Legal

Privacy Policy

Last updated: 2026-09-03

This Privacy Policy explains how the Clode for Slack application ("the app", "we", "us") accesses and handles information when you install it in a Slack workspace and use it to interact with Clode AI agents. Clode is an AI-agent platform operated at clode.io (also referred to as "aramb"). This policy covers the Slack app specifically.

Summary

  • The app is mention-only: it receives and processes message content only from conversations where an agent is explicitly @mentioned.
  • It does not passively read, monitor, or index your channels.
  • Message content from a mention is sent to the Clode platform to run the mentioned agent and generate a reply.
  • You can revoke all access at any time by removing the app from your workspace.

Data the app accesses

To function, the app accesses the following categories of data. Each is tied to the Slack scopes you authorize at installation.

  • Message content — only where an agent is mentioned. When an agent is @mentioned in a public channel, private channel, group message, direct message, or thread, the app reads the relevant messages in that conversation so the agent has the context needed to respond. This can include the mentioning message and surrounding messages in the same thread or conversation.
  • User profile and email. Via users:read and users:read.email, the app reads basic profile information (such as display name and user ID) and email address of users it interacts with, to attribute requests, address replies correctly, and associate activity with the correct Clode account or workspace.
  • Files you provide. Via files:read, when a file is shared in a conversation the agent is handling, the app can read that file so the agent can work with it. Via files:write, the agent can post files back into the conversation.
  • Channel and conversation metadata. Via the channels, groups, im, and mpim read scopes, the app reads metadata such as channel names, membership context, and conversation identifiers needed to deliver replies to the correct place. Via channels:join, channels:manage, and groups:write, the app can join or be added to conversations so an agent can participate where it is invited.
  • Interaction signals. Via chat:write and reactions:write, the app posts the agent's replies and can add emoji reactions. Via commands, it can receive slash-command invocations directed at it.

Requested Slack scopes

At installation the app requests the following OAuth scopes:

  • app_mentions:read
  • channels:history
  • channels:join
  • channels:manage
  • channels:read
  • chat:write
  • commands
  • files:read
  • files:write
  • groups:history
  • groups:read
  • groups:write
  • im:history
  • im:read
  • im:write
  • mpim:history
  • mpim:read
  • reactions:write
  • users:read
  • users:read.email

Some read scopes (for example the history scopes) are required by Slack so the app can retrieve the messages in a conversation where it is mentioned. The app uses this access only to build context for a mentioned agent — not to bulk-collect or continuously monitor conversations.

Why we process this data

We process the data above for a single purpose: to run the agent you mentioned and return its response. Concretely, that means reading the conversation context, running the configured agent on the Clode platform, and posting the reply, reactions, or files back into Slack. Profile and email data is used to route and attribute that activity. We do not sell your data, and we do not use your message content to train third-party models outside of generating your requested responses.

How message content is processed

When an agent is mentioned, the relevant message content and any provided files are transmitted to the Clode platform, which runs the agent configured by your workspace or builder. Generating a response typically involves sending the content to a large language model (LLM) provider configured for that agent. Content is processed to produce the reply and is handled according to this policy and the Clode platform's terms.

Data retention and limits

  • The app requests and processes message content on demand, in response to a mention. It does not maintain a standing copy of your channel history.
  • Operational records (such as the conversation context for an in-flight request, and logs needed for reliability, security, and abuse prevention) are retained only as long as needed for those purposes and then deleted or aggregated.
  • Agent interactions may be retained within your Clode account per the Clode platform's data settings so that your workspace can review its own agents' activity.
  • We apply reasonable technical and organizational measures to protect data in transit and at rest.

Sub-processors

To deliver the service, the app relies on:

  • The Clode / aramb platform — runs the agent and orchestrates the response.
  • The configured LLM provider — the large language model provider set for the agent, which processes the content sent to it to generate the response.
  • Slack — the messaging platform through which the app receives mentions and delivers replies.

The specific LLM provider depends on how the agent is configured in the Clode console.

Your rights and choices

  • Control participation. Because the app is mention-only, you control when it engages: it acts only when an agent is @mentioned.
  • Access and deletion. You may request access to, or deletion of, data associated with your use of the app by contacting us at the address below. Where data lives in your Clode account, your workspace administrators can also manage it there.
  • Workspace administration. Slack workspace administrators can control installation and remove the app for the whole workspace.

Data deletion and uninstalling

Removing the app from your Slack workspace revokes its OAuth tokens and its access to your workspace immediately. After uninstall, the app can no longer read messages, profiles, files, or metadata. To request deletion of any residual data associated with your prior use, contact us at support@srclode.online and we will process the request in line with applicable law and the Clode platform's data settings.

Children

The app is intended for use within workplaces and is not directed to children.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, through additional notice.

Contact

Questions or requests regarding this policy or your data can be sent to support@srclode.online.