Last updated: July 2026
Account information: when you sign up with email/password or Google, we store your email address and (for Google sign-in) basic profile info via Supabase Auth. Deck files: .pptx files you upload are stored in Supabase Storage, scoped to your account, and rendered client-side when you or a controller views a session. Session data: join codes, current slide index, and session status are stored to keep presenter and controller devices in sync. Usage data: basic request logs (IP address, timestamps) are processed for rate limiting and abuse prevention via Upstash.
We use your information to: - Authenticate you and keep your decks scoped to your account - Render your presentation to you and to anyone you share a join code with - Enforce the free-tier deck limit and 30-day expiry - Prevent abuse via rate limiting - Respond to support requests We do not sell your data or use your decks to train any model.
Joining a session as a controller (audience member) requires no account and we do not collect any personal information from controllers beyond what's needed to relay realtime slide-change events for that session.
We use essential cookies only, to maintain your signed-in session (via Supabase Auth). We do not use advertising or tracking cookies.
We share data with the following services only as necessary to operate ControlPPT: Supabase — authentication, database, and file storage. Upstash — rate limiting. Vercel — hosting. None of these are used for advertising, and none receive your deck content beyond what's needed to store and serve it.
Free-tier decks are automatically deleted 30 days after upload. You can delete any deck immediately from your dashboard. Deleting your account removes your stored decks and account information. To request full account deletion, contact admin@controlppt.com.
Questions about this policy: admin@controlppt.com