Slack calls your DMs "private." Your employer can export every private message, every deleted message, every file you ever shared — without telling you. On Business+ and Enterprise Grid, a single compliance export dumps your entire Slack history into a JSON file your boss can read over coffee. In 2023, a Reddit user discovered their employer had exported two years of DMs during a performance review. The word "private" in Slack means "private from coworkers, visible to management." Every frustrated DM about your boss is one compliance export away from being exhibit A. In May 2024, engineer Corey Quinn discovered Slack had silently opted every user into AI training on their messages. The opt-out required your workspace admin to email privacy@slack.com — you personally couldn't do anything. After outrage, Slack "clarified" but kept the default. By 2026, SimpleClosure began selling dead startups' entire Slack histories as AI training data, making over $1 million across nearly 100 transactions. Marc Rotenberg of the Center for AI and Digital Policy asked: did any employee consent to their workplace DMs becoming AI training fodder? They did not.
What they claim: Slack's privacy principles state it does not use customer data to train AI/ML models powering generative AI features.
What we found: In May 2024, engineer Corey Quinn discovered Slack silently opted all users into AI training using their messages. The opt-out required an admin to email privacy@slack.com — individuals couldn't opt out themselves. By April 2026, defunct startups' Slack workspaces were being sold as AI training data through SimpleClosure for $10,000-$100,000 per dead company.
What they claim: Slack protects customer data from unauthorized access.
What we found: In December 2022, stolen employee tokens accessed Slack's GitHub repositories. Months earlier, Slack was found leaking hashed passwords to workspace members. That same year, hackers compromised a Rockstar Games employee's Slack account through social engineering and stole 90 unreleased GTA VI videos.
What they claim: Slack provides enterprise-grade security for all customers.
What we found: Enterprise Key Management — controlling your own encryption keys — is only available on Enterprise Grid at ~$30/user/month. The 95% of workspaces on cheaper plans use Slack-managed encryption, meaning Slack holds the keys to all your data.
What they claim: Slack claims to provide a secure and private workspace for team communication.
What we found: Compliance Export on Business+ and Enterprise Grid allows administrators to export every message — including DMs, private channels, and deleted messages — without notifying employees. Your boss can read every private message, every deleted rant, every DM about job hunting.
What they claim: Slack states it retains data in accordance with workspace settings and applicable laws.
What we found: Default retention is keep everything forever. Free workspaces limited visible history but retained everything on servers. Messages you delete are soft-deleted and recoverable by administrators. Even custom retention policies are overridden for compliance and eDiscovery. The only true deletion is deleting the entire workspace.
What they claim: Slack Connect enables secure cross-organization collaboration.
What we found: Both organisations' admins can export everything from shared channels. In 2023, a researcher showed a malicious external participant could exfiltrate data through API integrations the host couldn't see or control. Data governance policies and retention settings conflict between organizations.
What they claim: Slack is an independent workspace platform.
What we found: Salesforce acquired Slack for $27.7 billion in 2021. Slack data flows into Salesforce Data Cloud, Einstein AI, and CRM tools. Internal complaints about a vendor could theoretically enhance that vendor's Salesforce CRM intelligence. The acquisition created a data feedback loop that didn't exist when companies chose Slack.