Privacy Policy
We store the email and lecture slides you give us, send slide images to Google's Gemini to generate explanations, and don't sell or use your content for AI training. You can delete everything any time at hello@slaim.app.
This Privacy Policy describes how Slaim ("Slaim", "we", "us") collects, uses, and shares information when you use Slaim at slaim.app and app.slaim.app (the "Service"). By using the Service you agree to this Policy.
1. Who we are
Slaim is the operator of the Service. For any privacy question, contact hello@slaim.app.
2. What we collect
Account information
- Email address
- Password hash (handled by our auth provider Supabase — we never see plaintext passwords)
- If you sign in with Google: your name, profile picture URL, and Google account email
- Optional display name and profile photo you set in Slaim
Content you upload or generate
- Lecture PDFs you upload
- AI explanations, annotations, summaries, and flashcards generated from those PDFs
- Note Style configurations (".slaim" files)
Local-only data
To make Slaim fast and offline-friendly, some content (rendered PDF caches, in-browser annotations, locally generated cards) is stored only in your browser via IndexedDB and OPFS. This data never leaves your device unless you act to share it.
Technical data
- IP address (kept briefly by our hosting and auth providers for security and abuse prevention)
- Browser type and device type, for compatibility
- Standard server logs
We do not use third-party advertising trackers. No Google Analytics, no Meta pixel, no behavioral ads.
3. Service providers
The following providers process data on our behalf under written contracts:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Authentication, database, file storage | Email, password hash, profile, library metadata, AI cache |
| Google Cloud Vertex AI (Gemini) | AI analysis of your slides | Rendered slide images and extracted text |
| Vercel | Hosting and edge functions | Request logs |
| jsDelivr | Lazy-loaded JavaScript modules (sql.js, JSZip) for .apkg export | None — static asset CDN |
4. How we use your data
- To provide the Service — authenticate you, store your library, render PDFs, generate AI explanations, build Anki decks
- To maintain service security and prevent abuse
- To respond when you contact us for support
We do not sell your data. We do not use your uploaded slides to train AI models, ours or anyone else's.
5. Legal basis (for users in the EEA / UK)
- Performance of a contract — to deliver the Service you signed up for.
- Consent — specifically for sending your slide content to Google's Vertex AI to generate explanations.
- Legitimate interests — service security, fraud prevention, basic analytics on usage.
6. Retention
- Account data: kept until you delete your account.
- Uploaded PDFs and AI cache: deleted with your account, or earlier on request.
- Local browser data: cleared when you click "Clear local data on this device" in your Slaim profile, or when you clear browser storage.
- Technical logs: typically retained 30–90 days by our providers.
7. Your rights
You can request:
- Access to a copy of the data we hold about you
- Correction of inaccurate data
- Deletion of your account and all associated data
- Export of your library and generated content
- Withdrawal of consent (this stops AI generation; previously stored content remains until you delete it)
Email hello@slaim.app with your request. We respond within 30 days.
8. International data transfers
Slaim is a U.S. company. Personal data is processed in the United States. By using the Service you consent to this transfer. Where required (for users in the EEA / UK), we rely on Standard Contractual Clauses with our subprocessors.
9. Security
- HTTPS / TLS for all data in transit
- Provider-level encryption at rest (Supabase, Vercel, Google Cloud)
- Access to production data limited to authorized engineering personnel
No system is perfectly secure. If we ever experience a breach affecting your data, we will notify you in line with applicable law.
10. Children
Slaim is intended for users 14 years of age or older. We do not knowingly collect personal data from children under 14. If you believe a child has provided data to us, contact hello@slaim.app and we will delete it.
11. Cookies
We use one essential cookie to keep you signed in (managed by Supabase). We do not use cookies for advertising or cross-site tracking.
12. Changes to this Policy
We may update this Policy. Material changes will be announced in the app or via email. Continued use of the Service after an update constitutes acceptance of the revised Policy.
13. Contact
Questions, requests, or complaints: hello@slaim.app.