GridKeeper

Privacy Policy

Privacy Policy

Last updated: 4 October 2026

In short

  • We read security information, never conversations. Settings, people, apps and the audit log. No messages, files, canvases or lists.
  • Your data stays in Ireland. It is stored, processed and emailed from there.
  • We never change anything in Slack. Every call GridKeeper makes is a read.
  • We never sell it, share it for marketing, or train models on it.
  • You stay in control. Export or delete everything yourself, at any time.

Who we are

GridKeeper is operated from the United Kingdom. Contact: privacy@gridkeeper.app.

Our role depends on the data:

  • Your Slack data (people, channels, apps, audit events): your organization is the controller and GridKeeper is the processor. We only use it as your organization instructs.
  • Your GridKeeper account (who signs in, and the address you choose for monitoring emails): GridKeeper is the controller.

What we collect

GridKeeper reads the following from Slack through its official API, limited to the permissions listed on our Trust & Scopes page. It also keeps what your team writes in GridKeeper itself.

WhatFor example
Organization settingsName, domain, and the security settings of each workspace
PeopleNames, email addresses, roles, admin status, whether a second factor is set, when an account was last active, and a session length an admin gave one person
ChannelsNames, member counts, whether they are shared outside the organization
Apps and workflowsNames, permissions granted, who installed or owns them
Audit log events
Enterprise Grid
Security-relevant changes and who made them. 101 action types are watched; ordinary Slack activity is not.
IP address and device
Enterprise Grid
For each audit event: the IP address and a coarse device label such as “Windows 10 · Slack 151”. For each person signed in to Slack: the devices their sessions came from, such as “Windows 10 · browser”, and the Slack app and version they use when it is more than 90 days old, such as “Windows desktop app 4.47.59”. You can turn this off.
What you write in GridKeeperReasons for accepting a finding, and messages between Leads and Delegates
Which audit log events are watched
  • Privilege grants and role changes
  • Authentication policy and SSO changes
  • App permission changes
  • Organization security settings, for example whether a password can be used instead of the identity provider, or whether members can change their own email address
  • Slack Connect direct messages offered to and accepted by people outside the organization
  • Content leaving the organization: public file links, channels connected to other organizations, and files, canvases or lists shared into them
  • Email domains being claimed or removed, and the two restrictions that go with a claim

Slack's audit API can only be filtered by action name, so shares are read and only the ones going outside the organization are kept. Internal sharing is discarded on arrival.

How IP addresses and devices are used

The IP address is used for one thing: to tell you when a privileged change came from an address that account has never used before. The address itself is never shown. The device label is shown next to each change, so that several people signed in to one shared admin account can be told apart, and the Active sessions card lists the devices each signed-in person's sessions came from. That card also flags a session that is still signed in after it was last used on a different kind of machine than it began on, or after Slack flagged it as unusual, because a copied session lets someone into Slack without a password; it names the machines only beside the session, never in change history or email. The Slack app versions card lists a person’s Slack app and version when it is more than 90 days old, compared with Slack’s public release lists, which are read without sending anything about you; it too names the app only on the card. Neither is sent anywhere for lookup or enrichment, and both are erased after 180 days, or straight away if you turn collection off.

Names of people who have left

When an account is deactivated, Slack replaces its name and email with placeholders, which makes “who approved this app?” impossible to answer. GridKeeper keeps the last real name or email it saw for that account, and uses it only where Slack now shows a placeholder. It is one label per account, and it is deleted with the rest of your data.

What we never collect

  • Message content, in channels or direct messages. No permission GridKeeper holds allows it.
  • The content of files, canvases or lists.
  • A record of who downloaded which file. Download events are only counted, to spot unusual bulk downloads, and then discarded.
  • Browser fingerprints. The full user agent on each audit event is discarded on arrival.

What we use it for

Only to produce your organization's security reports, spot changes over time, and show them to your organization. Nothing else: no benchmarks shared with other customers, no marketing, no profiling, no automated decisions, and no model training.

Legal basis. For your Slack data we act on your organization's documented instructions under our contract; the legal basis for that processing is your organization's to decide. For your GridKeeper account, our basis is the contract and our legitimate interest in running a secure service and reaching you when something needs attention. You can object to the latter.

Where your data is, and who can see it

Only signed-in people from your own organization can see your data, plus GridKeeper's operators when needed for support or maintenance. We use three providers:

ProviderWhat forWhere
SupabaseThe database where your reports and history are storedIreland
eu-west-1
VercelRuns GridKeeper, so your data passes through it during each check and page viewIreland
dub1 (Dublin)
ResendSends GridKeeper's emails: monitoring emails if you turn them on, and always the notices about who can use GridKeeper, such as a Lead or Delegate being added or removed, or access ending. It receives the recipients' addresses, some taken from Slack, and the email contents, which can name people, channels and apps, and keeps its delivery logs for 30 days.Ireland
eu-west-1

None of the three companies is based in the EEA: Vercel and Resend are in the United States, and Supabase in Singapore. If any of them accesses your data from outside the EEA, for example for support, their data processing terms cover it with the European Commission's Standard Contractual Clauses and the UK Addendum. We can send copies on request. If this list changes, we will update this page and tell pilot participants directly.

Security

  • Slack tokens are encrypted (AES-256-GCM) with a key kept outside the database, so the database alone does not give usable tokens. Tokens are never logged.
  • Every request is checked on the server against the organization it belongs to, so one customer cannot reach another's data.
  • GridKeeper never writes to Slack. The full list of API methods it uses is on the Trust & Scopes page.

How long we keep it

  • While you are connected: everything is kept, so change history and trends keep working.
  • When the access period ends: a pilot runs for 90 days from when your organization first connects, unless we agree a longer term. The Leads and the monitoring address are emailed 14 days before the end and again at the end. From then GridKeeper reads nothing more from Slack, and 14 days later it disconnects automatically. 30 days after that disconnect, everything is deleted, unless access is extended. The Leads, the Delegates and the monitoring address are told at least a week before and once it is done, and until then we send a copy on request to privacy@gridkeeper.app.
  • IP addresses and devices: erased automatically after 180 days.
  • After you disconnect: the Slack tokens are erased straight away and GridKeeper can no longer reach your Slack. Your history is kept on purpose, so no single admin can quietly erase what a check found, until it is deleted after the access period ends. You can also delete it yourself, below.

Disconnecting also signs everyone at your organization out of GridKeeper. If you want to export or delete your history yourself, do it before disconnecting; afterwards, email us and we will do it for you.

Your controls

On the Monitoring page in GridKeeper, under “Your data”, you can:

  • Turn off IP address and device collection. What is already held is erased at the same moment.
  • Export everything as a JSON file. Access tokens are never included.
  • Delete everything permanently, which also disconnects GridKeeper. There is no undo, so export first if you want a copy.

You can also remove GridKeeper from Slack's app management at any time, which stops its access immediately. One record survives deletion: our own note that we invited your organization to the pilot. It contains no Slack data.

Your rights

In the UK and the EEA you can ask to access, correct or erase your personal data, restrict or object to its use, or receive it in a portable form.

  • About your Slack data: ask your organization. They can answer directly with the export and delete controls, and we will help if asked.
  • About your GridKeeper account: email privacy@gridkeeper.app. We reply as soon as we can, and always within the one month the law allows.

You can also complain to a data protection authority: the ICO in the UK (ico.org.uk), or the authority where you live or work in the EEA. We would like to hear from you first, but you do not have to.

Data processing agreement

If your organization needs one before connecting, ask and we will provide it.

Changes and contact

If this policy changes in a material way, we will update the date at the top and, during the pilot, tell participants directly. Questions go to privacy@gridkeeper.app.