Privacy Policy
Last updated: July 8, 2026
1. Who Is Responsible for Your Data
The controller of your personal data is Momentum Ventures s.r.o., Jicinska 226/17, 130 00 Prague, Czech Republic (company ID: [blank]). For any privacy question or request, contact us at support@deckrage.com.
2. Data We Collect
- Account and profile data — email address, name (if provided), password (stored as a hash), and account settings.
- Uploaded files and extracted content — the presentation files and context documents you upload, and the text, images, and structure we extract from them for analysis.
- Analysis results — the AI-generated feedback, scores, and speaker notes tied to your account.
- Billing data — plan, purchase and invoice history, and payment status. Card details are collected and stored by Stripe, not by us.
- Usage and security logs — IP address, browser information, timestamps, and actions taken, used for security, debugging, and abuse prevention.
- Support communications — emails you send to support@deckrage.com.
3. Why We Process It & Legal Bases
- To provide the Service (storing and analyzing your files, showing results, managing your account and subscription) — performance of a contract (Art. 6(1)(b) GDPR).
- To secure and improve the Service (logs, error monitoring, abuse prevention) — our legitimate interests (Art. 6(1)(f) GDPR).
- To meet legal obligations (tax and accounting records, responding to lawful requests) — legal obligation (Art. 6(1)(c) GDPR).
We do not use your data for advertising and we do not sell it.
4. Where Your Data Is Stored
Your account data, uploaded files, and analysis results are stored on servers located in the United States, operated by DeckRage on infrastructure rented from Vultr (The Constant Company, LLC), a US hosting provider. Because this means your data is transferred outside the European Economic Area, we safeguard the transfer with the European Commission's Standard Contractual Clauses concluded with our hosting provider, alongside technical measures such as encryption in transit and access controls. The other US-based providers we use are listed in Section 5 with their respective safeguards.
5. Service Providers (Subprocessors)
We share personal data only with the following providers, strictly to operate the Service:
| Provider | Role | Location | Transfer safeguard |
|---|---|---|---|
| Vultr (The Constant Company, LLC) | Cloud hosting — application servers, database, and file storage | United States | Standard Contractual Clauses |
| Google LLC | AI analysis via the paid Gemini API | United States | EU–US Data Privacy Framework / SCCs |
| Stripe | Payment processing and billing | United States | EU–US Data Privacy Framework / SCCs |
| Cloudflare | Network security, connectivity (Tunnel), and bot protection (Turnstile) | United States | EU–US Data Privacy Framework / SCCs |
| Sentry (Functional Software, Inc.) | Error monitoring | United States | EU–US Data Privacy Framework / SCCs |
| Resend | Transactional email delivery | United States | EU–US Data Privacy Framework / SCCs |
| Gravatar (Automattic Inc.) | Avatar lookup via a hash of your email address | United States | Standard Contractual Clauses |
| Have I Been Pwned | Password-breach check at signup (only a k-anonymized hash prefix is sent — never your password or email) | Global | No personal data transferred |
6. AI Processing & No-Training Commitment
To generate feedback, we send content extracted from your uploaded files to Google's Gemini API. DeckRage never uses your content to train AI models. We use Google's paid Gemini API, which under Google's terms does not use API content to train Google's models. Google's terms can change; the current version is available in Google's Gemini API terms.
7. How Long We Keep Your Data
| Data | Retention period |
|---|---|
| Uploaded source files (PPTX, PDF, context documents) | 30 days after upload |
| Derived artifacts (extracted text, thumbnails, derived PDFs) | 1 year after creation |
| Analysis results and scores | Until you delete them or your account |
| Account and profile data | Until account deletion |
| Billing and invoice records | As long as tax and accounting law requires |
| Security and usage logs | Up to 12 months |
8. Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Have inaccurate data rectified
- Have your data erased ("right to be forgotten")
- Receive your data in a portable format
- Object to, or request restriction of, processing based on legitimate interests
To exercise any of these rights, email support@deckrage.com. You also have the right to lodge a complaint with the Czech data protection authority (Úřad pro ochranu osobních údajů, uoou.gov.cz) or the supervisory authority in your country of residence.
9. Account Deletion
You can request deletion of your account and associated data by emailing support@deckrage.com. We complete deletion within 30 days. Data we are legally required to keep (such as invoices, for the statutory retention period) is excluded from deletion and removed once that period expires.
10. Cookies & Local Storage
We do not use analytics or advertising cookies. The Service uses only strictly necessary storage: your authentication session is kept in your browser's storage (Supabase Auth), and Cloudflare Turnstile may set strictly necessary tokens to protect signup and login from bots. Because none of this is used for tracking or marketing, no cookie consent banner is required.
When Turnstile is used, Cloudflare processes client-side signals such as IP address, TLS fingerprint, user-agent, sitekey, and origin to distinguish human users from bots and protect the Service from abuse. Cloudflare may also process those signals to improve Turnstile's bot detection. More information is available in Cloudflare's Turnstile Privacy Addendum.
11. Security
We protect your data with encryption in transit (TLS), private storage buckets that are not publicly accessible, role-based access controls, hashed passwords, and continuous error and security monitoring. No system is perfectly secure, but we work to keep protections current and to respond quickly to incidents.
12. Children
The Service is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes we will notify you by email or an in-app notice before they take effect. The "Last updated" date at the top of this page shows the current version.
14. Contact
Momentum Ventures s.r.o., Jicinska 226/17, 130 00 Prague, Czech Republic — support@deckrage.com. Business customers can request a Data Processing Agreement (DPA) at the same address.