Privacy Policy

Last updated: August 2026

Overview

Korrali ThreadExtract ("ThreadExtract", "we", "us") is a Slack app, built and operated by Korrali, that turns a Slack thread into a Notion page when a workspace member reacts to it with 🧠. This policy explains what data we collect to provide that service, how we use it, and who we share it with.

Information We Collect

  • Account information — your name and email address, from Google sign-in or from a magic-link email you enter yourself.
  • Slack workspace data — your Slack team ID and an access token, generated when your workspace installs the app. The token is encrypted at rest and is only used to read reacted-to threads and post confirmation messages.
  • Thread content — when someone reacts to a Slack message with 🧠, we fetch that thread's messages via the Slack API to generate a summary. We do not read messages outside of triggered threads.
  • Notion data — an access token for the Notion workspace you connect, used solely to create pages in the database you choose.
  • Billing information — handled directly by Stripe. We never see or store your card number; we retain only your subscription status and plan tier.
  • Usage data — basic application logs (timestamps, error traces) used for debugging and reliability.

How We Use Your Information

  • To fetch the Slack thread you reacted to and generate an AI summary.
  • To publish that summary as a page in your connected Notion database.
  • To manage your account, subscription, and billing.
  • To operate, secure, and improve the service, and to communicate service-related updates.

Automated Secret Redaction

Because ThreadExtract's purpose is pulling raw Slack conversations — including ones where someone pasted a credential while debugging — we run a best-effort pattern-matching filter over thread text (catching things like API keys, private keys, JWTs, and card-number-shaped digit runs) before it is sent to any AI provider. This filter is pattern-based, not exhaustive: it catches well-known secret formats, not every possible sensitive string. Please avoid pasting sensitive credentials into Slack threads you intend to summarize.

Third-Party Service Providers

We share the minimum data necessary with the following processors to operate the service:

  • Slack — thread content is read via Slack's API under the permissions you grant at install.
  • Google Gemini (primary) and Groq (fallback) — redacted thread text is sent to generate the AI summary.
  • Notion — the generated summary is written to your connected database via Notion's API.
  • Stripe — processes subscription payments; card data is handled entirely by Stripe.
  • Resend — delivers magic-link sign-in emails.
  • Google — provides optional OAuth sign-in.

Data Retention

We retain workspace and account data for as long as your account is active. Uninstalling ThreadExtract from Slack revokes our access token; you may request deletion of any remaining account data at any time (see Contact below).

Data Security

Slack and Notion access tokens are encrypted at rest. Access to production data is restricted to those operating the service. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your data.

Your Rights

You may request access to, correction of, or deletion of your personal data by contacting us. Uninstalling the Slack or Notion integration at any time stops further data collection through that channel.

Children's Privacy

ThreadExtract is a workplace productivity tool not directed at, or knowingly used by, children under 16.

Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

Contact

Questions about this policy? Email hello@korrali.com.