1. Introduction
This Privacy Policy explains how Slickback (“Slickback,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you access or use the Slickback web application, related APIs, and services (collectively, the “Service”).
Slickback is an AI-powered marketing creative platform that helps organizations generate product images, video creatives, brand assets, and advertising content, and optionally publish or connect those assets to advertising platforms such as Meta and Google Ads.
By using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service. Capitalized terms not defined here have the meanings in our Terms & Conditions.
2. Scope and who this applies to
This Policy applies to:
- Account holders and organization members who sign in to Slickback
- Administrators who manage organizations, projects, and billing limits
- Visitors to public pages of the Service (such as this page, our Terms, and the public landing experience)
- Individuals whose personal data appears in content you upload or connect (for example, faces in product or campaign imagery), to the extent we process that data as a service provider to your organization
If you use Slickback on behalf of a company or other entity, that entity is typically the “controller” of Customer Content, and we process such data as a processor / service provider on their instructions.
3. Information we collect
We collect information in three broad categories: information you provide, information generated by your use of the Service, and information from integrations you authorize.
3.1 Account and organization information. When you or your administrator creates or manages an account, we may collect:
- Name, email address, and authentication credentials
- Organization name, slug, membership role (e.g. admin or member)
- Project names and configuration settings within an organization
- Preferences such as completed product tours or UI settings
3.2 Customer Content. To provide generation and editing features, you may upload or create:
- Product images, brand assets, logos, and reference media
- Prompts, templates, briefs, scripts, and campaign copy
- Generated images, videos, edits, upscales, and exports
- Brand DNA / website extraction inputs (e.g. URLs) and derived brand style data
- Field-agent or marketplace submissions and related metadata, where those features are enabled
3.3 Advertising and platform connection data. If you connect third-party ad accounts, we may receive and store:
- OAuth tokens and account identifiers for Meta Marketing API and/or Google Ads (as you authorize)
- Ad account, page, campaign, creative, and lead-form metadata needed to publish or manage ads from Slickback
- Privacy policy URLs and other compliance fields you supply for lead forms or ad creatives
3.4 Usage, technical, and operational data. We automatically collect:
- Session cookies and related authentication state needed to keep you signed in
- Device and browser information, IP address, approximate location derived from IP, timestamps, and request metadata
- Feature usage events, generation job status, error logs, and performance / cost metering related to AI usage and credits
3.5 Communications. If you contact us (for example at support@slickback.ai), we collect the content of that communication and associated contact details.
4. How we use information
We use information to:
- Provide, operate, secure, and improve the Service
- Authenticate users, manage organizations and roles, and enforce access controls
- Run AI image/video generation, editing, analysis, scoring, and related workflows you request
- Extract or analyze brand/website information when you initiate Brand DNA or similar features
- Publish or sync creatives to connected ad platforms when you instruct us to do so
- Meter usage, apply credit or generation limits, and produce usage / cost reports for your organization
- Diagnose bugs, prevent abuse, enforce our Terms, and protect the security and integrity of the Service
- Communicate service-related notices (security, account, or material product changes)
- Comply with legal obligations and respond to lawful requests
We do not sell your personal information. We do not use Customer Content to train public foundation models for unrelated third parties, except as necessary to provide the Service through our AI subprocessors under their applicable terms, or as otherwise disclosed to and agreed by your organization in a separate written agreement.
5. Artificial intelligence processing
Slickback uses third-party AI providers (including Google Gemini and, where enabled, other model or media providers) to process prompts, images, videos, and related inputs you submit. Those providers may process content in order to return generation or analysis results to us.
You are responsible for ensuring you have the rights to submit Customer Content for AI processing, including rights in product imagery, likenesses, trademarks, and third-party materials. Do not submit sensitive personal data (such as government IDs, health data, or financial account numbers) unless it is necessary and lawful for your use case and you have a valid legal basis.
AI outputs may be inaccurate, incomplete, or similar to content produced for others. Review outputs before publishing or relying on them commercially.
8. Data retention
We retain account information and Customer Content for as long as your organization maintains an active account and as needed to provide the Service. Generation assets, products, templates, and related records are generally retained until deleted by an authorized user or by us upon organization deletion / account closure, subject to backup and legal retention requirements.
Logs and security records may be retained for a longer period as needed for security, fraud prevention, dispute resolution, and compliance. Connected ad-platform tokens are retained while the connection remains active and are removed or invalidated when you disconnect or when we delete the related organization data.
9. Security
We implement administrative, technical, and organizational measures designed to protect information, including encrypted transport (HTTPS), server-side session authentication, role-based access within organizations, and restricted server-only access to our primary database.
No method of transmission or storage is 100% secure. You are responsible for protecting account credentials, inviting only trusted members to your organization, and configuring third-party ad accounts appropriately.
Note: certain stored media may be accessible via direct object URLs depending on storage configuration. Treat media URLs as sensitive, do not publish private asset links publicly, and contact us if you require stricter access controls for your organization.
10. International transfers
Slickback and its subprocessors may process and store information in the United States and other countries where we or our providers operate. If you access the Service from outside those regions, you understand that your information may be transferred to and processed in countries that may have different data-protection laws than your own.
Where required, we rely on appropriate transfer mechanisms (such as standard contractual clauses or provider certifications) offered by our infrastructure and AI vendors.
11. Your rights and choices
Depending on your location (including the EEA, UK, Switzerland, California, and other jurisdictions), you may have rights to:
- Access, correct, or delete personal information we hold about you
- Export or receive a portable copy of certain personal data
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Opt out of “sale” or “sharing” of personal information as those terms are defined under applicable US state laws (we do not sell personal information)
Organization members should first contact their organization administrator for access or deletion of Customer Content stored in a tenant. You may also email support@slickback.ai with the subject line “Privacy Request.” We may need to verify your identity and will respond within the time required by applicable law.
If you are in the EEA/UK, you may lodge a complaint with your local supervisory authority. We encourage you to contact us first so we can try to resolve your concern.
12. Children’s privacy
The Service is designed for business users and is not directed to children under 16 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
13. Third-party services and links
The Service may link to or integrate with third-party websites and platforms (including Meta, Google, and AI providers). Their privacy practices are governed by their own policies. We are not responsible for third-party practices outside our reasonable control once data is shared at your direction.
14. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. If changes are material, we will provide additional notice as appropriate (for example, via the Service or email). Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
15. Contact us
For privacy questions, requests, or concerns, contact:
- Email: support@slickback.ai
- Product: Slickback
- Related documents: Terms & Conditions