Data Protection

Privacy Policy

How LECTURE GURU, s. r. o. processes personal data when you use LectureGuru — what we collect, why, who we share it with and what rights you have under the GDPR.

Who we are

LECTURE GURU, s. r. o., Bottova 8005/5, 811 09 Bratislava, Slovak Republic, is the controller of personal data processed through the LectureGuru platform. You can reach our data-protection contact at privacy@lecture-guru.com.

What we do

LectureGuru converts documents and web pages into AI-generated, voice-narrated presentations and videos. To do this we process your account data, your uploaded content and technical data with the help of carefully selected service providers.

Two roles

For your account, billing and product analytics we act as controller. For the content you upload and for viewers of your presentations we act mainly as a processor on behalf of you or your organization.

1. Who is responsible for your data

The controller is LECTURE GURU, s. r. o., registered seat Bottova 8005/5, 811 09 Bratislava - mestská časť Staré Mesto, Slovak Republic, IČO 57517690 (‘LectureGuru’, ‘we’). For all privacy matters contact privacy@lecture-guru.com. We have not designated a data protection officer, as no obligation under Article 37 GDPR applies to us; privacy@lecture-guru.com is the single contact point for all privacy matters.

Where you or your organization upload content containing personal data of other people (for example documents about employees, or when other people view presentations you share), we process that data as a processor on behalf of you or your organization, which remains the controller of that data. This policy describes those processing operations for transparency; responsibility for them rests primarily with the controller who uploaded or shared the content. For business customers our Data Processing Agreement (DPA) applies automatically as an annex to the Terms and Conditions and is published on our website; enterprise customers may request a countersigned copy at privacy@lecture-guru.com.

2. What data we collect

Account and profile data: name, e-mail address, sign-in data and optional two-factor-authentication data, optional phone number and avatar, interface language, and — if you sign in with Google or Microsoft — the identifiers and tokens provided by those services.

Onboarding and organization data: your answers about your role, goals and how you found us; your organization’s name, contact and billing details (billing address, billing e-mail), team members and invitations; your company website, which we analyze to extract branding (logo, colours, fonts).

Content data: documents you upload (including their extracted text), URLs you submit, chat messages you exchange with the AI, and the presentations, scripts, audio, videos, images and exports generated from them. Contacts you store in the built-in contacts module. Content fetched from third-party accounts you connect (for example Notion or Google Drive).

Usage and billing data: subscription and order history, credit balance and per-action credit usage (attributed to the organization member who used them), invoices and payment status from Stripe.

Technical and security data: authentication cookies and session records, log-in timestamps, and your IP address, processed transiently and in security records to protect the Service and prevent abuse.

Product analytics data: events about how you use the application (pages, features used, generation events), processed through PostHog and linked to your user ID.

Viewer data (presentations you watch): if you open a shared presentation, we set a first-party cookie (‘lg_viewer_id’, valid 1 year) and record which slides you viewed, when, and your quiz answers; in live sessions also your chosen display name, poll votes and questions. This data is made available to the owner of the presentation as viewing analytics. If you view anonymously, it is linked only to the cookie identifier, not to your name.

Communications: messages you send us via the contact form, support, or feedback function.

3. Why we process it and on what legal basis

PurposeDataLegal basis (Art. 6 GDPR)
Providing the Service — account, content generation, storage, exports, sharing, live sessionsAccount, content, usage dataPerformance of a contract (Art. 6(1)(b))
Billing, credit metering and payment processingBilling and usage dataPerformance of a contract; legal obligation (accounting and tax law)
Account and Service security, authentication, and abuse preventionTechnical and security dataLegitimate interest in securing the Service (Art. 6(1)(f))
Product analytics and improvement of the ServiceProduct analytics dataLegitimate interest in understanding and improving the Service; consent where required for cookies
Transactional e-mail — verification, security alerts, invitations, export-ready and monitoring notifications, credit alertsAccount data, e-mailPerformance of a contract
Onboarding tips and product news by e-mailAccount data, onboarding answersLegitimate interest / consent; you can opt out at any time in the settings or via the unsubscribe link
Sales follow-up for enterprise interest, based on your self-provided onboarding answersOnboarding and organization dataLegitimate interest in developing our business
Viewer analytics for presentation ownersViewer dataProcessed on behalf of the presentation owner (processor role); the owner is responsible for its legal basis
Compliance with legal obligations and defence of legal claimsAny relevant dataLegal obligation (Art. 6(1)(c)); legitimate interest

4. AI processing

To generate presentations, narration and images, your content is sent to the AI service providers listed in section 5 (OpenAI, Anthropic, ElevenLabs and Replicate) via their business APIs.

Under the API terms we rely on, OpenAI and Anthropic do not use content submitted through their APIs to train their models. We do not use your content to train our own AI models.

The Service does not make automated decisions about you that produce legal or similarly significant effects.

5. Who we share data with

We use the following categories of service providers (processors and independent providers). We share with each of them only the data needed for its function:

ProviderPurposeLocation
VercelApplication hostingUSA/EU
SupabaseDatabase hosting (PostgreSQL)USA/EU
CloudflareFile and video storage; Service-security controlsUSA/EU
StripePayment processing and invoicingUSA/EU
OpenAIAI text generationUSA
AnthropicAI content generationUSA
ElevenLabsText-to-speech voice narrationUSA
ModalDocument conversionEU
FirecrawlFetching and monitoring web pages you submitUSA
ReplicateAI image generationUSA
UnsplashStock image search for slidesUSA
Trigger.devBackground job processingUSA/EU
ResendSending e-mailUSA
PostHogProduct analyticsEU
ComposioManaged connections to third-party apps you connectUSA
Browserbase / HyperbrowserBrowser sessions for automated demo-video recordingUSA/EU

In addition, data is disclosed: to members of your organization within the shared workspace; to viewers, when you share a presentation publicly or by invitation; to authorities where the law requires it; to our accounting, legal and professional advisers where necessary; and to a legal successor in the event of a corporate transaction. We do not sell personal data.

6. International transfers

Several of our providers are established in the United States or process data there. Where personal data is transferred outside the European Economic Area, we rely on the European Commission’s adequacy decisions (including the EU–U.S. Data Privacy Framework for certified providers) or on standard contractual clauses under Article 46 GDPR, supplemented where appropriate by additional safeguards. You can request further information about the specific mechanism for a given provider at privacy@lecture-guru.com.

7. How long we keep data

DataRetention
Account and profile dataFor the life of your account; deleted upon account deletion, at the latest within 30 days
Uploaded documents, chats, generated presentations, audio and videoUntil you delete them or delete your account/organization; deleting an organization also removes its stored files
Billing records and invoicesAs required by Slovak accounting and tax law (generally 10 years)
Viewer analytics and quiz answersFor the life of the related presentation; anonymized viewer records are no longer linked to you after account deletion
Security recordsShort-term, for the period needed for protection of the Service
Product analytics eventsPer our analytics provider’s retention settings
Support and contact-form correspondenceFor as long as needed to handle the matter and defend legal claims, at most 3 years

Residual copies may persist in encrypted backups for a limited period after deletion — at the latest 90 days — after which they are overwritten in the ordinary backup cycle. When you delete your account, records that must survive for other users (for example feedback, or questions you asked in someone’s live session) are de-identified rather than deleted.

8. Your rights

Under the GDPR you have the right to: access your personal data; have inaccurate data corrected; have data erased; receive data you provided in a machine-readable format (portability); restrict processing; object to processing based on legitimate interest, including direct marketing; and withdraw consent at any time where processing is based on consent.

To exercise any of these rights, e-mail privacy@lecture-guru.com. We may need to verify your identity. We will respond within one month, extendable by two further months for complex requests. You can also delete your account and its content directly in the application settings, and manage e-mail preferences there.

If you believe our processing violates the GDPR, you have the right to lodge a complaint with the Personal Data Protection Office of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk) or with the supervisory authority of your habitual residence.

9. Security

We protect personal data with technical and organizational measures appropriate to the risk, including access management, protection of data in transit and at rest, separation of customer environments, monitoring, vulnerability management, backups, and security-incident response procedures. We review these measures regularly.

A more detailed description of the security measures is available to authorized business customers in the confidential Customer Security Annex or through a security questionnaire, where disclosure would not compromise the security of the Service or third-party confidentiality.

No system is perfectly secure. If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority and, where required by Article 34 GDPR, you, without undue delay.

10. Children

The Service is intended for users aged 18 and over and is not directed at children. We do not knowingly process children’s data; if you believe a child has provided us personal data, contact privacy@lecture-guru.com and we will delete it.

11. Cookies

Details about the cookies and similar technologies we use, including the presentation-viewer cookie and analytics, are set out in our Cookie Policy.

12. Changes to this policy

We may update this policy to reflect changes in the Service or the law. We will publish updates on this page and notify you of material changes by e-mail or in the application at least 30 days before they take effect.

Contact information

LECTURE GURU, s. r. o.

Bottova 8005/5, 811 09 Bratislava - mestská časť Staré Mesto, Slovakia
Company ID (IČO): 57517690 · Tax ID (DIČ): 2122824154

Data protection contact

Email: privacy@lecture-guru.com

General questions: support@lecture-guru.com

Web: lecture-guru.com

You also have the right to lodge a complaint with the Personal Data Protection Office of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky) if you believe that the processing of your personal data violates the GDPR.

Privacy Policy | LectureGuru