Privacy Policy
Who we are
SideKind Inc. operates Alfred, an AI coworker that runs inside your Slack workspace. This policy explains what data Alfred processes and your rights over it.
What we collect
- Slack workspace and user identifiers (team ID, user ID, profile basics).
- Messages and reactions in channels Alfred is invited to, and direct messages to Alfred.
- Data from tools you explicitly connect via OAuth (CRM, email, calendar, docs) — only the scopes you approve.
- Operational metadata: action receipts, audit logs, and usage/cost telemetry.
- Durable memory Alfred saves from your conversations — profile facts and preferences — so it can draw on that context in later sessions, where this capability is enabled.
How we use it
To provide the product: drafting, research, meeting prep, and pipeline actions on your behalf, plus the manager rollups you consent to. We do not sell your data.
SideKind does not build, operate, or fine-tune its own AI models. Each request is routed to a third-party model provider — Anthropic, OpenAI, or Google, depending on the task — to generate that one response; see our sub-processor disclosurefor which providers are in the request path. What each provider does with the data it receives is governed by that provider's own API terms, including whatever data-retention and training policies apply to their business or API tier. We have not independently audited those terms as part of this page — if that matters to your own compliance decisions, review the provider's terms directly or email hello@sidekind.com and we will point you to what we have.
Retention
There is no single, org-configurable "delete everything after a fixed number of days" setting today, and we are not going to invent a number here. What is real:
Inside Alfred's Slack App Home, under Privacy, you can click "Delete my account" or "Request my data" at any time. A deletion request hard-deletes your personal data across every privacy table — private memory, connected-app credentials, schedules, pending approvals, and more — in a single database transaction, and is logged in a signed, tamper-evident audit entry that deliberately keeps your user id (never your content) as the record of what was deleted; rows that were never tied to only you, like a skill your team promoted to the shared library, aren't part of that request. If your organization has tracing/observability content-capture enabled, conversation content sent through that separate layer isn't wiped immediately by a deletion request — it ages out automatically on its own 90-day window instead (see Retention below). An approved request that has not been auto-completed yet is picked up by a daily sweep within 29 days.
You can disconnect any individual connected app at any time, which revokes that connector's stored credentials immediately. We do not yet have a separate step that automatically revokes every connector the moment your whole workspace uninstalls Alfred from Slack — if you remove Alfred, email hello@sidekind.com and we will confirm everything is revoked.
Connected-app credentials are stored encrypted; we never persist the plaintext token itself.
SideKind's internal tracing/observability content-capture is off by default, and only active where an organization opts in. When it is, full conversation content that flows through that path is retained for 90 days and then dropped automatically; separately, lightweight operational metadata from that same layer — which step ran, timing, cost, not the message text — is retained longer, on the order of 12 months.
Your rights (GDPR / CCPA)
You can request access, correction, deletion, or a portable export of your data. The fastest way is Alfred's Slack App Home Privacy section ("Request my data" / "Delete my account"). For anything else — an org-level request, a question, or if you do not use Slack — email hello@sidekind.com.
Sub-processors
See our sub-processor disclosure for the list of vendors that process data on our behalf.