Privacy Policy
Slack Says ("we", "us") provides a Slack application and web service that captures question-and-answer content from the Slack channels you authorize and organizes it into a searchable knowledge base. This policy explains what we collect, how we use it, and your rights.
1. Information We Collect
- Slack workspace data: When you install Slack Says and select channels, we receive messages from those channels via the Slack Events API, along with channel IDs, message timestamps, and the Slack user IDs of authors, solely to detect and store Q&A pairs.
- Account data: Your email address, name, and a hashed password (or Google account identifier if you sign in with Google).
- Billing data: Payments are processed by Stripe. We do not store your card details; Stripe does.
- Usage data: Basic technical logs (timestamps, error records) needed to operate and secure the service.
2. How We Use Information
- To detect questions and answers in your authorized channels and build your knowledge base.
- To authenticate you and provide the dashboard, search, and export features.
- To process subscription payments and provide support.
- To maintain security and improve reliability.
3. AI Processing
To extract clean Q&A entries, message content from your selected channels may be sent to a third-party large language model provider (OpenRouter and its underlying model providers) for processing. This content is used only to generate your knowledge base entries and is not used to train models where the provider offers that guarantee.
4. Data Sharing
We do not sell your data. We share it only with subprocessors necessary to run the service: Slack (source), Stripe (billing), our hosting provider (Railway), and the LLM provider (OpenRouter). Each processes data on our behalf.
5. Data Retention and Deletion
We retain knowledge base entries until you delete them or close your account. You can request deletion of your account and all associated data at any time by emailing [email protected]. Uninstalling the Slack app stops new data collection immediately.
6. Your Rights
Depending on your location (including under GDPR and CCPA), you may have rights to access, correct, export, or delete your personal data. Contact us to exercise these rights.
7. Security
We use HTTPS in transit, hashed passwords, scoped OAuth tokens, and access controls. No system is perfectly secure, but we take reasonable measures to protect your data.
8. Changes
We may update this policy. Material changes will be reflected by updating the effective date above.
9. Contact
Questions about this policy: [email protected].