Sidecar

Privacy Policy

Last updated: April 8, 2026

Sidecar ("we", "our", or "us") is a presentation tool that lets you view Google Slides alongside companion web content. This policy explains what data we collect, why, and how we protect it.

1. Information We Collect

Google Account Data

When you sign in with Google, we receive your name, email address, and profile picture from Google's OAuth service. We use this solely to identify you within a session and display your name to collaborators in the same room.

Google Slides and Drive Access

We request read-only access to your Google Drive and Presentations in order to export your slides as a PDF for display inside Sidecar. We do not store your slides or any Drive content on our servers. The export is performed server-side on demand and discarded after delivery to your browser.

Session Data

Your OAuth tokens are stored in an encrypted, HTTP-only cookie that expires after 7 days. We do not store tokens in any database or third-party service.

Comments

If you post comments on a presentation, those comments are stored in our database associated with your Google user ID. Comments are scoped to a specific presentation and are visible to other users who access the same presentation.

Realtime Collaboration

When you use the live collaboration features (presence, cursor, drawing), your name, profile picture, and current slide position are transmitted in real time via Ably to other users in the same session. This data is not persisted — it exists only for the duration of the session.

2. How We Use Your Information

  • To authenticate you and maintain your session
  • To display your slides within the app
  • To show your presence and activity to collaborators in the same session
  • To store and display comments you have posted

We do not sell, rent, or share your personal data with third parties for marketing purposes.

3. Third-Party Services

Google OAuth / APIs — used for authentication and slide export. Governed by Google's Privacy Policy.

Ably — used for real-time collaboration messaging. Governed by Ably's Privacy Policy. Only your name, picture URL, and session state are transmitted; no slide content is sent through Ably.

Vercel — our hosting provider. Standard access logs (IP address, user agent, request path) may be retained by Vercel per their data retention policies.

4. Data Retention

Session cookies expire after 7 days. Comments are retained until deleted by the user or until the associated presentation data is removed. We do not retain Google Drive or Slides content beyond the duration of a single export request.

5. Your Rights

You may revoke Sidecar's access to your Google account at any time via Google Account Permissions. Revoking access will sign you out of Sidecar on your next visit. To request deletion of your comments or account data, contact us at the address below.

6. Children's Privacy

Sidecar is not directed at children under 13. We do not knowingly collect personal information from children under 13.

7. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of Sidecar after changes constitutes acceptance of the revised policy.

8. Contact

Questions or requests regarding this policy can be sent to nikhildua@gmail.com.

Terms & ConditionsBack to Sidecar