policy
Privacy policy
Effective 31 August 2026
The short version
ucontex is a status layer. We store what we need to show the current state of the tools a workspace connected, and we show it in Slack. We do not scrape every channel. We do not sell the record. We do not send vendor tokens to a model.
Who this covers
This policy is for people who install ucontex on a Slack workspace, people in that workspace who see facts on Home or get an answer from @ucontex, and anyone who later opts into personal computer-use collection. The operator of ucontex.com is the controller for that hosted record.
What we collect from Slack
When someone clicks Add to Slack, Slack sends us an install payload. We keep:
- The workspace id and name (Slack
team_id). - The bot token, bot user id, and app id, so we can publish Home and reply when tagged.
- The installer's Slack user id. That is who connected the workspace, not a ucontex login.
- An incoming webhook, if Slack issued one, so a digest has somewhere to go if you turn it on.
- Which tools the workspace picked, any "request a source" note, and which Slack apps we already recognized as installed.
We read the bot list so we can prefill "Found in this workspace." We do not index public channels. We do not join rooms to lurk. We do not post unless someone tags @ucontex, or the workspace turns on a digest.
What we collect from connected tools
One person in the workspace OAuths the sources they connected. Those tokens live on the workspace, keyed by Slack team id, not on that person's private account. We store access tokens, refresh tokens, and a little vendor metadata (a Stripe account id, a Jira cloud id, a Salesforce instance URL, a GoHighLevel location). We pull objects we can show as facts: titles, status, amounts, timestamps, authors where the vendor gives them.
We keep the pull narrow on purpose:
- GitHub: open pull requests we can see.
- Stripe: balance and recent charges, not card numbers.
- HubSpot and Salesforce and GoHighLevel: deal and opportunity names, amounts, stages.
- Jira: recently updated issue keys, summaries, status.
- Google Drive: file names and modified times, not file bodies.
- Gmail: subject, from, and date. Not the body, not attachments.
Org tools (repo, CRM, board, billing) are workspace-scoped: anyone in the Slack can see the facts. Do not connect a personal inbox if you do not want that workspace to see that it exists. Personal mail and calendar as a private feed are a later, opt-in beta — not the default install.
What we send to Claude
If an Anthropic API key is configured on our coordinator, we send titles and status so Claude can write the one or two sentences that appear on Home. We never send access tokens, refresh tokens, raw mail, or file contents. Anthropic is a processor for that sentence. If the key is missing, we write a plain fallback ourselves.
What we never collect
- Password managers.
- Banking apps and bank credentials.
- A required screen recording or Accessibility grant to sign up.
- A map of every client, a score, or a live video of someone's desktop.
- Payment card PAN, CVC, or Stripe secret keys from your customers.
Computer use (tex), later and opt-in
A Mac agent can, if a person turns it on, record which selected app they are in and how long that session has been running. Password managers and banking are never in that list. That record is private to that person unless they promote a fact into the shared workspace feed. It is not a manager product. It does not ship as a requirement to use Slack Home.
Cookies and the website
The marketing site is static pages plus Add to Slack. We may set a short-lived cookie if someone used an access link on /start. We do not run a third-party ad pixel. Slack and the vendors you connect have their own cookies on their consent screens; those are theirs.
Where it lives, and for how long
The hosted record is sqlite on our coordinator. Tokens and facts stay there until the workspace uninstalls, reconnects (which replaces the token), or we delete the tenant after an uninstall. We do not keep a second marketing dossier of your deals. Server logs may hold IPs and error lines for a short operational window.
Who can see it
People in the Slack workspace that installed ucontex can see Home and can tag @ucontex. We can see the tenant in order to run the service and fix a break. We do not sell the record. We do not use it to train a public model. A vendor whose OAuth you approved can see that our app is connected, the same as any other OAuth app they list in their admin.
How to leave
Uninstall the Slack app. Revoke ucontex in GitHub, Google, Stripe, HubSpot, Salesforce, Atlassian, GoHighLevel, or whichever vendor you connected. That cuts the token. If you want a tenant wiped sooner than uninstall cleanup, say so from the installing workspace.
Children
ucontex is a workplace tool. It is not directed at children under 16.
Changes
If this policy changes in a way that affects what we store, we will update the date on this page. The current text is the one that applies.
Contact
There is no separate ucontex login. The account is the Slack install. For this policy, this page is the record; for the workspace, uninstall or revoke the vendor connection.
