Privacy Policy
Last updated: 17 July 20261. Who we are and how to contact us
Slidiz (“Slidiz”, “we”, “us”, or “our”) is operated by Embrella Labs Ltd. This policy explains how we handle personal data when you use the Slidiz website, editor, saved projects, exports, support channels, and billing flows.
For the processing described in this policy, Embrella Labs Ltd is the data controller unless a provider or external platform acts as a separate controller for its own service.
For privacy questions, rights requests, complaints, or deletion requests, email getslidiz@gmail.com or use our Contact page. A separate privacy-office or Data Protection Officer contact has not been identified in the current business records.
This policy was updated on 17 July 2026. It is not legal advice and remains subject to review by a qualified solicitor familiar with UK GDPR, data protection, and online-platform integrations.
2. What we collect
- Account information: email address, account identifier, and authentication records when you sign in.
- Content and project information: uploaded images, slide copy, edits, captions, project names, briefs, project drafts, and support messages.
- Service and technical information: feature activity, upload status, error information, browser information, IP address, and security events where these are made available to us by the service configuration or providers.
- Billing information: contact, customer, subscription, transaction, and invoice information needed for paid plans. Paddle handles checkout and is the merchant of record for those purchases.
Signed-out demo mode may keep projects and image data in your browser. Exported MP4s and ZIP files are downloaded to your device; the current export flow renders them in your browser and does not create a Slidiz social-publishing job.
Please do not upload sensitive personal information, confidential third-party information, or material you do not have permission to use.
3. Why we use information and our legal bases
- Provide, secure, maintain, and improve Slidiz.
- Authenticate accounts and save projects across sessions.
- Store uploaded images and create slideshow exports requested by you.
- Monitor reliability, prevent misuse, investigate errors, and provide support.
- Process subscriptions, billing, refunds, and customer-portal requests.
- Meet legal obligations and enforce our Terms of Service.
Where UK GDPR or another applicable law requires a legal basis, the basis may be performance of our contract with you, our legitimate interests in operating and securing the service, compliance with legal obligations, or consent where consent is required. The appropriate basis depends on the processing activity and the facts of your request.
4. Image processing, projects, and exports
Slidiz stores and processes uploaded images to provide editor previews, saved projects, and platform-sized exports. Signed-in project images are stored in the private slideshow-images storage bucket associated with the project. Deleting a project currently removes its project record and the image paths referenced by that project where the storage operation succeeds.
Local demo projects and their image cache are kept in browser storage. Clearing browser storage or deleting a local project removes that local copy; it does not remove files you have separately downloaded to your device.
5. Service providers and sharing
We share information only where needed to operate the service or comply with law, including with:
- Supabase for authentication, database, and private image storage.
- Vercel for hosting and the site analytics package currently included in the application.
- Paddle.com Market Limited for checkout, subscriptions, invoices, and payment administration.
- Google and YouTube when you authorize a YouTube channel and request a private video upload.
- Professional advisers, regulators, courts, or law enforcement where legally required.
We do not sell your personal data. If we restructure, merge, or sell part of our business, information may transfer subject to appropriate safeguards and applicable law. YouTube receives video and metadata only when you expressly request an upload. TikTok, Meta, and Instagram do not currently receive connected-account data from Slidiz.
6. International transfers
Slidiz and its providers may process information outside the country where you live. The current repository identifies providers but does not establish the complete list of processing countries, transfer mechanisms, or sub-processors.
[REQUIRED: CONFIRM PROCESSING LOCATIONS, INTERNATIONAL TRANSFER MECHANISMS, AND CURRENT SUB-PROCESSORS BEFORE THIS POLICY IS TREATED AS FINAL]
7. Retention
We retain account and project information while it is needed to provide the service, support a request, maintain security, resolve disputes, process billing, or meet legal obligations. Project deletion removes the project data described in section 4. Limited backup, billing, security, or support records may remain where necessary for those purposes.
[REQUIRED: INSERT THE OPERATIONALLY VERIFIED RETENTION SCHEDULE FOR EACH DATA CATEGORY; NO FIXED DELETION PERIOD IS PROMISED BY THIS POLICY]
8. Security
We use reasonable technical and organisational safeguards designed to protect information, including authenticated access controls and private image storage. No online service is completely secure. You are responsible for protecting access to your email account, devices, and Slidiz sessions.
9. Your rights and complaints
Depending on your location and the applicable law, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, receive a copy of certain data, and withdraw consent where processing relies on consent. Contact us at getslidiz@gmail.com to exercise a right.
We may need to verify your identity before acting on a request. You may also complain to the data-protection regulator responsible for your location. In the UK, this is generally the Information Commissioner's Office (ICO).
10. Account deletion and data requests
The current product provides project-level deletion but does not expose a self-service account-deletion control or an automated platform-data deletion callback. To request deletion of your Slidiz account, project data, or any information associated with a YouTube connection, follow the instructions on our Data Deletion page or email support.
Deleting information from Slidiz does not delete an MP4, image, or project file already downloaded to your device. It also does not delete content already published or stored on YouTube, TikTok, Instagram, or another external platform; use that platform's own controls for external content.
11. External social-platform integrations
Current status checked 17 July 2026: Slidiz uses YouTube API Services to let signed-in users connect a YouTube channel and explicitly upload a video as private. TikTok, Meta, and Instagram account connections are not currently available.
When Slidiz offers an external-account integration, it will describe the integration as available before asking for authorization, request only permissions required for the feature, explain the data received and why it is needed, and require the user's express approval for any upload or publishing action. Users will retain control of their external accounts. The platform's own terms, privacy rules, content moderation, availability, and deletion controls will continue to apply.
YouTube API Services
Slidiz accesses the YouTube channel identity you authorize, including the channel name, channel handle, channel ID, and channel thumbnail where available. Slidiz stores that channel identity, the encrypted refresh token, connection status, and records needed to prepare and track an upload. YouTube access tokens are used transiently and are not stored. Slidiz does not access your YouTube viewing history, subscriptions, comments, likes, contacts, or unrelated videos.
Authorization is used only to connect the channel you choose and upload a video, title, description, audience declaration, and synthetic-media declaration when you expressly select Upload privately to YouTube. Videos are uploaded as private so you can review them in YouTube Studio before changing visibility. Slidiz follows the Google API Services User Data Policy, including applicable Limited Use requirements.
You can revoke Slidiz's YouTube access by disconnecting YouTube in Slidiz Connections, or through Google's third-party access settings. To request deletion of your Slidiz account, connected-channel information, encrypted refresh token, upload records, or other YouTube-related data stored by Slidiz, follow our Data Deletion instructions or email getslidiz@gmail.com. Disconnecting YouTube, revoking authorization, or deleting data held by Slidiz does not delete videos or other content held by YouTube. Delete or manage those videos in YouTube or YouTube Studio.
See the YouTube API Services Developer Policies, Google API Services User Data Policy, Google Privacy Policy, and YouTube Terms of Service.
TikTok for Developers — future integration only
If Slidiz later uses TikTok for Developers services, the relevant authorization screen will identify the TikTok account information and permission categories requested, why each is needed, whether the flow is Upload or Direct Post, and what data is sent. Users will expressly approve sending or publishing content and will be able to edit captions and relevant metadata when the feature supports it. TikTok may process, moderate, delay, restrict, or remove content, and controls final visibility and availability.
Users will remain subject to TikTok's Terms of Service, Community Guidelines, music rules, branded-content rules, and other applicable policies. Slidiz will not describe Direct Post as audited or public until documentary evidence supports that statement. See the TikTok App Review Guidelines, Content Posting API guidelines, and TikTok developer guidelines.
Meta and Instagram Platform — future integration only
If Slidiz later uses Meta or Instagram Platform services, the authorization flow will identify the information accessed, each permission category requested, the purpose for each permission, and any service-provider sharing. Availability may be limited to eligible Instagram account types under the then-current Instagram Platform documentation. Meta and Instagram will control processing, moderation, and availability of content on their services.
Users will be able to disconnect the account through Slidiz when that control exists and request deletion of Meta or Instagram data stored by Slidiz. Deleting data from Slidiz will not automatically delete content already published on Instagram; use Instagram or the relevant Meta product to manage that content. See the Meta Platform Terms, Meta Developer Policies, and Instagram content-publishing documentation.
12. Cookies and local storage
Slidiz uses essential cookies or browser storage for authentication, session security, local demo projects, and the local image cache. The application includes Vercel Analytics; the exact activation, consent, and retention configuration must be confirmed before any non-essential analytics claim is treated as final.
13. Changes to this policy
We may update this policy as Slidiz, its providers, the law, or any external integration changes. We will update the date above and provide additional notice where required.
14. Trademarks
All product names, logos and brands are property of their respective owners. Use of these names does not imply endorsement. Slidiz is not affiliated with, sponsored by, or endorsed by YouTube, Google, TikTok, Meta, or Instagram unless a formal relationship is expressly confirmed.