Privacy policy

How SecureLore handles Slack review data.

SecureLore is designed for pre-submission and admin-readiness review. It stores only the data needed to preserve review history, evidence, and generated artifacts for users in the workspace.

Slack data collected

Slack user, team, and channel identifiers needed to save review context; submitted manifests, MCP tools/list JSON, structured app disclosures, artifact fingerprints, generated review packets, feedback, and evidence entered by users.

How data is used

To run preflight reviews, retrieve relevant policy guidance, save review history, reopen Review Rooms, and generate admin-ready artifacts.

Slack Real-Time Search

When a user explicitly requests workspace precedent, SecureLore searches public-channel messages using Slack's Real-Time Search API and the request's short-lived action token. Search results are displayed with Slack permalinks and are not copied into SecureLore storage, learning memory, evals, or model-training data.

AI providers

OpenRouter-hosted language models are used for review enrichment. Cohere embeddings are used for policy retrieval over SecureLore policy memory.

Training

SecureLore does not use Slack data, submitted manifests, MCP payloads, feedback, or evidence to train large language models.

Retention

Review packets, feedback, and evidence are retained while the workspace uses SecureLore so users can reopen review history and admin artifacts.

Deletion

Users can open SecureLore App Home, choose Delete my review data, and confirm deletion. This removes their workspace-scoped review sessions, evidence, feedback, candidate evals, and promoted lessons.

Contact for privacy requests

For access, transfer, correction, or deletion requests, use the contact path listed on the Devpost project submission. Include the workspace name, Slack team ID if available, and the review ID when relevant. Do not send secrets, OAuth tokens, signing secrets, or private customer data in support messages.