GA

gamma-data-handling

Guidelines for handling user data, PII, and compliance within Gamma presentation generation workflows.

Install

mkdir -p .claude/skills/gamma-data-handling && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/7932" && unzip -o skill.zip -d .claude/skills/gamma-data-handling && rm skill.zip

Installs to .claude/skills/gamma-data-handling

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Handle data privacy, retention, and compliance for Gamma integrations.
70 charsno explicit “when” trigger
Intermediate

Key capabilities

  • Sanitize PII from content before API transmission
  • Enforce data retention policies for exports and logs
  • Handle GDPR access and erasure requests
  • Archive export files to encrypted storage

How it works

The skill provides a framework to sanitize PII from prompts and logs before sending data to the Gamma API, while managing temporary export URLs through secure storage.

Inputs & outputs

You give it
User-submitted content or prompts
You get back
Sanitized content and archived export files

When to use gamma-data-handling

  • Implement data retention policies
  • Handle PII within user-submitted content
  • Ensure GDPR compliance for Gamma workflows
  • Map data flows for compliance auditing

About this skill

Gamma Data Handling

Overview

Data handling, privacy controls, and compliance for Gamma API integrations. Gamma processes user-submitted content through AI to generate presentations -- understand what data flows where and how to handle PII, retention, and GDPR requirements.

Prerequisites

  • Understanding of data privacy regulations (GDPR, CCPA)
  • Completed gamma-install-auth setup
  • Data classification policies defined

Data Flow Map

User Input (content, prompts)
     │
     ▼
┌──────────────┐
│  Your App    │  ← PII may be in content (names, company data)
│  (API key)   │
└──────┬───────┘
       │ POST /v1.0/generations
       ▼
┌──────────────┐
│  Gamma API   │  ← Content processed by AI
│  (gamma.app) │  ← Images generated
└──────┬───────┘
       │ gammaUrl + exportUrl
       ▼
┌──────────────┐
│  Generated   │  ← Presentation stored in Gamma workspace
│  Content     │  ← Export files (PDF/PPTX/PNG) temporary
└──────────────┘

Data Classification

Data TypeClassificationWhere StoredRetention
API keySecretYour env varsActive use only
Content/promptsMay contain PIIGamma servers (during generation)Gamma's policy
Generated gammasUser dataGamma workspaceUser-controlled
Export files (PDF/PPTX)User dataTemporary URLsDownload promptly, URLs expire
User prompts in logsPII riskYour infrastructureYour policy (sanitize!)
Credit usageBilling dataGammaPer Gamma ToS

Instructions

Step 1: Sanitize Content Before Sending

// src/gamma/sanitize.ts
// Remove PII from content before sending to Gamma if not needed

interface SanitizeOptions {
  removeEmails: boolean;
  removePhones: boolean;
  maskNames: boolean;
}

function sanitizeContent(content: string, opts: SanitizeOptions): string {
  let sanitized = content;

  if (opts.removeEmails) {
    sanitized = sanitized.replace(/[\w.-]+@[\w.-]+\.\w+/g, "[email]");
  }
  if (opts.removePhones) {
    sanitized = sanitized.replace(/\+?[\d\s()-]{10,}/g, "[phone]");
  }
  if (opts.maskNames) {
    // Only mask if you have a list of known names
    // Generic regex would be too aggressive
  }

  return sanitized;
}

// Usage: sanitize before generation
const safeContent = sanitizeContent(userContent, {
  removeEmails: true,
  removePhones: true,
  maskNames: false,
});

await gamma.generate({
  content: safeContent,
  outputFormat: "presentation",
});

Step 2: Sanitize Logs

// src/gamma/logging.ts
// Never log raw content or API keys

function logGeneration(request: any, result: any) {
  console.log(JSON.stringify({
    event: "gamma_generation",
    timestamp: new Date().toISOString(),
    generationId: result.generationId,
    outputFormat: request.outputFormat,
    contentLength: request.content?.length,
    // NEVER log: content (may have PII), apiKey
    status: result.status,
    creditsUsed: result.creditsUsed,
  }));
}

Step 3: Export File Handling

// src/gamma/exports.ts
// Export URLs are temporary — download and store securely

import { writeFile } from "node:fs/promises";
import { S3Client, PutObjectCommand } from "@aws-sdk/client-s3";

async function archiveExport(
  exportUrl: string,
  metadata: { generationId: string; userId: string }
) {
  // Download immediately — URLs expire
  const res = await fetch(exportUrl);
  if (!res.ok) throw new Error(`Export download failed: ${res.status}`);
  const buffer = Buffer.from(await res.arrayBuffer());

  // Store with encryption
  const s3 = new S3Client({ region: "us-east-1" });
  const key = `gamma-exports/${metadata.userId}/${metadata.generationId}.pdf`;

  await s3.send(new PutObjectCommand({
    Bucket: process.env.EXPORTS_BUCKET!,
    Key: key,
    Body: buffer,
    ContentType: "application/pdf",
    ServerSideEncryption: "aws:kms",
    Metadata: {
      generationId: metadata.generationId,
      archivedAt: new Date().toISOString(),
    },
  }));

  console.log(`Archived: s3://${process.env.EXPORTS_BUCKET}/${key}`);
}

Step 4: Data Retention Policy

// src/gamma/retention.ts
interface RetentionPolicy {
  exportMaxDays: number;     // Delete local export copies
  logRetentionDays: number;  // Anonymize generation logs
  promptRetentionDays: number; // Delete stored prompts
}

const POLICY: RetentionPolicy = {
  exportMaxDays: 90,       // Keep exports 90 days
  logRetentionDays: 30,    // Anonymize logs after 30 days
  promptRetentionDays: 7,  // Delete prompts after 7 days
};

async function enforceRetention() {
  const cutoff = new Date();

  // Delete old exports from S3
  cutoff.setDate(cutoff.getDate() - POLICY.exportMaxDays);
  await deleteOldExports(cutoff);

  // Anonymize old logs
  cutoff.setDate(cutoff.getDate() + POLICY.exportMaxDays - POLICY.logRetentionDays);
  await anonymizeLogs(cutoff);

  // Delete stored prompts
  cutoff.setDate(cutoff.getDate() + POLICY.logRetentionDays - POLICY.promptRetentionDays);
  await deletePrompts(cutoff);
}

Step 5: GDPR Request Handling

// Handle data subject access/erasure requests
async function handleGdprRequest(
  type: "access" | "erasure",
  userId: string
) {
  if (type === "access") {
    // Return all data we store about this user
    return {
      generations: await db.generations.findMany({ where: { userId } }),
      exports: await listS3Objects(`gamma-exports/${userId}/`),
      // Note: data stored IN Gamma's workspace is Gamma's responsibility
      // Direct user to gamma.app to access/delete their workspace data
    };
  }

  if (type === "erasure") {
    // Delete from our systems
    await db.generations.deleteMany({ where: { userId } });
    await deleteS3Prefix(`gamma-exports/${userId}/`);
    // Instruct user to delete Gamma workspace data at gamma.app
    return { deleted: true, note: "Delete Gamma workspace data at gamma.app" };
  }
}

Compliance Checklist

  • Content sanitized before sending to Gamma API (PII removed if not needed)
  • API keys never logged
  • Export URLs downloaded promptly and stored encrypted
  • Retention policies defined and enforced
  • GDPR access/erasure request process documented
  • User consent obtained for AI processing of their content
  • Gamma DPA signed (if required by your jurisdiction)
  • Logs sanitized (no raw content or PII)

Error Handling

ErrorCauseSolution
Export URL expiredDownloaded too lateDownload immediately on generation completion
PII in logsMissing sanitizationAdd log sanitization middleware
Retention job failedScheduler stoppedMonitor cron job health
GDPR request incompleteGamma workspace not addressedDirect user to gamma.app for workspace data

Resources

Next Steps

Proceed to gamma-enterprise-rbac for access control.

When not to use it

  • When managing data stored directly within the Gamma workspace
  • When logging raw user content or API keys

Prerequisites

Understanding of GDPR and CCPA regulationsCompleted gamma-install-auth setupDefined data classification policies

Limitations

  • Export URLs are temporary and must be downloaded immediately
  • Gamma workspace data management remains the user's responsibility

How it compares

Unlike standard API integrations, this approach explicitly maps data flows and enforces retention policies to maintain compliance.

Compared to similar skills

gamma-data-handling side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
gamma-data-handling (this skill)027dCautionIntermediate
slidev3719moReviewIntermediate
github-code-review132moReviewAdvanced
windows-ui-automation178moReviewAdvanced

Try saying

Example prompts that trigger this skill in your AI assistant.

More by jeremylongshore

View all by jeremylongshore

analyzing-logs

jeremylongshore

Analyze application logs to detect performance issues, identify error patterns, and improve stability by extracting key insights.

14123

ollama-setup

jeremylongshore

Configure auto-configure Ollama when user needs local LLM deployment, free AI alternatives, or wants to eliminate hosted API costs. Trigger phrases: "install ollama", "local AI", "free LLM", "self-hosted AI", "replace OpenAI", "no API costs". Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.

1167

backtesting-trading-strategies

jeremylongshore

Backtest crypto and traditional trading strategies against historical data. Calculates performance metrics (Sharpe, Sortino, max drawdown), generates equity curves, and optimizes strategy parameters. Use when user wants to test a trading strategy, validate signals, or compare approaches. Trigger with phrases like "backtest strategy", "test trading strategy", "historical performance", "simulate trades", "optimize parameters", or "validate signals".

1071

generating-database-seed-data

jeremylongshore

Process this skill enables AI assistant to generate realistic test data and database seed scripts for development and testing environments. it uses faker libraries to create realistic data, maintains relational integrity, and allows configurable data volumes. u... Use when working with databases or data models. Trigger with phrases like 'database', 'query', or 'schema'.

1033

cursor-codebase-indexing

jeremylongshore

Execute set up and optimize Cursor codebase indexing. Triggers on "cursor index setup", "codebase indexing", "index codebase", "cursor semantic search". Use when working with cursor codebase indexing functionality. Trigger with phrases like "cursor codebase indexing", "cursor indexing", "cursor".

885

testing-mobile-apps

jeremylongshore

Execute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".

810

Search skills

Search the agent skills registry