Slack AI Agents — privacy & data policy
Provider: Salesforce. PromptPrivacy score: 75/100. Last verified August 26, 2026.
What happens to your data?
Slack processes your messages and uploaded content on behalf of your organization, which acts as the data controller. Workspace metadata and account details are used to operate the platform, power predictive productivity features, and maintain system security. Data is shared with approved subprocessors and integrated third-party applications enabled by your administrator.
Does it train on your data?
Customer Data (messages, files, and content) is processed only under customer instructions and the Customer Agreement. Other Information (such as usage metadata, logs, and interaction data) is processed under legitimate interests to build predictive models, rank search relevance, and create productivity tools.
Can you opt out?
Yes. Users can manage marketing preferences, adjust workspace profile settings, enable Global Privacy Control in their browsers, and object to processing based on legitimate interests by contacting privacy@slack.com.
Data retention
Customer Data is retained according to customer instructions and can be customized at the workspace, channel, or message level by administrators. Other information, such as metadata and account details, is retained for as long as necessary to provide the services, pursue legitimate business interests, conduct audits, and meet legal obligations.
Encryption & security
The policy states that Slack implements security measures appropriate to the sensitivity of the data and has obtained internationally recognized security certifications, referring users to external security documentation for specific technical implementations.
Is it safe for work?
Yes. Slack provides enterprise-grade governance controls, standard contractual clauses, international security certifications, and strict controller/processor separation suitable for workplace use.
Source policy: https://slack.com/trust/privacy/privacy-policy