← Messaging Apps
D

Slack

Serious concerns
Salesforce · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
Manufacturer: Salesforce

The bottom line

Slack calls your DMs "private." Your employer can export every private message, every deleted message, every file you ever shared — without telling you. On Business+ and Enterprise Grid, a single compliance export dumps your entire Slack history into a JSON file your boss can read over coffee. In 2023, a Reddit user discovered their employer had exported two years of DMs during a performance review. The word "private" in Slack means "private from coworkers, visible to management." Every frustrated DM about your boss is one compliance export away from being exhibit A. In May 2024, engineer Corey Quinn discovered Slack had silently opted every user into AI training on their messages. The opt-out required your workspace admin to email privacy@slack.com — you personally couldn't do anything. After outrage, Slack "clarified" but kept the default. By 2026, SimpleClosure began selling dead startups' entire Slack histories as AI training data, making over $1 million across nearly 100 transactions. Marc Rotenberg of the Center for AI and Digital Policy asked: did any employee consent to their workplace DMs becoming AI training fodder? They did not.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Audited by: Unknown (SOC 2 Type II, Jun 2024) · Unknown (SOC 3, Jun 2024)
An audit is a snapshot, not a guarantee. How reliable are these auditors?
Spying
0/4 N/A
Is someone spying on me?
Data Sharing
2/4 MODERATE
Who gets my data?
Security
2/4 MODERATE
Is it actually secure?
Honesty
4/4 EXTREME
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
Use Signal instead
Subpoenaed twice, could only produce two timestamps
See report →
7Contradictions
0Critical
6High
1Medium
7Sources
Findings by concern
Data Sharing 2/4 MODERATE 1 finding
⚡ highpolicy claims vs policy claims
In May 2024, engineer Corey Quinn discovered Slack had silently opted every user into AI training on their messages. The opt-out required your workspace admin to email privacy@slack.com — you personally couldn't do anything. After outrage, Slack "clarified" but kept the default. By 2026, SimpleClosure began selling dead startups' entire Slack histories as AI training data, making over $1 million across nearly 100 transactions. Marc Rotenberg of the Center for AI and Digital Policy asked: did any employee consent to their workplace DMs becoming AI training fodder? They did not.

What they claim: Slack's privacy principles state it does not use customer data to train AI/ML models powering generative AI features.

What we found: In May 2024, engineer Corey Quinn discovered Slack silently opted all users into AI training using their messages. The opt-out required an admin to email privacy@slack.com — individuals couldn't opt out themselves. By April 2026, defunct startups' Slack workspaces were being sold as AI training data through SimpleClosure for $10,000-$100,000 per dead company.

Security 2/4 MODERATE 2 findings
⚡ highpolicy claims vs network analysis
In December 2022, stolen Slack employee tokens gave attackers access to private GitHub repositories. Months earlier, a researcher found Slack was leaking hashed passwords to other workspace members. That same year, hackers compromised a Rockstar Games employee's Slack account and stole 90 unreleased Grand Theft Auto VI videos — one of the biggest gaming leaks in history. The platform that promises to secure your workplace communications couldn't secure its own employee tokens, its own code repositories, or even its own password handling.

What they claim: Slack protects customer data from unauthorized access.

What we found: In December 2022, stolen employee tokens accessed Slack's GitHub repositories. Months earlier, Slack was found leaking hashed passwords to workspace members. That same year, hackers compromised a Rockstar Games employee's Slack account through social engineering and stole 90 unreleased GTA VI videos.

⚫ mediumpolicy claims vs regulatory findings
Slack advertises "enterprise-grade security." Enterprise Key Management — the feature that lets you control your own encryption keys — costs $30+ per user per month on Enterprise Grid. The other 95% of Slack workspaces? Slack holds all the keys. Your messages are encrypted, but Slack has the master key. It's like a bank vault where the bank keeps a copy of your key. Real security is a premium feature. Everyone else gets security theatre.

What they claim: Slack provides enterprise-grade security for all customers.

What we found: Enterprise Key Management — controlling your own encryption keys — is only available on Enterprise Grid at ~$30/user/month. The 95% of workspaces on cheaper plans use Slack-managed encryption, meaning Slack holds the keys to all your data.

Honesty 4/4 EXTREME 4 findings
⚡ highpolicy claims vs app permissions
Slack calls your DMs "private." Your employer can export every private message, every deleted message, every file you ever shared — without telling you. On Business+ and Enterprise Grid, a single compliance export dumps your entire Slack history into a JSON file your boss can read over coffee. In 2023, a Reddit user discovered their employer had exported two years of DMs during a performance review. The word "private" in Slack means "private from coworkers, visible to management." Every frustrated DM about your boss is one compliance export away from being exhibit A.

What they claim: Slack claims to provide a secure and private workspace for team communication.

What we found: Compliance Export on Business+ and Enterprise Grid allows administrators to export every message — including DMs, private channels, and deleted messages — without notifying employees. Your boss can read every private message, every deleted rant, every DM about job hunting.

⚡ highpolicy claims vs app permissions
Slack's default is to keep every message forever. When you delete a message, it's soft-deleted — still on Slack's servers, still exportable by your employer. Even with a 90-day retention policy, Slack keeps data beyond that for "compliance." A fired employee at a tech startup discovered during a wrongful termination lawsuit that Slack had preserved two years of messages the company claimed were auto-deleted. The delete button in Slack is decorative. Your messages are permanent.

What they claim: Slack states it retains data in accordance with workspace settings and applicable laws.

What we found: Default retention is keep everything forever. Free workspaces limited visible history but retained everything on servers. Messages you delete are soft-deleted and recoverable by administrators. Even custom retention policies are overridden for compliance and eDiscovery. The only true deletion is deleting the entire workspace.

⚡ highpolicy claims vs app permissions
Slack Connect lets you create shared channels with external companies and calls it "secure collaboration." Both organisations' admins can export everything from the shared channel. A security researcher in 2023 showed a malicious external participant could use invisible API integrations to exfiltrate data your IT team couldn't see or control. You invited a partner to collaborate. You actually gave them a pipeline into your data. The security boundary exists on a marketing slide, not in the architecture.

What they claim: Slack Connect enables secure cross-organization collaboration.

What we found: Both organisations' admins can export everything from shared channels. In 2023, a researcher showed a malicious external participant could exfiltrate data through API integrations the host couldn't see or control. Data governance policies and retention settings conflict between organizations.

⚡ highpolicy claims vs regulatory findings
Salesforce bought Slack for $27.7 billion in 2021, and your workplace messages became part of the Salesforce ecosystem. Slack data flows into Salesforce Data Cloud, Einstein AI, and CRM tools. Imagine complaining about a vendor in Slack — that vendor uses Salesforce CRM, now fed by Slack data. Your internal gripe could theoretically enhance the sales intelligence of the company you're complaining about. When you signed up for Slack, you chose a messaging tool. After the acquisition, you got enrolled in a CRM data pipeline without being asked.

What they claim: Slack is an independent workspace platform.

What we found: Salesforce acquired Slack for $27.7 billion in 2021. Slack data flows into Salesforce Data Cloud, Einstein AI, and CRM tools. Internal complaints about a vendor could theoretically enhance that vendor's Salesforce CRM intelligence. The acquisition created a data feedback loop that didn't exist when companies chose Slack.

Sources