Last updated: April 8, 2026
Sidecar ("we", "our", or "us") is a presentation tool that lets you view Google Slides alongside companion web content. This policy explains what data we collect, why, and how we protect it.
When you sign in with Google, we receive your name, email address, and profile picture from Google's OAuth service. We use this solely to identify you within a session and display your name to collaborators in the same room.
We request read-only access to your Google Drive and Presentations in order to export your slides as a PDF for display inside Sidecar. We do not store your slides or any Drive content on our servers. The export is performed server-side on demand and discarded after delivery to your browser.
Your OAuth tokens are stored in an encrypted, HTTP-only cookie that expires after 7 days. We do not store tokens in any database or third-party service.
If you post comments on a presentation, those comments are stored in our database associated with your Google user ID. Comments are scoped to a specific presentation and are visible to other users who access the same presentation.
When you use the live collaboration features (presence, cursor, drawing), your name, profile picture, and current slide position are transmitted in real time via Ably to other users in the same session. This data is not persisted — it exists only for the duration of the session.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
Google OAuth / APIs — used for authentication and slide export. Governed by Google's Privacy Policy.
Ably — used for real-time collaboration messaging. Governed by Ably's Privacy Policy. Only your name, picture URL, and session state are transmitted; no slide content is sent through Ably.
Vercel — our hosting provider. Standard access logs (IP address, user agent, request path) may be retained by Vercel per their data retention policies.
Session cookies expire after 7 days. Comments are retained until deleted by the user or until the associated presentation data is removed. We do not retain Google Drive or Slides content beyond the duration of a single export request.
You may revoke Sidecar's access to your Google account at any time via Google Account Permissions. Revoking access will sign you out of Sidecar on your next visit. To request deletion of your comments or account data, contact us at the address below.
Sidecar is not directed at children under 13. We do not knowingly collect personal information from children under 13.
We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of Sidecar after changes constitutes acceptance of the revised policy.
Questions or requests regarding this policy can be sent to nikhildua@gmail.com.