Privacy

Privacy policy.

Last updated · 2026-07-16

Luffy is a Slack app operated by Zonko Labs Private Limited. This policy explains what Slack workspace data and connected Google Workspace data Luffy uses, how Luffy uses AI and connected tools, and how workspace admins and users can control that data.

01

Who we are

Luffy is an AI coworker for Slack. Luffy's authorization and execution layer stores workspace settings, connected-tool grants, audit metadata, and requester-bound credentials. References to “we”, “us”, “Luffy”, or “Zonko Labs” mean Zonko Labs Private Limited.

02

Slack data Luffy collects

Luffy collects only the Slack data needed to install the app, route requests, answer user-initiated work, and keep an audit trail for workspace admins.

  • Installation and workspace data. Slack workspace IDs and names, enterprise IDs where applicable, bot IDs, installing user IDs, OAuth scopes, app configuration, channel IDs, and install timestamps.
  • Conversation context. Slack messages, thread metadata, channel metadata, direct-message metadata, and group-message metadata from conversations where Luffy is installed, invited, mentioned, directly messaged, or otherwise addressed by a user.
  • Files, canvases, lists, and reactions. Files shared with Luffy, canvases or lists that a user asks Luffy to read or update, and reaction metadata needed to understand or mark workflow state.
  • User profile data. Slack user IDs, names, mentions, timezone/profile metadata, and email addresses where Slack grants that permission. We use this to route work to the requester and match a Slack user to their authorized Luffy account.
  • Run and audit metadata. Request IDs, timestamps, status, error category, selected tool, workspace, requester, and high-level execution metadata. We use this to troubleshoot failures and show what happened.
03

How Luffy uses Slack data

  • To install Luffy, verify OAuth, and keep the Slack app connected to a workspace.
  • To answer messages, app mentions, direct messages, and app-agent conversations that users send to Luffy.
  • To summarize Slack threads, draft follow-ups, prepare reports, create files or canvases, and run workspace-approved actions that a user requests.
  • To resolve channels, users, and conversations so Luffy can post responses in the right Slack surface.
  • To secure the service, enforce requester-bound authorization, prevent abuse, debug reliability issues, and maintain workspace auditability.

Luffy does not use Slack data for advertising, does not sell Slack data, and does not use Slack data to train large language models.

04

Slack scopes

Luffy requests Slack app permissions only for features available in the product and testable by Slack reviewers. The current Slack app uses these scope groups:

  • app_mentions:read lets Luffy receive mentions and respond in Slack conversations where users address the app.
  • channels:history, groups:history, im:history, and mpim:history let Luffy read the conversation context needed to answer a request in public channels, private channels, direct messages, and group direct messages where it is present or addressed.
  • channels:read, channels:join, channels:write, groups:read, groups:write, im:read, and mpim:read let Luffy resolve conversation metadata for installation, routing, self-joining a selected public channel, requested public/private-channel membership changes, and replies.
  • chat:write, im:write let Luffy post requested responses and continue setup.
  • files:read and files:write let Luffy inspect files shared with it and upload generated artifacts, such as reports or requested files.
  • canvases:read and canvases:write let Luffy read canvases users share with it and create longer Slack-native work outputs only when a user asks it to use that surface.
  • lists:read and lists:write let Luffy read and update Slack lists only when a user asks it to work with them.
  • reactions:read and reactions:write let Luffy read reactions used as request signals and mark processing or delivery status.
  • assistant:write and commandslet Luffy respond in Slack's native AI assistant surface and to the /luffy slash command.
  • users:read and users:read.email let Luffy resolve requesters, mentions, and authorized account matches. We do not use Slack email addresses to contact users outside Luffy support, security, or requested product workflows without separate consent.
  • openid, email, and profile are requested only for Sign in with Slack so Luffy can match the signed-in user to their authorized Luffy account.
05

AI processing

Luffy uses AI models and runtime systems to interpret requests, draft responses, plan tool use, and produce artifacts. When a user asks Luffy to work with Slack context, we send the minimum context needed for that request to the model or runtime provider configured for the workspace. AI output can be wrong or incomplete, so users should review important outputs before relying on them.

Luffy does not train models on Slack workspace data. Luffy does not send Slack data to model providers for advertising, user profiling, or unrelated product development.

06

Connected tools

Workspace admins can connect external tools to Luffy through Luffy's authorization layer. Luffy can use only the tools, credentials, grants, and workspace policies that have been approved for that workspace. Credentials stay server-side and are not exposed in Slack messages, model-visible tool arguments, generated artifacts, or sandbox files.

07

Google user data

Users can optionally connect Google Workspace to Luffy through Google's OAuth consent screen. When a user connects, Luffy requests access to Gmail, Google Drive, Google Calendar, Google Docs, Google Sheets, Google Slides, Google Contacts, and Google Tasks on that user's behalf. Access is granted per user, and Luffy uses it only to complete the tasks that user requests.

  • What we access. Emails, files, calendar events, documents, spreadsheets, presentations, contacts, and tasks are read or created only as needed to fulfill a specific user request, such as searching an inbox, drafting an email, listing events, or creating a document.
  • How we use it.Google user data is used solely to complete the requesting user's work and deliver the result back to them. We do not use Google user data for advertising, do not sell it, and do not use it to train AI or machine-learning models.
  • AI processing.Content retrieved from Google APIs may be processed by the AI models that fulfill a request, limited to the minimum context needed. Model providers are not permitted to train on it. No human reads Google user data except with the user's explicit consent, for security or abuse investigation, or to comply with law.
  • Storage. Google OAuth tokens are encrypted at rest and held server-side only. Luffy does not keep Gmail messages, Drive file contents, or other Google content as default application records; content is processed transiently to complete the request.
  • Revoking access. Users can disconnect Google from Luffy at any time, or revoke access from their Google Account permissions page. On disconnection or revocation we delete the stored tokens, and users can request deletion of any associated data via support@zonko.ai.

Luffy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

08

Retention and deletion

  • Slack OAuth tokens are stored until the app is uninstalled, access is revoked, the workspace connection is deleted, or the token expires.
  • Luffy does not keep raw Slack message bodies, file contents, canvas bodies, or list contents as default application records. Request context is processed to complete the user-requested work.
  • If a user asks Luffy to create or save an output, that output may include summarized, transformed, or quoted Slack content and remains available until the workspace deletes it or requests deletion.
  • Audit and operational metadata are retained for 90 days by default unless a workspace agreement or security requirement calls for a different period.
  • When a workspace uninstalls Luffy or asks us to delete Slack app data, we delete or de-identify associated Slack API data within 14 business days, except where retention is required for security, fraud prevention, legal compliance, or dispute records.
09

Subprocessors

Luffy uses a small set of service providers to operate the app:

  • Cloudflare - compute, database, object storage, and edge networking.
  • Sentry - error tracking with payload scrubbing for tokens, secrets, and message bodies.
  • Model and runtime providers - AI inference and tool execution required to complete user-requested Luffy work.
10

Security

Slack tokens and connected-service credentials are encrypted at rest and decrypted only when needed to fulfill an authorized request. Luffy verifies Slack requests, keeps credentials server-side, and limits actions through requester identity, workspace membership, configured scopes, and workspace authorization policy.

11

Your controls

  • Workspace admins can uninstall Luffy from Slack or revoke Slack app access.
  • Users can disconnect their Luffy account or connected-tool credentials.
  • Workspace admins can remove connected tools and narrow authorization grants.
  • Users and admins can request export, correction, or deletion by emailing support@zonko.ai.
12

Children

Luffy is for workplace use and is not intended for children. We do not knowingly collect data from anyone under 16. If you believe a minor has used Luffy, contact us and we will remove the account or associated data.

13

Changes to this policy

If we make material changes to this policy, we will update the “Last updated” date and provide notice where required. Continued use of Luffy after an update means the updated policy applies.

14

Contact

Questions, data requests, support requests, or security reports go to support@zonko.ai. Luffy is operated by Zonko Labs Private Limited.