Privacy Policy
What Jev for Slack stores, where it is stored, how long it is kept, and who else processes it. The app runs on Cloudflare Workers with D1 storage and sends configured classification requests to OpenRouter, which routes them to TypeSafe. This website is hosted on Cloudflare Pages.
Who we are
Jev for Slack is published by We The Folks sp. z o.o., based in Poznań, Poland. Our address and registration details are in the Contact section. The application runs on Cloudflare Workers with Cloudflare D1 storage.
What this policy covers
This policy covers Jev for Slack and this website. Slack itself is governed by its own policies and your organisation’s agreement with Slack. Jev for Slack is an independently published application.
Our role
For workspace content processed according to an organisation’s automation rules, the organisation determines the purposes of processing and We The Folks processes that content to provide the configured service. Administrators select channels, prompts, variables, outcomes and actions.
We use contact and service-administration information to respond to requests, provide the service and maintain security. Contact us to arrange any data processing agreement required for your organisation before use.
What the app stores
Application records are scoped to the installed Slack workspace. Full message bodies and expanded action text are excluded from activity and pending recovery records. Rule templates may contain personal information if an administrator enters it.
Credentials
We The Folks supplies and pays for the OpenRouter credential. Customers do not need their own API key. The provider credential and token-encryption secret stay on the backend. Slack workspace bot tokens are encrypted before storage and are used to perform the configured Slack operations.
What is sent for classification
The app sends the prompt, outcome descriptions, configured outcome labels and the Slack values explicitly referenced by those templates through OpenRouter to TypeSafe’s Jev model. It does not add implicit whole-workspace context.
Values used only in action templates are expanded by the app and are not included merely because an action references them. The complete expanded model request is limited to 30,000 UTF-8 bytes. Oversized input fails without silent truncation.
A workspace administrator or owner must authorize external processing before classifications or tests run. Consent is checked before each action. Withdrawing it cannot recall data already sent or reverse an operation already accepted by Slack.
Provider health checks verify OpenRouter account access and remaining credits without Slack message content. They do not run synthetic model inference. A successful account check does not clear a retained inference failure; that problem remains visible until a real classification succeeds. Account checks create no activity entries and perform no Slack actions.
Retention and deletion
Activity, pending recovery and action receipts have a fixed 14-day deadline from the original event receipt. Retries and progress updates do not extend that deadline. Expired operational records are excluded from application access and purged by scheduled maintenance.
Temporary editor drafts and dry-test modal results are stored in Cloudflare D1, bound to the workspace and administrator, and expire after 30 minutes. Test results can include rendered action text containing referenced Slack message content. These records use D1 storage protection; the app does not apply its separate bot-token encryption to draft or test-result JSON.
Rules remain until deleted or the app is uninstalled. Uninstall removes application data, but billing identity and trial history remain and the recurring Stripe subscription is not automatically canceled. Cancel through the billing portal before uninstalling. Deletion does not recall data already sent to providers or reverse prior Slack actions.
Expired billing links are purged; processed Stripe webhook identifiers are retained for 90 days. Billing identity and trial history have separate retention and survive reinstall. Contact us for workspace-specific deletion requests or information about support correspondence and required billing records.
Services involved
The app does not enforce provider zero retention, a no-training setting or a fixed external processing region. Do not infer those guarantees from the application’s 14-day activity window.
Access and security
Workspace administrators and owners manage rules, tests, activity and processing consent. Administrative operations check access on the server. Installations, drafts, rules, logs and consent are isolated by workspace.
Slack requests are verified with signing secrets and timestamp checks. OAuth installation uses state validation, and bot tokens are encrypted before storage. Both the bot and the rule owner need current access to the source and destination channels; administrative status alone does not establish private-channel membership.
When a non-idempotent Slack post may have succeeded but cannot be confirmed, the app records an uncertain result and does not blindly replay it.
This website
This website is hosted on Cloudflare Pages. Cloudflare receives request information such as IP addresses and headers to deliver and protect it.
Google Analytics is configured on the public domain to understand visits and interactions. It may use cookies and receive page URLs, referrers, device details and online identifiers. Website analytics is separate from the Slack app and does not connect to a workspace.
Fonts are served by Google Fonts, which receives the request metadata needed to deliver them. Illustrative demos operate locally and do not send their sample messages to Slack or a model provider.
Your choices and requests
Workspace administrators can disable or delete rules, withdraw external-processing consent, and uninstall the app. These controls do not reverse reactions or messages already delivered. Uninstalling does not cancel Stripe billing; cancel the subscription in the billing portal first.
For personal information in workspace content, contact the organisation that operates the workspace. We assist with authorized requests. Contact [email protected] for access, correction, deletion, restriction or portability requests involving information we handle directly. You may also raise a complaint with the appropriate supervisory authority.
Personal information embedded in administrator-written templates or labels may require a workspace-specific review. We cannot automatically locate every personal reference or remove data already transmitted to another provider.
International processing
Providers may process information outside the European Economic Area. The app does not restrict all processing to an EEA region. Contact us to review applicable contracts and transfer arrangements before using the app with data that requires them.
Changes to this policy
This Slack-specific policy is version 1.0, updated September 21, 2026. Material changes will be published with an updated date and version, with notice where required.
Contact
We The Folks sp. z o.o., Wawrzyńca Engeströma 10, 60-571 Poznań, Poland. KRS: 0001185995. VAT ID: PL7812093366.
Privacy questions and data requests: [email protected].
For security reports and general enquiries, contact [email protected]. See also our App Terms.