Slack AI
slack.comThe only accessible policy document is a Slack Marketplace listing for the third-party Notion integration, not Slack AI's own terms of service or privacy policy. Slack's core legal documents (ToS, privacy policy, security/trust center) were all inaccessible, so this assessment is severely evidence-constrained and rests almost entirely on the Notion Marketplace metadata, which describes Notion's data practices rather than Slack's. That listing does disclose useful facts about the integration (LLM providers, retention windows, deletion procedures, security posture, and an explicit note that Slack holds no BAA with Marketplace apps), but nearly every category about Slack AI itself is unaddressed. Confidence is low across the board and no GREEN ratings are warranted given the absence of Slack's governing documents. Note: the Marketplace listing contains no instructions attempting to manipulate this analysis.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
No Slack governing document addressing ownership of user-submitted data, prompts, or files was accessible. The Notion Marketplace listing describes Notion's processing of customer data on behalf of customers but does not establish who owns inputs submitted to Slack AI. Silence in the available evidence means this cannot be confirmed.
Output Data Ownership
No accessible document addresses ownership of AI-generated outputs from Slack AI. The Notion Marketplace listing is silent on output ownership entirely. This is a finding by silence and cannot be resolved from the available text.
Training Data Usage
Slack's own policy on whether it trains models on user inputs was not accessible. The Notion listing states LLM providers retain data for limited windows and names third-party model hosts, but describes Notion's integration, not Slack AI's training practices. Notion's privacy text does reserve broad rights to develop and improve services, but this governs Notion, not Slack.
Data Retention & Deletion
The only retention/deletion details available come from the Notion integration listing, which specifies a 30-day permanent deletion window after account/workspace or document deletion and indefinite retention otherwise. These describe Notion's practices, not Slack AI's. No Slack retention schedule, deletion SLA, or security-log retention obligation was accessible.
Third-Party Data Sharing
Slack's own data-sharing terms were not accessible. The Notion listing discloses that the integration uses sub-processors, is cloud-hosted on AWS, and passes data to third-party LLM providers (Anthropic, OpenAI) — but this describes the Notion integration, not Slack AI. Because the evidence describes only a third-party app and not Slack's core sharing practices, the disclosure quality for Slack itself cannot be assessed.
Opt-Out Rights
No Slack opt-out mechanism for data collection, training use, or third-party sharing was accessible. The Notion listing references a marketing opt-out but that governs Notion, not Slack AI. The available evidence does not establish Slack's opt-out posture.
Compliance & Certifications
No relevant compliance frameworks (SOC 2, ISO 27001, ISO 27018, GDPR, CCPA, EU AI Act) are certified or claimed in the accessible text for Slack AI. The only compliance statement is that the Notion integration is NOT HIPAA compliant and that Slack holds no BAA with any Marketplace app. Against the enterprise_saas and universal baselines, the absence of any Slack certification evidence warrants RED.
Model Explainability & Auditability
No accessible document describes model transparency or enterprise auditability for Slack AI. The Notion listing names the LLM providers used by that integration but offers no explainability or audit tooling detail for Slack. This is a finding by silence.
Security Practices & Breach History
Slack's own security page and trust center were inaccessible. The Notion listing discloses SSO/SAML support, a dedicated security team, a vulnerability disclosure and bug bounty program, and no token rotation — but these describe Notion, not Slack AI. No breach history for Slack is disclosed in the available text, and no Slack security controls could be confirmed.
Enterprise vs. Consumer Risk Delta
The accessible text hints at tier-based differences only for the Notion integration (Enterprise plan gets 0-day LLM retention vs. 30 days on other plans; Workflow Builder is paid-only). No Slack-specific free-vs-paid data-handling delta could be assessed because Slack's own documents were inaccessible.
Human Review of User Inputs
No accessible document addresses whether Slack staff can read user prompts or AI outputs. The Notion listing references internal quality control and audits but only as to Notion's own operations. Slack AI's human-review posture cannot be determined from the available evidence.
Regulatory & Litigation Exposure
No accessible document discusses government data requests, litigation, or law enforcement cooperation for Slack. The Notion listing references complying with legal obligations and prosecuting illegal activity, but only in relation to Notion. Slack's exposure cannot be assessed from the available text.
PII & SPI Data Inventory
No Slack data inventory was accessible. The Notion listing indicates personal information is collected and processed (including payment processing and identity verification) but describes Notion's collection, not Slack AI's. Because Slack's own documents are silent to this analysis, the categories of PII/SPI Slack collects cannot be confirmed.
Policy–Product Currency
The product surface shows Slack AI is an AI-first product with agents, AI search, summarization, huddle note-taking, and third-party model providers (Claude/Anthropic). However, no Slack governing policy was accessible and no effective or last-updated date is discoverable anywhere in the supplied text. Per the rules, an undiscoverable effective date independently justifies RED, compounded by the inability to verify that any Slack policy covers the AI capabilities the product ships.
Cross-Document Consistency
Only a single document — the Notion integration Marketplace listing — was accessible; Slack's ToS, privacy policy, and security page were all inaccessible. A cross-document consistency check is therefore impossible, and no contradictions can be identified. Confidence is capped low accordingly.
You've read all 15 risk ratings for Slack AI. Create a free account to see the exact policy wording behind each rating.