PRIVACY
Privacy, in product terms
This notice describes the data flows that exist in the current SlideBlocks pre-production product and the controls available to an account holder.
01
Scope and roles
This notice covers the SlideBlocks website, account, Prompt delivery, Creator submission, moderation, support, and administration surfaces. It does not cover a third-party site you choose to open.
SlideBlocks has not yet published a Production legal entity, postal address, jurisdiction-specific controller designation, or data-residency commitment. Those items require owner and legal approval before Production.
02
Data we process
- Account and authentication data: email, verification state, password-derived credentials, sessions, optional GitHub account link, role, status, locale, and security events.
- Product activity: Prompt unlock counters, anonymous request context, Creator drafts and immutable revisions, declared licenses and asset sources, validation findings, moderation decisions, and feature state.
- Support and safety data: request category, subject, details, status history, administrator ownership, audit events, request identifiers, and abuse-control signals.
- Technical data: IP-derived request context, user agent and browser signals, timestamps, origin, release identifiers, operational logs, and Turnstile verification results.
03
Why we use it
- Create and protect accounts, deliver requested product features, and maintain attributable submission and support history.
- Validate untrusted uploads, investigate abuse and security reports, enforce content rules, and recover from incidents.
- Operate, diagnose, rate-limit, and improve reliability without exposing private Prompt, source, secrets, or unnecessary personal data in public Registry output.
04
Cookies and local storage
SlideBlocks uses security and product storage that is necessary for the requested service: secure session cookies, bounded anonymous Prompt context, and browser-local theme and locale preferences. Turnstile may process browser and environment signals when abuse verification is required.
The current product does not install advertising cookies or optional product-analytics cookies. If non-essential tracking is introduced later, this notice and any required consent control must be updated before activation.
05
Service providers and transfers
Cloudflare provides website and Worker delivery, abuse verification, object and queue infrastructure. Neon provides PostgreSQL infrastructure. GitHub is used only when an account holder chooses the optional link or sign-in flow. An email delivery provider receives the minimum delivery fields required for account messages.
These providers may process data in locations determined by their services. SlideBlocks does not currently promise a specific data-residency region. The maintained provider register records the engineering boundary; legal transfer terms remain a Production review item.
06
Retention and deletion
Retention follows the documented product lifecycle rather than an unlimited default. Sessions, one-time tokens, idempotency records, support bodies, quarantined uploads, observability data, and deletion tombstones have bounded operational windows. Immutable submission and audit records are retained only where the product needs attribution, safety, dispute, or integrity evidence.
Deletion removes or anonymizes account-linked product data through the account deletion workflow. Backups and already-produced security evidence can expire on their own bounded provider or incident schedule rather than disappearing immediately. Public content may require a separate withdrawal or rights decision so that Registry provenance remains auditable.
07
Your choices and requests
- Export account data and request account deletion from Account. Reauthentication may be required for high-risk actions.
- Withdraw a Creator submission from its Creator workflow where the current state permits it.
- Use Support & requests for access, correction, deletion, privacy, security, or rights questions. Do not include passwords, session values, tokens, private Prompt, source, or unrelated personal data.
- A request can be limited where identity cannot be verified, another person’s rights would be exposed, or minimum security, audit, dispute, and legal evidence must be preserved.
08
Security and changes
SlideBlocks uses verified identities, least-privilege roles, exact Origin checks, request schemas, rate limits, encrypted or secret-managed credentials, isolated submission validation, fresh-session gates for high-risk administration, and auditable state changes. No system is risk-free.
Material changes will update the version and effective date on this page. Use the security category in Support & requests for suspected compromise or unsafe content; urgent reports are prioritized by risk, but no public response-time promise is made before Production operations are approved.