Privacy Policy

Last updated: 12 June 2026

This policy explains what personal data Slidewell collects, why, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and applicable national law.

1. Who is responsible for your data

The data controller responsible for your personal data is the operator of Slidewell, based in Greece. A postal address is available on request by emailing slidewellapp@gmail.com. For any privacy matter, contact us at slidewellapp@gmail.com. We have not appointed a Data Protection Officer; if that changes we will update this policy.

2. What data we collect

CategoryExamples
Account dataEmail address, password (stored only as a secure hash by our authentication provider), and — if you sign in with Google — your Google account identifier and basic profile.
Profile / brand dataYour profession or creator type, brand name, social handle, and any logo or brand details you choose to add.
Usage dataThe health topics you enter, the content blocks and templates you choose, the carousels you generate, and your export actions.
Billing dataSubscription plan, billing status and history. Payments are handled by Stripe; we do not receive or store your full card number.
Technical dataIP address, device and browser information, and cookie / local-storage identifiers needed to run the Service (see our Cookie Policy).
CommunicationsMessages you send us, support requests, and — for the custom design service — information you share during a consultation.

3. Health data — important limit

Slidewell is a tool for producing general, educational health content from published research. It is not a tool for handling patient information. You must not enter into the Service any personal health information, clinical details, or any other data about an identifiable individual (such as a patient). The "topics" you search are general subjects (for example, "magnesium and sleep"), not personal health records. If you misuse the Service to enter such data, you do so in breach of our Terms and you are the controller of that data.

4. Why we use your data and our legal bases

PurposeLegal basis (GDPR Art. 6)
Create and run your account; generate carousels; provide the ServicePerformance of a contract (Art. 6(1)(b))
Process payments and manage subscriptionsPerformance of a contract (Art. 6(1)(b))
Keep the Service secure, prevent abuse, debug and improve itOur legitimate interests (Art. 6(1)(f))
Send service / transactional emails (e.g. verification, billing)Performance of a contract (Art. 6(1)(b))
Send marketing emails, where applicableYour consent (Art. 6(1)(a)), which you can withdraw at any time
Keep records required by law (e.g. tax/accounting)Legal obligation (Art. 6(1)(c))
Non-essential cookies / analytics, if usedYour consent (Art. 6(1)(a))

5. AI processing of your topics and prompts

To generate a carousel, the topic and instructions you provide, together with abstracts retrieved from PubMed, are sent to our AI provider (Anthropic) to produce the draft text. Search terms are also sent to PubMed / NCBI. We instruct our AI provider under commercial terms intended to ensure your inputs and the outputs are used only to provide the response and are not used to train their models. Please do not include any personal or confidential information in your topics or prompts.

6. Who we share data with (processors)

We do not sell your personal data. We share it only with service providers who process it on our behalf under data-processing agreements, and only as needed to run the Service:

ProviderPurposeRegion
SupabaseDatabase, authentication, backend hostingEU / global
NetlifyWebsite / app hostingUS / global
AnthropicAI generation of carousel textUS
NCBI / PubMed (U.S. National Library of Medicine)Search of published research; receives your search termsUS
StripePayment processing and subscription billingUS / EU
ResendTransactional email deliveryUS
Google"Sign in with Google" authentication (only if you use it)US / global

We may also disclose data where required by law, to enforce our Terms, or in connection with a business transfer (with notice where required).

7. International transfers

Some providers are located outside the European Economic Area, including in the United States. Where we transfer personal data outside the EEA, we rely on appropriate safeguards under GDPR Chapter V — typically the European Commission's Standard Contractual Clauses, an adequacy decision (such as the EU–US Data Privacy Framework where the provider is certified), or another lawful transfer mechanism. You can ask us for details using the contact below.

8. How long we keep data

We keep account and profile data for as long as your account is active. After you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must retain certain records to meet legal obligations (for example, billing and tax records, which are typically kept for the period required by law). Generated carousels stored in your account are deleted when you delete them or your account.

9. Your rights

Under the GDPR you have the right to: access your data; correct inaccurate data; erase your data ("right to be forgotten"); restrict or object to certain processing; data portability; and to withdraw consent at any time where we rely on consent. Withdrawing consent does not affect processing already carried out. To exercise any right, email slidewellapp@gmail.com. We will respond within the time limits set by the GDPR (generally one month).

10. How to delete your account and data

You can request deletion of your account and associated personal data at any time by emailing slidewellapp@gmail.com. We will confirm once deletion is complete, subject to any records we must retain by law.

11. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and reputable infrastructure providers. No method of transmission or storage is completely secure, but we work to protect your data and will notify you and the relevant authority of a personal-data breach where the law requires.

12. Cookies

We use cookies and similar local-storage technologies. Essential ones are needed to sign you in and run the Service; others are used only with your consent. See our Cookie Policy.

13. Children

The Service is for professional users aged 18 and over and is not directed at children. We do not knowingly collect data from anyone under 18.

14. Changes

We may update this policy. We will post the new version here with an updated date and, for material changes, give notice (for example, by email or in-app).

15. Contact and complaints

Contact us about privacy at slidewellapp@gmail.com. A postal address is available on request. If you believe we have not handled your data properly, you have the right to complain to a data protection supervisory authority — in particular the authority in your EU country of residence or work. If we are established in Greece, the competent authority is the Hellenic Data Protection Authority (HDPA, www.dpa.gr). We would appreciate the chance to address your concern first.