MentionDraft
How it works Pricing Contact
Home AI disclaimer Privacy Terms Support

Privacy Policy

Effective 30 September 2026 · MentionDraft by Talakraft · Contact: talakraft@talakraft.com

This policy describes what Slack data MentionDraft collects, why, how long we keep it, and how you can access or delete it. MentionDraft is a drafting assistant (Chrome extension). We do not sell data and we do not use Slack content to train language models.

Who we are

MentionDraft is operated by Talakraft. Privacy requests go to talakraft@talakraft.com. Registered business details for privacy requests are available on request at that email.

What data we collect

  • Slack identifiers — workspace/team id, your user id, channel ids, message timestamps.
  • Message content we need to draft — on each draft we may send the incoming message and up to about 40 messages from the open pane (including a sample of your recent messages there) to our server. That content is processed in memory to build the draft and is not kept in our database afterward. We do not backfill the whole workspace.
  • Draft metadata — we store only enough to enforce your monthly draft limit and avoid duplicate work (Slack user id, channel id, timestamps, status). We do not retain the incoming message text or the generated draft text on our servers.
  • Billing identifiers — your Slack user id is sent to Lemon Squeezy in checkout custom data so a subscription can be tied to this account. Lemon Squeezy stores the email and payment details you enter at Lemon Squeezy checkout.
  • Subscription records — after checkout or a Lemon Squeezy webhook, we store on our servers your Slack user id linked to Lemon customer/subscription/variant ids, plan, status, and current period end so we can enforce paid limits.
  • Style cards — a compact behavioral profile per (you × channel): language, length, formality, do/don’t habits. Encrypted at rest. We do not store message quotes. Cards can be rebuilt on a draft, not only about every 30 days.
  • Extension sessions — a hashed session token stored in chrome.storage.local after you sign in with Slack. It does not sync to other Chrome profiles.
  • Local draft inbox — recent incoming text, a short thread, your pane samples, and drafts for this browser session (chrome.storage.session). It clears when Chrome is fully quit. It is not synced to other profiles.
  • Guest rephrase — if you use Rephrase or Improve before Continue with Slack, we store a random guest id in chrome.storage.local and send the text you typed (and optional channel name) to our server for AI processing. We store quota metadata only (guest id, optional channel name, timestamps, trigger) — not the typed text or the rewritten text. When you later Continue with Slack, that month’s guest usage is merged into your Slack user’s draft count.
  • Voice dictation (optional) — if you tap the microphone in the composer, Chrome’s speech-to-text runs in your browser. Audio is handled by Chrome (and its speech provider) to produce text in the side panel. We do not receive raw audio on our servers. If you then tap Rephrase or Improve, that typed text is sent to our server as above.
  • Composer preferences — dictation language and optional “force English” for Rephrase/Improve are stored in chrome.storage.local on this browser.
  • Operational logs — HTTP request metadata (timestamps, event type). We do not log full message bodies in production logs.

Chrome extension

The Chrome extension runs only on https://app.slack.com. You can type or dictate a reply and tap Rephrase without signing in; that path does not scrape the open pane. After you tap Continue with Slack:

  • A content script reads messages in the Slack conversation you already have open: the incoming message and up to about 40 pane messages (including a sample of your recent messages there).
  • Slack Sign-in (OpenID) tells us your Slack user id. We issue a session stored in this browser — no keys to paste.
  • That payload is sent to our backend (Google Cloud Run). A hosted AI model may receive those samples to build or refresh a style card, plus the incoming message and a related-thread subset to write the draft. The draft is shown in the side panel.
  • When you tap Send or Add as draft, the extension pastes your text into the Slack composer in the tab you have open. It does not send unless you confirm in Slack (Send tries to submit only when you explicitly tap it).
  • Microphone access is requested only for optional voice dictation. Chrome may route speech recognition through its own provider; we do not store audio.

Uninstalling the Chrome extension stops capture in that browser; it does not by itself erase server style cards, sessions, or draft metadata. Email us to delete those.

How we use it

  • To generate a short reply in your voice and deliver it in the Chrome side panel.
  • To keep the source conversation unread — we never call Slack mark-read APIs.
  • To send pane samples to a hosted AI model (currently GPT-4o-mini) to build or refresh a style card, plus the incoming message and a related-thread subset to write the draft. We do not use Slack data to train models.

We do not sell personal data. We do not use it for ads.

LLM processing

Draft generation uses a hosted AI model (currently GPT-4o-mini). On each draft we may send the incoming message and up to about 40 messages from the open pane (including a sample of your recent messages there) to our server. The model may receive those samples to build or refresh a style card, plus the incoming message and a related-thread subset to write the draft. Style cards can be rebuilt on a draft, not only about every 30 days. We do not use Slack data to train MentionDraft or third-party models. See also the AI disclaimer.

How long we keep it

  • Style cards — up to about 45 days of inactivity, then purged (or sooner if you ask us to delete). They can be rebuilt on a later draft.
  • Draft metadata — kept only to enforce the monthly limit (about 40 days), then purged. Message bodies are not retained.
  • Subscription/entitlement records — kept while the subscription is active and for a reasonable period after cancel or churn so we can honor the paid period and resolve billing disputes; deleted on request (email us).
  • Extension sessions — hashed tokens, up to about 90 days, or until you disconnect / request deletion. Uninstalling the extension does not by itself erase the server session.
  • Product funnel events — up to about 14 days (no message bodies).

Access, export, and deletion

Email talakraft@talakraft.com from the Slack account you use with MentionDraft. We will confirm what we store, export style-card features, draft metadata, and entitlement records on request, and delete stored data for your user id. We cannot export message bodies from the server because we do not keep them.

If you are in the EEA/UK, you may have GDPR rights (access, rectification, erasure, restriction, portability, objection). You may lodge a complaint with your local supervisory authority.

If you are a California resident, we do not sell or share personal information as defined by CCPA/CPRA.

Subprocessors

  • Google Cloud — hosts the backend (Cloud Run) and application data (Firestore with time-to-live on style cards, draft metadata, sessions, and funnel events).
  • Cloudflare — DNS, CDN, and edge proxy for mentiondraft.talakraft.com.
  • OpenAI — generates drafts from the prompt we send.
  • Slack — source of events; destination of the Chrome side panel session.
  • Lemon Squeezy — merchant of record and authorized reseller for paid subscriptions (payment, invoices, VAT/sales tax). Lemon Squeezy is an independent controller for payment data you enter at Lemon Squeezy checkout.

International transfers

Google Cloud runs our API in the EU (europe-west1). OpenAI and Lemon Squeezy may process data in the United States. We rely on each provider’s published transfer mechanism for EEA/UK users; the exact instrument (for example SCCs or another valid tool) is as documented by that provider. We do not claim a separate MentionDraft-specific transfer contract beyond what those providers document.

Lawful basis

We process Slack identifiers, open-conversation content (ephemerally to generate drafts), guest rephrase text you typed (ephemerally), encrypted style-card features, draft metadata for quota, and sessions to perform the contract of providing drafts after you connect Slack or request a guest rephrase. We process operational logs (HTTP metadata, no message bodies) for our legitimate interests in running and securing the service. Lemon Squeezy is an independent controller for payment data you enter at Lemon Squeezy checkout.

Security

Production APIs require a Slack-connected extension session, an operator key, or a guest rephrase header. Slack Events require Slack's signing secret. Extension sessions are hashed at rest. We will notify affected users if we become aware of a breach involving Slack user data.

Children

MentionDraft is for workplace Slack use. It is not directed at children under 16.

Chrome Web Store Limited Use

The use of information received from Google APIs (and user data this extension collects) adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Changes

We will update this page when collection or processors change. If collection or sharing practices change after you install, we will notify you in the Chrome extension UI before the new practice applies.

MentionDraft
Privacy Terms AI Disclaimer Support

© 2026 Talakraft. All rights reserved.