A bot with a nosy name and boring privacy habits.
Last updated 27 August 2026
Snitch handles company data, so this page is written to be read rather than skimmed past. It says what we collect, why we need it, who else touches it, and how to make it go away.
Who we are
Snitch (“Snitch”, “we”, “us”) operates the Slack application and the hosted org chart at snitchforslack.com and snitch.team. If your employer installed Snitch into your Slack workspace, they are the controller of the personal data in it and we process it on their behalf. Reach us at hello@snitchforslack.com.
What we collect
From Slack, when the app is installed
- Your Slack team ID, workspace name and workspace domain, which becomes your chart address.
- The installing user's Slack ID, so we know who to send setup and billing messages to.
- An access token for the bot, encrypted at rest with AES-256-GCM.
- The workspace member directory: Slack user ID, full name, display name, email address, avatar URL and job title. Bots, deactivated accounts and guest accounts are skipped.
From the people using it
- The answer to “who do you report to?”, and the timestamps of when we asked and when they replied.
- Anything a person chooses to put on their own profile card: title, team, location, start date, pronouns and an “ask me about” line.
- The text of questions asked of the bot, so it can answer them.
When someone signs in to view the chart
- Slack ID, name, email and avatar, received through Sign in with Slack (OpenID Connect) and held in a signed, HttpOnly session cookie for seven days.
Billing
- Payments run through Stripe. We store a Stripe customer ID, a subscription ID, your plan and its status. We never see or store card numbers.
Operations
- Ordinary server logs — IP address, user agent, timestamps, error traces — kept briefly for security and debugging.
What we deliberately do not collect
Snitch does not read your channels, your files, your huddles or anybody's direct messages other than the ones sent to Snitch itself. It has not requested the Slack permissions that would allow it to. It holds no salary, compensation, performance or disciplinary data of any kind, and there is nowhere to put it even if you wanted to. We do not run advertising trackers or third-party analytics on this site.
Why we process it
- To provide the service — building the chart, answering questions, keeping it current. This is performance of a contract with your employer.
- To bill for it — plan status, tier and invoices.
- To keep it secure and working — logging, abuse prevention and debugging, on the basis of our legitimate interest in running a service that stays up.
- To contact admins — setup, trial and billing messages sent to the person who installed the app.
Who else processes it
We keep the list short and we do not sell data to anyone, ever.
- Slack (Salesforce) — the platform the bot lives on.
- Vercel — application hosting.
- Neon — the Postgres database where your chart is stored.
- Stripe — subscription payments.
- Anthropic — when someone asks the bot a question in plain English, the question and a compact roster of your org data are sent to Anthropic's API to generate the answer. Anthropic does not use API inputs to train its models.
Cookies
Two, both strictly necessary: a signed session cookie set after you sign in with Slack, and a short-lived state cookie used to make that sign-in secure. There are no advertising, analytics or profiling cookies, so there is no consent banner to click through.
How long we keep it
Your data stays for as long as Snitch is installed. If a trial ends without a subscription, nothing is deleted — the chart simply becomes read-only. If the app is removed from Slack, the bot stops immediately and the data is retained in case you reinstall.
When a workspace admin asks us to delete it, we delete it within 30 days, and it clears our backups within a further 30 days. Server logs roll off within 30 days.
Your rights
Depending on where you live, you may have the right to access, correct, export, delete or restrict the processing of your personal data, and to object to it. Most corrections you can make yourself: ask the bot to update your profile, or ask a workspace admin to fix a reporting line. For anything else, email hello@snitchforslack.com and we will respond within 30 days.
Because your employer controls this data, requests to erase an individual from a live chart may be routed to them. If you are in the EEA or UK you also have the right to complain to your local data protection authority.
Security
- Everything is served over TLS.
- Slack bot tokens are encrypted at rest with AES-256-GCM using a key held outside the database.
- Charts are reachable only after Slack sign-in, and every page checks that the signed-in person belongs to the workspace being viewed. There are no public or unguessable-link charts.
- No security is absolute. If we ever have a breach affecting your data, we will tell affected workspace admins without undue delay.
Where it lives
Our hosting and database run in the United States. If you are in the EEA or UK, that means your data is transferred internationally, and we rely on Standard Contractual Clauses with our providers to cover it.
Children
Snitch is a workplace tool sold to companies. It is not directed at anyone under 16 and we do not knowingly collect their data.
Changes
If this policy changes we will update the date at the top, and for anything material we will DM workspace admins in Slack rather than hoping you re-read this page.
Contact
hello@snitchforslack.com. A person reads it.