1. Introduction
SlideFarm ("we," "us," or "our") respects your privacy. This Privacy Policy explains what information the SlideFarm mobile app and its related services collect, how we use it, who we share it with, how long we keep it, and the choices you have.
Summary: We collect what we need to run SlideFarm. Your images and content remain yours. We never sell your personal data. AI providers process some of your content, including images, to make your posts (Section 4.2). We share ad-measurement data with TikTok only if you allow it, and you can turn it off at any time (Section 4.3). You can delete your account and its data from inside the app.
2. Data Controller
The data controller responsible for your personal data is:
As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring your data is handled in accordance with applicable privacy laws.
3. Information We Collect
3.1 Information You Give Us
Account Information: Your email address. If you sign in with Google or Apple, also the name and profile photo they share with us (Apple may share only a name, or a private relay email address). If you sign up with an email and password, the password is handled by Firebase Authentication and we never see it.
Your Content: Images you upload from your photo library or camera, your collections, prompts, briefs, the messages you send to the AI agent in Studio, reference images you attach, screenshots you upload so the AI can set up an automation, slide text and captions, schedules and automation settings, and the posts SlideFarm prepares for you.
Feature Requests: The title and description of any feature request you post, which other users see together with your display name, and your votes on requests.
TikTok Account Data: When you connect a TikTok account: its TikTok ID, display name, username where TikTok provides it, profile photo, the tokens that let SlideFarm post for you (stored encrypted), your publishing preferences, and the list and statistics of your videos (views, likes, comments, shares) shown in the app's analytics.
Pinterest Account Data: When you connect your Pinterest account, we receive your Pinterest user ID, profile name, board names and IDs, and basic Pin metadata (title, description, URLs, images). We do not receive your Pinterest password, and your Pinterest tokens are stored only on your device.
Payment Information: Your plan, purchase history and credit balance. Payments are made through the Apple App Store or Google Play; we never receive your card details.
Messages to Us: Anything you send us by email, such as a support request.
3.2 Automatically Collected
Device Info: Device model, operating system and version, app version, language, and IP address (our providers use it, for example, to estimate your country).
Identifiers: Your SlideFarm user ID, an app instance ID from Firebase Analytics, and a push notification token for your device. Firebase Analytics may also read your device's advertising ID: on iOS only if you allow tracking, and on Android unless you have deleted it in your device's Google settings. The TikTok Business SDK reads it only as described in Section 4.3.
Usage Data: The screens you open and actions such as signing up, signing in, buying a plan, connecting an account, creating an automation and publishing a post.
Crash and Performance Data: Crash reports, which include your user ID so we can investigate problems you report, error logs, and measurements of the app's speed and network requests.
4. How We Use Your Information
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Provide the Service (account, collections, posts, schedules) | Account info, your content, settings | Contractual necessity |
| Make your posts with AI | Prompts, briefs, chat messages, reference images, screenshots, settings (Section 4.2) | Contractual necessity (features you use) |
| Check uploaded images for safety | Images you upload | Legitimate interest (safety) |
| Publish to TikTok and show how your posts perform | Slides and captions, TikTok tokens, video statistics | Contractual necessity |
| Display Pinterest content | Pinterest boards, Pins, metadata | Contractual necessity (user-initiated) |
| Process subscriptions and credits | Purchase history, user ID, transaction IDs | Contractual necessity; legal obligation (accounting) |
| Notify you about your posts | Push notification token | Contractual necessity (you can turn notifications off in your device settings) |
| Improve the Service and fix crashes | Usage data, crash and performance data, identifiers | Legitimate interest |
| Measure SlideFarm's own ads on TikTok | Hashed email, user ID, advertising ID, app events and purchases (Section 4.3) | Consent |
| Run feature requests | Requests, votes, display name | Legitimate interest |
4.1 Pinterest Integration
When you connect your Pinterest account, SlideFarm displays your boards and Pins inside the app, and you can add Pin images to your collections. We want to be clear about what our Pinterest integration does and does not do:
- SlideFarm only requests read-only permissions (
pins:readandboards:read). - SlideFarm does not create, edit, publish, or delete any Pins or boards on Pinterest.
- Pinterest content is displayed only inside the app, to you.
- A Pin you add to a collection is stored as its Pin ID and a link to its image, not as a copy of the image.
4.2 AI Processing
SlideFarm uses AI models from OpenAI, Google and xAI to write and make your posts. To do that, we send them the content each feature needs, and that includes images, not only text:
- OpenAI runs most AI features: the AI agent that plans and makes posts from your briefs (it receives your brief, your chat messages and prompts, the reference images you attach and, when it plans a new post for a brief, the titles and view and like counts of that brief's earlier posts); AI setup from the screenshots you upload; image generation and editing; and the safety check of every image you upload to a collection.
- OpenAI, Google (Gemini) or xAI (Grok), whichever model an automation is set to, writes that automation's slides and captions from its topic, prompts and settings, and generates or edits its images, including any reference or outfit photo you chose for it.
- We do not send your password, payment details or account tokens to AI providers.
- Images the AI makes for you are stored in our cloud storage (Firebase/Google Cloud) under your account and are deleted with your account.
- Each provider processes this data under its own terms and privacy policy, and may keep it for a limited time, for example to monitor abuse.
4.3 Ad Measurement with TikTok (TikTok Business SDK)
SlideFarm advertises on TikTok. To measure which of our ads bring people to the app, the app includes TikTok's Business SDK. It runs only with your permission:
- On Android, the app asks you once, after you sign in. Nothing is sent to TikTok unless you tap Allow; until you answer, the SDK does not run.
- On iOS, Apple's "Allow Tracking" prompt decides. If you allow tracking, the data below is sent. If you don't, TikTok receives no email, no user ID and no advertising ID, only app events that are not linked to your account.
With your permission, TikTok receives:
- a hashed (one-way scrambled) copy of your email address and of your SlideFarm user ID;
- your device's advertising ID (IDFA on iOS, the Google advertising ID on Android);
- app events: installing and opening the app, signing up, signing in, connecting an account, and buying a subscription (plan, price and currency); on iOS the SDK also records in-app purchases itself;
- device information sent with each event, such as IP address, device model, operating system and language.
TikTok uses this to match our ads to the installs and purchases they lead to, and to report the results to us. TikTok processes it under its own privacy policy.
To withdraw your permission: in the app, turn off Share ad measurement with TikTok in the You tab, under Privacy (on iOS the switch appears once you have allowed tracking). From that moment the app stops identifying you to TikTok and stops sending it SlideFarm's events; the SDK itself, which can record app launches and purchases on its own, stops when the app is next closed and does not start again. On iOS you can also turn off tracking for SlideFarm in Settings › Privacy & Security › Tracking, which stops your email, user ID and advertising ID from being sent. Data already sent stays with TikTok under its policy.
5. Data Storage and Security
Your data is stored on Google Cloud Platform (Firebase) servers in the United States. We implement security measures including:
- Encryption in Transit: Industry-standard encryption for data transmitted between your device and our servers
- Encryption at Rest: All stored data is encrypted by Google Cloud, and your TikTok tokens are additionally encrypted by us
- Access Controls: Strict role-based access
Pinterest tokens are stored only on your device, in its secure storage. Pinterest data is not retained longer than necessary for providing the service.
6. International Data Transfers
Your data is processed and stored on servers located in the United States (Google Cloud Platform/Firebase), and the service providers listed in Section 7 may process it in the United States and other countries. If you are located outside the United States, including in the European Economic Area (EEA), your personal data will be transferred internationally.
For transfers from the EEA to the US, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data processing agreements with our service providers that include appropriate safeguards
By using the Service, you acknowledge that your data may be transferred to and processed in the United States.
7. Who We Share Data With
We do not sell your personal information. We share data only with the services that run SlideFarm for us, with services you choose to connect, and with TikTok for ad measurement if you allow it:
- Google Firebase and Google Cloud: sign-in (Firebase Authentication), database (Cloud Firestore), file storage (Cloud Storage), our server code (Cloud Functions, Cloud Tasks, Cloud Scheduler, Cloud Logging), usage analytics (Google Analytics for Firebase), crash reports (Firebase Crashlytics), performance measurements (Firebase Performance Monitoring), push notifications (Firebase Cloud Messaging), and app integrity checks (Firebase App Check, using Google Play Integrity and Apple App Attest)
- RevenueCat: Subscription and payment processing. RevenueCat receives your SlideFarm user ID and your App Store or Google Play purchase records
- Apple and Google: Payments for subscriptions, Sign in with Apple and Google Sign-In, and delivery of push notifications
- TikTok (API): When you connect an account, SlideFarm uses TikTok's official APIs to read your profile and video statistics and to publish the posts you create or schedule, including their images and captions
- TikTok (Business SDK): Ad measurement, only with your permission (Section 4.3)
- Pinterest: Read-only access to your boards and Pins via the official Pinterest API when you connect your account. We use this data solely to display your own boards and Pins within the app and to let you add Pin images to your collections. We do not sell Pinterest data or share it with any other third parties. We only store Pinterest data to the minimum extent necessary and prefer to call the API when updated data is needed.
- OpenAI: The AI agent, AI text generation, AI image generation and editing, AI setup from screenshots, and content moderation of uploaded images (Section 4.2)
- Google AI (Gemini): AI text generation, and AI image generation and editing, for automations set to a Gemini model (Section 4.2)
- xAI (Grok): AI text generation, and AI image generation and editing, for automations set to a Grok model (Section 4.2)
- AI assistants you connect: If you create an API key under AI assistant access, the app you give it to (such as Claude or Cursor) can read and change your SlideFarm data on your behalf. Delete the key to stop it.
- Legal reasons: We may disclose information if the law requires it, or to protect the rights, property or safety of our users or others.
8. Your Rights and Choices
- Access: Request a copy of your data
- Correction: Update your account information
- Deletion: Delete your account and its data (see below)
- Ad measurement: Allow or stop sharing with TikTok at any time (Section 4.3)
- Disconnect TikTok: Disconnect an account in the app (You tab › TikTok accounts) or remove SlideFarm in TikTok's settings at any time
- Disconnect Pinterest: Revoke SlideFarm's access to your Pinterest account at any time from your Pinterest account settings or from within the SlideFarm app
- Notifications: Turn push notifications off in your device settings
8.1 How to Request Data Deletion
You can delete your account and its data by following these steps:
- Open the SlideFarm app
- Go to the You tab
- Tap Account and sign-out
- Tap Delete my account
- Confirm the deletion when prompted (you may be asked to sign in again first)
Alternatively, you can request deletion by emailing favamvv@gmail.com with the subject line "Data Deletion Request" and include the email address associated with your account.
8.2 What Account Deletion Removes
Deleting your account deletes, from our database and file storage: your profile; your collections and uploaded images; AI-generated images; your posts, schedules and post history; your briefs, Studio chats and AI agent runs; your automations; your connected TikTok accounts, their tokens and video statistics; your analytics; your API keys; your devices' push tokens; your credit history; and the feature requests you wrote, together with your votes on other people's requests. Because your TikTok tokens are deleted, SlideFarm can no longer reach your TikTok account; you can also remove SlideFarm in TikTok's settings. Your Pinterest tokens are on your device and are removed when you delete the app. Section 9 lists what deletion does not remove.
9. Data Retention
We keep your data while your account exists. When you delete your account, we delete the data listed in Section 8.2 as soon as you confirm, normally within minutes and in any case within 30 days. Some records are kept longer, or are held by others:
- Posts on TikTok: Posts already published stay on TikTok until you delete them there
- Purchases: Apple, Google and RevenueCat keep purchase records under their own policies. We keep a minimal record of each subscription event we receive (your user ID, the product and the type of event) for accounting and to avoid processing the same event twice
- Analytics and diagnostics: Google Analytics for Firebase keeps event data for up to 14 months, Firebase Crashlytics keeps crash reports for 90 days, and our server logs are kept for about 30 days
- Data already sent to others: Data already processed by AI providers, or sent to TikTok for ad measurement, is subject to those third parties' own retention policies and cannot be recalled by us
10. Children's Privacy
The Service is not intended for users under 18. We do not knowingly collect data from children.
11. California Privacy Rights (CCPA)
California residents have rights to know, delete, and correct their personal information, and to opt out of its sale or sharing. We do not sell personal information. Sending your hashed email, user ID, advertising ID and app events to TikTok to measure our ads may count as "sharing" for cross-context behavioral advertising under California law; it happens only if you allow it, and you can opt out at any time as described in Section 4.3. Contact us at favamvv@gmail.com.
12. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate personal data
- Right to Erasure: Request deletion of your personal data (see Section 8.1)
- Right to Restrict Processing: Request limitation of how we process your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interest
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time
12.1 Legal Bases for Processing
We process your personal data under the following legal bases as required by Article 6 of the GDPR:
- Contractual Necessity (Art. 6(1)(b)): Processing necessary to provide the Service you requested, including account management, AI processing of your content to make your posts (text and images), publishing to TikTok, notifications about your posts, and payment processing
- Legitimate Interest (Art. 6(1)(f)): Processing for service improvement, analytics, crash and performance monitoring, fraud prevention, content moderation to ensure platform safety, and feature requests
- Consent (Art. 6(1)(a)): Ad measurement with TikTok (Section 4.3), which on iOS also needs Apple's tracking permission. You may withdraw consent at any time, without affecting processing that took place before
- Legal Obligation (Art. 6(1)(c)): Processing required to comply with applicable laws, such as tax and accounting requirements
To exercise any of these rights, contact us at favamvv@gmail.com. We will respond within 30 days as required by law. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. For users in Poland, this is the President of the Personal Data Protection Office (UODO).
13. Changes to This Policy
We may update this Privacy Policy. Material changes will be communicated via email or in-app notification.
14. Contact Us
For questions about this Privacy Policy or to exercise your rights:
- Email: favamvv@gmail.com