Data Policy

1. Permissions in Slack

Permissions

channels:read
View basic information about public channels in a workspace.
Reason for request: To retrieve the channel name.

channels:history
View messages about public channels in a workspace.
Reason for request: In order for the bot to respond to messages.

chat:write
Send bot messages on allowed channels.
Reason for request: To send direct messages.

chat:write.public
Send messages to channels Assort isn't a member of.
Reason for request: To create a poll on a channel where Assort is not a member.

commands
Use /poll slash command.
Reason for request: To create polls from slash commands.

groups:read
View basic information about private channels that Assort has been added to.
Reason for request: To retrieve the channel name.

groups:history
View messages about private channels that Assort has been added to.
Reason for request: In order for the bot to respond to messages.

im:read
View basic information about direct messages that Assort has been added to.
Reason for request: To retrieve the channel name.

im:history
View messages and other content in direct messages that your slack app has been added to. Reason for request: In order for the bot to respond in direct messages.

mpim:read
View basic information about group direct messages that Assort has been added to.
Reason for request: To retrieve the channel name.

team.billing:read
Get a billing plan for a workspace.
Reason for request: To determine Assort's billing structure.

team:read
Get the workspace name, icon and email domain.
Reason for request: To display the team name and team image in the admin panel.

users:read
Get the data of users in a workspace.
Reason for request: To determine display language. To display names when voting in a survey. To display in the admin panel.

app_mentions:read
To view messages that have been mentioned to the app.
Reason for request: In order for the bot to respond to messages.

Slack Permissions Documentation

https://api.slack.com/scopes

2. Data stored by Assort

Data that can be retrieved via Slack.

  • Information about workspace
    • ID
    • Name
    • Profile Image
    • Price Plan
  • Channel (set up for presenting questions)
    • ID
    • Channel Name

Information about members.

  • User
    • ID
    • Display Name
    • Profile Image
    • Position
    • Language

Service Information.

  • Poll Details
  • Poll Responses

Time Tracking Information

  • Clock-in, clock-out, and break timestamps
  • Configuration required for the integration when freee HR integration is enabled

AI Chat Information

  • Messages and threads sent to the AI chat are transmitted to the OpenAI, L.L.C. API solely for the purpose of generating responses. Assort does not store the content of conversations in its database; only usage volume (token counts) is recorded.
  • Under OpenAI's policy, data sent to the OpenAI API is not used to train OpenAI's models.

Knowledge Feature Information (only when enabled by an administrator)

When the knowledge feature is used, the following data is stored in OpenAI's Vector Store (a search-purpose storage), isolated per workspace, so that the AI can search it to generate answers. Under OpenAI's policy, stored data is not used to train OpenAI's models.

  • Documents uploaded from the administration page (these can be deleted from the administration page at any time)
  • Messages in public channels that an administrator has configured as ingestion targets (removing a channel from the ingestion targets stops further ingestion)

Other Settings.

  • Information about the various settings made on the Assort administration page

3. Data not stored by Assort

  • Payment information
  • User email addresses that can be retrieved from slack.