Pretty

Terms & legal notices

Privacy Policy

Version 1.2Current

Effective 27 August 2026

This Privacy Policy explains how Pretty GmbH (“Pretty”, “we”, or “us”) processes personal data when you visit make-pretty.com, communicate with us, or use the Pretty web editor and PowerPoint add-in where Pretty acts as the controller.

When an organization provides Pretty to its users, that organization normally controls the personal data in presentations, prompts, and other Customer Content. Pretty processes that data on the organization’s instructions under our Data Processing Agreement.

1. Controller and contact information

The controller for the processing described in this Privacy Policy is Pretty GmbH. Questions about privacy, data protection, or this Policy can be sent to support@make-pretty.com.

If you use Pretty through your employer or another organization, contact that organization first about Customer Content and account administration. We will support the organization in handling your request where required.

2. What data we collect and why

a. Visiting our website

When you visit make-pretty.com, our systems process technical request data such as your IP address, date and time of access, requested URL, referrer where provided, device and browser information, transferred data, response status, and error information.

We use this data to deliver and secure the website, diagnose errors, and prevent misuse. The legal basis is our legitimate interest in operating a secure and reliable website under Article 6(1)(f) GDPR. We retain server logs only for the period needed for those purposes unless an incident requires longer retention.

b. Registration and account administration

When an account or organization workspace is created, we may process:

  • name, business email address, organization, role, and user identifier;
  • authentication, session, invitation, and sign-in data;
  • workspace settings, permissions, and subscription information; and
  • SSO or identity-provider attributes when the Customer enables an identity integration.

We use this data to provide accounts, authenticate users, administer workspaces, and prevent fraud or misuse. The legal bases are performance of a contract under Article 6(1)(b) GDPR and our legitimate security interests under Article 6(1)(f) GDPR.

c. Contact, sales, feedback, and support

If you contact us, book a meeting, submit feedback, or request support, we process your contact details, organization, the content of your message, and any material you choose to attach. When you request debugging support, diagnostic console or network data may be included with your submission.

We use this data to answer the request, investigate the issue, manage our business relationship, and document the outcome. The legal bases are Article 6(1)(b) and Article 6(1)(f) GDPR. Detailed diagnostic data is received only for customer-requested debugging and temporary diagnostic copies are automatically deleted after 14 days.

d. Billing and payment

For paid subscriptions, we process the Customer’s company and billing details, contact person, plan, invoice history, payment status, and tax information. Payment or marketplace providers process payment credentials under their own privacy terms. We retain invoices and related records for statutory commercial and tax periods. The legal basis is Article 6(1)(b) and Article 6(1)(c) GDPR.

e. Email communications

We use email to send one-time authentication codes, invitations, service notices, security information, and replies to requests. These communications are necessary to provide the Service or serve our legitimate interest in keeping users informed. We send marketing email only where permitted by law and provide an unsubscribe method when required.

f. Use of the Pretty service

Pretty processes account data, Customer Content, configuration data, usage events, and technical diagnostics to provide the editor and PowerPoint add-in. Customer Content may include presentation files, slide text, images, notes, prompts, selected presentation context, source documents, and AI-generated output.

Pretty stores presentation files and source documents when a user uploads or saves them. Chat prompts and generated responses are retained as part of chat history. Temporary processing copies created from uploaded content are automatically deleted after 14 days. We do not use customer prompts, presentation content, uploaded files, or generated output to train AI models.

When product analytics is enabled, PostHog processes defined product events and exception data to help us understand feature use and diagnose errors. On the public marketing website, PostHog also captures page views and interactions with links, buttons, and forms. When session replay is enabled, it can record rendered page and canvas content, console logs, network request and response headers and bodies, and text entered in form fields. Current project settings do not mask form inputs in session replay.

On the public marketing website and in the editor, PostHog stores analytics identifiers in cookies and local storage. In the PowerPoint add-in, it uses local storage. Pretty processes analytics data to perform the Customer contract and for its legitimate interests in securing, diagnosing, and improving the Service under Article 6(1)(b) and Article 6(1)(f) GDPR. Analytics data is kept for the retention period configured in Pretty’s PostHog EU project.

g. PowerPoint add-in and connected services

The add-in reads and modifies the active presentation when the user invokes a Pretty function. It does not require general access to the Customer’s internal network. If a Customer connects its own AI gateway or another service, Pretty transmits the data required for the requested function to that endpoint under the Customer’s configuration. The Customer controls the endpoint, credentials, upstream providers, and their retention settings.

h. Business calls, social media, and applications

We process contact and communication data when you join a business call, contact us through a social platform, or apply to work with Pretty. We record a call only after informing participants and obtaining any consent required by law. Application data is used to assess and manage the application and is deleted when it is no longer needed, subject to legal retention and defense periods.

3. How we process data

a. Security

Pretty uses encryption in transit and at rest, logical tenant isolation, role-based access, staff multi-factor authentication, environment separation, access logging, managed secrets, monitoring, backups, and incident-response procedures. More information is available on our Safety page.

b. Processors and third parties

We use service providers for infrastructure, transactional email, product analytics and diagnostics, feedback and support, payments, business communications, security, and professional advice. Providers may process data only for the contracted service and must protect it under applicable data protection terms.

The current processors used for Customer Content and service operation are listed in the DPA Sub-Processor appendix. We may also disclose data where law requires it, to protect rights and security, in a corporate transaction under confidentiality obligations, or at your direction.

c. International data transfers

Core application and storage resources for the managed Service are configured in the European Union. Some providers may process account, email, support, operational monitoring, or technical data outside the EEA. Operational monitoring data may include chat prompts, responses, files, images, and error details. Where the GDPR requires a transfer mechanism, we use an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, EU Standard Contractual Clauses, or another lawful safeguard.

Contact support@make-pretty.com to request information about a specific transfer safeguard.

4. Data retention and deletion

How long we keep personal data depends on why we process it and whether Pretty acts as the controller or processes it for an organization. We retain data only as long as needed for the relevant purpose, contract, legal obligation, security requirement, or the establishment or defense of claims.

a. Data Pretty controls

  • Account and workspace records are retained while the customer relationship is active. Where Pretty controls those records, we delete or anonymize them after offboarding unless security, legal, or compliance obligations require longer retention.
  • Where Pretty acts as controller, product analytics processed through PostHog Cloud EU and feedback and support data processed through Gleap are retained only as long as needed to operate, secure, troubleshoot, and improve the Service, subject to configured retention settings and applicable contracts. Temporary customer-supplied diagnostics are automatically deleted after 14 days.
  • Application, security, and access logs are retained only for operational and security needs. We may retain relevant logs longer when needed to investigate an incident.
  • Business, contract, accounting, and tax records are retained for the periods required by applicable law.

b. Customer Content Pretty processes for organizations

Stored Customer Content, including presentations, uploaded files, generated assets, and chat history, remains available until a user or workspace administrator deletes it or the Customer contract ends. Temporary processing copies created from uploaded content are automatically deleted after 14 days.

After the Customer contract ends, Pretty makes available any standard export function and deletes Customer Content from active systems within 30 days, unless the Customer requests earlier deletion and it is technically feasible. Pretty creates backups at least daily, and backup copies expire through Pretty’s 30-day backup retention cycle rather than through immediate selective deletion. Pretty may retain records required by law or needed to demonstrate compliance, but will isolate them and use them only for that purpose.

c. Deletion requests

To request deletion of personal data that Pretty controls, contact support@make-pretty.com. If your request concerns Customer Content controlled by your employer or another organization, submit the request to that organization. Pretty will support the organization and act on its documented instructions where required.

5. Cookies and similar technologies

We use cookies, local storage, and similar browser technologies that are necessary for authentication, session management, security, preferences, and delivery of the website and Service. The legal basis is Article 6(1)(f) GDPR together with Section 25(2) TDDDG where applicable.

Configured analytics starts when the deployed public marketing website, Pretty editor, or PowerPoint add-in initializes; these surfaces do not currently show a separate analytics-consent prompt. Pretty relies on the legal bases stated in Section 2(f). Advertising and other marketing technologies are used only where permitted and, when required, after consent. You can manage browser storage through your browser. Blocking necessary technologies may prevent sign-in or other Service functions from working.

6. Automated decision-making and profiling

Pretty does not make solely automated decisions about individuals that produce legal or similarly significant effects within the meaning of Article 22 GDPR. We may use technical signals to identify abuse, protect accounts, and limit malicious traffic. A person can review a disputed account restriction on request.

7. Your rights as a data subject

Subject to the conditions in the GDPR, you may have the right to:

  • obtain access to your personal data and information about its processing;
  • correct inaccurate or incomplete personal data;
  • request erasure or restriction of processing;
  • receive data you provided in a structured, machine-readable format;
  • object to processing based on legitimate interests;
  • withdraw consent with effect for the future; and
  • lodge a complaint with a competent data protection supervisory authority.

To exercise a right concerning data controlled by Pretty, contact support@make-pretty.com. We may ask for information needed to verify your identity. For Customer Content controlled by your employer or another organization, submit the request to that organization.

8. Changes to this Privacy Policy

We update this Privacy Policy when our services, legal obligations, or processing practices change. The current version and effective date are published on this page. We will provide additional notice where required by law.