Data retention policy
We do not retain any user data except user identification data like name, Slack username, email. We process user conversation data and history through OpenAI API (https://openai.com/policies/terms-of-use) and provide user with the return. There is nothing that gets retained. Data archiving and removal policy
We comply with major data regulations such as GDPR, CCPA, HIPAA, and SOC 2 Type II. To comply with GDPR, we collect and process personal data transparently and with user consent. For CCPA, we provide users with the right to access, correct, and delete their personal data. Regarding HIPAA, we ensure that PHI is collected and processed securely with appropriate safeguards in place. Overall, we strictly follow data archival and removal policies to protect user data and comply with relevant regulations.
Data storage policy
We follow major data storage policies such as GDPR, CCPA, HIPAA, and SOC 2 Type II. To comply with GDPR and CCPA, we ensure that all data is stored securely and protected from unauthorized access, disclosure, or destruction. Regarding HIPAA, we store all PHI in secure databases and ensure that only authorized individuals have access to the data. To comply with SOC 2 Type II, we implement strict access controls, monitoring, and incident response procedures to protect user data. Overall, we take data storage policies seriously and adhere to them to protect user data and stay compliant with relevant regulations.
Data center location(s)
United States
Data hosting details
AWS Cloud Infrastructure and MongoDB AWS Instance.
Data hosting company
AWS, MongoDB
App/service has sub-processors
no
App/service uses large language models (LLM)
yes
LLM model(s) used
Our app uses OpenAI GPT-4 via the OpenAI API to generate responses within Slack.
LLM retention settings
We do not retain any Slack message content or metadata beyond the duration of processing the request. Data is not stored, logged, or reused after a response is generated. Additionally, OpenAI does not use API-submitted data for training unless users opt i
LLM data tenancy policy
The app operates in a multi-tenant architecture. User data is processed per request and not isolated per customer. However, access controls and token-based authentication ensure data privacy and separation between Slack workspaces.
LLM data residency policy
Data is processed by OpenAI servers, which may be located in the United States or other regions where OpenAI infrastructure operates. Our app does not control or configure the physical location where data is processed by OpenAI.