Reviewed Jun 2026 · policies are checked weekly for changes · stated — every cell is read from Slack's published policy; none has been tested (run by us) yet.
1Accessstated
Slack handles data-subject access requests through its Data Request policy, but for the typical member the personal data lives inside a workspace controlled by the organization owner rather than being self-serve, so access is scored at the partial level.
Slack — Data Request policy · accessed Jun 2026 ↗
0Trains AIstated
Slack trains "global" machine-learning models (channel / emoji recommendations, search) on customer messages, files, and other content by default, with opt-out available only by emailing feedback@slack.com — an opt-out, not opt-in, default that drew public criticism in May 2024; generative-AI training is separately gated to opt-in consent. Default training on your content scores this cell at zero.
Slack — Privacy Principles (global models, email opt-out) · accessed Jun 2026 ↗
1API access — feeds Agent Readiness, not the /12stated
Slack has an OAuth 2.0 API, but access to a member's data is scoped to apps installed in a workspace and gated by the workspace admin rather than a consumer self-granting access to their own personal data, so agent access is scored at the partial level.
Slack — Data Request policy (admin-gated export) · accessed Jun 2026 ↗
Reviewed Jun 2026 from Slack's Privacy Principles, Data Request policy, and the May 2024 global-model reporting. All cells "stated", not tested. Slack is a B2B tool: individual data rights are largely mediated by the workspace owner, and export (Corporate Export) is admin-only on paid plans, so access / portability / friction / deletion all score at the partial level. The decisive issue is AI — Slack trains "global" machine-learning models on customer messages and files by default, with opt-out only by emailing feedback@slack.com; that zero on training caps the grade at C. Slack does not sell customer data.