Skip to main content

Privacy Policy

Last updated: February 23, 2026

1. Introduction

Deckflo ("we," "us," or "our"), located in Mumbai, India, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our AI-powered content creation platform ("the Service").

By accessing or using the Service, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use the Service.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Full name, email address, and password when you create an account
  • Profile Information: Any additional information you choose to add to your profile
  • Payment Information: Billing details processed through our third-party payment providers (LemonSqueezy and PayPal). We do not store your credit card numbers or bank account details directly
  • Content Data: Presentations, flowcharts, infographics, dashboards, and any text, images, or data you upload or create using the Service
  • Communications: Any messages, feedback, or correspondence you send to us

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, actions taken within the Service, and time spent on pages
  • Device Information: Browser type, operating system, device type, and screen resolution
  • Log Data: IP address, access times, referring URLs, and error logs
  • AI Usage Data: Prompts submitted for AI generation, token usage, and generation metadata (we track this for usage limits and cost management)

2.3 Information from Third Parties

  • Authentication Providers: If you sign in using Google or Microsoft, we receive your name, email, and profile picture from those services
  • Payment Providers: Transaction confirmations, subscription status, and billing events from LemonSqueezy and PayPal

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the Service: To create and manage your account, generate AI content, store your creations, and enable collaboration features
  • Processing Payments: To manage subscriptions, process payments, and handle billing inquiries
  • Improving the Service: To analyze usage patterns, diagnose technical issues, and improve features and performance
  • Communication: To send you service-related notices, updates, security alerts, and support messages
  • AI Model Improvement: Aggregated, anonymized usage patterns may be used to improve AI generation quality. Your specific content is not used to train third-party AI models
  • Security: To detect, prevent, and respond to fraud, abuse, or security incidents
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers: With third-party providers who help us operate the Service, including:
    • Supabase (authentication and database hosting)
    • OpenAI (AI content generation - your prompts are sent to their API)
    • Unsplash (image search)
    • LemonSqueezy and PayPal (payment processing)
  • Collaboration: When you share content with collaborators, they can access the shared content according to the permissions you set (viewer, editor, owner)
  • Published Content: Content you choose to publish will be accessible via a public URL
  • Legal Requirements: When required by law, court order, or governmental authority
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction

5. Data Storage and Security

Your data is stored on secure servers provided by Supabase (built on PostgreSQL). We implement industry-standard security measures including:

  • Encryption in transit (TLS/SSL) and at rest
  • Row-level security (RLS) ensuring data isolation between users
  • Secure authentication with JWT tokens
  • Regular security monitoring and updates
  • Environment variable protection for API keys and secrets

While we take reasonable measures to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you the Service. Specifically:

  • Account Data: Retained until you delete your account or request deletion
  • Content Data: Retained until you delete the content or your account
  • AI Usage Logs: Retained for up to 12 months for analytics and billing purposes
  • Payment Records: Retained as required by applicable financial regulations

After account deletion, we may retain certain anonymized data for analytics purposes. Backup copies may persist for a limited period in accordance with our data backup policies.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete personal data
  • Deletion: Request deletion of your personal data (subject to legal retention requirements)
  • Data Portability: Request your data in a structured, commonly used, machine-readable format
  • Objection: Object to the processing of your personal data in certain circumstances
  • Withdrawal of Consent: Withdraw consent where processing is based on consent

To exercise any of these rights, please contact us at the email address provided below. We will respond to your request within 30 days.

8. Cookies and Tracking

The Service uses essential cookies and local storage for:

  • Authentication: To keep you signed in and maintain your session
  • Preferences: To remember your settings and preferences (theme, layout)
  • Session Data: To temporarily store content between pages (e.g., transferring generated content to editors)

We do not currently use third-party advertising or analytics cookies. If this changes, we will update this policy and provide notice.

9. AI and Data Processing

When you use AI generation features, your prompts and uploaded documents are sent to OpenAI's API for processing. Please note:

  • Prompts are transmitted securely to OpenAI's servers for processing
  • OpenAI's data usage is governed by their own privacy policy and API terms
  • We do not send your personal account information (name, email) to AI providers
  • Uploaded documents (PDF, DOCX, CSV, TXT) are processed server-side and only the extracted text is sent to the AI provider
  • AI-generated content is stored in your account and is not shared with other users unless you explicitly share or publish it

10. Children's Privacy

The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you become aware that a child under 13 has provided us with personal data, please contact us and we will take steps to delete such information.

11. International Data Transfers

Your information may be transferred to and processed in countries other than India, including countries where our service providers (Supabase, OpenAI, payment processors) are located. These countries may have different data protection laws. By using the Service, you consent to such transfers.

We ensure that appropriate safeguards are in place when transferring data internationally, including contractual protections with our service providers.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. For significant changes, we will notify you via email or a prominent notice within the Service.

Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.

13. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:

Email: akshat.ratanpal@gmail.com

Location: Mumbai, India

Platform: Deckflo

For data protection inquiries or to exercise your rights, please include "Privacy Request" in the subject line of your email.