Privacy Policy
Last updated: September 14, 2026
This Privacy Policy describes how Image2PPT ("we", "us", "our") collects, uses, and protects your information when you use our service at image2ppt.com (the "Service").
1. Information We Collect
| Data Type | What | Why | Retention |
|---|---|---|---|
| Email address | Provided during account creation | Account authentication, service communications | Until account deletion |
| Google Account identity | If you choose Google sign-in: Google's stable account identifier, verified email address, and Workspace domain when applicable | Account authentication and preventing duplicate accounts | Until account deletion |
| Uploaded files | Images and PDFs you upload for conversion | Processing your conversion request | Kept until you ask us to delete them or delete your account, apart from the exceptions listed under the table |
| Generated files | PPTX files produced by the Service | Delivering your conversion result | Kept until you ask us to delete them or delete your account, apart from the exceptions listed under the table |
| Usage data | Job status, credit transactions, quality ratings | Service operation and quality improvement | Until account deletion |
| Technical data | IP address, browser type, request timestamps | Security, rate limiting, debugging | Until account deletion; server access logs rotate automatically |
| Device characteristics | An irreversible hash derived from your browser and device characteristics (browser type, language, time zone, screen, and canvas rendering). No plaintext device information is stored. | Anti-abuse: detecting duplicate-account and fraud signals | Until account deletion |
| Anti-abuse identifier | A random identifier we generate and store in your browser. It is not derived from you or your device and contains no personal information. If a sign-up attempt is blocked because it used a disposable email address, we keep a short-lived record of that identifier and of the network the request came from. | Anti-abuse: requiring a human-verification step on later sign-in requests after a blocked attempt | The identifier stays in your browser for up to one year and is removed if you clear your browser data. The associated record stops being used after 24 hours and is then deleted automatically. It is never linked to an email address or account. |
When uploaded and generated files are deleted without you asking
We do not run your files through a general expiry timer — your conversion history is meant to stay available to you. These are the cases where files go anyway:
- Enterprise API results. PPTX files produced through our API are deleted automatically 7 days after the job completes. This is stated in the API documentation and applies only to jobs submitted with an API key.
-
Held copies that make "re-run" possible. Some conversions keep a working copy of your uploaded images so the job can be run again later — that copy is exactly what the re-run option uses. Those working copies are reclaimed 7 days after you uploaded them, whether or not the conversion ran and whether it succeeded or failed. The clock runs from upload, not from when the conversion finished. When a copy goes, the re-run option for that job goes with it; your converted PPTX and the job's history stay.
So a finished job that still offers a re-run still holds your upload — that is the check you can make yourself. A job that has not finished yet holds its upload too and gains the re-run option when it finishes; but a job that finishes after its 7 days have already passed has its copy reclaimed on the next sweep, so it may offer a re-run only briefly, or never show one at all.
Today this covers batch decks, conversions started from a plugin that stages its upload first, and — on free accounts — single slides that go through our complexity pre-check.
- Uploads whose conversion never started. An upload that never became a conversion is discarded rather than kept, in every case we know of: an editor or assistant plugin session you did not convert (discarded 30 minutes after the session's deadline was last set — opening the session sets it, and going to checkout or starting a conversion resets it; sending the files does not, so a slow upload eats into that window rather than restarting it); a slide held for your decision because it needs extra credits, discarded if you do not go ahead within 7 days; a submission we rejected or you cancelled; and an upload still waiting to be accepted when our servers restart.
- Re-running or retrying a conversion. A new attempt supersedes the one before it, and the superseded copy is deleted: re-running a finished job deletes its previous PPTX, and retrying a failed conversion in a plugin deletes that failed attempt's uploaded copy (your retry uploads its own). This only ever happens because you asked for the new attempt.
- Storage capacity. If our servers run out of room, we may remove older uploaded and generated files to keep the Service running. This is a manual operational action, not a schedule, and we take the oldest files first.
2. How We Use Your Information
- Service delivery: Processing your business slide and PDF-to-PPTX conversions.
- Account management: Authenticating your identity, managing credits.
- Quality improvement: Analyzing conversion quality metrics (aggregated, not individual files).
- Communications: Sending login codes, service notifications, and responses to support requests.
- Security: Detecting abuse, preventing fraud, enforcing rate limits.
- Troubleshooting: When a conversion fails or comes out wrong, we may open that job's own files — including the images or PDF you uploaded — and run them through the conversion pipeline again to reproduce the problem and fix it.
3. How We Do NOT Use Your Information
- We do not use your uploaded files to train AI models.
- We do not sell, rent, or share your personal data with third parties for marketing purposes.
- We do not display advertising or use tracking pixels from ad networks.
- We do not use your uploaded files for anything beyond the purposes listed in section 2 — producing the conversion you asked for, and reproducing that job when something goes wrong with it. We keep them so that your conversion history stays available to you, and we delete them when you ask us to or when you delete your account (see section 6, Your Rights). The exceptions — the cases where files are removed without you asking — are listed in full under the table in section 1, and there is no general expiry timer beyond those.
4. Third-Party Services
We use selected service providers to host and operate the Service, process conversions, deliver transactional emails, and handle payments. Converting a slide involves sending your uploaded image to third-party cloud and AI providers for processing; the main ones are listed below. They process personal data only as needed to provide their services to us, and we do not authorize them to use your data for their own marketing.
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Google Identity Services | Optional Google Account sign-in | Google receives the browser's sign-in request and related technical data; Google returns a signed account identifier and verified email to us after you choose an account | Google Privacy Policy |
| Google Cloud Platform | Hosting, storage, and server infrastructure | Account data, uploaded files, generated files, and technical logs | Google Cloud Privacy Notice |
| OpenAI API (paid service) | AI-powered slide element extraction | Uploaded slide images, PDF page images, and extraction prompts/responses. For the paid OpenAI API, OpenAI does not use submitted data to train its models; it may retain data for a limited period for abuse monitoring. | OpenAI Privacy |
| Google Gemini API (paid service) | Backup provider for AI-powered slide element extraction, used only when we switch extraction away from OpenAI | While in use: uploaded slide images, PDF page images, and extraction prompts/responses. For the paid Gemini API, Google does not use prompts, uploaded files, or responses to improve its products; Google may temporarily log or cache data for safety, security, abuse prevention, and legal compliance. | Gemini API Terms |
| OpenAI API (paid service) | Signup abuse screening — judging whether an email address looks machine-generated, and what kind of service an email domain is | The email address used to sign in or sign up, its domain, and — as comparison material for the same check — the email addresses of other accounts registered on this site in the preceding 24 hours (at most 200). This check sends no files, slide content, account balances, or payment details; slide images reach an AI provider only through the extraction step in the rows above. Same OpenAI retention terms as the extraction row. | OpenAI Privacy |
| Paddle | Payment processing and Merchant of Record | Email address, checkout/customer information, payment and billing details, purchase/refund records | Paddle Privacy |
| Alibaba Cloud DirectMail | Transactional emails, including login codes | Recipient email address, login-code email content, and delivery metadata | Alibaba Cloud Privacy |
5. Data Storage and Security
- Our servers are hosted on Google Cloud Platform (GCP).
- All data in transit is encrypted via HTTPS/TLS.
- Database files are stored on encrypted volumes.
- Access to production systems is restricted to authorized personnel.
- We perform regular backups of account data (not uploaded files).
6. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your account and associated data, or of specific uploaded and generated files while keeping your account.
- Export: Request your data in a portable format.
To exercise any of these rights, contact us at support@image2ppt.com. We will respond within 30 days.
7. Cookies and Analytics
We use minimal cookies strictly for:
- Session management: Keeping you logged in (authentication token).
- Language preference: Remembering your chosen language (Chinese/English).
- Anti-abuse: A random identifier used only to apply an additional human-verification step after a blocked sign-up attempt. It contains no personal information and is not used for analytics, advertising, or tracking across sites.
We collect aggregate page-view metrics using a self-hosted, cookieless analytics service (Umami) to understand traffic and improve the Service. It does not set cookies, does not track users across sites, and does not share data with third parties. We do not use advertising cookies or third-party tracking cookies.
8. Children's Privacy
The Service is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
9. International Data Transfers
Our servers are located outside of mainland China. By using the Service, you consent to the transfer of your data to our servers. We take appropriate measures to protect your data in accordance with this Privacy Policy.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The "Last updated" date at the top indicates when the most recent revision was made.
11. Contact
For questions about this Privacy Policy or to exercise your data rights, contact us at:
