Legal

PRIVACY POLICY

Last updated: April 30, 2026 · Effective immediately

GhostDeck is built by Apexian Labs LLC. We take your privacy seriously. This policy explains what data we collect, why we collect it, and how we protect it. We do not sell your data. We never will.

1. Who We Are

GhostDeck is operated by Apexian Labs LLC ("we", "us", "our"). Our registered address is in the United States. You can reach us at privacy@ghostdeck.ai.

2. Information We Collect

Account information: When you sign up, we collect your name, email address, and (if using Google or Apple sign-in) your OAuth profile information.

Deck generation inputs: When you generate a deck, we receive the company information you provide — company name, description, market, traction, and funding ask. This is used solely to generate your deck.

Generated decks: Your generated decks (slides, content, speaker notes) are stored in your account so you can access them later from My Decks.

Payment information: We use our payment processor to process payments. We never store your full card number. our payment processor handles all payment data under their own privacy policy.

Usage data: We collect basic usage metrics (number of decks generated, features used) to improve the product. We do not track individual keystrokes or record sessions.

3. How We Use Your Information

  • To generate your pitch decks using AI
  • To store your decks so you can access them later
  • To process your subscription payments via our payment processor
  • To send you transactional emails (receipts, password resets)
  • To improve GhostDeck's AI generation quality
  • To respond to support requests

We do not use your company information to train AI models or share it with third parties for marketing purposes.

4. Data Storage and Security

Your data is stored in our database provider (PostgreSQL database) hosted on AWS infrastructure in the United States. All data is encrypted at rest and in transit using industry-standard TLS encryption.

We implement row-level security on all database tables, meaning each user can only access their own data — even in the event of a breach at the application layer.

We perform daily automated backups and maintain point-in-time recovery capabilities.

5. Third-Party Services

To operate GhostDeck, we work with carefully selected third-party service providers across the following categories:

  • Database and authentication — Secure cloud storage for your account data and generated decks, hosted in the United States
  • Payment processing — PCI-compliant handling of all subscription and one-time payments. We never store your card number
  • Application hosting — The infrastructure that serves the GhostDeck web application
  • API infrastructure — The backend services that power deck generation and account management
  • Sign-in providers — Optional third-party authentication (such as social login) to make signing in easier

All third-party providers are bound by contractual data protection obligations. We select partners who meet high security and privacy standards, and we never allow them to use your data for their own commercial purposes.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data and generated decks within 30 days.

Payment records are retained for 7 years as required by US tax law.

7. Your Rights

Depending on your location, you may have the following rights:

  • Access — Request a copy of all data we hold about you
  • Correction — Request correction of inaccurate data
  • Deletion — Request deletion of your account and data
  • Portability — Request an export of your data in a portable format
  • Objection — Object to certain types of processing

To exercise any of these rights, email us at privacy@ghostdeck.ai.

8. Cookies

We use a minimal number of cookies — only what is necessary to keep you logged in and maintain your session. We do not use advertising cookies or third-party tracking cookies.

9. Children's Privacy

GhostDeck is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it immediately.

10. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes by email or by displaying a notice in the application. The "last updated" date at the top of this page will always reflect the most recent version.

11. Contact Us

If you have any questions about this privacy policy or how we handle your data, please contact us:

Email: privacy@ghostdeck.ai
Company: Apexian Labs LLC