Privacy Policy

Last updated: July 20, 2026

This is a reference English translation provided for convenience. The Japanese-language version is the sole legally binding text; in the event of any discrepancy, the Japanese version prevails. You can view it at /ja.

Swift-Triad LLC (the “Company”) handles the personal information of Users in Swift-Slide (the “Service”) as set out below, in compliance with Japan's Act on the Protection of Personal Information (APPI) and other applicable laws.

1. Information We Collect

  • Account information: email address, name, and profile image obtained upon authentication with a Google or Microsoft account.
  • Uploaded content: PDF and image files uploaded for conversion, and the text and layout information extracted from them.
  • Payment information: information regarding plan contracts and credit purchases (payment details such as card numbers are processed by the payment processor Stripe; the Company does not retain card numbers).
  • Usage information: number of converted pages, processing logs, access logs, cookies, and device/browser information.
  • Inquiry information: the email address you enter when contacting us, the content of your inquiry, and the record of your correspondence with us (including inquiries from persons who do not have an account).
  • Launch-notification sign-up: the email address registered by those who wish to be notified when the Service officially launches.

Where uploaded content contains third parties' personal information or special-care-required personal information (e.g., health or medical history), the User is responsible for securing the necessary consent and lawfulness. The Company processes content mechanically only to the extent necessary for conversion, and does not obtain or use it for the purpose of sorting or extracting special-care-required personal information.

2. Purposes of Use

  • Providing the Service (analyzing PDFs/images, removing text, restoring backgrounds, generating PPTX).
  • Account management and user authentication.
  • Billing and payment processing.
  • Detecting and preventing fraud and ensuring the security of the Service.
  • Responding to inquiries and sending important notices (for a faster response, the content of your inquiry may be sent to the AI processing providers listed in Section 3 to automatically generate and send a reply; where the AI cannot answer, our staff will respond).
  • Sending information about new features, campaigns, and other announcements (you may opt out from the email notification settings on the Settings page, using the method described in the relevant email, or by contacting our inquiry desk).
  • Improving service quality and statistical analysis (conducted in a form that does not identify individuals).
  • Publishing user testimonials (only with your consent; to withdraw a published testimonial, please contact us via the inquiry desk).

3. Provision to External Services (Subcontractors / Sub-processors)

The Service uses the following external services to provide its features, and entrusts or shares information with them to the extent necessary. Images of uploaded documents are sent to the following AI processing providers for text recognition, background restoration, and similar processing.

ProviderPurposeMain location
Microsoft (Azure Document Intelligence)Text recognition (OCR)Japan / USA
Google (Vertex AI / Gemini)Layout and style estimation; generating replies to inquiriesUSA, etc.
RunPodBackground restoration (image inpainting)Japan / USA
Google Cloud (Cloud Run / Cloud Tasks)Application infrastructure and job executionJapan (Tokyo) / USA, etc.
SupabaseAuthentication, database, storageJapan (Tokyo) / USA, etc.
StripePayment processingUSA, etc.
Vercel / CloudflareHosting, delivery, anti-abuseUSA, etc.
Google (Gmail / Workspace)Sending notification emailsUSA, etc.
PostHog, Inc.Analysis of service usage (analytics)USA

Among the above, the AI processing providers are configured so that input data is not used to train models. Except as required by law, the Company does not provide personal information to third parties without the individual's consent.

Among the above external services, for providers to which the Company entrusts the handling of personal data, the Company exercises necessary and appropriate supervision as the entrusting party. Transfers to providers located abroad are governed by Section 9 (Cross-Border Transfers).

4. Data Retention Period (Data Minimization Policy)

For data minimization, the Company adopts the following retention policy.

Type of dataRetention period
Original uploaded PDF/image filesDeleted promptly after conversion is completed.
Editing data (processed images and text information)Free: 24 hours; Starter: up to 7 days; Pro / Business / Enterprise: up to 30 days (can be shortened in settings; the default may be shorter than these). After the retention period, data is automatically erased.
Generated PPTX filesGenerated from the editing data each time they are downloaded, and automatically deleted within 24 hours of generation as temporary files used solely to deliver the download (deleted immediately upon deletion of the project or the account).
Conversion records (date, page count, processing time, processing cost, file name)These are retained for 90 days from the conversion in order to explain your billing. After 90 days, the information linked to you (such as the file name) is deleted, and the remainder is retained as aggregate data that cannot identify an individual for cost management for up to 400 days, after which it is deleted.
Processing logs, access logs, email sending records (recipient, subject, delivery result), operation recordsRetained for troubleshooting, fraud prevention, explaining billing, and legal compliance, and are automatically deleted after 30 to 400 days depending on the type.
Content of inquiries and the record of correspondenceInquiries from persons without an account are automatically deleted 90 days after the last exchange. Inquiries from account holders are deleted upon deletion of the account.
Comments and reasons entered upon cancellationRetained for 90 days for service improvement and automatically deleted thereafter.
Payment records (transaction date, your name and email address, amount, plan name, etc.)In order to comply with statutory retention obligations, these are retained for 10 years from the last day of the fiscal year to which the transaction belongs, even after your account is deleted (aligned with the retention period for accounting books and material business records that Article 615(2) of the Companies Act requires of a membership company; the periods under the Corporation Tax Act and the Consumption Tax Act may be shorter). Thereafter, your name, email address, the payment processor's transaction ID, and the receipt link are deleted, and only the amount, date, and plan name are retained for revenue aggregation.
Email address registered to be notified of the official launchThis is deleted 30 days after that notice is sent, or after one year if the notice has not been sent.
Information retained after account deletion to prevent abuseSolely to the extent necessary to prevent abuse (such as duplicate acquisition of free credits), the Company retains a non-reversible hashed form of the email address and login identifier together with the remaining credit count for up to 90 days. This information alone cannot directly identify an individual and is automatically deleted after that period.

* Due to backup retention, data may remain until the backup generation's storage period elapses, in addition to the retention periods above.

5. Handling of Data in the Team Feature

If you use the team feature (Business plan), the following information is shared among members belonging to the same team, for team administration and billing.

  • Each member's email address and name, join date, and role (visible to all team members).
  • The team's overall credit balance, seat count, and contract details (visible to all team members).
  • Each member's usage for the current month (credits consumed). This is visible only to the team owner and administrators; ordinary members can see only their own usage.

By contrast, files uploaded for conversion, editing data, and conversion results can be viewed only by the member who uploaded them. The team owner, administrators, and other members cannot view them.

* Joining a team occurs by accepting an invitation, and acceptance is treated as consent to the sharing described above. After leaving a team, the above sharing no longer takes place.

6. Security Management Measures

The Company takes the following measures to prevent the leakage, loss, or damage of personal information and for other security management.

  • Technical measures: encryption of communications (TLS), access control (row-level security), and access management based on the principle of least privilege.
  • Organizational and personnel measures: clarifying responsibility for handling personal data and providing necessary management for the personnel who handle it.
  • Understanding the external environment: where personal data is handled in a foreign country, the Company takes security management measures after understanding that country's systems.

The specific content of the security management measures is disclosed upon inquiry.

7. Requests for Disclosure, Correction, Suspension of Use, or Deletion

For disclosure of retained personal data, Users can obtain the data themselves in electronic form (JSON) from “Download your retained personal data” on the settings screen. To verify your identity, you must enter a confirmation code sent to your registered email address. The download includes your account information, your list of projects, conversion records, credit purchase history, support correspondence, any cancellation comments, andpayment records. If the volume is very large, some entries may be omitted; the data itself states when that happens. If you need the complete set, please request it from the inquiry desk below.

By deleting their account from the settings screen, Users can request deletion of the account information and project data the Company holds. For other requests, such as disclosure, correction, or suspension of use of retained personal data, please contact the inquiry desk below. For such requests, we will verify your identity, for example by contact from your registered email address. Fees for these requests are, as a rule, free of charge. You may also make the above requests through the inquiry desk while your use of the Service is suspended (including while your account is suspended).

8. Use of Cookies, etc.

The Service uses cookies and the like to maintain login state, understand usage, and guard against unauthorized access. These are mainly first-party cookies necessary to provide the Service. Users can disable cookies via their browser settings, but in that case some features of the Service may be unavailable.

The Company also uses an analytics tool (provided by PostHog, Inc. (USA)) to improve the Service. The analytics uses the browser's local storage and does not send directly identifying information such as name or email address. The information sent consists of usage logs such as a random user identifier, operation events, and device/browser information.

In addition, on the payment screen your browser loads a script provided by the payment processor Stripe, Inc. (USA). This allows card numbers and similar details to be sent directly to Stripe without passing through the Company's servers, and also sends device/browser information and the like to Stripe for fraud detection. Stripe's handling of such information is governed by its own privacy policy.

In addition, to prevent abuse and automated access, your browser loads a verification script (Turnstile) provided by Cloudflare, Inc. (USA) when you upload a file or submit an inquiry. This sends device/browser information and the like to Cloudflare. Cloudflare's handling of such information is governed by its own privacy policy.

If we introduce additional analytics tools or other mechanisms that send user information to third parties, we will separately notify the recipient, the information sent, and the purpose of use in this Policy.

9. Provision to Third Parties Located Abroad (Cross-Border Transfers)

In providing the Service, the Company may transfer personal data to providers located abroad as listed in Section 3 by entrusting its handling to them. The main destination countries include the USA (depending on the cloud/CDN configuration, data may pass through data centers in other countries).

By concluding data-protection agreements (such as data processing agreements) with these destinations, or by confirming that the destination has a framework based on internationally recognized standards for the protection of personal information, the Company takes the necessary steps so that measures equivalent to those the Company must take under the APPI are continuously taken at the destination. An outline of the measures taken by the destination and information on that foreign country's personal-information-protection system are provided upon request.

Where personal data is provided to a third party located abroad based on the individual's consent, we will inform you in advance of the name of the destination country, information on that country's personal-information-protection system, and information on the measures taken by the destination.

10. Inquiry Desk

Inquiries and complaints regarding the handling of personal information (including retained personal data) are accepted at the following desk.
Business name: Swift-Triad LLC
Address: 3F R-Cube Aoyama, 1-3-1 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan
Representative: Tsuyoshi Kubota (Representative Member)
Email: info@swift-slide.com

11. Response in the Event of a Leak, etc.

If a leak, loss, damage, or other event relating to the security management of personal data handled by the Company (a “Leak, etc.”) occurs or is likely to have occurred, the Company will, in accordance with the APPI and other applicable laws, take necessary investigation, root-cause analysis, and measures to prevent the spread of harm, and will then carry out the responses required by law, such as reporting to the Personal Information Protection Commission and notifying the affected individuals.

Notification to individuals will, as a rule, be made by contact to the registered email address. Where notification to an individual is difficult and it is necessary to protect the individual's rights and interests, we will take alternative measures such as publication on the Service (e.g., setting up an inquiry desk). For Leaks, etc. relating to third parties' personal information contained in uploaded content, direct contact with such third parties may be difficult, so we may respond primarily through the alternative measures above and, as necessary, also by contacting the User who uploaded that content.

Where a Leak, etc. occurs at an external service to which the Company entrusts the handling of personal data, the Company will respond as the entrusting party in accordance with the preceding paragraphs. By keeping retained data to the necessary minimum and limiting the retention period (Section 4), the Company endeavors to minimize the scope of impact in the event of a Leak, etc.

12. Revision of This Policy

The Company may revise this Policy in response to changes in laws or the content of the Service. For material changes, we will give notice on the Service.