Slack stores your messages and files and your workspace owner (employer) controls and can export them. Data is used to operate the service and disputes may go to arbitration.
The clauses that could affect you the most. Read these even if you skip everything else.
Your workspace data (messages, files, etc.) is used by default to train Salesforce's AI and machine learning models β you must actively opt out.
Salesforce accepts zero liability for AI-generated outputs, even if they are inaccurate, harmful, or legally non-compliant β you bear full responsibility.
Insights and patterns derived from your data through machine learning become Salesforce's permanent intellectual property.
Salesforce can change the terms at any time, and continuing to use Slack counts as acceptance of new terms.
Your company name and logo can be used by Salesforce for marketing without needing your case-by-case approval.
Browse what the terms actually say β filter by severity or by topic.
Customer data used for AI/ML training
π€AI training on your dataπ¬ Slack (Salesforce) can access your workspace data β messages, files, and other content β to train its machine learning models, improve its products, and conduct R&D. While they frame this as acting on your 'instruction,' it is effectively a default permission that you must affirmatively opt out of.
βSFDC may access Customer Data in Slack for these purposes, with Customer's instruction: 1. Training models for accessible services and features 2. Improving accessible services and features 3. Conducting research and development of products Customer will access at no additional costβ
SFDC retains ownership of aggregated ML results
π€AI training on your dataπ¬ While you keep ownership of your raw data, Salesforce owns anything its models learn from your data in aggregate form. This means insights and patterns derived from your data become Salesforce's intellectual property permanently.
βCustomers retain ownership of their data, while SFDC retains ownership in aggregated machine learning results.β
Opt-out is not the default
π€AI training on your dataπ¬ You must actively visit a separate page and follow instructions to opt out of having your data used for AI training. This is not an opt-in system β your data is used by default unless you take action.
βFor opt-out instructions and additional information, visit the Privacy Principles page.β
Customer bears all responsibility for AI outputs
π‘οΈLimits their liabilityπ¬ Slack's AI features can produce wrong or even harmful results, but Salesforce takes zero responsibility. You are entirely liable for anything the AI generates, including if it produces something inaccurate, unsafe, or legally problematic. The AI output is treated as your own content.
βThese features may produce unpredictable, inaccurate, or harmful outputs. Customers bear sole responsibility for reviewing all outputs for accuracy, safety, and legal compliance before use. Customers assume all responsibility for generated output, which constitutes Customer Data.β
Third-party AI providers may process your data
πShares with third partiesπ¬ Slack's AI features may be powered by third-party companies, meaning your data could be processed by external providers. The details are in separate documentation you'd need to look up yourself.
βServices include generative AI features potentially provided by third-parties as documented in Trust and Compliance Documentation.β
Data may leave FedRAMP security boundary
πShares with third partiesπ¬ If you use features that connect Slack with Salesforce (like Salesforce Channels), your data may move to infrastructure that does not meet the same security and privacy standards as Slack's core service. This is especially concerning for government or regulated-industry customers.
βCustomer acknowledges that data shared with these "Interoperable (but not Authorized)" products extends outside Slack's FedRAMP authorization boundary.β
Different privacy/security protections across infrastructure
πOtherπ¬ When Slack and Salesforce services work together, your data could be subject to different (potentially weaker) privacy and security rules depending on which infrastructure it's stored on.
βServices interoperating between Slack and Salesforce, including Salesforce Channels, operate on separate infrastructure with potentially different privacy and security protections, as described in Infrastructure and Subprocessor Documentation.β
Your company name/logo used for marketing
πClaims your contentπ¬ By using Slack, you give Salesforce permission to publicly use your company's name and logo to market their services β essentially making you a reference customer without requiring your explicit case-by-case approval.
βSFDC may use Customer's company name and logo as a reference for marketing and promotional purposes on websites and in communications with existing or prospective customers, subject to Customer's standard trademark usage guidelines.β
Jurisdiction locked to specific venues
πJurisdictionπ¬ Any legal disputes must be handled in specific courts depending on where you're located. For US/Canadian users, that's San Francisco, California. For most international users, it's London, England. This could be inconvenient and expensive if you're located far from these venues.
βFor online Slack purchases, the contracting entity, notice address, governing law, and jurisdiction vary by domicile: United States and Canada β California, San Francisco County; Rest of World (Except Japan) β England, London; Japan β Tokyo, Japanβ
Terms can be changed unilaterally
πCan change terms anytimeπ¬ Salesforce can change these terms whenever they want. While they promise 'reasonable advance notice' for material changes, simply continuing to use Slack after changes means you've accepted them β there's no requirement for you to affirmatively agree.
βSFDC may modify these Supplemental Terms periodically. Material changes receive reasonable advance notice before taking effect. Continued use of Slack Services following any changes constitutes acceptance of the updated terms.β
Note: The Supplemental Terms themselves do not enumerate explicit user rights such as deletion, access, or portability. They reference a Privacy Principles page for opt-out instructions regarding AI/ML training. Additional rights may exist in the Salesforce Main Services Agreement (MSA) or applicable privacy policies, which were not included in this document.