Last updated
Privacy Policy
What we collect
When a Workspace installs AI HR Bot we store your Slack team identifier, your Slack workspace name — which also becomes the default company name — the identifier Slack assigns to our bot user, and the installation token, encrypted before it is written to storage. The Slack account that runs the install is recorded as an HR Head for the Workspace.
When an Employee uses the bot, or when an HR Head asks the bot to act on them — setting someone’s Leave Balance works even if that person has never messaged the bot — we store their Slack user identifier and an Employee profile: name, role, department, their Lead, their HR Contact, Hire Date, birthday, GitHub handle, and both Leave Balances. Some of those fields are read from the Employee’s Slack profile automatically the first time the bot meets them — their name, their job title, and your workspace’s birthday and GitHub custom fields where you have defined them. The rest are filled in through conversation.
We also store the conversation itself: every message an Employee sends the bot and every reply the bot sends back, together with the Slack channel and thread it belongs to. Memory entries the assistant records about an Employee are stored as text alongside a search embedding.
When your HR team configures the bot we store the Knowledge Base entries they write, the company-wide directives they set, Leave Policies and their Accrual settings, Approval Chains, and Requests — each Request’s type, status, dates, the reason an Employee gave and the reason attached to a decision. We store Knowledge Gaps: the text of a question the Knowledge Base could not answer, and the Slack identifier of the Employee who asked it. Privileged actions such as approvals and configuration changes are written to an audit record.
Why we collect it
To answer HR questions, keep Leave Balances current, route Requests through your Approval Chain, and show your HR team where the Knowledge Base has gaps. None of it is collected for advertising or resale.
Who processes it
Two AI providers receive Workspace content in the course of answering. They act as processors on our instruction, for that purpose only.
Anthropic — Claude generates the assistant replies. It receives: Conversation text, plus the Employee profile, Leave Balances, applicable Leave Policy, Memory entries, any Knowledge Base entries used to answer, and any company-wide directives your HR team has set.
Google — Gemini creates embeddings for Knowledge Base and Memory search. It receives: Knowledge Base entries, Memory entries, and the search text the assistant sends on the Employee’s behalf to look them up.
What those two providers may do with the data under their own terms is set by their policies, not by this one. We do not make commitments here on their behalf.
How to delete it
One Employee’s data. An HR Head asks the assistant, in Slack, to delete it. The dashboard has no button for this. There are two modes, and the mode has to be chosen when the deletion is made:
- Forget, the default, hard-deletes that Employee’s profile, Memory entries, conversations, and the Knowledge Gaps they raised. Their Request records are left intact.
- Anonymize records does all of the above and additionally blanks the personal fields on those Request records, replacing the Employee identifier with the placeholder
DELETED.
The choice cannot be revisited afterwards. Forgetting deletes the Employee record first, and the anonymize path begins by looking that record up — so "forget now, anonymize later" fails instead of anonymizing.
The whole Workspace. Removing the app from Slack, and pressing Disconnect in the dashboard, both run the same removal: the Workspace record is deleted, and with it every Employee profile, conversation, Memory entry, Knowledge Base entry, Knowledge Gap, Request, Leave Policy and its Accrual settings, Approval Chain, company-wide directive, and audit record held against it. The stored installation token is dropped at the same time.
What this notice does not yet cover
It does not state a lawful basis for processing, how long data is kept, or the rights available to you under any particular law. Those are being prepared and will be added here.
Contact
Questions about this policy: hello@aihr.bot