Plain-language privacy notice
Your email is cargo,
not our data.
Send to Slack is a relay. When you explicitly press Send, the app moves the open Gmail message and its attachments to the Slack channel you selected. It does not create or retain a copy of that content.
SL LABS
- Legal form
- Individual entrepreneur
- SIREN
- 809 041 601
- Registered activity
- Computer programming · APE 62.01Z
- Registered location
- Béziers, France
- Contact
- contact@stanleon.cc
SL LABS publishes and operates Send to Slack and is the controller for the integration configuration and service-security data described below.
The short version
- We do not store email subjects, headers, recipients, bodies, or attachments in our database.
- We do not use email content or attachments for analytics, advertising, profiling, training, or product development.
- We do not scan your mailbox, run background forwarding, or sell personal data.
- Content exists in app memory only for the time technically necessary to transmit it from Google to Slack, then becomes unreachable to the app.
Exactly what happens
When the Gmail add-on is open, Google provides temporary, context-bound access. The add-on reads the message in the active Gmail context so it can show the sender, subject, and attachment count. Nothing is sent at this stage.
After you choose a Slack channel and press Send, the add-on retrieves the message body and attachment bytes from Google and sends them over encrypted HTTPS to the app endpoint. The endpoint validates the request and immediately calls Slack’s APIs to post the message and upload the files. The endpoint does not write that payload to D1, object storage, cache, analytics, or an application log.
Once Slack accepts the post or upload—or the request fails—the app does not retain the email or attachment payload. Slack and the destination workspace then control retention, access, deletion, and export of the delivered content under their own settings and policies.
What is stored—and what is not
Never stored by us
- Email subject and body
- Sender, recipients, and message headers
- Attachment names, metadata, and file bytes
- A history of messages sent to Slack
- Google message or thread identifiers
Configuration we must retain
- A random installation identifier
- Slack workspace and authorising-user identifiers
- Slack workspace name and granted scopes
- The Slack access token, encrypted at rest
- Short-lived OAuth state during Slack connection
The stored Slack configuration is used solely to list channels and deliver content at your request. OAuth state expires after ten minutes and is deleted when consumed. Installation configuration is retained while the Slack connection is active and should be deleted when the integration is disconnected or a verified deletion request is completed.
Infrastructure may generate security and reliability telemetry such as request time, status code, IP address, or error category. Application code is designed not to add email content, attachment data, subjects, or email addresses to logs. Infrastructure telemetry is not used to reconstruct message content.
Purpose and legal basis
The service processes message content only to perform the action requested by the user: transmitting a selected Gmail message to a selected Slack channel. For an individual user, the legal basis is performance of the requested service. In an organisation, the organisation may be the controller and the app may act as its processor; the organisation is responsible for ensuring that sharing the message into Slack is authorised and appropriate.
Limited configuration and security data are processed to provide, secure, troubleshoot, and prevent abuse of the integration. Depending on context, this is necessary to perform the service and/or serves the legitimate interest of operating a secure, reliable relay.
Permissions and user control
The Gmail manifest requests the add-on execution permission, external-request permission, and Google’s current-message read-only add-on scope. It does not request mailbox-wide Gmail read access. Google describes this add-on scope as temporary access to the content and metadata of the open message context while the add-on is running.
Slack permissions allow the authorising user to list public and private channels, post messages, and upload files. The app acts only after a user chooses a channel and presses Send. Access can be revoked through Google account permissions and Slack’s app management controls.
Recipients and service providers
The flow depends on three infrastructure providers: Google supplies the Gmail message and runs the add-on; Cloudflare runs the relay endpoint and encrypted configuration database; Slack receives and stores the content in the selected workspace. These providers process data under their own contracts, security measures, locations, and privacy documentation.
We do not disclose message content to other third parties unless required by law. Because Google, Cloudflare, and Slack may process data internationally, transfers can occur outside the user’s country. Organisations should review their agreements and workspace settings with those providers.
Security and incidents
Requests from the add-on to the relay are authenticated with an application secret and an installation identifier. Connections use HTTPS. Slack access tokens are encrypted using AES-GCM before database storage, and OAuth state is single-use and time-limited. Access is restricted to the permissions required for the relay.
No internet service can promise absolute security. If a security incident affecting personal data is confirmed, the operator will investigate, contain it, cooperate with relevant customer administrators and providers, and make legally required notifications.
Your choices and rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, or object to processing of personal data, request portability, and lodge a complaint with a supervisory authority. Since email content is not stored by the app, there is no app-side message archive to access or erase. Messages already delivered to Slack must be managed in Slack by the workspace owner or administrator.
To exercise a right concerning stored integration configuration, disconnect the app and email contact@stanleon.cc. A request may require verification of the installation or workspace. You may also lodge a complaint with the French data protection authority, the CNIL.
Changes to this notice
Material changes will be reflected on this page with a new “last updated” date. A change to the product must not silently weaken the core no-content-storage commitment. If future functionality requires storing email content or attachments, it must be opt-in, disclosed before use, and covered by a revised notice.