Privacy policy
DeckAlong is built to collect as little as possible. This page explains in plain language what we store, why, who helps us run the service, and what rights you have. It follows the EU General Data Protection Regulation (GDPR), which also applies in Norway.
The short version
- Listeners need no account, and we do not track which presentations they follow.
- Presenters give us a name, an e-mail address and a password, and we store the decks they create.
- Everything is hosted in Norway. E-mail is sent through Mailgun's EU region.
- We use Pirsch for simple visitor statistics. It sets no cookies and does not track you across sites.
- We do not sell your data, show ads, or build profiles.
If you follow a presentation (listeners)
- You need no account and give no name or e-mail address.
- We set no cookies. We do not run analytics while you follow a presentation, and we load no third-party scripts, fonts or other external content.
- We do not record which presentations or slides you view.
- Your display settings stay on your device, and so does your place in the slides if you refresh. A copy of the presentation is kept by your browser so you can keep reading offline.
- To stop guessing of join codes we limit how often one device can ask for a code. For that we keep a salted, one-way hash of your network address for about a minute. The address itself is not stored by the application, and the web server's access logs are rotated within 7 days. Our legal basis is our legitimate interest in keeping the service secure.
If you present (presenters)
- We store your name, e-mail address and a hash of your password, plus the security settings you enable such as two-factor authentication or passkeys. Our legal basis is that we need this to provide the account you asked for (contract).
- We store your decks, uploaded images and a history of when sessions were held. We never store who followed them.
- Private speaker notes (
Note:) are only ever shown to you. They are not part of what listeners download. - You can download all of your data, or delete your account and everything in it, from your account settings.
Cookies
Listeners get none. When you sign in as a presenter we set a session cookie and a security cookie that protects forms against forgery. They are strictly necessary for signing in, are not used for tracking, and need no consent.
We only send e-mails that the service needs: confirming your address, resetting your password and security notices. We send no newsletters or marketing. Your e-mail address and the message are passed to Mailgun, which sends it for us from its EU region. Mailgun keeps delivery logs for a short time under our agreement with it.
Visitor statistics
On our public pages and the presenter area we use Pirsch, a privacy-friendly analytics service based in Germany. It sets no cookies and stores no personal profile of you. To count visits it sees your page address, referrer, browser, device type and a shortened country or region, and it turns your network address into a daily-changing anonymous code that cannot be traced back to you. We use it only to see which pages are used and whether they work. Our legal basis is our legitimate interest in improving the service. Pirsch is not used while you follow a presentation.
How long we keep things
- An ended session stays readable for listeners for 24 hours by default. You can choose up to 7 days in your settings. After that it is deleted and its join code can be used again.
- A deck you delete is removed permanently after 30 days, once no session still uses its images.
- Deleting your account removes your decks, images and sessions at once. Backups containing them are overwritten within the normal backup cycle.
- Web server access logs are rotated within 7 days.
Where data is processed
The service, its database, image storage and backups are hosted in Norway. Norway is part of the European Economic Area and applies the GDPR. Your data is not moved outside the EU/EEA by us. Mailgun is owned by a US company; we use its EU region, and where it may need to handle data from the US side it relies on the EU's approved safeguards (standard contractual clauses or the EU-US Data Privacy Framework).
Sub-processors
These companies process data on our behalf, under a data processing agreement. We do not share data with anyone else, unless the law requires it.
- Mailgun (EU region): Sends account e-mails such as verification and password reset (EU)
- Pirsch: Cookie-free visitor statistics (Germany, EU)
Your rights
Under the GDPR you can ask us to:
- show you what we hold about you (access) and give you a copy you can move elsewhere (portability),
- correct data that is wrong,
- delete your data,
- limit how we use your data, or object to uses based on our legitimate interest.
Presenters can do most of this themselves in their account settings. For anything else, write to us. We reply within one month. You may also complain to the Norwegian Data Protection Authority (Datatilsynet), or to the authority in your own country.
Changes
If we change this policy in a way that matters, we tell signed-in presenters by e-mail before it takes effect.