Privacy Policy
Last updated: July 2026
1. Overview
Stashly ("we", "our", "the app") is a Slack app that collects emoji-reacted messages and organizes them into Slack Canvas documents. This policy describes what data we collect, how we use it, and your rights.
2. Data We Collect
- Workspace information: Team ID and team name, collected during OAuth installation.
- Bot access tokens: Encrypted using AES-256-GCM before being stored in our database.
- Installer user ID: The Slack user ID of the person who installed the app.
- Message permalinks: Public Slack URLs of collected messages, stored in Canvas documents. We do not store message text, reaction counts, or any other message content in our database.
- Channel names/IDs: Used temporarily during command execution to find matching messages. Not stored permanently.
3. Data We Do Not Collect
- Message content or text
- Direct messages or private conversations
- User profile information beyond what Slack provides for locale detection
- Any data beyond what is necessary to operate the service
4. How We Use Your Data
We use collected data solely to:
- Authenticate and connect to your Slack workspace
- Execute the
/canvas-collectcommand on your behalf - Create and update Canvas documents in your Slack workspace
We do not sell, rent, or share your data with third parties for marketing purposes.
5. Data Storage and Security
- Data is stored in a PostgreSQL database hosted on Railway.
- All Slack tokens are encrypted at rest using AES-256-GCM.
- In-memory caches (locale, locks) are not persisted and are cleared on server restart.
6. Sub-processors
Stashly uses the following third-party sub-processors to deliver its service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway | Application hosting and PostgreSQL database | United States |
| Stripe | Payment processing for Pro plan subscriptions | United States |
7. Data Retention
Installation data (team ID, encrypted tokens) is retained until you uninstall the app from your workspace. Upon uninstallation, all associated data is deleted from our database.
8. Your Rights
You have the right to request access to, deletion of, and transfer of the data we hold about you or your workspace.
- Access: You can request a copy of the data we hold about you or your workspace (team ID, team name, installer user ID, and subscription status) by emailing [email protected] with the subject "Data Access Request". We will respond with a copy of your data within 30 days.
- Deletion: You can request deletion of your workspace data at any time by uninstalling the app from your Slack workspace, or by emailing [email protected] with the subject "Data Deletion Request". Deletion requests are fulfilled within 30 days.
- Transfer (Portability): You can request your data in a structured, machine-readable format (e.g., JSON) by emailing [email protected] with the subject "Data Transfer Request".
To help us verify and process your request, please include your Slack workspace (team) ID or workspace URL. We may ask for additional information to verify that you are authorized to make the request on behalf of your workspace.
9. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via our GitHub repository.
10. Contact
For questions or concerns, contact us at [email protected].
プライバシーポリシー
最終更新: 2026年7月
1. 概要
Stashly(以下「本アプリ」)は、絵文字リアクション付きのSlackメッセージを収集し、Slack Canvasに整理するSlackアプリです。本ポリシーでは、収集するデータ、その利用方法、およびお客様の権利について説明します。
2. 収集するデータ
- ワークスペース情報: OAuthインストール時に取得するチームIDおよびチーム名。
- Botアクセストークン: AES-256-GCMで暗号化した上でデータベースに保存。
- インストールユーザーID: アプリをインストールしたSlackユーザーのID。
- メッセージのパーマリンク: 収集対象メッセージのSlack URL。Canvas内に記録されます。メッセージ本文・リアクション数などのコンテンツはデータベースに保存しません。
- チャンネル名/ID: コマンド実行中に一時的に使用します。永続的には保存しません。
3. 収集しないデータ
- メッセージの本文テキスト
- ダイレクトメッセージやプライベートな会話の内容
- ロケール検出に必要な最小限以外のユーザープロフィール情報
- サービス提供に不要な一切のデータ
4. データの利用目的
収集したデータは以下の目的にのみ使用します:
- Slackワークスペースへの認証・接続
/canvas-collectコマンドの実行- SlackワークスペースへのCanvasドキュメントの作成・更新
マーケティング目的で第三者にデータを販売・貸与・共有することは一切ありません。
5. データの保存とセキュリティ
- データはRailwayがホストするPostgreSQLデータベースに保存されます。
- すべてのSlackトークンはAES-256-GCMで暗号化して保存します。
- インメモリキャッシュ(ロケール、ロック)は永続化されず、サーバー再起動時に消去されます。
6. サブプロセッサー
Stashlyはサービス提供のために以下のサードパーティサブプロセッサーを利用しています:
| サブプロセッサー | 用途 | 所在地 |
|---|---|---|
| Railway | アプリのホスティングおよびPostgreSQLデータベース | 米国 |
| Stripe | Proプランの決済処理 | 米国 |
7. データの保持期間
インストール情報(チームID・暗号化トークン)は、アプリをアンインストールするまで保持されます。アンインストール時に関連するすべてのデータをデータベースから削除します。
8. お客様の権利
お客様は、当方が保持するお客様およびワークスペースのデータについて、アクセス(開示)・削除・移転を請求する権利を有します。
- アクセス(開示): 当方が保持するデータ(チームID、チーム名、インストールユーザーID、サブスクリプション状況)の写しを、件名「データアクセスリクエスト」として [email protected] 宛にご請求いただけます。30日以内にデータの写しをお送りします。
- 削除: Slackワークスペースからアプリをアンインストールすることで、いつでもワークスペースのデータ削除を要求できます。また、件名「データ削除リクエスト」として [email protected] 宛にご連絡いただくことも可能です。削除リクエストは30日以内に対応します。
- 移転(ポータビリティ): 構造化された機械可読形式(JSONなど)でのデータ提供を、件名「データ移転リクエスト」として [email protected] 宛にご請求いただけます。
ご本人確認およびリクエスト処理のため、Slackワークスペース(チーム)IDまたはワークスペースURLを添えてご連絡ください。ワークスペースを代表してリクエストする権限の確認のため、追加情報をお願いする場合があります。
9. ポリシーの変更
本ポリシーは随時更新される場合があります。重要な変更はGitHubリポジトリを通じてお知らせします。
10. お問い合わせ
ご質問やご不明点は [email protected] までご連絡ください。