Who is responsible
David Guillemette, a sole proprietor doing business as Technologies SlideMind (“SlideMind”, “we”), operates SlideMind from Montréal, Québec. This policy explains how we handle personal information on our website, in the SlideMind application and in the learning activities connected to it.
We decide how account, billing, security and support information is used to run our service. Learner information is different: the organisation that offers a course decides what is collected and why. SlideMind processes that information on the organisation’s behalf and according to its instructions.
If your question concerns a course you are taking, contact the organisation that offers it first. We will help that organisation respond, and you can also write to our privacy officer directly.
Visiting our website
Cloudflare hosts our website. To deliver pages and protect the site against abuse, it processes technical information such as your IP address, your browser and the page requested. Our fonts and images are served from our own domain.
The demonstrations run entirely in your browser. What you type there is not sent to SlideMind or to an AI provider, and it disappears when you reload the page.
With your consent, we use Google Analytics to understand how the site is used. We send the page address without its query parameters, the referring site, the language and a few actions, such as starting or completing a demonstration. We never send what you type in a demonstration, your name or your email address. Google’s advertising features are disabled.
Your choice is saved in your browser for 180 days. If you accept, Google Analytics sets cookies that last up to 180 days. You can change your choice at any time with the Analytics preferences link at the bottom of each page. Withdrawing consent stops collection and removes these cookies, but does not delete data Google has already received.
When you use our contact form, we receive your name, your email address, your organisation if you provide it, the topic and your message. Cloudflare Turnstile checks that the request is not automated, and the message reaches us by email through Mailtrap. We use this information only to answer you.
Accounts, billing and support
To create and protect your account, we use your name, email address, password, two-factor authentication settings, workspace memberships and roles. Passwords are stored only in hashed form. We also keep security records, such as active sessions and a log of sensitive actions with the IP address and browser used, to protect accounts and investigate misuse.
A workspace contains what its members add to it: courses, slides, AI instructions, variables and settings. AI provider API keys saved in a workspace are encrypted and used only to call the provider they belong to.
Stripe processes payments. We receive the details of each transaction and the information needed to invoice you and calculate taxes, such as an organisation name, a billing address and, if you provide one, a tax number. Stripe handles your card details; we never see or store them.
When you ask for help, from the application or by email, we receive your message, any screenshots you attach and technical context such as your workspace, your plan and the page you were on. Support requests are delivered by email through Mailtrap and kept in our support mailbox. Please do not include passwords, API keys or learner records in a request.
We send the emails the service needs: invitations, sign-in and security messages, receipts, usage alerts and notices about the service. We do not send marketing emails without your consent.
Learner information
A course connected to SlideMind can send a learner identifier, the learner’s answers and selected variables, such as a role, a learning goal, a score or a reflection. The organisation that offers the course chooses what is collected, where it can be reused and how long it is kept.
The learner identifier is whatever the organisation chooses: an ID from its learning platform, another code or an email address. SlideMind does not look it up in any other system, but it is not anonymous. An email address, for example, directly identifies a person.
Learner identifiers and saved values are encrypted in our database, with a separate key for each workspace. Courses can only reuse the saved values the organisation has chosen, and these requests are rate-limited and monitored. In the SlideMind portal, only the workspace owners can open a learner’s saved values, and each opening is recorded.
The organisation is responsible for informing its learners, obtaining any consent required and collecting only what its activities need. The workspace owner can consult, export and delete a learner’s saved information at any time.
SlideMind is designed for professional and adult learning. An organisation that uses it with learners under 14 must first obtain the consent of a parent or guardian, as Québec law requires.
SlideMind does not make decisions about learners. An organisation that uses AI responses to make a decision based exclusively on automated processing must inform the learners concerned, as the law requires.
When an activity uses AI
When an activity uses AI, SlideMind sends the provider the instructions configured for that activity, the learner’s current message and any saved information the activity is set up to include. An activity that only saves or retrieves information does not call an AI provider.
Each AI request is also recorded in the workspace’s interaction logs, with the model used, its cost and duration, the website that sent the request and the learner’s IP address. These logs do not contain the learner’s answers, the AI’s replies or the learner identifier.
SlideMind does not use your content or your learners’ information to train AI models. With SlideMind Credits, requests go through OpenRouter to paid AI services whose terms exclude training on that content. We review those terms whenever we change the models offered.
Excluding training does not mean nothing is kept. Providers may retain requests for a limited time, for security and abuse monitoring, under their own terms. These periods vary by provider and service. The main providers’ policies are summarised here:
If a workspace uses its own API keys, requests go directly to that provider account, and the workspace’s agreement and settings with that provider apply.
Service providers and locations
Our application, its database and its encrypted backups are hosted by OVHcloud in Beauharnois, Québec. Some of the providers below process information outside Québec, including in the United States and the European Union. Before entrusting them with personal information, we assess the protection it will receive and bind them by contract to protect it.
- OVHcloud: application hosting, database and backups, in Québec.
- Cloudflare: website hosting and protection against automated requests.
- Stripe: payments, invoicing and taxes.
- OpenRouter and AI model providers: processing of AI requests made with SlideMind Credits.
- Mailtrap: delivery of service emails, contact messages and support requests.
- Sentry: error monitoring, in the European Union. Learner identifiers, request contents and secrets are removed before an error is reported.
- Better Stack: availability monitoring. It receives no customer content.
- Google: website audience measurement, only with your consent.
We do not sell personal information and we do not share it for advertising.
Security and access
Information is encrypted in transit. Learner information, learner identifiers and saved API keys are also encrypted at rest, and each workspace’s data is isolated in the database.
Within SlideMind, only the people who operate the service, provide support or handle our legal obligations can access personal information, and only when their task requires it. We do not consult a workspace’s content or its learners’ information except to provide support you request, protect the service or comply with the law.
If a confidentiality incident presents a risk of serious injury, we notify the people concerned and the Commission d’accès à l’information, as the law requires. When an incident involves learner information, we promptly inform the organisation responsible for it.
Retention and deletion
We keep personal information only as long as it is needed for the purposes described in this policy or to meet a legal obligation.
- Saved learner information: kept until the workspace deletes it or until the retention period set by the workspace owner, counted from the last update. By default, it has no automatic expiry.
- Interaction logs: 90 days by default. The workspace owner can change this period.
- Previous versions of slides: 15 or 90 days, depending on the plan.
- Deleted workspace or closed account: a 30-day recovery period, with read-only access and export, followed by permanent deletion.
- Billing records: kept for the period required by tax and accounting law. The record of prepaid usage is anonymised when its workspace is deleted.
- Security records: kept while the workspace exists and deleted with it.
- Contact and support messages: kept for up to two years after the last exchange.
- Backups: taken every six hours, encrypted and kept for 30 days. Deleted information therefore disappears from backups within 30 days. If a backup is ever restored, deletions made since are applied again.
You can ask us to delete your information without waiting for these periods. We then delete it from our active systems within 30 days, unless the law requires us to keep it. Information already received by a service provider follows that provider’s retention rules.
Your rights and complaints
You can ask whether we hold personal information about you, access it, have it corrected or deleted, and receive a copy in a structured, commonly used technological format. You can also withdraw your consent, subject to legal or contractual restrictions, and exercise the other rights provided by law.
Send your request or complaint to our privacy officer. We may ask for information to confirm your identity, and we reply within 30 days. If we cannot grant a request, we explain why and tell you how to contest the decision.
If the request concerns a course, we forward it to the organisation responsible or help it respond, since that organisation decides how its learners’ information is used.
If you are not satisfied with our response, you can file a complaint with the Québec privacy authority:
Commission d’accès à l’information du Québec
Technologies SlideMind
Sole proprietorship of David Guillemette
Québec enterprise number (NEQ): 2270629407
3891 rue Ethel
Montréal, Québec H4G 1S2
Canada
Privacy officer: privacy@slidemind.app
Support for customers: support@slidemind.app
General enquiries: info@slidemind.app or the contact form
Changes to this policy
We update this policy when our practices change. The date at the top of the page shows the current version, and previous versions are available on request. We will notify account holders of significant changes by email or in the application before they take effect, and ask for consent again where required.