Privacy policy.
Last updated · 2026-09-04
Luffy is a Slack app operated by Zonko Labs Private Limited. This policy explains what Slack workspace data and connected Google data, including Google Workspace and Google Ads data, Luffy uses, how Luffy uses AI and connected tools, and how workspace admins and users can control that data.
Who we are
Luffy is an AI coworker for Slack. Luffy's authorization and execution layer stores workspace settings, connected-tool grants, audit metadata, and requester-bound credentials. References to “we”, “us”, “Luffy”, or “Zonko Labs” mean Zonko Labs Private Limited.
Slack data Luffy collects
Luffy collects only the Slack data needed to install the app, route requests, answer user-initiated work, and keep an audit trail for workspace admins.
- Installation and workspace data. Slack workspace IDs and names, enterprise IDs where applicable, bot IDs, installing user IDs, OAuth scopes, app configuration, channel IDs, and install timestamps.
- Conversation context. Slack messages, thread metadata, channel metadata, direct-message metadata, and group-message metadata from conversations where Luffy is installed, invited, mentioned, directly messaged, or otherwise addressed by a user.
- Files, canvases, lists, and reactions. Files shared with Luffy, canvases or lists that a user asks Luffy to read or update, and reaction metadata needed to understand or mark workflow state.
- User profile data. Slack user IDs, names, mentions, timezone/profile metadata, and email addresses where Slack grants that permission. We use this to route work to the requester and match a Slack user to their authorized Luffy account.
- Run and audit metadata. Request IDs, timestamps, status, error category, selected tool, workspace, requester, and high-level execution metadata. We use this to troubleshoot failures and show what happened.
How Luffy uses Slack data
- To install Luffy, verify OAuth, and keep the Slack app connected to a workspace.
- To answer messages, app mentions, direct messages, and app-agent conversations that users send to Luffy.
- To summarize Slack threads, draft follow-ups, prepare reports, create files or canvases, and run workspace-approved actions that a user requests.
- To resolve channels, users, and conversations so Luffy can post responses in the right Slack surface.
- To secure the service, enforce requester-bound authorization, prevent abuse, debug reliability issues, and maintain workspace auditability.
Luffy does not use Slack data for advertising, does not sell Slack data, and does not use Slack data to train large language models.
Slack scopes
Luffy requests Slack app permissions only for features available in the product and testable by Slack reviewers. The current Slack app uses these scope groups:
app_mentions:readlets Luffy receive mentions and respond in Slack conversations where users address the app.channels:history,groups:history,im:history, andmpim:historylet Luffy read the conversation context needed to answer a request in public channels, private channels, direct messages, and group direct messages where it is present or addressed.channels:read,channels:join,channels:write,groups:read,groups:write,im:read, andmpim:readlet Luffy resolve conversation metadata for installation, routing, self-joining a selected public channel, requested public/private-channel membership changes, and replies.chat:write,im:writelet Luffy post requested responses and continue setup.files:readandfiles:writelet Luffy inspect files shared with it and upload generated artifacts, such as reports or requested files.canvases:readandcanvases:writelet Luffy read canvases users share with it and create longer Slack-native work outputs only when a user asks it to use that surface.lists:readandlists:writelet Luffy read and update Slack lists only when a user asks it to work with them.reactions:readandreactions:writelet Luffy read reactions used as request signals and mark processing or delivery status.assistant:writeandcommandslet Luffy respond in Slack's native AI assistant surface and to the/luffyslash command.users:readandusers:read.emaillet Luffy resolve requesters, mentions, and authorized account matches. We do not use Slack email addresses to contact users outside Luffy support, security, or requested product workflows without separate consent.openid,email, andprofileare requested only for Sign in with Slack so Luffy can match the signed-in user to their authorized Luffy account.
AI processing
Luffy uses AI models and runtime systems to interpret requests, draft responses, plan tool use, and produce artifacts. When a user asks Luffy to work with Slack context, we send the minimum context needed for that request to the model or runtime provider configured for the workspace. AI output can be wrong or incomplete, so users should review important outputs before relying on them.
Luffy does not train models on Slack workspace data. Luffy does not send Slack data to model providers for advertising, user profiling, or unrelated product development.
Connected tools
Workspace admins can connect external tools to Luffy through Luffy's authorization layer. Luffy can use only the tools, credentials, grants, and workspace policies that have been approved for that workspace. Credentials stay server-side and are not exposed in Slack messages, model-visible tool arguments, generated artifacts, or sandbox files.
Google user data
Users can optionally connect Google Workspace or Google Ads to Luffy through Google's OAuth consent screen. For Google Workspace, Luffy may request access to Gmail, Google Drive, Google Calendar, Google Docs, Google Sheets, Google Slides, Google Contacts, and Google Tasks. For Google Ads, Luffy may request access to Google Ads accounts and data. Access is granted per user, and Luffy uses it only to complete tasks that the user requests.
- What we access. Google Workspace data can include emails, files, calendar events, documents, spreadsheets, presentations, contacts, and tasks. Google Ads data can include account identity and settings, manager and client relationships, campaigns, budgets, ad groups, ads, keywords and criteria, assets, audiences, conversions, recommendations, experiments, billing and account administration data, planning and forecasting data, and reporting or performance metrics. Luffy reads, creates, updates, or removes this data only as needed to fulfill a specific user request.
- How we use it. Google user data is used solely to complete the requesting user's work and deliver the result back to them. We do not use Google user data for advertising, do not sell it, and do not use it to train AI or machine-learning models.
- AI processing. Content retrieved from Google APIs may be processed by the AI models that fulfill a request, limited to the minimum context needed. Model providers are not permitted to train on it. No human reads Google user data except with the user's explicit consent, for security or abuse investigation, or to comply with law.
- Who we share it with. We disclose Google user data only to recipients needed to provide the user-requested feature: Google, for OAuth and calls to the selected Google APIs, including Google Workspace and Google Ads APIs; Cloudflare, which hosts connection services and stores encrypted Google Ads OAuth grants in Cloudflare KV; Modal, which hosts application runtime and processes request and response data transiently; Neon, which stores encrypted OAuth tokens and connection metadata for integrations that use Luffy's main connection layer; and the AI provider used for the request. Our current AI providers are OpenAI and Anthropic. If a workspace selects an alternative model, data may pass through Vercel AI Gateway to the selected provider, such as xAI, Moonshot AI, or DeepSeek. These service providers may process Google user data only on our instructions and only to provide their services to Luffy. We do not disclose Google user data to PostHog, Meta, Sentry, advertisers, data brokers, or information resellers. Outside these service providers, we disclose Google user data only with the user's explicit consent, when necessary to investigate security or abuse, when required by law, or as part of a merger, acquisition, or sale of assets after obtaining the user's explicit prior consent.
- Storage. Google OAuth access and refresh tokens are encrypted at rest with AES-256-GCM and held server-side only. Luffy does not keep Gmail messages, Drive file contents, calendar events, Google Ads account data, or other Google content as default application records. Data is fetched or changed through Google APIs to complete a user request and is otherwise processed transiently.
- Data protection for sensitive data. Google Workspace and Google Ads requests are handled by services that proxy each call directly to Google over TLS (HTTPS) and do not retain Google content or Google Ads payloads as default application records. OAuth tokens are encrypted at rest with AES-256-GCM under an encryption key held separately from the encrypted data, are scoped to the individual user, are decrypted only in memory to serve that user's authorized request, and are never written to Slack messages, model prompts, generated artifacts, logs, or sandbox files. Access is requester-bound and revocable at any time, after which the stored tokens are deleted.
- Revoking access. Users can disconnect Google from Luffy at any time, or revoke access from their Google Account permissions page. On disconnection or revocation we delete the stored tokens, and users can request deletion of any associated data via support@zonko.ai.
Luffy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
- Slack OAuth tokens are stored until the app is uninstalled, access is revoked, the workspace connection is deleted, or the token expires.
- Luffy does not keep raw Slack message bodies, file contents, canvas bodies, or list contents as default application records. Request context is processed to complete the user-requested work.
- If a user asks Luffy to create or save an output, that output may include summarized, transformed, or quoted Slack content and remains available until the workspace deletes it or requests deletion.
- Public signup interest records (work email, selected platform, and team-size range) are retained until we contact the submitter about availability, the record is no longer needed for that purpose, or the submitter requests deletion.
- Audit and operational metadata are retained for 90 days by default unless a workspace agreement or security requirement calls for a different period.
- When a workspace uninstalls Luffy or asks us to delete Slack app data, we delete or de-identify associated Slack API data within 14 business days, except where retention is required for security, fraud prevention, legal compliance, or dispute records.
Analytics and subprocessors
We use PostHog to understand public-site and product journeys, including where visitors come from and what they do before and after sign-in. Analytics includes page URLs (including campaign and query parameters), referrer URLs, campaign parameters, browser and device metadata, and onboarding milestones. Visitors who have not signed in are tracked under a random analytics profile. After sign-in, that profile is linked to Luffy's internal user and workspace IDs together with the account's display name, email address (when present), Slack workspace name, and Slack workspace ID. When a visitor submits the public signup flow, we also send the selected communication platform, team-size range, and submitted work email to PostHog. We do not send message content or other form values to PostHog.
PostHog session replay masks every input and masks text throughout onboarding and the authenticated dashboard. Network bodies and headers, console output, canvas content, and cross-origin frames are not recorded. We use this data for product usability and reliability, not to sell personal data or build advertising profiles.
Luffy uses a small set of service providers to operate the app:
- Cloudflare - compute, database, object storage, and edge networking.
- PostHog - privacy-masked product analytics and session replay.
- Meta - public-site page-view, campaign, and conversion measurement through the Meta Pixel and Meta's server-side Conversions API. We send page URLs and campaign parameters, Meta's click and browser cookies (_fbc, _fbp), IP address, user agent, an opaque site visitor identifier stored in our luffy_attribution_v1 cookie for 90 days, and subscription purchase value and currency. We do not send Slack, Google, or message data to Meta.
- OpenAI - public-site page-view and conversion measurement for ads in ChatGPT through the OpenAI Measurement Pixel and Conversions API. We send page URLs, OpenAI's click and browser references (oppref, __obref), IP address, user agent, a hashed opaque visitor identifier, and subscription plan and amount.
- Stripe - payment processing and subscription billing.
- Sentry - error tracking with payload scrubbing for tokens, secrets, and message bodies.
- Model and runtime providers - AI inference and tool execution required to complete user-requested Luffy work.
Security
Slack tokens, Google OAuth tokens, and connected-service credentials are encrypted at rest with AES-256-GCM and decrypted only in memory when needed to fulfill an authorized request. All data in transit is protected with TLS (HTTPS). Luffy verifies Slack requests, keeps credentials server-side, and limits actions through requester identity, workspace membership, configured scopes, and workspace authorization policy.
Sensitive Google Workspace content (Gmail, Drive, Docs, Sheets, Slides, Calendar, Contacts, and Tasks) and Google Ads account data are processed transiently to complete a specific user request and are not persisted as default application records. Credentials and user content are never exposed in Slack messages, model-visible tool arguments, generated artifacts, logs, or sandbox files, and access is scoped to the individual requesting user.
Your controls
- Workspace admins can uninstall Luffy from Slack or revoke Slack app access.
- Users can disconnect their Luffy account or connected-tool credentials.
- Workspace admins can remove connected tools and narrow authorization grants.
- Users and admins can request export, correction, or deletion by emailing support@zonko.ai.
Children
Luffy is for workplace use and is not intended for children. We do not knowingly collect data from anyone under 16. If you believe a minor has used Luffy, contact us and we will remove the account or associated data.
Changes to this policy
If we make material changes to this policy, we will update the “Last updated” date and provide notice where required. Continued use of Luffy after an update means the updated policy applies.
Contact
Questions, data requests, support requests, or security reports go to support@zonko.ai. Luffy is operated by Zonko Labs Private Limited.