Privacy Policy
SlimPPT ("we") explains in this Privacy Policy how 上海轻柚信息科技有限公司, as operator, collects, uses, stores, shares, and protects personal information when we operate the Service globally, and what choices you have. By using the Service, you acknowledge this policy. Privacy requests (including account deletion): contact@sliiu.com (subject: "privacy request").
Version 1.3.0 · Effective August 26, 2026
1. Scope
This policy applies to slimppt.cn, the account console at dash.slimppt.cn, the online editor at edit.slimppt.cn, and related support channels we operate.
Third-party sites we link to have their own policies.
2. Information we collect
Depending on how you use SlimPPT:
- Deck content: core editing runs locally in your browser. When you open a file from the marketing site into the editor, we prefer a browser-to-editor handoff; if the popup is blocked and you are signed in, the full file may transit our servers briefly. After it opens, drafts are kept in your browser by default, and you may choose to sync to the cloud. When you save .pptx or export HTML, PDF, PNG, or similar formats, the content needed to generate the file is sent to our servers (used only for that generation; see section 4). If you use online storage or online share, encrypted backups or read-only presentation copies are retained on our servers while you use those features
- Account data: email, display name, password hash when you register and sign in; necessary identifiers when you use OAuth sign-in
- Subscription and usage: plan tier, subscription status, export page counts, online storage bytes used (not deck content)
- Payment metadata: customer or order identifiers, billing period, and subscription status handled by our payment providers (Stripe globally; Alipay / WeChat Pay channels in mainland China); we never receive or store full card numbers or CVV
- Technical data: IP address, device/browser, OS, timestamps, paths, referrer, and coarse location derived from IP
- Communications: emails and attachments you send us
- Cookies and storage: language, theme, legal and cookie consent records; analytics cookies after consent (Baidu Analytics in China, Baidu Analytics globally)
3. How we use information
We process information for the purposes below on legal bases such as contract, legitimate interests (balanced against your rights), consent, or legal obligation:
- Provide, maintain, secure, and improve the Service
- Manage accounts, quotas, and abuse prevention
- Respond to support and send necessary service notices
- Run aggregated analytics via consented analytics cookies when you consent (see Cookies and similar technologies)
- Comply with law and protect rights
4. Local-first SaaS and AI
SlimPPT is an online SaaS service. Core editing runs in your browser. When you open a file from slimppt.cn into the editor, we prefer a browser-to-editor handoff; if the popup is blocked and you are signed in, the full .pptx may transit our servers briefly. After it opens, it is kept in your browser by default, and you may choose to sync to the cloud (online storage).
Routine editing does not keep full decks on our servers by default; content sent for save or export is not retained long term after the file is generated. Online storage, online share, live collaboration, and similar features require separate opt-in.
Online storage (encrypted upload): your deck is encrypted in the browser with a passphrase you choose before upload, and we store ciphertext and metadata only. Please note: if you turn on passphrase sync so you do not have to re-enter it on each device, that passphrase is stored in our account database, and we are then technically able to decrypt your cloud files. If you leave that option off we cannot decrypt them — but we also cannot recover your data if you lose the passphrase.
While a paid subscription with online storage is active, we do not delete files for inactivity. After cancellation or loss of entitlement, ~180 days without access may trigger an email reminder; ~365 days without access may delete ciphertext (per in-product notices).
Online share: we host a read-only HTML playback copy on our servers. Unlike online storage, this copy is stored unencrypted and is technically readable by us, so please do not share decks containing sensitive information. Default link lifetime is ~90 days, with optional link passwords stored as hashes. Share does not count toward export pages or online storage quota.
Live collaboration: when enabled, your real-time edits are relayed through and temporarily stored on our servers, unencrypted, so that others in the same room stay in sync.
Server-side save and export: when you save .pptx / .pptm, or export HTML, HTML zip, PDF, PNG, video, or similar formats, we send the content needed to generate the file to our gateway—including the deck structure, embedded media, and (for PPTX save) any original archive included with the request. PDF and PNG also send page images already rendered in your browser. That data is used only to produce the requested download and is not retained long term. JSON export still runs in your browser. Creating or updating an online share also sends the full deck so we can generate the hosted read-only HTML copy (see Online share above).
Custom AI skills: if you edit custom skills while signed in, their text is synced to our servers so it is available across your devices.
To enforce plan quotas, when you download a deck locally (e.g. .pptx, PDF), we record slide/page counts for monthly accounting; creating/updating shares, cloud uploads, and local autosave typically do not count.
Account, quota, and security-related data may be processed where we or our infrastructure providers operate; see Global processing and Region-specific notices.
AI features are bring-your-own-key (BYOK): you purchase model access separately from a third-party vendor (e.g. OpenAI, Anthropic, Google, or any other compatible platform you configure) and enter your own API key. Prompts, the deck text you select or that AI tools read, and the generated output are sent from your browser directly to that vendor and never pass through our servers. Your API key is kept only in your browser's local storage; we do not store it server-side and do not bill you for model usage.
A consequence of this design is that the vendor receives your IP address along with that content directly. We do not guarantee accuracy or legality of model output; review before use and comply with the vendor's terms and privacy policy.
5. Training, analytics, and advertising
We do not sell personal information and do not run targeted ads inside the editor.
We do not use your decks, uploaded ciphertext, share copies, or AI chats to train machine learning or generative models.
We may collect non-content operational data (errors, performance, API volume) to keep the service secure and reliable.
6. Sharing, disclosure, and third parties
We do not sell personal information. We may share when:
- You consent
- Processors under contract need data to help us (hosting, database, email, payments, identity) — see the next section for the list
- Law or valid government request requires it
- Needed to protect rights, safety, or property
- Business transfer with continued protection
7. Third parties we use
The third parties below take part in processing. Which ones apply depends on the features you use and on our deployment configuration. Services marked as browser-direct are contacted by your device itself, so the vendor receives your IP address directly and their own privacy policy governs that processing.
Called server-side by us, as our processors:
- Payments: Stripe in the global market (receives your email, account identifier, subscription and billing status; full card numbers and CVV are collected by Stripe directly and never reach us); in mainland China, our payment provider settles via Alipay / WeChat Pay (receives order number, amount, and an account identifier for reconciliation)
- Sign-in: Google and Apple third-party sign-in (we receive the email address and user identifier they return)
- Email: Resend or an operator-configured SMTP provider, used for verification codes, password resets, and idle online-storage reminders (receives your email address and the message body, which for idle reminders may include deck names)
- Infrastructure: the cloud providers hosting our gateway, database (PostgreSQL), and file storage, which hold account data, encrypted files, and share copies
- Site analytics: loaded only after your consent (Baidu Analytics in mainland China, Google Analytics globally) — see section 12
8. Browser-direct third parties
The services below are requested by your browser when you use the corresponding feature. That data does not pass through our servers and we cannot see the request contents:
- AI model and AI image vendors you configure yourself (see section 4) — receive prompts, referenced deck text, and image generation descriptions
- Stock imagery: Unsplash and Pexels, enabled only after you supply your own API key — receive your search keywords
- Fonts: Google Fonts, requested by family name when a theme or font is applied
- Lookup and translation: MyMemory translation, Datamuse thesaurus, Free Dictionary, and Wikipedia summaries, only when you open the translate / thesaurus / smart lookup panels — receive the words you look up
- Public CDNs (jsDelivr, unpkg): load runtime libraries and language packs on demand for handwriting recognition (OCR) and recording transcoding; the recognition and transcoding themselves run on your device
- Addresses you enter yourself: custom model endpoints, proxy URLs, remote MCP servers, and remote 3D model links — you choose these and accept the associated risk
9. Retention
We keep data only as long as needed for the purposes above or as law requires.
Decks imported from the marketing site are kept in your browser by default; if you choose cloud sync, they are retained per online storage rules and this policy. Server-side data used only to complete import is handled per in-product notices after the import purpose is fulfilled.
Online storage ciphertext is kept until you delete it or idle rules apply after cancellation; share copies are kept until link expiry or you revoke.
After account closure or deletion requests, we delete or anonymize within a reasonable period unless retention is legally required.
10. Global processing and safeguards
We operate a global Service. Your information may be processed in any country where we or our providers operate, which may have different data protection laws than your residence.
When we transfer personal data across borders, we implement appropriate safeguards required by applicable law, such as standard contractual clauses or equivalent mechanisms.
We apply the same global processing principles to all users; we do not maintain separate “domestic” and “foreign” privacy regimes. See Region-specific notices for local deployment details.
11. Security
We use HTTPS, access controls, and logging appropriate to risk.
No method of transmission is 100% secure—protect your password and log out on shared devices.
12. Cookies and similar technologies
Essential storage remembers language (app-locale), theme, and your choices about these Terms, the Privacy Policy, and cookies.
Non-essential analytics cookies load only after consent, enabling Baidu Analytics under Baidu under https://tongji.baidu.com/web/help/article?id=330&type=0. We enable 去标识化等隐私增强设置 where supported.
Decline non-essential cookies on the banner or withdraw via footer settings; we stop loading analytics afterward.
Browser controls may also block cookies; some features may be affected.
See each analytics provider's privacy policy and terms (Baidu help center at https://tongji.baidu.com/web/help/article?id=330&type=0).
13. Your rights
Where applicable law grants them (e.g., GDPR, UK GDPR, certain US state laws, PIPEDA, LGPD, or other local privacy laws), you may:
We respond within 15 business days of receiving your request, unless law requires otherwise
- Access, correct, or delete personal information
- Restrict or object to certain processing
- Receive a portable copy where technically feasible
- Withdraw consent without affecting prior lawful processing
- Lodge a complaint with a supervisory authority
Mainland China (PIPL)
If you are in mainland China, 上海轻柚信息科技有限公司 processes personal information under the Personal Information Protection Law (PIPL) and related rules.
- Controller: 上海轻柚信息科技有限公司
- Personal information protection contact: contact@sliiu.com (subject: "PIPL request")
- Purposes and categories: see Sections 2–3; we collect only what is necessary
- Retention: see the Retention section
- You may access, copy, correct, supplement, delete data, withdraw consent, or request an explanation of processing
- How to exercise rights: email contact@sliiu.com; we respond within 15 business days
- Complaints: you may contact your provincial cyberspace administration or other competent authority
- Mainland analytics: China deployments use Baidu Analytics (domestic service), not Google Analytics
- Cross-border transfers: except where necessary to operate the Service (e.g. linked products, marketing-site import) or features you actively choose (third-party links, cloud sync, cloud storage, or APIs you configure), our China deployments prioritize domestic processing and storage
14. Region-specific notices
EEA/UK: Processing may rely on contract, legitimate interests, or consent; you may complain to your local authority.
California and similar US states: we do not sell personal information; you may request access, deletion, or correction where applicable.
Other regions: contact us to exercise rights available under your local law; we respond within statutory or reasonable timeframes.
15. Minors
Our services are intended for adults. We do not knowingly collect personal information from children under 14.
Users under 14 need express guardian consent and supervision and should not submit personal information.
If we learn we collected a child's data without guardian consent, we will delete it promptly.
16. Your responsibility under local law
You are responsible for ensuring your use of the Service and your Content comply with laws where you live and where Content is used, including privacy, IP, and export rules.
We may disclose information when legally required or reasonably necessary.
17. Changes to this policy
We may update this policy with a new version and effective date on this page. Material changes may be announced on the site and may require renewed consent where required by law.
Privacy requests: contact@sliiu.com.