> ## Documentation Index
> Fetch the complete documentation index at: https://docs.make-pretty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and privacy

> What the add-in can reach, how sign-in works, where your data is processed, and the controls you have over it.

This page covers the PowerPoint add-in. For Pretty's company-wide security posture, see
[Safety at Pretty](https://make-pretty.com/safety).

## What the add-in can access

The add-in can read and change the presentation you currently have open in PowerPoint, and
nothing else on your machine.

* No access to other files, other decks, or other applications.
* No access to your mailbox, drive or network shares.
* It runs in an isolated sandbox.

## Where things run

Pretty is hosted in the EU. The model picker marks models that run in EU infrastructure with a
*"Hosted in the EU"* badge.

Model inference depends on whether you bring your own provider key:

| Setup                                            | What it means for your data                                                                                           |
| ------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------- |
| Default                                          | Requests run on Pretty's own provider accounts, EU-hosted where the badge says so.                                    |
| Your **OpenAI** key                              | Requests run on your account. A **region** selector picks EU or US data residency.                                    |
| Your **AWS Bedrock** or **Google AI Studio** key | Requests run on your account, in the region you configure.                                                            |
| Your **LiteLLM** proxy                           | Everything routes through a proxy you host, at a base URL you set. Pretty never talks to the model provider directly. |

See [Model providers](/admin/model-providers).

## Your data and models

**No model training.** Your decks, prompts and files are not used to train models.

## Compliance posture

* **ISO 27001 - audit ready.** Pretty's ISO audit is scheduled for September 2026.
* **Designed for GDPR.** EU hosting, self-service export and deletion, and the data-residency
  options above.

<Note>
  This page is a plain-language summary, not a compliance pack. If you need current
  documentation (certificates, data-processing terms, hosting detail), email
  [support@make-pretty.com](mailto:support@make-pretty.com) and ask.
</Note>

## Your controls

| Control              | Where                  | What it does                                                                                      |
| -------------------- | ---------------------- | ------------------------------------------------------------------------------------------------- |
| **Export your data** | Settings → Account     | Downloads a ZIP of everything stored about you. See [Preferences](/help/preferences).             |
| **Delete account**   | Settings → Danger zone | Permanently removes your account, chats, presentations and files. No recovery.                    |
| Membership           | Settings → Members     | Workspace admins add and remove people and change roles. See [Members and roles](/admin/members). |
| Model routing        | Workspace settings     | Admins choose the provider, key and region. See [Model providers](/admin/model-providers).        |

Removing someone from the workspace cuts their access to shared skills, components and
libraries. It does not delete their personal account. That is theirs to delete.
