Privacy — Decodeme for Slack

Last updated:

This page explains exactly what the Decodeme app for Slack can see, what it stores, and how to remove it. It complements the general Decodeme privacy policy and prevails over it for anything specific to Slack.

What the app can access

Decodeme requests the minimum permissions it needs to work. It has no access to your channel history and receives no message events, so it is technically incapable of reading a conversation.

  • commands — receive the /decodeme command and the message shortcut.
  • chat:write — post the result back to you, visible only to you.
  • im:write — send you a direct message with your connection link.
  • users:read and users:read.email — read your own profile once, to match you to your existing Decodeme account.

What text is sent for analysis

Only the text you explicitly submit, one message at a time, through the message shortcut or the /decodeme command. Nothing is collected in the background, and no message is read because it passed through a channel.

Who processes it

Submitted text is analyzed by Decodeme using Microsoft Azure OpenAI as a subprocessor, under an agreement that forbids using customer content to train models. The analysis is stored in your Decodeme account so you can revisit it.

What is stored in Slack

The workspace access token, encrypted; the link between your Slack user and your Decodeme account; your language preference. Message text is not stored by the Slack app itself.

Removing the app

Removing Decodeme from your workspace deletes the access token and every linked session, automatically and immediately. To also delete the analyses stored in your Decodeme account, use the privacy settings in your account or write to us.

Data location and retention

Data is processed on infrastructure located in the United States and the European Union. Analyses follow the retention period of your Decodeme plan; Slack tokens live only as long as the app is installed.

Questions about this statement? Write to privacy@decodeme.ai.