How we handle your data
2ldr; is an AI-collaborative presentation platform owned by Ed.Pro.AI. This policy describes what we collect, why we collect it, how long we keep it, and what rights you have over it.
Last updated: 2026-05-11. We will update the “last updated” date when this policy changes substantively and email registered users to notify of material changes.
1. What we collect
1.1 When you sign up for beta access
- Email address — required, to send you beta-access notifications and verify your account.
- Display name — required, shown to other reviewers on decks you participate in.
- Use-case description — optional free-text describing what you'd use 2ldr; for. We use this to prioritize beta invites and improve onboarding.
- Age attestation — we require confirmation you are 13 or older. We do not collect or store actual age. 2ldr; is intended for users 13+.
- Product-updates preference — optional opt-in for product announcements.
1.2 When you participate in a deck review
- Boarding-pass profile (name, role, lens, coach areas) — stored only in your browser's localStorage. Never sent to our servers unless you explicitly download a TLDR markdown that includes it.
- Notes, proposals, agenda items, votes — the content you contribute to deck discussions. Attributed to the display name from your boarding pass.
- Read timestamps — when an agent fetches the latest deck state, we log the timestamp + IP (anonymized to /24 prefix) for rate-limit enforcement.
1.3 When you create a deck (admin/creator)
- Authentication tokens from AWS Cognito (our identity provider). Tokens are short-lived (60 min access, 60 min ID, 30 days refresh) and stored in your browser per Cognito's standard SDK flow.
- Deck content — the configuration, slide content, templates, and metadata you author.
- UserHistory (optional) — a bio + tags + visibility setting that helps the platform soft-guard reviewer context. Stored in our database, encrypted at rest, with visibility you control (admin-only / reviewers / public).
1.4 What we automatically collect
- CloudFront access logs for the deck pages and admin app — IP address (we anonymize the last octet before any log analysis), user-agent string (hashed for log analysis), request path, response status. Retained 90 days, transitioned to glacial storage thereafter, expired at 365 days.
- API Gateway access logs — structured request logs (no request bodies). 90-day CloudWatch retention.
- CloudWatch metrics — aggregate-only counters and timing percentiles. No personal data.
1.5 What we do NOT collect
- Third-party tracking pixels (no Google Analytics, no Facebook Pixel, no Hotjar, no anything).
- Cookies for advertising or behavioral profiling. See our Cookie Policy for the full list of cookies we use.
- Age beyond the binary “13 or older” attestation.
- Location data beyond what's inherent in your IP address (which we anonymize).
- Biometric, health, financial, or government-ID data.
2. How we use what we collect
- To run the service — authenticate you, render decks, persist notes/proposals/agenda items/votes, send emails (welcome, beta invite, password reset).
- To improve the platform — aggregate usage analytics (which slide types are common, which deck templates are popular). Never tied back to individual users in external reporting.
- To enforce rate limits + detect abuse — CloudWatch alarms on auth-failure spikes, 5xx rates, and unusual access patterns trigger automated rate-limiting + Chris-side review.
- To communicate with you — if you opted into product updates, we may email you about platform changes. Always include unsubscribe.
3. How long we keep your data
| Category | Retention | Notes |
|---|---|---|
| Beta signups | 36 months from last activity, or until you request deletion | If your beta access has not been granted within 36 months, the record auto-expires. |
| User accounts (active) | While the account is active | Deleted within 30 days of you submitting a deletion request. |
| Deck content + notes + agenda items + votes | While the parent deck is active | Cascade-deleted when the deck is archived; archived decks are kept 90 days then permanently deleted. |
| Audit logs (writes to UserHistory + Cognito admin actions) | 7 years | SOC 2 baseline retention. Required for forensic + compliance. |
| CloudFront / API access logs | 90 days hot, Glacier through 365 days, then deleted | Anonymized at log-collection time. |
| CloudWatch metrics + alarms | 15 months (AWS default) | Aggregate-only. |
4. Where your data lives
All Ed.Pro.AI / 2ldr; data is hosted on Amazon Web Services in the us-east-1 region (Northern Virginia, USA). We do not replicate across regions, and we do not use any sub-processors beyond AWS for data storage.
Encryption at rest: AES-256 (S3 SSE-S3, DynamoDB KMS, Cognito-managed). Encryption in transit: TLS 1.2+ (CloudFront, API Gateway, SES).
5. Your rights
Regardless of your jurisdiction, you have these rights over the data you've provided:
- Access — download all data associated with your account as JSON via the in-product Export endpoint (when authenticated), or by emailing privacy@2ldr.ai.
- Deletion — delete your account and all associated data via the in-product Delete-account endpoint, or by emailing the same address. We process deletion requests within 30 days. Cascade-deletes your notes/proposals/agenda items/votes across all decks.
- Correction — edit your boarding-pass profile + UserHistory directly in the admin app. For other corrections, email us.
- Portability — the Export endpoint returns standard JSON.
- Withdrawal of consent — opt out of product-update emails at any time via the unsubscribe link in any email or in your account settings.
If you are an EU/UK resident, you additionally have GDPR rights including the right to lodge a complaint with your local supervisory authority. We act as the data controller for data you provide directly to the platform; AWS acts as a sub-processor.
6. Subprocessors
The complete list of subprocessors we use to operate the service:
- Amazon Web Services, Inc. — infrastructure (S3, CloudFront, API Gateway, DynamoDB, Cognito, SES, KMS, CloudWatch). Region: us-east-1.
That's the entire list. No third-party analytics. No third-party ad networks. No third-party fonts that track. We load Google Fonts CSS but Google does not receive your IP for that load when served via CloudFront caches.
7. Children
2ldr; is intended for users 13 and older. We do not knowingly collect data from children under 13. If you believe a child under 13 has signed up or otherwise provided data, please email privacy@2ldr.ai and we will delete the data promptly.
If you are in the EU/UK, the age threshold under GDPR-K may be 16 in your member state. The 13+ baseline is a floor, not a ceiling. We are not currently region-aware on this; v2 plans to add region-aware age gating.
8. Changes to this policy
If we make material changes to this policy, we will (a) update the “last updated” date above, (b) email registered users at least 30 days before the change takes effect, (c) maintain a public changelog of substantive revisions.
9. Contact
For any privacy question, data-rights request, or just to flag something:
- Privacy: privacy@2ldr.ai
- Security: security@2ldr.ai
- General: hello@2ldr.ai