Legal
Privacy notice
Slidebites is the data controller for the personal data described here. Last updated 9 September 2026.
Your data, in one place
You do not have to email anyone to exercise your rights. Open your profile and you can:
- Download everything — one file containing your profile, every session and slide you made, your flashcards and revision history, the sessions you attended, your certificates and your contributions. This is your right of access and portability.
- Correct your details — name, role, hospital, handle, bio, photo and links are all editable in the app.
- Delete your account and everything in it, permanently, including the images you uploaded. This is your right to erasure.
For anything else — restriction, objection, or a request on behalf of someone who only attended a session — email hello@slidebites.com or use the contact form and pick "Data or privacy request". We reply within one month, free of charge.
Who we are
Slidebites is operated by Slidebites, established in the United Kingdom, and is the controller for the data described here. Contact us about anything in this notice at hello@slidebites.com. Where you upload teaching material, you are responsible for making sure it contains no patient-identifiable data — see our acceptable use policy.
What we collect, why, and on what legal basis
- Account data (name, email, password hash, profile handle, bio, avatar, links) — to create and secure your account and show your public profile. Basis: performance of our contract with you.
- Sign-in data from Google or Apple, where you use them (name, email address, profile picture, and the provider's account identifier) — only to create and authenticate your account. We do not post anything to those accounts, do not read your contacts, calendar, email or files, and never sell this data. Basis: performance of our contract. If you use Apple's Hide My Email, we only ever see the relay address.
- Content you create (topics, briefs, slides, notes, images you upload, flashcards, folders) — to provide the service. Basis: performance of our contract.
- Topic text sent for AI generation — passed to our AI provider to build your session, and not used by us to train models. Basis: performance of our contract. Never include patient-identifiable information in a prompt.
- Session delivery data (join codes, attendance, answers to questions, reactions, confidence signals, feedback responses, certificates) — to run live sessions and issue attendance records. Answers can be given anonymously. Basis: performance of our contract and our legitimate interest in useful teaching analytics.
- Emails you ask us to send (certificate emails, contact-form messages and our reply) — to deliver what you requested and to answer you. Basis: performance of our contract and legitimate interests.
- Contribution data (amount, frequency, the optional display name and message you choose to publish, and the payment reference from Stripe) — to record support and show the public goal. We never receive or store your card details. Basis: performance of our contract and legitimate interests; publishing your name on the supporter wall is optional and based on your consent.
- Technical and security data (IP address, device and browser information, log and error data) — to keep the service secure, prevent abuse and fix faults. Basis: legitimate interests.
Where we rely on consent — publishing your name on the supporter wall, or emailing a certificate to an address you type in — you can withdraw it at any time and we will act on it. We do not use your data for advertising and we do not make automated decisions that have a legal effect on you.
Who we share it with
- Supabase — the database, authentication, file storage and realtime infrastructure that holds your account and content.
- Our AI provider — receives the topic and brief you type in order to generate a session. It does not receive your account details.
- Resend — sends transactional email such as certificates, contact-form messages and replies.
- Stripe — our payment processor for contributions: payments, subscription management, tax compliance, invoicing, refunds and related customer service.
- Google and Apple — only if you choose to sign in with them, to authenticate you.
- Hosting, error-monitoring and content-delivery providers that run the site.
- Professional advisers (legal, accounting) and authorities, where we are required or permitted by law.
Every provider acts on written terms as our processor and may only use the data to provide their service to us. We do not sell your personal data, and we do not use your clinical teaching content to sell advertising.
What other people can see
Your profile is private unless you make it public. Sessions and flashcard sets are shared to the library only when you choose to share them, and you can make them private again at any time. Live answers can be given anonymously, and a supporter name or message only appears publicly if you tick the box.
International transfers
Some of our providers process data outside the UK and EEA. Where that happens we rely on UK/EU adequacy decisions or on Standard Contractual Clauses (with the UK Addendum where relevant), together with additional safeguards such as encryption in transit and at rest. You can ask us for details of the safeguards for any particular provider.
How long we keep it
- Account and content: while your account is active. When you delete your account it is removed immediately, along with your sessions, slides, uploads, flashcards and certificates.
- Attendance and certificate records of sessions you taught: kept while your account exists, so learners can verify their teaching record; removed with the account.
- Contribution records: the transaction, amount and date are kept for 7 years for tax and accounting. When you delete your account we immediately strip your name, message and email from those records, so only the anonymous financial entry remains. Stripe keeps its own copy as the payment processor.
- Contact-form correspondence: up to 24 months.
- Security and error logs: typically up to 12 months.
When data is no longer needed we delete it or irreversibly anonymise it.
Your rights in full
- Access — get a copy of your data. Download it yourself from your profile.
- Rectification — have inaccurate data corrected. Edit it in the app or ask us.
- Erasure — have your data deleted. Delete your account from your profile, or ask us.
- Portability — receive your data in a structured, machine-readable format. Our export is JSON.
- Restriction and objection — ask us to pause processing, or object to processing based on our legitimate interests.
- Withdraw consent — for anything we do on the basis of consent, at any time.
- Complain — to the UK Information Commissioner's Office at ico.org.uk, or to the supervisory authority where you live or work.
Requests are free and answered within one month. We may ask you to confirm your identity so we do not disclose your data to someone else.
If you only attended a session
You do not need an account to join a session. In that case we hold the display name you typed, your answers, any feedback you gave, and — if you asked for one — a certificate and the email address you sent it to. To see or delete that record, email hello@slidebites.com with the session date and the name you used, and we will action it within one month.
Security
We use appropriate technical and organisational measures: encrypted connections, encryption at rest, row-level access rules so users can only reach their own data, private file storage with short-lived signed links, least-privilege service credentials, secret management and monitoring. No system is perfectly secure, so please use a strong, unique password. If a breach is likely to risk your rights, we will tell the regulator within 72 hours and tell you without undue delay.
Children
Slidebites is intended for clinicians, healthcare staff and students aged 16 or over. We do not knowingly collect data from children. If you believe a child has an account, contact us and we will remove it.
Cookies and similar storage
Storage that is strictly necessary — signing you in, security, and keeping your place and your answers in a live session — is used on the basis that you asked for the service. Anything optional, such as remembering your text size or presenter notes, is only used with your consent, asked for in a banner where the law requires it and always changeable from “Cookie settings” at the bottom of any page. We run no advertising, no cross-site tracking and no third-party analytics, we do not sell or share your personal information, and our typeface is served from our own site so nothing about you goes to a font host. Full detail is in the cookie notice.
Changes to this notice
If we change this notice we will update the date at the top and, for anything significant, tell you in the app. If the change affects optional storage we will ask you again.