Effective Date: 11 August 2026 Last Updated: 11 August 2026 Version: 1.0
This Policy explains what personal data Slides by Karya collects, why, who we share it with, how long we keep it, and what rights you have.
Who we are. Karya, a partnership firm registered under the Indian Partnership Act, 1932 (Reg. No. 3263 of 2026), of New Delhi, India ("we", "us", "our"). We are the controller (Data Fiduciary under India's DPDP Act) for the data described in §3, except where §2 says otherwise.
Region-specific rights are in the annexes: EEA/UK · United States · India
1. The short version
- Your decks are stored on our servers — slides, speaker notes, and version history — so you can reach them from any device and restore earlier versions. A working copy is also cached in your browser.
- Your brief and uploaded source files are sent to a US AI provider to generate your deck, and are kept on our servers for up to 7 days so a crashed generation can resume without charging you twice. Then deleted.
- We do not use your content to train AI models, and our AI provider is contractually barred from doing so.
- We run no advertising, no behavioural analytics, no tracking pixels, and we do not sell or share your data for advertising.
- You can export or delete everything from your account page.
2. Our role
2.1. We are the controller for your account, authentication, billing, usage, security, audit, and support data.
2.2. We are a processor for personal data that you put into the Service about other people — including the content of your briefs and source files, and responses your audience gives to interactive poll blocks in a deck you share. For that data you are the controller, you decide the purpose, and you are responsible for having a lawful basis and giving the required notice. Our Data Processing Addendum governs that processing for business customers.
3. What we collect and why
| Data | Why | Where it lives | How long | Lawful basis |
|---|---|---|---|---|
| Email, name, password (hashed with bcrypt — never stored in plain text), date of birth, email-verification status | Create and secure your account; confirm you are 18+ | Postgres | Until deletion + 30 days | Contract; legal obligation (age) |
| Session token | Keep you signed in | httpOnly cookie | Session lifetime | Contract |
| IP address | Rate limiting and abuse prevention | Postgres, transient | Short rolling window | Legitimate interest (security) |
| Approximate country from IP | Show prices in your currency | Not stored — looked up at request time | Not retained | Legitimate interest |
| Payment references from our payment processor, plan, subscription status | Take payment; prevent double-charging; issue invoices | Postgres | Financial record — up to 8 years (Indian tax law) | Contract; legal obligation |
| Credit balance and ledger | Run the credits system; refunds | Postgres | Financial record | Contract |
| Briefs, prompts, and uploaded source files | Generate your deck; resume a crashed generation without re-charging you | Sent to Model Provider; stored in Postgres | Up to 7 days, then deleted automatically | Contract |
| Generated slide content (during generation) | Resume a crashed job without paying for the model twice | Postgres job checkpoints | Up to 7 days, then deleted automatically | Contract |
| Your decks — title, theme, slides, and speaker notes | The product | Postgres, plus a working copy cached in your browser | Until you delete it, or 12 months after you last open or edit it | Contract |
| Shared deck content | Serve your public share link | Postgres | 90 days, then permanently deleted | Contract |
| Audience responses to poll blocks | Show aggregate results | Postgres | Deleted with the share | You are the controller |
| Usage and cost telemetry | Measure AI cost; set credit prices | Postgres | 365 days | Legitimate interest |
| Audit events (sign-in, billing, admin, deletion) | Security and accountability | Postgres | Defined window; purged on account deletion | Legal obligation; legitimate interest |
| Organization membership and roles | Team features and shared wallet | Postgres | Until deletion | Contract |
| Support emails | Answer you | Mailbox | 24 months | Legitimate interest |
We do not collect: payment card numbers (our payment processor handles those; we never see them), government identifiers, biometric data, precise location, or advertising identifiers.
4. How AI processing works
This is the most important section for a product like ours. Please read it.
4.1. What is sent. To generate or edit a deck, we transmit your brief, your prompts, your uploaded source files, and any style references to a Model Provider that runs the AI model and returns the result.
4.2. Where the processing happens. Text generation and copilot editing use an open-weights AI model run by a third-party inference provider located in the United States. Image generation uses a separate third-party provider, also in the United States.
We deliberately run the open-weights model on a US-based host rather than using the model author's own API, so that your content is handled by a provider with SOC 2 Type II assurance, contractual zero data retention, and enforceable EU and UK data-protection commitments.
We identify our providers by name to business customers on request — see §6.
4.3. No training on your data. We do not use your content to train, fine-tune, or improve any AI model. Our Model Providers are contractually required not to train on, or retain beyond what is operationally necessary, the content we send them. Our text provider's default position is that prompts and generations are not logged or stored without explicit opt-in, and we do not opt in.
4.4. What we keep, and for how long. Your brief, source files, and the generated slides are stored on our servers for up to 7 days, in the generation job record. This exists for one reason: if the generation crashes partway, we can resume it without calling the AI model again and without charging you twice. After 7 days the job and everything in it is deleted automatically. Deleting your account deletes it immediately.
4.5. We do not read your content. We do not routinely access, review, or monitor your briefs, decks, or outputs. We may access specific content only to investigate a security incident, respond to a valid legal demand, or act on an abuse report — and only to the minimum extent necessary.
4.6. AI output. Decks and edits produced by the Service are AI-generated and are labelled as such where shared. See the AI Transparency Notice.
5. Where your decks are stored
Your decks are stored on our servers, in our database. That includes the slide content, your theme and formatting, and any speaker notes you write. A working copy is also cached in your browser so the editor stays fast.
Decks expire after 12 months. A deck you have not opened or edited for 12 months is deleted automatically, along with everything in it. We do this so old work does not sit on our servers indefinitely. Export anything you want to keep long-term.
Who can see your decks. By default, only you. If you belong to an organization, you can set a deck's visibility to organization, which lets every approved member of that organization view it. That is your choice per deck and is off unless you turn it on.
Can we read them? We do not routinely access, review, or monitor your decks — see §4.5. But they are on our systems, so technically we can, and we will if a security incident, a valid legal demand, or an abuse report requires it. Do not store anything in a deck that you would not want us to be able to access.
Deletion. Deleting a deck deletes it and all its content. Deleting your account deletes all of them. See §8.
Published shares are a separate copy, served at a public link and deleted after 90 days — see Terms §13.
6. Who we share data with
We share the minimum necessary with vendors who process data on our behalf under contract. By category:
| Category | Location | What they get |
|---|---|---|
| AI inference provider — text and copilot | United States | Briefs, prompts, uploaded source content |
| AI image provider | United States | Image prompts |
| Payment processor | India | Name, email, payment reference, amount. Card details go directly to them — we never receive or store them. |
| Email provider | United States | Email address, message content |
| Hosting provider | [[CONFIRM REGION]] | All server-side data |
| IP-to-country lookup | — | IP address at request time, to display your currency. Not stored. |
Named list on request. We identify each provider by name, with its location and the safeguards that apply, to any customer who asks — support@the-karya.com. Business customers under our Data Processing Addendum also receive 30 days' notice before we add or replace one, with a right to object.
We also disclose data where legally required — to comply with a valid court order or legal process, to enforce our Terms, or to protect the rights, property, or safety of our users, the public, or us. Where we are legally permitted to tell you first, we will.
If we are involved in a merger, acquisition, reorganisation, incorporation, or sale of assets — including any conversion of Karya to a successor entity of any form — data may transfer as part of it, with notice to you beforehand.
We do not sell your personal data. We do not share it for cross-context behavioural advertising. We do not use it for advertising at all.
7. International transfers
We are based in India. Our AI providers are in the United States. If you are in the EEA, UK, or Switzerland, your data therefore leaves your region.
We rely on the European Commission's Standard Contractual Clauses (2021), the UK International Data Transfer Addendum, and the Swiss addendum where applicable, together with technical and organisational safeguards — encryption in transit and at rest, contractual zero-retention, and data minimisation. We have carried out a transfer impact assessment; a summary is available to business customers on request. See Transfer Mechanisms.
Where you are in India, transfers outside India are made in accordance with the conditions permitted under the DPDP Act.
8. How long we keep data
Retention is set out per data type in the table at §3. The principles:
- Account data — until you delete your account, plus a 30-day grace period. You can ask us to skip the grace period and delete immediately.
- Decks (slides and speaker notes) — until you delete them, or 12 months after you last opened or edited them, whichever comes first.
- Generation jobs (briefs, source files, generated slides) — 7 days.
- Shared decks — 90 days, then permanently deleted.
- Usage telemetry — 365 days.
- Financial records — as long as tax and accounting law requires (in India, typically up to 8 years). These cannot be deleted on request.
- Everything else — deleted when the purpose is served.
Deletion is a real database delete, not a soft flag. Limited copies may persist in encrypted backups for a short period before those backups rotate.
Full detail: Data Retention Schedule.
9. Security
We apply, among other measures: passwords hashed with bcrypt and never stored in plain text; JWT sessions with server-side version invalidation, so a password reset or "sign out everywhere" kills old sessions; per-route rate limiting; cross-origin request protection; server-side authorisation on every data access; sanitisation of all model-generated HTML before it is stored or rendered; sandboxed, script-free rendering of untrusted deck content; input validation and request size limits; audit logging of authentication, billing, admin, and deletion events; and encryption in transit.
No system is completely secure and we do not claim otherwise. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulator where the law requires — see Incident Response Plan.
Report a vulnerability: support@the-karya.com.
10. Your rights
Wherever you are, you can:
- Access and export everything we hold about you — one click from your account page, as a machine-readable file (never including your password hash).
- Correct inaccurate details.
- Delete your account and associated data permanently.
- Object or withdraw consent where processing relies on it.
- Complain to us, and to your data protection regulator.
We respond within 30 days. We may need to verify your identity first — we will ask for the minimum needed. Exercising these rights is free; we may charge only for manifestly unfounded or excessive repeat requests.
Some data cannot be deleted on request: financial records we must keep for tax law, and a minimal record that an account was deleted (so it is not silently recreated). Some deletions require closing the account, because the Service cannot run without account data.
Region-specific rights and how to exercise them: Annex A, Annex B, Annex C.
Contact: support@the-karya.com
11. Cookies
We use strictly necessary cookies only — a session cookie to keep you signed in, and cookies our payment processor sets during checkout. We use no advertising, remarketing, behavioural-analytics, or profiling cookies, and we embed no third-party trackers or social pixels.
Because we set no non-essential cookies, we do not show a consent banner. If that ever changes, we will ask for your consent first and honour Global Privacy Control signals. Details: Cookie Notice.
Disabling essential cookies will prevent you from signing in.
12. Children
The Service is for people aged 18 and over. We ask for your date of birth at sign-up and block under-18 registration. We do not knowingly collect data from children, and we do no tracking or targeted advertising directed at anyone.
If you believe a child has given us data, contact support@the-karya.com and we will delete it.
13. Changes
We may update this Policy. For material changes we will notify you by email or in-product at least 15 days before they take effect, and post the updated version with a new date. Previous versions are available on request.
14. Contact
Karya — New Delhi, India
| Privacy and data requests | support@the-karya.com |
| Grievance Officer (India) | Aarya Banthia — support@the-karya.com |
| Security | support@the-karya.com |
Annex A — EEA/UK (GDPR)
A.1. Controller. Karya, address above. We have no establishment in the EU or UK. You can reach us directly, in English, at support@the-karya.com, and we respond to data protection requests within 30 days — see §10.
A.2. Lawful bases. Set out per data type in §3. In summary: contract (Art 6(1)(b)) for account, generation, and billing; legal obligation (Art 6(1)(c)) for tax, accounting, and age verification; legitimate interests (Art 6(1)(f)) for security, abuse prevention, and cost telemetry — we have balanced these against your rights and you may object at any time; consent (Art 6(1)(a)) where we ask for it, which you may withdraw at any time without affecting prior processing.
A.3. Your rights. Access (Art 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21) — including an absolute right to object to direct marketing — and the right not to be subject to solely automated decisions with legal or similarly significant effects (22).
A.4. Automated decision-making. We do not make decisions producing legal or similarly significant effects about you by automated means. AI generates presentation content at your instruction; it does not evaluate, score, or make decisions about you.
A.5. Transfers. See §7. SCCs, UK Addendum, and the transfer impact assessment are available to business customers on request.
A.6. Complaints. You may complain to your national supervisory authority. In Ireland, the Data Protection Commission (dataprotection.ie); in the UK, the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to resolve it first.
A.7. No statutory requirement to provide data — but we cannot provide the Service without account data.
Annex B — United States
B.1. Scope. This annex applies to residents of US states with comprehensive privacy laws, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect. We extend these rights to all US residents regardless of whether we currently meet a given state's applicability threshold.
B.2. We do not sell or share your personal information. We have not sold or shared personal information for cross-context behavioural advertising in the preceding 12 months, and we do not do so now. We do not process personal information for targeted advertising or profiling in furtherance of decisions producing legal or similarly significant effects.
B.3. Categories collected (CCPA/CPRA terminology): identifiers (name, email, IP); commercial information (purchases, credits); internet activity (usage events); and, where you put it there, the content of your briefs and files. We collect no sensitive personal information as defined by the CPRA. Sources, purposes, and recipients are in §3 and §6.
B.4. Your rights. To know, access, and obtain a portable copy; to correct; to delete; to opt out of sale, sharing, and targeted advertising (nothing to opt out of — see B.2); to limit use of sensitive personal information (none collected); and to be free from discrimination for exercising any of these. Exercise them from your account page or at support@the-karya.com.
B.5. Global Privacy Control. We honour GPC signals. Because we do not sell or share data, a GPC signal has no processing to stop, but it is recorded and respected.
B.6. Authorised agents. An authorised agent may submit a request on your behalf with written proof of authorisation; we may ask you to verify directly.
B.7. Appeals. If we refuse a request, you may appeal by replying to our decision or writing to support@the-karya.com with "Appeal" in the subject. We respond within 45 days. If we deny the appeal you may complain to your state Attorney General.
B.8. Response times. We confirm within 10 business days and substantively respond within 45 days, extendable once by a further 45 days with notice.
B.9. Shine the Light (California Civil Code §1798.83). We do not disclose personal information to third parties for their own direct marketing.
B.10. Children. The Service is 18+. We do not knowingly collect data from anyone under 18 and therefore do not sell or share the data of consumers under 16.
Annex C — India (DPDP Act)
C.1. Data Fiduciary. Karya, address above. Grievance Officer: Aarya Banthia, support@the-karya.com.
C.2. Notice and consent. We give this notice before or at collection, in clear plain language, itemising the data and the purpose. Where we rely on your consent, it is free, specific, informed, unconditional, and unambiguous, given by affirmative action, and withdrawing it is as easy as giving it — from your account page or by email. Withdrawal does not affect processing already carried out. You may request this notice in English or any language in the Eighth Schedule to the Constitution.
C.3. Legitimate uses. Beyond consent, we process for the legitimate uses the Act permits — including where you voluntarily provide data for a specified purpose, and for compliance with law and judgments.
C.4. Your rights as a Data Principal. To access a summary of your personal data and our processing; to correction, completion, updating, and erasure; to nominate another individual to exercise your rights if you die or become incapacitated; and to grievance redressal.
C.5. Grievance redressal. Write to the Grievance Officer. We acknowledge promptly and respond within the timelines the Act and Rules prescribe. If you are not satisfied, you may complain to the Data Protection Board of India — but you must raise it with us first.
C.6. Children. We do not process the data of anyone under 18. We block under-18 registration and undertake no tracking or targeted advertising directed at children.
C.7. Erasure. We erase personal data when the purpose is no longer served, when you withdraw consent, or when retention lapses — unless the law requires us to keep it.
C.8. Breach. We will notify the Data Protection Board and affected Data Principals where and within the timelines the DPDP Act requires.
C.9. Transfers. Made in accordance with the conditions permitted under the DPDP Act. See §7.