Deckle

Privacy Policy

Last updated: 2026-05-20

What we collect

  • Account data — email, password hash, organization name. Required to sign in.
  • API content — the HTML, templates, or data you submit. Required to render PDFs.
  • Generation metadata — timestamps, page count, file size, status. Used for billing and dashboards.
  • Billing data — Stripe customer ID, subscription status. Card details live in Stripe, not here.

What we don't do

  • We do not sell your data.
  • We do not train AI on your content.
  • We do not embed third-party trackers on the dashboard.

Storage and retention

Generated PDFs are stored in your chosen storage provider (Cloudflare R2, AWS S3, Google Cloud Storage, or local filesystem on self-hosted). On the hosted plan, PDFs are retained for 30 days then deleted. Generation metadata is retained until the account is deleted.

Subprocessors

  • Clerk — authentication
  • Stripe — billing
  • Resend — transactional email
  • Fly.io — application hosting (US + EU regions available)
  • Anthropic — only when you call the /v1/ai/generate-template endpoint

Your rights

EU/UK residents have rights under GDPR (access, rectification, erasure, portability, objection). Account deletion via the dashboard removes your account and all generated PDFs; subprocessor records (Stripe, Clerk) are deleted on request. Contact us via the contact page to file a data request.

Changes

Material changes are announced via email and on this page at least 30 days before they take effect.

A signable DPA (Data Processing Agreement) is available on request for customers who require one.