Privacy Policy
Last updated 25 August 2026
What we collect
- Account data: name, email, organisation name, and a bcrypt hash of your password. We never store the password itself.
- Content you upload: the .pptx, .xlsx, .docx, .pdf, .csv and .md files you attach, plus the text extracted from them.
- Content you generate: decks, slides and chat messages.
- Usage records: which actions ran, when, and what they cost in credits and provider tokens. This is what billing is computed from.
- Product analytics: which pages you open and which actions you take, recorded against your account id so we can see where the product is confusing. Pages are recorded as patterns, so
/decks/[id], never the id of your deck. We do not capture clicks automatically, we do not record your screen, and we do not store your IP address. Deck contents, prompts, file names and uploaded documents are never sent.
We do not use tracking or advertising cookies. Your session token and your analytics id are held in your own browser’s storage, and nothing about you is shared with advertisers or data brokers.
Who else processes your data
- Anthropic and OpenAI: the text of your prompts and the relevant parts of your documents are sent to these providers to generate slides. This is the core function of the product and cannot be switched off.
- Stripe: payments. Card details go to Stripe, never to us.
- Resend: verification and password-reset email.
- Product analytics: a third-party analytics provider, hosted in the United States. It receives the events above and your account id. It never receives your documents or decks.
- Fly.io and Neon: application hosting and database.
We do not sell your data, and we do not use your documents or decks to train models.
Where it is kept, and for how long
Data is held for as long as your account is open. Delete a document or deck and it is removed from the database; close your account and we delete your organisation, its content and its analytics profile within 30 days. Backups age out within a further 30 days. Usage and billing records are kept as long as tax and accounting rules require.
Security
Traffic is encrypted in transit. Passwords are bcrypt-hashed. Verification and reset links are stored only as hashes, expire, and can be used once. Every organisation’s data is scoped to that organisation at the query level.
Your rights
You can request a copy of your data, correct it, or have it deleted. Email privacy@bankerdeck.com and we will respond within 30 days. If you are in the UK or EU you may also complain to your data protection authority.
Children
Bankerdeck is a business tool and is not intended for anyone under 18.
Changes
Material changes will be emailed to the address on your account before they take effect.