Slides by Karya is built so your work stays yours.
Your work stays yours
Your decks are stored on our servers so you can reach them from any device, share them inside your organization, and restore an earlier version when an edit goes wrong.
- Private by default. Only you can see a deck unless you deliberately set it to organization-visible or publish a share link.
- We don't read your decks. We don't access, review, or monitor them — only where a security incident, a valid legal demand, or an abuse report requires it.
- Decks expire after 12 months of inactivity, so old work doesn't sit on our servers indefinitely. Export anything you want to keep long-term.
- Delete means delete. Deleting a deck removes all of its content. Deleting your account removes everything.
Stated plainly: your decks are on our systems, so we are technically able to access them. We tell you that rather than implying otherwise. For genuinely sensitive material, consider whether any cloud presentation tool is the right place for it.
We never train on your content
| We do not train AI models on your data. | Ever. Not for us, not for anyone. |
| Our AI provider is contractually barred from training on it. | Written into our agreement. |
| Zero retention at the AI provider. | Prompts and generations are not logged or stored. There is no opt-in we have taken. |
| We do not sell or share your data. | No advertising. No data brokers. No exceptions. |
Where your data goes
| What | Where | How long |
|---|---|---|
| Your brief and source files | AI model provider (US) → our database | 7 days, then automatically deleted |
| Your decks — slides and speaker notes | Our database (cached in your browser) | Until deleted, or 12 months after last use |
| Published share links | Our database | 90 days, then permanently deleted |
| Account and billing | Our database | Until you delete your account |
Full detail: Privacy Policy. Our providers are listed by name, with locations and safeguards, on request — just ask.
Our AI provider choice
The open-weights model we use is published by a company based in China. We deliberately do not use their API.
Instead we run the same open-weights model on a US-based provider with SOC 2 Type II certification, contractual zero data retention, and enforceable EU/UK data-protection commitments.
Same model quality. A materially stronger data-protection position. It costs us more, and we think it is the right call.
Security
| Encryption | TLS 1.2+ in transit, encrypted at rest |
| Passwords | bcrypt hashed — we cannot read your password |
| Sessions | Resetting your password or signing out everywhere immediately invalidates every existing session |
| Card data | Never touches our systems. Handled entirely by our payment processor, an RBI-licensed payment aggregator. |
| Content isolation | All AI-generated HTML is sanitised before storage and again before serving. Shared decks render in a sandboxed, script-free context. |
| Audit logging | Authentication, billing, admin, and deletion events are logged |
| Rate limiting | Per-route and per-IP |
Report a vulnerability: support@the-karya.com. Good-faith research is welcome and we will not pursue legal action against researchers who follow our disclosure rules.
Compliance
| Framework | Status |
|---|---|
| GDPR / UK GDPR | DPA with Article 28 terms, EU Standard Contractual Clauses, UK Addendum, and a transfer impact assessment available to customers |
| India DPDP Act | Grievance Officer appointed; consent, rights, and erasure processes in place |
| US state privacy laws | Rights extended to all US residents; we do not sell or share; Global Privacy Control honoured |
| EU AI Act | Article 50 transparency — AI interaction and AI-generated content disclosed |
| SOC 2 | Not currently held. Our AI and infrastructure providers are SOC 2 Type II certified. |
We publish what we have and what we do not. We do not hold SOC 2, and we will not imply otherwise. If you need it for procurement, tell us — it helps us prioritise.
Your rights
From your account page you can export everything we hold about you and permanently delete your account. No email required, no retention call.
We respond to data requests within 30 days.
- Privacy questions and data requests: support@the-karya.com
- Grievance Officer (India): Aarya Banthia
- EU, EEA, and UK residents: contact us directly at the same address — we have no EU establishment and respond in English within 30 days
For procurement
| Document | Availability |
|---|---|
| Data Processing Agreement | On request, or linked |
| Standard Contractual Clauses | Included in the DPA |
| Sub-processor list | On request, with 30 days' notice of change and a right to object |
| Transfer Impact Assessment | On request under NDA |
| Security overview | This page; detail on request |
| Enterprise MSA and SLA | On request |
| Penetration test report | Not currently available |
Contact support@the-karya.com and we will turn a security questionnaire around quickly.
What we do not do
Sometimes the absence is the point.
- ❌ No advertising, remarketing, or ad tech
- ❌ No behavioural analytics, session recording, or heatmaps
- ❌ No device fingerprinting
- ❌ No selling or sharing personal data
- ❌ No training AI on your content
- ❌ No cookie banner, because we set no non-essential cookies
- ❌ No dark patterns on cancellation — cancel online, in the same number of clicks it took to subscribe
Karya · New Delhi, India Partnership firm, Reg. No. 3263 of 2026