Privacy Policy

What Skiaw collects, why it collects it, and who else sees it. In plain language, because a policy nobody can read protects nobody.

Last updated 31 July 2026

Who we are

Skiaw is operated by Skiaw, [registered address]. We are the data controller for the information described on this page.

For anything to do with your data — a question, a correction, a deletion — write to contact@skiaw.com.

What we collect

Four things, and nothing beyond what the product needs to run.

  • Your account. Name, email address and profile picture. If you sign in with Google, we receive those from Google rather than asking you to type them. If you sign in with a password, we store a hash of it — never the password itself. Two-factor secrets and passkeys are stored the same way.
  • What you create. The prompt or brief you write, any files you upload, the decks generated from them, your edits, your brand kits and your exports.
  • Billing. Your plan, subscription status, credit balance and invoice history. Card numbers are entered on Stripe's systems and never reach ours.
  • How the product is used. Pages viewed, features opened, decks generated, plus the technical details every server receives — IP address, browser, device type. This is what tells us which parts of the product are working.

Why we use it

  • To run the product — generating decks, authenticating you, storing your work, sending the emails the product depends on. Legal basis: performance of our contract with you.
  • To take payment and prevent fraudulent charges. Legal basis: contract, and our legitimate interest in not being defrauded.
  • To improve the product — understanding which features are used, where generation fails, what people ask for. Legal basis: your consent for analytics cookies, or our legitimate interest for server-side diagnostics.
  • To meet legal obligations, such as keeping invoices for the period tax law requires.

We do not sell your data, and we do not train our own models on your decks. Your content is sent to the model providers listed below solely to produce the deck you asked for.

Who we share it with

Generating a deck means calling other companies' systems. These are all of them, and the only reason we send anything is to deliver the feature next to it.

ProviderWhat forWhat they receive
StripePayments, subscriptions and invoicingName, email, billing address, card details (held by Stripe, never by us)
GoogleSign in with Google, and the Gemini models used for generationName, email, profile picture; deck prompts and content
OpenAI, Anthropic, GroqThe models that research, write and lay out your decksDeck prompts, uploaded briefs, and the slide content produced from them
PostHogProduct analytics — which features get used, and where people get stuckPseudonymous usage events, device and browser information
DiscordRouting in-app feedback to the team that reads itYour message, and the email of the account that sent it
Object storage and email providersStoring uploads and exports; sending transactional emailFiles you upload, decks you export, your email address

Some of these providers are based outside the European Economic Area. Where that is the case, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard.

We will also disclose data where the law requires it, and to a buyer if the business is ever sold — in which case this policy travels with it.

Cookies

Essential cookies keep you signed in and the app working; they cannot be switched off. Everything else is off until you accept it in the cookie banner, and you can change your mind at any time.

  • Essential — authentication, security, and remembering the choice you made in the banner.
  • Analytics — product usage and performance.
  • Marketing — measuring which campaigns bring people here.
  • Session replay — diagnosing interface problems we cannot reproduce.

How long we keep it

Account data and the decks you create are kept while your account is open. Delete your account and we remove them within 30 days, except where law requires otherwise — invoices, for example, must be kept for the statutory accounting period. Analytics events are pseudonymous and expire on a rolling basis.

Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, export it in a portable format, restrict how we use it, or object to processing based on legitimate interest. Where processing rests on consent, you can withdraw that consent at any time.

Email contact@skiaw.com and we will respond within one month. If you think we have handled your data badly, you can also complain to your national data protection authority.

Security

Traffic is encrypted in transit, passwords are hashed, and access to production data is limited to the people who need it to operate the service. Databases enforce row-level isolation so one account cannot read another's work. No system is perfect; if a breach ever affects your data, we will tell you and the relevant authority within the deadlines the law sets.

Children

Skiaw is not intended for anyone under 16. We do not knowingly collect their data, and we delete it if we discover we have.

Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects how we use your data, we will tell you by email before it takes effect.

Questions about this page? Write to contact@skiaw.com and a person will answer.