Trust · Legal

Gamma privacy policy for AI presentations

Gamma editorialPrivacy & product trust

This privacy page explains what Gamma collects when you browse the marketing site, create an account, or generate presentations, and how we use that information. It is written for skeptical buyers and privacy reviewers, not as a wall of unreadable clauses. Product details can change; when they do, we update this page and the “Updated” date. For contractual terms of use, see /terms. For how we write about the product publicly, see the editorial policy.

Related trust context: /about, /method, and /authors.

Who this notice covers

This notice covers visitors to Gamma’s marketing pages, users who create accounts, and people who submit prompts, outlines, or files to generate or edit presentations. It does not replace customer agreements that may apply to enterprise deployments, and it does not describe every third party you might paste content from (for example, a CRM export you upload). If you use Gamma on behalf of a company, your organization may have additional rules that govern what you may paste into a deck.

We aim for plain language. Where the law requires specific phrasing, we will add it, but we will not hide material practices behind undefined jargon. If a sentence here conflicts with a newer in-product disclosure shown at signup, treat the newer disclosure as controlling for that feature until this page is refreshed.

Information we collect

Account data. When you sign up, we collect identifiers such as email address, authentication tokens from your login provider, and basic profile fields you choose to provide. Billing flows may collect payment metadata through a payment processor; we do not store full card numbers on Gamma servers when a processor handles checkout.

Product content. To generate and edit decks, we process the prompts, outlines, slide text, uploaded files, and settings you provide. That content is the core of the service. Treat sensitive personal data, secrets, and credentials as out of scope for prompts — do not paste API keys, passwords, or regulated health or financial identifiers unless you have a contractual basis and controls that allow it.

Usage and device data. We collect logs that help operate the service: IP address, browser type, approximate location derived from IP, pages viewed, feature events (for example, export attempted), and error diagnostics. On the marketing site, analytics may record which guides and compares people open so we can improve documentation quality.

Support communications. If you email support or submit a correction request, we keep the message content and metadata needed to resolve the issue, including URLs you cite for editorial corrections.

How we use information

We use account and product data to provide the service you request: authenticate you, generate and store decks, enable present links, process exports, and show billing status. We use usage data to keep the product reliable, debug failures, prevent abuse, and understand which workflows need better defaults. We use marketing-site analytics to improve guides — for example, noticing that export documentation needs clearer cleanup expectations.

We may use aggregated or de-identified metrics to understand category demand (pitch versus sales versus classroom jobs) without identifying a specific customer’s confidential narrative. We do not sell personal information as a standalone data product. If we ever change that posture, this page must say so before the practice ships, not after.

Concrete example: if you paste three dated traction metrics into a seed pitch prompt, those metrics are processed to draft slides you can edit. They are not published on our marketing site. They may appear in operational logs that engineers use to debug a failed generation. Access to customer content is limited to people and systems that need it to run or secure the product.

AI processing and subprocessors

Gamma uses model providers and infrastructure vendors to generate outlines, slide copy, and related outputs. That means prompt text and necessary context may be sent to subprocessors under contracts that restrict use to providing the service. The exact processor set can change as models and regions evolve; request a current list from support if you are running a vendor review.

You remain responsible for whether your organization allows specific categories of data to be sent to AI providers. Our editorial pages teach craft; they do not grant legal permission to paste customer PII into a prompt. When in doubt, use synthetic examples for experimentation and keep production facts inside approved systems.

We distinguish product AI processing from the AI drafting aids used on this marketing site (disclosed in the editorial policy). Marketing drafts are our claims. Your decks are your arguments. Mixing those mental models is how teams accidentally publish confidential metrics, or how vendors accidentally imply they train on your slides without saying so.

Cookies and similar technologies

Essential cookies keep you logged in, protect forms, and remember required preferences. Analytics cookies or local storage keys, where enabled, help us measure which trust and product pages are useful. You can block non-essential cookies in your browser; the site may still work for reading guides, though account features need essentials.

We do not use cookie banners as a substitute for this page. If we add advertising pixels or cross-site tracking, we will disclose that category here with enough detail for a privacy reviewer to decide. Decorative “we value your privacy” language without a practice list is not enough.

Sharing and disclosures

We share data with service providers who process it on our behalf (hosting, authentication, payments, analytics, model inference, email delivery). We may disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition, in which case this notice should be updated or successors bound to equivalent protections.

We do not sell deck contents to data brokers. Present links you create may be viewable by anyone who has the URL, depending on your sharing settings, treat link access as a sharing decision you control, similar to sending a file. If you need tighter access controls for enterprise reviews, confirm current sharing options in-product before you put sensitive material behind a link.

Retention and deletion

We retain account and deck data while your account is active and for a limited period afterward as needed for backups, dispute resolution, and legal obligations. Support threads are retained long enough to resolve issues and detect abuse patterns. Marketing analytics retention follows the analytics tool’s configuration and our need to improve documentation.

To request deletion or export, contact support with the email on the account and describe the scope (account wipe versus specific decks). We may retain records we are legally required to keep, such as billing invoices. Deletion of a present link does not guarantee that recipients who already downloaded an export still delete their copies, exports are files under the recipient’s control.

Security posture (plain language)

We use standard safeguards: encrypted transport, access controls, monitoring for abuse, and least-privilege access to production systems. No internet service is perfectly secure. If you discover a vulnerability, report it responsibly through support rather than posting exploit details publicly. Do not use this page as a penetration-test invitation against production without authorization.

Your security obligations matter too: use a strong unique password or SSO, avoid sharing account credentials, and do not paste secrets into slide prompts. A model that drafts a pitch cannot undo a key you published in speaker notes.

Children and sensitive categories

Gamma is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). Do not create accounts for children in a way that violates applicable law. Classroom use by teachers and students should follow school policies for educational tools and student data.

Avoid pasting special-category data (health diagnoses, government IDs, precise biometrics, and similar) into prompts unless you have a written basis that allows it. Our craft guides for education and fundraising are not a green light to ignore those constraints.

Your choices and requests

Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Send requests to the support channel listed on /about with enough detail to verify the account. We may ask for confirmation before completing sensitive actions. Editorial correction requests about marketing claims follow the editorial policy; privacy requests about personal data follow this page.

International transfers

Gamma may process data in the United States and other countries where we or our providers operate. If you are in a region with data-transfer rules, we rely on appropriate contractual and technical measures with providers. Enterprise customers with residency requirements should confirm current options before migrating regulated workloads.

When you should distrust vague privacy claims

Distrust any vendor, including us, that says “we never see your data” while offering cloud AI generation. Distrust “enterprise-grade” language without a processor list or retention story. Distrust cookie banners that obscure analytics. Distrust marketing pages that invent certifications. Prefer dated, specific practices you can verify in-product and in contracts. If this page drifts into slogan territory, treat that as a defect and tell us.

Also distrust present links shared too widely, exports left in shared drives, and prompts that include customer lists “just for one draft.” Privacy failures are often workflow failures. Gamma can scaffold a deck; it cannot replace your judgment about what belongs in a model prompt.

Changes to this page

We will update this page when collection, use, sharing, or retention practices change in a material way. The “Updated” date reflects those changes. For historical marketing claims about privacy that are wrong, use the editorial correction path; for personal data requests, use support. Continued use after a material update means you should re-read the sections that affect your workflow, especially AI processing and sharing settings.

Frequently asked questions

Product prompts and deck content are processed to provide the service you request. We do not sell your deck contents as a public training corpus. Provider subprocessors may process data under their terms when required to generate outputs, ask support for the current processor list.

Use in-product account settings where available, or contact support with the email on the account. We aim to acknowledge deletion and export requests within a reasonable period and complete them subject to legal retention needs.

Yes, for essentials (session, security, preferences) and, where enabled, analytics that help us understand which guides and product pages are useful. You can control non-essential cookies via your browser settings.

Privacy practices are product and legal obligations. The marketing pages that describe them are still subject to our editorial standards for accuracy, see /editorial-policy and /authors/gamma-editorial.

Read how we evaluate tools

Privacy pages state practices. Method pages show how we score product claims, including our own.