01
What we collect
Two categories, and we keep them separate. Account data is what we need to run your workspace: names, email addresses, avatars, workspace and channel names, roles and billing details. Workspace content is what your team creates: messages, files, voice notes, tasks, events and reactions.
We also record technical telemetry — device type, app version, error traces, and timing for socket delivery. That is what lets us tell you an incident is real before you open a ticket.
02
What we use it for
Running the product, supporting you when something breaks, billing, and security. That is the complete list.
checkDelivering messages, task updates, events and call state in real time.
checkSending web push notifications you have opted into.
checkInvestigating incidents and abuse, and keeping accounts secure.
checkInvoicing, tax compliance and fraud prevention.
03
What we never do
We do not sell personal data, we do not rent it to advertisers, and we do not train models on your workspace content. Support engineers access workspace content only when you ask us to look at something, and that access is logged.
04
Who else touches it
We use a small number of sub-processors: cloud infrastructure and storage, LiveKit for huddle media transport, a payment processor for billing, and a transactional email provider. Each is contractually bound to process data only on our instructions, and the current list is available on request.
dedicated instance
On-premise deployments use none of these except the ones you already run yourself. Managed private hosting uses our infrastructure provider in the region you choose, and nothing else unless you ask for it.
05
How long we keep it
Workspace content stays until you or your workspace admin deletes it, or until 30 days after a workspace is closed, after which it is purged from live systems and rolls out of backups within a further 30 days. Live call reactions are never stored at all. Telemetry is retained for 90 days.
06
Your rights and controls
You can export your workspace content, correct your profile, delete messages and files, and close the workspace. Where you have statutory rights — access, rectification, erasure, portability, objection — we honour them for personal data we control, and we help your workspace admin do the same for content they control.
07
Where data lives
Our multi-tenant cloud runs in a primary region with backups in the same jurisdiction. If you need data pinned to a specific country, that is what managed private hosting is for; if you need it never to leave your network, that is on-premise.
dedicated instance
With a dedicated instance you choose the region — or the rack. We hold no copy of your workspace content, so international-transfer questions largely disappear.
08
Cookies and local storage
We use an HttpOnly session cookie and a rotating refresh token to keep you signed in, plus local storage for your theme and interface preferences. There are no advertising or cross-site tracking cookies, and the marketing site carries no third-party trackers.
09
Changes and contact
If we make a material change we will tell you in the product before it takes effect — in a channel, not buried in a footer. Questions, data requests and DPAs all go to the same place: our security and privacy queue on the contact page, answered by a person.