Legal

Privacy Notice

What personal data we process, why, where it's processed, and how to exercise your data rights. We don't sell your personal information and we run no advertising cookies.

· Version 2026-08-19

This is a Comprehensive Privacy Notice (“Aviso de Privacidad Integral”) under Mexican law on personal data held by private parties — a different, more prescriptive instrument than a US-style privacy policy, which is why some of the structure below may look unfamiliar if you’re used to reading American privacy policies.

1. Identity and address of the data controller

Atarani, S.A.P.I. de C.V., Mexican tax ID (RFC) ATA200624TY5, registered address at Av. Popocatépetl 415, interior D-1706, Santa Cruz Atoyac, Benito Juárez, C.P. 03310, Mexico City, is the “Controller” of your personal data.

SlideWeave is the registered trademark under which the Controller offers the service. It is not a separate legal entity or a separate controller.

Personal Data Department: privacidad@slideweave.com.

2. Personal data we process

2.1 Identification and contact data (via Google or Microsoft)

Access to the service is exclusively through your Google or Microsoft account. From that provider we receive and store:

  • Email address
  • Display name
  • Profile photo URL
  • Your account identifier with that provider, and the provider’s name

We do not receive or store your password, and we don’t retain the identity provider’s access tokens.

If you join the waitlist without an account. The Pricing page lets you leave an email address to be told when the Pro and Team plans open. We keep that address, which plan you asked about, the language of the page, and the date. It isn’t linked to any account, it is used for nothing else — no marketing, no newsletter — and you can have it deleted at any time by writing to privacidad@slideweave.com.

2.2 Technical and connection data

  • IP address and user agent (browser and operating system), associated with your sessions and the actions recorded in the audit log.
  • Session and request identifiers.
  • Date and time of your last sign-in.

2.3 Content you create

The documents and presentations you create, edit, publish, or share, including their text, images, prior versions, and notes. They’re stored in full, and their text is indexed to enable search within your account or organization.

⚠️ You determine that content. If you include third-party personal data or sensitive personal data, it becomes subject to this notice and you’re responsible for having the legal basis to include it.

2.4 Third-party data you provide us

If you invite someone to your organization, we store their email address even if that person doesn’t have an account yet, so we can link them once they join. By inviting them, you represent you’re authorized to provide us that data.

2.5 Billing data

When you purchase a paid plan we process your name or company name, billing country and address, amount, currency, taxes, status, and transaction references. If you request an individual CFDI, we also process your RFC, tax name or company name, tax address postal code, tax regime, CFDI use, and, where applicable, a foreign tax identification number.

Stripe processes your payment-method data. The Controller doesn’t receive or store your complete card number or security code. At launch, Atarani will issue and reconcile CFDIs manually using SAT’s tools or its accounting process, and will retain fiscal data and receipts for the period stated in §11.

As of today, SlideWeave only offers the Free plan — this section takes effect once the service lets you purchase paid plans.

2.6 Sensitive data

We don’t request sensitive personal data (health, racial or ethnic origin, beliefs, sexual orientation, union or political affiliation, genetic or biometric data). Don’t request it or include it in your content unless you have a legal basis to do so.

3. Purposes of processing

3.1 Primary purposes (necessary to provide the service)

  • Create and manage your account and authenticate your access.
  • Store, version, process, render, and back up your documents.
  • Run the features you activate: publishing, sharing via link, and exporting to PDF or PPTX.
  • Generate content with artificial intelligence when you request it (see §5).
  • Manage organizations, memberships, roles, and review/approval flows.
  • Apply usage and quota limits under your plan.
  • Hold your address on the waitlist and write to you once, when the plan you asked about opens.
  • Maintain an audit log of actions taken on documents. This log is a core function of the service, not an add-on — it exists to demonstrate who did what and when (see §7.3).
  • Security: prevent unauthorized access, abuse, and fraud; investigate incidents.
  • Billing and compliance with tax and legal obligations.
  • Communicate operational matters and changes to the service or this notice.

We don’t need your consent for these purposes: they’re necessary for the legal relationship that arises from using the service.

3.2 Secondary purposes

We send no advertising or marketing communications. We don’t have a mailing list, and the waitlist address is used only for the single message described in §2.1.

Audience measurement is the one secondary purpose. We want to know which pages and features are actually useful, so this site and the application both run Google Analytics. We tell you here and in the Cookie Policy.

On this site it runs by default and you can refuse at any time — “Cookie settings” in the footer switches it off in one click, on any page, without writing to anyone, and that refusal also applies inside the application. Inside the application, signing in already covers this: acknowledging this notice when you create an account — Terms §2 already requires that acknowledgement — is what discloses it there, the same way you’re already informed about billing and the audit log, so there is no separate toggle inside the product. Opening a shared presentation without an account runs no analytics by default.

We chose notice-and-refusal over a consent banner deliberately. It is the model this notice is written under, and interrupting every visitor with a dialog to ask about a measurement that carries no advertising, no profiling, and no cross-site tracking is friction without a corresponding gain in protection. Refusing costs you nothing: every page, every feature, and your account work exactly the same. §4.3 sets out what is collected, and §B.1 the territorial scope this rests on.

4. Cookies and tracking technologies

4.1 Strictly necessary cookies

Every cookie we set by default is necessary for authentication, security, or remembering the cookie choice you made. The service’s session cookies are all httpOnly (not accessible from JavaScript):

Cookie Purpose Lifetime SameSite
rt Session refresh token 7 days Lax
rt_csrf Cross-site request forgery (CSRF) protection 7 days Lax
oauth_state Federated sign-in flow protection Minutes Lax

Disabling them prevents signing in. They’re removed on sign-out.

One further strictly necessary cookie is set by the website rather than by the application:

Cookie Purpose Lifetime SameSite
sw_consent Records your analytics choice, so a refusal is remembered 24 months Lax

Unlike the ones above it is written by the site rather than the application, and is therefore readable from JavaScript. It holds one value — on or off — and no identifier of any kind. It exists only once you use the settings; until then there is nothing to remember. It is scoped to .slideweave.com so a refusal made on the website also applies inside the application.

We use no advertising or cross-site tracking cookies.

4.2 Local storage in your browser

The service stores information in your browser’s local storage, including your profile (name, email, photo), your editing preferences, your document list, and — as a safety net — the unsaved draft of the document you’re editing.

⚠️ Signing out doesn’t clear everything. Your cached profile and document previews are removed, but your document list, your preferences, and unsaved drafts remain in the browser until you clear the site’s data. If you’re on a shared computer, sign out and also clear the site’s data.

Your access token is never saved in your browser: it lives only in memory during the session.

4.3 Analytics, and how to switch it off

We use Google Analytics 4 here and in the application to measure which pages and features are useful. It sets two cookies:

Cookie Purpose Lifetime
_ga Tells one browser apart from another 13 months
_ga_<property> Holds session state for the property 13 months

The property is configured with Google Signals off and ad personalization off: the data is not joined to a Google account, is not used to build advertising audiences, and is not shared for cross-context behavioral advertising. Event data is retained for a maximum of 14 months.

Switching it off takes one click, and it undoes something. “Cookie settings” in the site footer turns analytics off from any page. Doing so deletes the _ga cookies already in your browser and halts all further collection — it is not merely a preference recorded for next time. The refusal is stored on .slideweave.com, so it applies in the application too.

Inside the application specifically: with an account, analytics runs by default once you’ve acknowledged this notice at sign-up — this section is that disclosure, the same as it already covers billing and the audit log — unless you have refused here, which always wins. Viewing a shared presentation without an account runs no analytics unless you have separately turned it on here.

We also honor the Global Privacy Control signal. A browser that sends it never loads analytics at all, without your having to do anything.

If we ever direct the service to the European Union, analytics there moves to prior opt-in, as Annex B.2 requires. Annex B.1 records the territorial scope this section rests on and the commitment to reassess it before that changes.

5. Artificial intelligence

When you use the generation feature, the text you type on that screen is transmitted to Microsoft, through the Azure AI Foundry service. The service resource is located in the United States geography, region East US 2, but the deployment used is global: Microsoft may process the prompt and response in any Azure region where the model is available.

⚠️ That means that text leaves Mexico every time you generate. If you don’t want text to leave the country, don’t type it on that screen — the rest of the service doesn’t transmit it to that provider.

The exact scope of that transmission:

  • Only the text you type on that screen is sent, along with non-personal parameters (language, number of slides, visual theme) and a fixed system instruction.
  • Your already-saved documents are never sent to the AI provider. No feature transmits your library’s content to it.
  • We don’t use your content to train our own models.
  • Our integration uses Chat Completions with no persistent history, and doesn’t activate the Files, Assistants, stored-response, batch-processing, or fine-tuning features.
  • Microsoft states its base models are stateless and that it doesn’t use prompts or responses to train, retrain, or improve them. It does apply abuse monitoring: a flagged sample may be stored and reviewed by authorized Microsoft personnel. SlideWeave doesn’t have a retention exception enabled for that monitoring and therefore doesn’t promise zero retention. See Microsoft Foundry’s privacy information.

6. Disclosures and transfers

6.1 Disclosures to processors

To operate the service we share data with providers. Except for the note about Stripe after the table, these providers process data on behalf of and under instructions from the Controller, with no purposes of their own:

Provider For what What it receives Where processed
Server4You — a server managed by the Controller on velia.net’s network Host the application and PostgreSQL Account data, relationships between documents, technical data, and logs United States (St. Louis, Missouri)
Microsoft — Azure Blob Storage Store document content and files Content and technical metadata United States (Central US)
Microsoft — Azure AI Foundry Content generation and abuse monitoring The text you type and the generated response Resource in the United States (East US 2); inference processed globally
Google / Microsoft Federated authentication Your identity, at sign-in The provider’s global infrastructure
Google — Google Analytics 4 Audience measurement on the site and in the application Pages visited, referrer, approximate location derived from the IP address, browser and device Google’s global infrastructure, including the United States
Stripe Payments México, S. de R.L. de C.V. and Stripe, LLC Subscription billing, fraud prevention, and financial compliance Billing, transaction, and payment-method data Mexico, the United States, and other locations in Stripe’s global infrastructure

Stripe acts as a processor for certain operations carried out on Atarani’s behalf, and as an independent controller for certain purposes of its own, such as fraud prevention, security, regulatory compliance, and financial risk management. Stripe, LLC takes part in processing under the terms applicable to Mexican accounts. See Stripe’s Mexico Services Agreement, the Data Processing Agreement, and Stripe’s Privacy Center.

Disclosures made solely on the Controller’s behalf don’t require your consent; Stripe’s own transfers and processing are additionally governed by its own documentation and applicable legal bases.

6.2 Transfers to third parties

We don’t sell or trade your personal data. We’ll only transfer it to a third party where the law allows it without consent: pursuant to a duly founded and reasoned request from a competent authority, to exercise or defend rights in a proceeding, or as part of a merger, spin-off, or asset sale, in which case the acquirer will assume the obligations of this notice.

6.3 Data location and international transfers

Part of your data is processed outside Mexico.

  • Application and database: the production server and PostgreSQL are hosted in St. Louis, Missouri, United States, on a server managed by the Controller whose public network is operated by velia.net and marketed under the Server4You brand. Atarani administers the operating system, the application, and PostgreSQL.
  • Content and files: Microsoft Azure Blob Storage in Central US, United States, with local redundancy. When a file is deleted from active storage, Azure retains a recoverable copy for 7 days under its current configuration.
  • Analytics: on the site and in the application, unless you refuse it. Google processes the measurement data on its global infrastructure, including the United States, under its standard contractual clauses and its certification under the EU–US Data Privacy Framework.
  • AI generation: the Microsoft Azure AI Foundry resource is in East US 2, United States. Because the deployment is global, the prompt and response may be processed in any Azure region where the model is available; any data Microsoft stores for the service stays in the resource’s US geography.

7. Data subject rights (access, rectification, cancellation, objection)

You have the right to access your personal data, rectify it when inaccurate or incomplete, cancel it when you consider it’s no longer needed for the stated purposes, and object to its processing for specific purposes.

7.1 How to exercise them

Send your request to privacidad@slideweave.com including:

  1. Your name and a way to communicate the response to you.
  2. A copy of an official ID proving your identity (or your legal representation, if applicable).
  3. A clear description of the data you’re seeking to exercise the right over, and which right you want to exercise.
  4. Anything that helps locate the data.

We’ll respond within the period the applicable law sets. If the request is granted, we’ll fulfill it within the legal deadlines. Exercising these rights is free; only shipping or reproduction costs the law permits may be charged.

7.2 Tools available directly in the service

Without a formal request, from your account you can:

  • Access and rectify the content of your documents at any time.
  • Delete a document. It stays recoverable in trash for 30 days; after that, its active record is removed and deletion of its stored content is requested. Azure’s current configuration allows recovering deleted blobs for an additional 7 days.
  • Delete your account from your profile. This deletes your user record and the records of your personal documents, and requests deletion of their stored content, subject to the limitations explained next. This isn’t possible while you’re the owner of an organization: you must first transfer or dissolve it.

In both cases, deleting stored content happens as a step separate from deleting the record. If that step fails due to a storage-provider error, the file may persist with no record pointing to it. The system currently logs the error but has no automatic retries or an orphan-file sweep, so we can’t guarantee a physical-deletion date when that failure occurs. You can report the case to privacidad@slideweave.com for investigation, without that alone constituting a certification of deletion.

7.3 ⚠️ Limit on the right to cancel: the audit log

You should know this limitation before using the service.

The service maintains a cryptographically chained audit log: every record includes the hash of the previous one, so altering or deleting any of them breaks the chain and destroys the verifiability of the entire log. That verifiability is the whole point of the feature.

As a result, deleting your account doesn’t delete these records. They retain:

  • Your internal user identifier
  • The IP address and user agent from which the recorded actions were taken
  • The date, time, and type of each action
  • For organization-related events, the associated email address

To balance traceability against the principle of limited retention:

  • High-volume access records, including anonymous views, are kept for 12 months from each access.
  • Audit, security, and contractual-compliance events are kept for 72 months from each event. This period allows investigating incidents, defending or asserting claims, and matches the period Mexican law provides for data relating to breach of contractual obligations.

When you delete your account, these records are locked for ordinary use and may only be processed for security, legal compliance, and handling or defending claims. Once the applicable period expires, they’re deleted or irreversibly dissociated, unless they must be kept longer due to a legal obligation, an investigation, a dispute, or an authority’s order. In that case they’re kept only while the exceptional cause persists.

You may withdraw, at any time, the consent given for secondary purposes.

For analytics you don’t need to write to anyone: “Cookie settings” in the site footer switches it off, which deletes the cookies already set and stops collection immediately (§4.3). For anything else, write to privacidad@slideweave.com.

Withdrawal doesn’t apply to primary purposes while you maintain an active account: the service can’t be provided without them. To fully end processing, delete your account, subject to the effects and limitation described in §7.

9. Limiting use or disclosure

Beyond the above, you can request that the use or disclosure of your data be limited by writing to privacidad@slideweave.com.

Keep in mind that you directly control most of the disclosure of your content, and its effects differ depending on the mechanism:

  • A document marked public is accessible to anyone who knows its identifier, with no expiration, and without signing in.
  • A share link uses a random, non-guessable token. It can have a password and an expiration date, but if you don’t set an expiration, it never expires. You can rotate or revoke it whenever you want.
  • An export generates a signed download URL valid for 30 minutes; while valid, anyone who has it can download the file.
  • Revoking cuts off future access; it does not recover copies already downloaded.

Anonymous views of public or shared documents are logged (date, IP, user agent) in the log described in §7.3.

10. Organization content

When a document belongs to an organization, members with sufficient role can view or edit it, and admins can publish, archive, or delete it. Drafts and content under review are visible to those members, including snippets that appear in search results within the organization.

Your personal documents aren’t accessible to any organization’s admins.

If your organization was assigned to you by your employer or by a third party, that entity may be the controller of the data contained in the organization’s documents, and you should also consult its own privacy notice.

11. Retention

Data Retention
Account and profile While the account stays active
Documents and their versions While they exist; 30 days in trash after deletion
Session tokens Refresh 7 days; access 15 minutes
Signed download URLs 30 minutes (export); 15 minutes (editing content)
Analytics choice (sw_consent) 24 months from when you set it; mirrored in local storage as a Safari backstop
Analytics events, unless refused Up to 14 months from each event
Waitlist address Until the plan opens and we write to you, or until you ask us to delete it
Access log 12 months from each access
Audit, security, and contractual-compliance log 72 months from each event; longer only for an exceptional legal cause (§7.3)
Billing data and documentation At least 5 years from when the related tax return was or should have been filed; longer where tax law, an audit, or a dispute requires it

12. Security

We apply reasonable administrative, technical, and physical measures, including: encryption in transit (HTTPS required), session tokens stored only as a hash and never in plain text, CSRF protection, role-based access control, rate limits, short-lived signed download URLs, and a tamper-evident audit log.

No system is completely secure. If a breach significantly affects your rights, we’ll notify you as applicable law requires.

13. Minors

The service is not directed at minors, and we don’t knowingly collect data from minors. If we detect a minor’s account, we’ll delete it.

14. Changes to this notice

We may modify this notice. The current version and its date are always published at https://slideweave.com/legal/privacy/.

When the change is material — new purposes, new transfers, or changes to processing conditions — we’ll communicate it through a notice visible within the application at least 30 calendar days in advance. Where applicable law requires new consent, the corresponding change won’t apply to your data until we obtain it.

15. Authority

If you believe your right to data protection has been violated, you can go to the Secretaría Anticorrupción y Buen Gobierno, the federal authority that — under the 2025 constitutional reform and the Federal Law on Personal Data Held by Private Parties in force since March 20, 2025 — took over the personal-data-protection functions previously held by INAI (dissolved on March 20, 2026).

Address: Avenida de los Insurgentes Sur 1735, Guadalupe Inn, C.P. 01020, Álvaro Obregón, Mexico City. Official site: gob.mx/buengobierno. You can also file your request through the Plataforma Nacional de Transparencia.

16. Governing version and annexes

We publish this notice in Spanish and English. Which version binds you depends on where you reside, under the Annexes. Both are published at the same time and with the same date.

This notice includes two annexes that prevail over the body wherever they conflict with it:

  • Annex A — if you reside in the United States.
  • Annex B — if you reside in the European Economic Area, Switzerland, or the United Kingdom.

If you don’t reside in either territory, only the body of this notice, in Spanish, applies to you.

17. Contact

Personal Data Department: privacidad@slideweave.com Address: Av. Popocatépetl 415, interior D-1706, Santa Cruz Atoyac, Benito Juárez, C.P. 03310, Mexico City


Annex A — United States

Applies only if you reside in the United States. The English version is binding on you. Where it conflicts with the body of this notice, this Annex prevails.

A.1 Scope

Supplements the body of this notice with the information and rights recognized by state consumer privacy laws. We recognize these rights voluntarily for all users in the United States, without conditioning them on the volume or revenue thresholds those laws set.

A.2 Categories of personal information

Category Do we collect it? Source
Identifiers (name, email, account ID, IP) Yes You and your identity provider
Commercial information (subscription history) Yes, when there’s a charge You and the payment processor
Internet activity (Service use, access logs) Yes Automatic
Precise geolocation data No
Biometric data No
Protected characteristics No
Sensitive information We don’t request it
Content you create (audio, image, text in your documents) Yes You
Inferences for profiling No

Purposes and retention periods are those in the body of this notice (§3 and §11).

A.3 We don’t sell or share your personal information

We don’t sell personal information, and we don’t share it for cross-context behavioral advertising, as those terms are defined under California law. We haven’t done either in the past twelve months, nor with anyone under 16. Analytics does not change this: the property runs with Google Signals and ad personalization disabled, so no data leaves for advertising purposes.

We honor Global Privacy Control (GPC). A browser that sends the signal never loads analytics at all, with no action needed from you.

A.4 Your rights

  • Know and access the personal information we hold about you and obtain a copy.
  • Correct inaccurate information.
  • Delete your personal information, subject to legal exceptions and the limitation described in §7.3 of the body (audit log).
  • Opt out of sale or sharing — not applicable, because we do neither.
  • Limit the use of sensitive information — not applicable, because we don’t collect it.
  • Not be discriminated against for exercising any of these rights.
  • Appeal a denial. If we deny your request, you can ask for a review of that decision by writing to privacidad@slideweave.com; we’ll respond within the deadlines your state law sets.

A.5 How to exercise them

Write to privacidad@slideweave.com. We’ll verify your identity against the data associated with your account before handling the request. You can designate an authorized agent, who must prove your written authorization.

You can carry out many of these actions directly from your account (§7.2 of the body).


Annex B — European Economic Area, Switzerland, and United Kingdom

Applies only if you’re located in the EEA, Switzerland, or the United Kingdom and the relevant mandatory law applies, or when this Annex expressly grants a contractual protection. Publishing it, and the possibility of incidentally accessing the Service, don’t by themselves mean Atarani directs its offering to a European state. The English version is binding, unless we’ve actively marketed the Service in your language. Where it conflicts with the body of this notice, this Annex prevails.

B.1 Controller, territorial scope, and representation

Controller: Atarani, S.A.P.I. de C.V., Av. Popocatépetl 415, interior D-1706, Santa Cruz Atoyac, Benito Juárez, C.P. 03310, Mexico City.

Atarani has no establishment or designated representative in the European Union. At launch, the Service directs no advertising, campaigns, domain, euro pricing, or localized offers to a Union state. We don’t block a sign-up or an incidental purchase solely because of a person’s location.

Mere accessibility of the Service, or an incidental purchase, aren’t by themselves enough to trigger the targeted-offering test of GDPR Article 3(2). Atarani will reassess its territorial scope before directing commercial activity to the Union and when its relationship with users there stops being incidental. If Article 3(2) becomes applicable and the limited Article 27(2) exception doesn’t apply, Atarani will designate a representative in writing and publish their details in this section.

Purpose Legal basis
Creating and managing your account; authenticating you Performance of a contract
Storing, versioning, processing, and backing up your documents Performance of a contract
Publishing, sharing, and exporting when you activate it Performance of a contract
AI generation at your request Performance of a contract
Managing organizations, roles, and review flows Performance of a contract
Billing and tax record-keeping Legal obligation
Audit log, security, abuse and fraud prevention Legitimate interest in the Service’s integrity and traceability
Usage and quota limits Legitimate interest in the Service’s availability
Product analytics Consent

You have the right to object to processing based on legitimate interest for reasons relating to your particular situation. You can request the corresponding balancing assessment by writing to privacidad@slideweave.com.

B.3 Your rights

In addition to those in the body, you have the right to:

  • Portability: receive, in a structured, commonly used format, the data you’ve provided us, and transmit it to another controller. Your documents are exportable from the Service.
  • Restriction of processing in the cases the law provides.
  • Objection to processing based on legitimate interest (§B.2).
  • Erasure, subject to the limitation in §7.3 of the body.
  • Withdraw consent at any time, with no retroactive effect on processing already carried out.

We’ll respond within one month, extendable by two further months for complexity, with notice to you.

B.4 Automated decisions

We don’t make automated decisions that produce legal effects on you or similarly significantly affect you, and we don’t subject you to profiling. AI content generation produces a draft that you review, edit, and decide whether to use or discard — it decides nothing about you.

B.5 International transfers

Your data is transferred outside the EEA, in at least two hops:

  1. To the Controller, in Mexico — a country the European Commission has not issued an adequacy decision for.
  2. From the Controller to Server4You, which hosts the production server in the United States on the public network operated by velia.net, to host the application and PostgreSQL.
  3. From the Controller to Microsoft Azure Blob Storage, in the United States (Central US), to store content and files.
  4. From the Controller to Microsoft Azure AI Foundry when you use generation. The resource is in the US geography (East US 2), but inference is global and may be processed in other Azure regions where the model is available.

Mexico has no adequacy decision from the European Commission. These transfers rely on Standard Contractual Clauses approved by the Commission, accompanied by a transfer impact assessment. You can request a copy of those safeguards by writing to privacidad@slideweave.com.

B.6 Data processors

We enter into a contract with each processor containing the content European law requires. The list of processors is the one in §6.1 of the body.

B.7 Retention

The periods are those in §11 of the body. Retaining access records for 12 months and the audit log for 72 months is subject to the balancing assessment in §B.2 and applicable legal exceptions.

B.8 Security breaches

We’ll notify the competent supervisory authority within a maximum of 72 hours of becoming aware of a security breach that poses a risk to your rights, and you without undue delay when the risk is high.

B.9 Complaint to a supervisory authority

You can lodge a complaint with the supervisory authority of your country of residence, your place of work, or the place where the alleged infringement occurred. If you reside in the United Kingdom, the competent authority is the Information Commissioner’s Office (ICO).