure the connection and to monitor its operation. The legal basis is Art. 6 (1) point (b) GDPR (providing the service you request through the assistant) and, where you approve the permissions on the consent page, Art. 6 (1) point (a) GDPR; you can withdraw the approval at any time, with effect for the future, by disconnecting the connection. For operating data, abuse prevention and the event counters it is Art. 6 (1) point (f) GDPR (a stable, secure Service and the question of whether the integration works).
Recipients: The provider of the assistant you choose (for example OpenAI, Anthropic, xAI) receives the content named above and processes it under its own responsibility in accordance with its own privacy terms, including in third countries such as the USA. It is not our processor, and we have no influence on its processing. As soon as an assistant reads a document, its content is also present in your conversation with the provider. Therefore connect only assistants whose terms you accept, and let them read only documents that you wish to entrust to the provider. For processing on our side, Sections 9 and 12 apply.
Retention periods:
| Data | Duration |
|---|---|
| Open consent request; authorization code | 10 minutes; 60 seconds |
| Access token | 1 hour |
| Refresh token | up to 60 days; used refresh tokens (hash value only) remain stored for up to 7 days after the connection is disconnected, to detect abusive reuse |
| Connection data | until disconnected; afterwards marked as revoked and deleted after 7 days |
| Jobs of the assistant and generated export files | 7 days, then deleted |
| Protection against duplicate execution of the same job | 24 hours |
| Download and image links | 15 minutes |
| Generated preview images on our servers | only transiently in working memory, reuse for 15 minutes at most |
| Documents and attachments | like your other documents, until you delete them (Section 16) |
| Server logs, error reports, event counters | only for the period necessary for troubleshooting and security (Sections 11 and 16) |
Expired tokens, codes and requests are deleted automatically on a regular basis. If you delete your account, we remove your connections together with their tokens, open requests, the assistants' jobs and the generated export files immediately with the account, without waiting for the periods above.
Your control: You can disconnect any connection at any time in Slaide under Settings → Account → AI assistants. When you disconnect, the tokens lose their effect immediately, and download and image links already issued for this connection stop working as well. In addition you can remove the connection in your assistant; what the assistant has already received then lies with the provider and can only be deleted according to its terms. An assistant can only do what your permissions and the tools of the interface allow: it can neither delete documents nor change a plan or buy anything, and every change it makes to a document is saved as a version and can be undone in Slaide. You can delete documents and attachments yourself at any time; you will find your further rights in Section 17.
14. Referral and ambassador programme
If you register through another user's referral link or share a referral link yourself, we process the assignment required for this in order to credit both sides correctly and to prevent abuse. The legal basis is Art. 6 (1) points (b) and (f) GDPR.
For selected ambassador links we additionally store a random-looking code, the time of the first call of the link and, after a verified registration, the one-time assignment. This serves the one-time credit of the ambassador welcome bonus, the operation of the ambassador programme, the settlement of qualifying remuneration and abuse prevention. The link assignment before registration expires after 90 days; after a verified registration the assignment remains stored for the settlement of further qualifying payments. In the ambassador area only aggregated results are shown, no data of referred persons.
15. Cookies and local storage
We use technically necessary cookies or comparable storage mechanisms, in particular to maintain your sign-in session (session/authentication). Under § 25 (2) of the German TDDDG no consent is required for this, because storage is strictly necessary to provide the service you expressly requested. For the ambassador link assignment described in Section 14, a time-limited first-party cookie may additionally be used; its legal classification will be finally reviewed before the public launch of the programme.
An order typed in before sign-in may be briefly cached in your browser's local storage or session storage so that it is not lost after login or registration. This storage takes place solely in your browser.
The Chrome extension first stores explicitly added web pages and highlighted passages locally in its extension storage, so that the research is preserved when the side panel is opened. These local drafts are only transmitted to Slaide after your action and can be removed by deleting the extension data. Login uses the existing Slaide session; passwords are not stored.
Source attribution (first-party, 180 days): On your first visit we store in a first-party cookie (slaide_ft) which page of our website you entered through and from which rough source (for example search engine, AI assistant, referral link, direct visit, utm_* parameters from a campaign). Of the referrer we store only the host name, never the full address, so that no search terms are recorded. If you register, this value is assigned once to your profile; it is not overwritten afterwards. The only purpose is to answer the question of which of our content actually brings new users. There is no cross-site tracking, no matching with third parties and no profiling for advertising purposes; the data does not leave our own infrastructure. The legal basis is our legitimate interest in an economically sensible orientation of our content (Art. 6 (1) point (f) GDPR). You can delete the cookie in your browser at any time; use of the Service is unaffected.
Optional Google ad measurement: If this function is switched on, we ask for your consent separately. Only after you agree do we store an ad click identifier passed on by Google (gclid, gbraid or wbraid) in a cookie of its own (slaide_google_click, for at most 30 days). In addition we store the time, the public entry path and, where the ad contains them, the campaign, ad group and ad identifiers and the keyword we booked. When you register, we assign this click to your account. Your choice is stored in slaide_ads_consent for at most 180 days. Declining and consenting are possible on equal terms; use of Slaide is independent of that choice.
To recognise which Google ads bring paying new customers, we may transmit the first successful live payment at Stripe to Google Ireland Limited from our servers. The report contains the ad click identifier, the time of payment, the amount, the currency and the Stripe transaction identifier. Document contents, orders, file names, private document addresses, email addresses and IP addresses are not transmitted to Google through this measurement function. We do not use it for ad personalisation. The function loads no Google advertising scripts in the browser; approving them in the content security policy is therefore not necessary.
The legal basis for the optional storage and the transmission to Google is your consent (Art. 6 (1) point (a) GDPR and § 25 (1) of the German TDDDG). You can withdraw it at any time via “Change Google measurement”. We then delete the click assignment and any transmission jobs for your account that are still stored with us; no further reports are sent. The withdrawal takes effect for the future and does not affect the lawfulness of processing that has already taken place. Information on processing by Google and possible international transfers can be found in Google's Privacy Policy and the information for users of websites that use Google services.
Click identifiers are also deleted from your profile and from open transmission jobs after 30 days at the latest; after successful processing by Google we remove them from the transmission job earlier. We keep the technical proof of delivery and any details needed for refund corrections for at most 60 days after the payment. An internal marker of the first purchase remains stored until the account is deleted or consent is withdrawn, so that a renewal is not reported again as a new purchase.
The cookie-free usage and performance measurement described in Section 11 remains separate from this choice. The rough source attribution, which is used exclusively internally, contains no Google click identifier.
16. Retention and deletion
We store personal data only for as long as necessary for the purposes named in this policy. Account, order and document data and uploaded files are stored for as long as your account exists. When your account is deleted, the associated content is irrevocably removed; you can delete individual documents and files yourself beforehand.
Data subject to commercial or tax retention duties (in particular payment and invoice records in connection with Stripe) we retain for the statutory periods (generally up to ten years) and block for other purposes. Server logs and the rate-limiting counters used for abuse defence (Section 5) are kept only for a short period necessary for security. For the data of the connection with AI assistants, the periods named in Section 13 apply; when your account is deleted, they are removed immediately with it.
17. Your rights as a data subject
Under the GDPR you have the following rights:
- Access to the data processed about you (Art. 15),
- Rectification of inaccurate data (Art. 16),
- Erasure (Art. 17),
- Restriction of processing (Art. 18),
- Data portability (Art. 20),
- Objection to processing based on legitimate interest (Art. 21).
Where processing is based on consent, you can withdraw it at any time with effect for the future, without affecting the lawfulness of the processing carried out until then. To exercise your rights, a message to the contact address named in Section 1 is sufficient.
18. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, your place of work or the place of the alleged infringement. The supervisory authority responsible for us is:
The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI BW) Lautenschlagerstraße 20, 70173 Stuttgart, Germany https://www.baden-wuerttemberg.datenschutz.de
19. Currency and changes
We adapt this privacy policy when data processing or the legal situation changes. The version published on this page at the time applies. As of: October 2026.
Imprint · Terms · Back to home