Privacy Policy

Last updated: 19 September 2026. This policy covers the SlideSmith Chrome extension, the SlideSmith sidekick add-on for Google Slides, and the website useslidesmith.com.

1. Who is responsible

SlideSmith is published by Olivier Fournier, an individual developer based in France, who is the data controller. Contact for anything in this policy: [email protected].

2. The short version

3. What SlideSmith processes, and why

DataPurposeKept for
Email address (from Google sign-in or typed for an email code)Identify your account and resolve your license or seatWhile your license or your organisation's subscription exists; deleted on request afterwards
One-time sign-in codes (stored hashed)Email-code sign-in10 minutes
Session records: a hashed session token, a random identifier of the extension installation, extension version, browser family, first and last activity datesKeep you signed in, count devices per account, detect license sharingDeleted 30 days after the last activity or after you sign out
Organisation and seat records: organisation name, administrators' and members' emails, seat count, validity datesLicense management by you or your organisation's administratorWhile the subscription exists; deleted on request afterwards, except invoices, kept as long as the law requires
Chart numbers: the numeric values of a chart, series visibility flags and measured label widthsCompute the chart model and the label layout on the serverNot linked to your account. The computed result is cached for up to 24 hours under a hash of the numbers, then deleted
Feedback you choose to send: your message, optional attachments, extension version and a technical log of the session (never slide content)Support and product improvement24 months
Audit log: sign-ins, license decisions (sampled), administrative actions, with the email concernedSecurity and dispute resolution12 months
Server request logs: IP address, time, route, status. Request bodies are never loggedSecurity, rate limiting, debuggingA few days, at our hosting provider
Payment data, once paid plans open: handled by Stripe. SlideSmith receives the customer and subscription identifiers, never the card or bank detailsBillingAs long as the law requires for accounting records

Legal bases under the GDPR: performance of the contract with you (account, license, chart computation, billing), legitimate interest (security, abuse prevention, product improvement from feedback), and legal obligation (accounting records).

4. What stays on your side

5. Google user data

When you sign in with Google, SlideSmith requests the openid, email and profile scopes and keeps only your email address. The add-on requests access to Google Slides presentations and permission to show its interface inside Slides; it uses them only to insert and update SlideSmith charts in the presentation you are editing. SlideSmith's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used for advertising, never sold, never used to train models, and is not read by humans except where you ask for support, for security purposes, or where the law requires it.

6. Cookies

The website sets two strictly necessary cookies: one that keeps you signed in on useslidesmith.com and a short-lived one that protects the Google sign-in round trip. There are no analytics, advertising or third-party tracking cookies, so there is no cookie banner.

7. Who processes data on SlideSmith's behalf

ProviderRoleLocation
CloudflareHosting of the API, the database (Western Europe) and the website; request logsEU and worldwide edge network
GoogleSign-in; fonts loaded by the website and the extension; the platform the add-on runs onEU and United States
ResendSending sign-in codes and forwarding feedback by emailUnited States
Zoho MailThe support mailboxEU
Stripe (once paid plans open)Payments, invoices, tax calculationEU and United States

Transfers outside the European Economic Area rely on the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework, as offered by each provider.

8. Security

All traffic is encrypted in transit. Session tokens and sign-in codes are stored hashed. The administration console is behind a separate identity check. Request bodies are never written to logs.

9. Your rights

You can ask for access to your data, its correction, its deletion, its portability, or object to or restrict its processing, by writing to [email protected]. Signing out in the extension's Settings revokes the session on that device; the Account page lists and revokes your other devices. If your seat comes from your employer, some requests may need to go through your organisation's administrator. You may also lodge a complaint with your data protection authority; in France that is the CNIL (cnil.fr).

10. Children

SlideSmith is a professional tool and is not directed at children under 16.

11. Changes

When this policy changes materially, the date at the top changes and signed-in users are told by email or in the extension before the change takes effect.