Privacy Policy
What Decker does
Decker is a Figma plugin that converts a Figma design into a Google Slides presentation. To create that presentation in your Google account, Decker asks you to sign in with your Google account (OAuth).
Google data Decker accesses
- Google Drive API (
drive.filescope): limited to files created by Decker itself. This is what lets Decker create and populate the presentation you ask to export through the Google Slides API; Decker cannot read or modify any of your other Drive or Slides files. - Email address: used only to display, inside the plugin, which Google account is currently connected.
What Decker doesn't do
Decker does not collect any data for analytics, advertising, or resale purposes. Decker does not sell or transfer Google user data to third parties, and does not use Google user data to train or improve AI/ML models, whether generalized or personalized. No third party has access to your data. The only processing performed is the strict technical minimum described below, needed to run the export you request.
How Decker protects your data
- Encryption in transit: every connection between the plugin, Decker's backend, and Google's APIs is made over HTTPS/TLS. Decker never transmits your credentials or tokens over an unencrypted channel.
- Encryption at rest: your Google refresh token is never stored in plain text. It's encrypted with AES-256-GCM before being written to storage, using a secret key that only Decker's backend holds.
- No standing access to your files: Decker only touches the Google Slides presentation it creates for you (via the
drive.filescope). It cannot browse, read, or modify any other file in your Drive. - Signed, time-limited URLs: images generated during an export are served through short-lived signed URLs (see retention below) so that they can't be accessed after their purpose is served.
- Access control: only Decker's backend service can decrypt your refresh token or access exported assets; there is no admin dashboard or bulk export of user data.
Data retention and deletion
- Google refresh token and account email: kept encrypted for up to 90 days of inactivity so you don't have to sign in again for every export, and deleted immediately when you sign out of the plugin or disconnect Decker from myaccount.google.com/permissions. An inactive session expires and is deleted automatically after 90 days.
- Exported images: hosted only for the duration of the export and automatically deleted within at most 1 hour of being generated, whether or not the export succeeds.
- Export job status (progress/result of a single export): automatically deleted after 24 hours.
- Sign-in state (temporary OAuth data used only while you're completing the Google sign-in flow): automatically deleted after 10 minutes.
- You can request deletion of any data Decker holds about you at any time, in addition to disconnecting Decker from your Google account. See Contact below.
Contact
For any question about your data or a deletion request, write to b.tighidet0@gmail.com.