Security
Built for teams that have to ask the hard questions
Everything an admin needs to review before rolling Super Duper out — access scope, retention, deletion, encryption, and who processes your data.
What the bot can — and can’t — see
Super Duper only reads channels it has been invited to and conversations it is part of. It cannot browse your workspace or read other people’s DMs. See the full permissions breakdown →
No training on your data
We do not use your workspace content to train third-party foundation models. Your messages and files are used to answer your requests — not to train models for others.
Retention
We retain data while your account and installation are active. Removing Super Duper from Slack stops further processing. Some records may be kept where required for legal, accounting, or security purposes.
Deletion
Delete your account from Settings at any time to remove your associated profile data. Uninstalling from Slack immediately revokes the bot’s access to your workspace.
Token storage
Third-party access tokens (Slack and any tools you connect) are encrypted at rest. Card details are handled by Stripe — we never store full card numbers.
Encryption & access control
Data is encrypted in transit. Access to production systems is scoped and controlled, and the bot’s reach is limited to the channels and tools you explicitly grant.
Subprocessors
We share data only with the providers that help us run the service, each under contract.
Security contact
Reporting a vulnerability or have a security question? We respond within 2 business days.
