Privacy Policy

Privacy you control.

Last updated: 11 July 2026

Currant is built to collect as little as it needs and to put you in control of what it can see. This policy explains what we collect by default, the optional content features you can turn on, how we use data, who we share it with, how long we keep it, and the rights you have — including under the EU/UK GDPR and the California CCPA/CPRA. Currant is operated by Currant Software, LLC, a Texas limited liability company ("Currant," "we," "us"). Questions or requests: hello@currant.work.

The short version. By default, Currant works on metadata only — it records that you were @mentioned, by whom, in which public channel/thread, and whether/when you replied. That powers your personal queue of what's waiting on you and a content‑free view for leaders. By default it does not read or store your message text or DMs. Setting your Slack status automatically is a separate opt‑in. Some optional, opt‑in features process message text to produce things like topic labels, ask summaries, or focus signals — and even then we store the derived result, never raw transcripts. Reading your DMs and private channels happens only if you connect your inbox, and the output stays with you unless you separately opt in to contribute it. Data is encrypted at rest, hosted in the US, and never sold. You're in control: opt in per person, choose which features to enable, pause or turn it off anytime, and uninstalling erases your workspace's data.

1. Scope and our role

This policy covers the Currant Slack app (app.currant.work), the Currant marketing site (currant.work), and the admin dashboard (together, the "Service"). A workspace administrator installs Currant into a Slack workspace; individuals then choose whether to enable the features that apply to them.

Controller vs. processor. For most workspace data Currant handles on a customer's behalf (Slack metadata, and any content processed when a workspace turns on content features), the customer's organization is the data controller and Currant acts as a processor under its instructions. For our own account, dashboard sign‑in, billing, marketing‑site, and operational/security data, Currant is the controller. Where a data‑processing agreement (DPA) with a customer applies, that DPA governs the processing of that customer's content.

2. What we collect

Slack metadata (the default — no message text). We record content‑free signals about unanswered @mentions in public channels the bot is in: that a mention happened, who sent it, which channel/thread, its timestamp, and whether/when it was answered. We keep a lightweight, text‑free message‑timing log (channel, thread, author, timestamp) used to detect replies, and a reaction log — who reacted to whose message, when, and a coarse positive/negative score from a fixed emoji list (the emoji itself isn't stored). None of this includes message bodies.

Slack identity & profile. User and workspace (team) IDs, display names, and timezone from Slack — to show names on the dashboard and to set your status.

Collaboration patterns (derived from the metadata above). Group‑level aggregates computed from the timing and reaction logs: an interaction‑weight graph (who converses with whom, how often), community groupings with short generated labels, communication‑health markers (e.g., turn‑taking balance, reciprocity, recognition spread), and per‑group timezone‑overlap windows. Stored at workspace and group level; per‑person intermediate values are transient.

Authentication tokens. The workspace bot token and, for individuals who enable token‑based features, a user token — stored encrypted at rest (AES‑256‑GCM with a separate key).

Dashboard sign‑in. If you sign in to the admin dashboard with Sign in with Slack (OpenID Connect), we use your Slack identity (user ID, team, email, role) to authenticate you and set a signed session cookie.

Message content — only with content features on, and only as much as you consent to. When a workspace turns on the optional, paid content tier, Currant reads relevant message text transiently to derive useful outputs (see §4 and §6) and stores only the derived result, never the raw text. Which messages are in scope depends on the per‑person consent in §3.

Connected tools (optional integrations). If a workspace admin connects other tools (for example GitHub or Jira), Currant ingests only the data needed to map how work waits across tools (such as references, status, assignees, and timestamps). Each connection requests its own permissions at connect time and can be disconnected.

Operational logs. Standard server logs (e.g., IP address, request metadata) for security and reliability. We strip tokens and secrets from logs.

Billing (when paid plans launch). Handled by Stripe; we do not store your card details.

3. Enrollment and the layers of consent

Currant separates two things many tools bundle: tracking what's waiting on you and setting your status, and it keeps reading your private messages strictly separate from sharing anything derived from them.

  • Public‑mention tracking (default). When a workspace installs Currant, content‑free tracking of public @mentions is on by default, so your personal queue and the leaders' content‑free view work. This is metadata only — no message text.
  • Automatic status (opt‑in). Currant sets your Slack status from that load only if you turn it on; doing so grants a single Slack scope (users.profile:write). Only you can set your status, and you can pause or turn it off anytime.
  • Public content (content tier). If your workspace enables content features, the text of public‑channel messages can be processed to derive topics, summaries, and focus signals that power your features and the shared company view. This is on by default within the content tier and governed by the workspace grant.
  • Your inbox — DMs & private channels (opt‑in, "A complete inbox"). Only if you connect it does Currant read your own DMs and private channels — and only for your own features (inbox triage, your focus). This output is never shared with your company. Connecting it grants additional Slack scopes at that moment; disconnecting revokes them.
  • Contribute to the company picture (explicit opt‑in, default off). Separately, you can choose to let signals derived from your private/DM activity feed the shared company views. This is the only path that exposes any private‑origin signal, and it happens only on your own initiative: no admin or workspace setting can turn it on for you, and it requires first connecting your inbox. Sharing works per channel: volunteering a private channel or DM makes that channel's ask metadata (who's waiting on whom, since when — never text) visible in company views for all its participants, and lets its topics count toward shared themes behind a minimum‑diversity floor — a shared topic can never be one person's private thread.

Each of these is independent, disclosed where you turn it on, and reversible.

4. What we don't store

  • Raw message text / transcripts — never stored at rest. With content features off (the default), text is read only transiently to detect a mention, whether a message needs a reply, and reply/reaction signals, then discarded. With content features on, text is still read only in‑flight to produce a derived result, then discarded.
  • Ask summaries — computed on demand and held in a short‑lived cache, not stored as durable records.
  • Your DMs — not read at all unless you connect your inbox (§3); even then the text is processed transiently and never stored.
  • We don't sell or "share" your personal information (as those terms are defined under the CCPA/CPRA), and we don't show ads or use advertising cookies.

5. Slack permissions (least‑privilege, just‑in‑time)

The baseline personal permission is a single scope, users.profile:write, granted only if you turn on automatic status. Additional user scopes — reading your private channels and DMs (im/groups/mpim history) — are requested only at the moment you connect your inbox. Workspace (bot) permissions are requested only as features need them, when a workspace admin turns a feature on (for example, joining public channels for full‑workspace coverage). We don't request permissions our current functionality doesn't use.

6. How we use your information, and our legal bases

We use the data above to: set your Slack status from your unanswered‑@mention load; power your personal queue and the content‑free leaders' dashboard (where work is waiting, response‑pace trends, suggested fixes); when content features are on, derive topics, ask summaries, focus, and bottleneck signals; authenticate dashboard sign‑in and keep the Service secure and reliable; communicate with you about the Service and, with consent, product updates; and administer paid subscriptions.

Legal bases (EU/UK GDPR). Where the GDPR applies, we rely on: legitimate interests (Art. 6(1)(f)) to provide and secure the Service's content‑free, metadata‑based features in a way that minimizes data; consent (Art. 6(1)(a)) for optional content features, automatic status, reading your inbox, contributing private‑derived signal, and non‑essential communications — withdrawable anytime; contract (Art. 6(1)(b)) to provide the Service to a customer and administer subscriptions; and legal obligation (Art. 6(1)(c)) where we must retain or disclose data by law. We do not use message content to make solely‑automated decisions with legal or similarly significant effects about you.

7. The content tier in detail

When a workspace enables content features (off by default, and paid), the following rules apply to every such feature:

  • Transient text, derived persistence. Message text is read in‑flight to produce an output and then discarded. We persist only the derived artifact — for example a topic label, a topic‑assignment id and score, a needs‑reply score, or an embedding over a bounded recent window — and never raw message transcripts.
  • Embeddings. To group related messages, we may compute numeric embeddings (vectors derived from text, not the text itself), stored only over a bounded recent window (up to roughly 45 days), version‑tagged, and encrypted at rest. Durable topic records and assignments are tiny pointers and labels — no text.
  • AI subprocessors, not training. We use AI providers to generate labels, summaries, and classifications (Anthropic / Claude) and to compute embeddings (Voyage). Data sent is used only to provide the feature and is not used to train their models; we require short retention from these providers.
  • Per‑tenant isolation. Every content record is scoped to a single workspace; no query, cache, or AI request mixes data across workspaces.
  • Disclosed and erasable. What a feature processes, where it goes, and how long derived data is kept are disclosed when you enable it; derived data is erasable and is purged on uninstall.

8. Who we share it with (subprocessors)

We share data only with the service providers needed to run Currant, under contracts that require appropriate protection. We don't sell personal information.

ProviderPurpose
SlackThe platform Currant runs on; identity provider for dashboard sign‑in.
RailwayApplication hosting, database, and job queue (US). SOC 2 Type II; reports available on request.
CloudflareObject storage (R2) for backups and cold/bulk derived data; DNS and marketing‑site hosting; routing for inbound support email.
Anthropic (Claude)Content tier only (§7): topic labels, ask summaries, classification. Not used for model training; off by default.
Voyage AIContent tier only (§7): text embeddings for grouping related messages. Not used for model training; off by default.
StripePayment processing for paid plans (PCI‑DSS). Active once billing launches.

We may also disclose information if required by law, or to protect rights, safety, and the integrity of the Service. Tools you connect (e.g., GitHub, Jira) are independent services governed by their own terms; Currant accesses them only with the permissions you grant. As we add or change subprocessors, we'll update this list.

9. How long we keep it (retention & erasure)

  • Message‑timing and reaction metadata — pruned on a rolling window of twelve weeks (84 days), sized to power the recent‑trends and collaboration‑pattern views.
  • Mention records — retained to power recent trends.
  • Embeddings — kept only over a bounded recent window (up to ~45 days); topic labels and assignments (no text) may be kept longer because they are tiny and content‑free.
  • Ask summaries — short‑lived cache only (days).
  • Tokens — cleared when access is revoked or you opt out.
  • Opt‑out / uninstall — when an individual opts out we stop processing their data; when an admin uninstalls Currant, we purge that workspace's data, metadata and derived.

10. How we keep it safe

We encrypt data at rest (tokens and sensitive derived fields with a separate encryption key), enforce least‑privilege permissions and per‑tenant isolation, host on SOC 2 Type II infrastructure, and keep tokens and personal data out of logs. No method of transmission or storage is 100% secure, so we can't guarantee absolute security — but we work to protect your information and to minimize what we hold in the first place.

11. Your rights & choices

In‑product controls (everyone). Turn automatic status on/off; connect or disconnect your inbox; opt in or out of contributing to the company picture; pause or override your status; and (admins) uninstall to purge the workspace's data.

EEA/UK (GDPR). Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to processing of your personal data; to data portability; and to withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with your local supervisory authority. Where your organization is the controller (workspace content), we will refer your request to them or assist them in responding.

California (CCPA/CPRA). Subject to applicable law, you have the right to know/access the personal information we collect and how it's used, to delete it, to correct it, and to be free from discrimination for exercising these rights. We do not sell or share personal information (as defined by the CCPA/CPRA), and we do not use sensitive personal information for purposes beyond providing the Service.

How to exercise. Email hello@currant.work. We will verify and respond in line with applicable law. You may use an authorized agent where the law permits.

12. International data transfers

Currant is operated from, and hosted in, the United States. If you use Currant from outside the US (including the EEA or UK), your information is processed in the US. Where required, we rely on appropriate safeguards for international transfers (such as the EU Standard Contractual Clauses and the UK Addendum) with our subprocessors, and we make information about those safeguards available on request.

13. Cookies

The app uses an essential, signed session cookie for dashboard sign‑in. The marketing site uses minimal or no tracking. We don't use advertising cookies.

14. Children

Currant is a workplace tool not directed at children, and we don't knowingly collect personal information from anyone under 16 (or the applicable age in your region).

15. Changes to this policy

We may update this policy as the product evolves; we'll revise the "Last updated" date above and, for material changes, take reasonable steps to let you know.

16. Contact

Questions, concerns, or a data request: hello@currant.work — Currant Software, LLC, 5900 Balcones Drive STE 100, Austin, TX 78731, USA.