MentionDraft
How it works Pricing Contact
Home AI disclaimer Privacy Terms Support

Privacy Policy

Effective 20 August 2026 · MentionDraft by Talakraft · Contact: talakraft@talakraft.com

This policy describes what Slack data MentionDraft collects, why, how long we keep it, and how you can access or delete it. MentionDraft is a drafting assistant (Chrome extension). We do not sell data and we do not use Slack content to train language models.

Who we are

MentionDraft is operated by Talakraft (the brand). A registered legal name and postal address are not published on this page yet. Privacy requests go to talakraft@talakraft.com.

What data we collect

  • Slack identifiers — workspace/team id, your user id, channel ids, message timestamps.
  • Message content we need to draft — on each draft we may send the incoming message and up to about 40 messages from the open pane (including a sample of your recent messages there) to our server. We do not backfill the whole workspace.
  • Generated drafts — we store the incoming text and the generated draft so we can deliver it to you and enforce the monthly draft limit for your plan, until you ask us to delete them.
  • Billing identifiers — your Slack user id is sent to Polar Software Inc. as an external customer id so a subscription can be tied to this account. Polar stores the email and payment details you enter at Polar checkout.
  • Style cards — a compact profile per (you × channel), not a dump of raw history. They can be rebuilt on a draft, not only about every 30 days.
  • Extension sessions — a hashed session token stored in chrome.storage.local after you sign in with Slack. It does not sync to other Chrome profiles.
  • Local draft inbox — recent incoming text, a short thread, your pane samples, and drafts for this browser session (chrome.storage.session). It clears when Chrome is fully quit. It is not synced to other profiles.
  • Operational logs — HTTP request metadata (timestamps, event type). We do not log full message bodies in production logs.

Chrome extension

The Chrome extension runs only on https://app.slack.com. After you tap Continue with Slack:

  • A content script reads messages in the Slack conversation you already have open: the incoming message and up to about 40 pane messages (including a sample of your recent messages there).
  • Slack Sign-in (OpenID) tells us your Slack user id. We issue a session stored in this browser — no keys to paste.
  • That payload is sent to our backend (Railway). OpenAI may receive those samples to build or refresh a style card, plus the incoming message and a related-thread subset to write the draft. The draft is shown in the side panel.
  • The extension never posts into Slack as you. You copy, paste, and send.

Uninstalling the Chrome extension stops capture in that browser; it does not by itself erase server drafts or sessions. Email us to delete those.

How we use it

  • To generate a short reply in your voice and deliver it in the Chrome side panel.
  • To keep the source conversation unread — we never call Slack mark-read APIs.
  • To send pane samples to OpenAI (currently GPT-4o-mini) to build or refresh a style card, plus the incoming message and a related-thread subset to write the draft. We do not use Slack data to train models.

We do not sell personal data. We do not use it for ads.

LLM processing

Draft generation is performed by OpenAI (GPT-4o-mini). On each draft we may send the incoming message and up to about 40 messages from the open pane (including a sample of your recent messages there) to our server. OpenAI may receive those samples to build or refresh a style card, plus the incoming message and a related-thread subset to write the draft. Style cards can be rebuilt on a draft, not only about every 30 days. We do not use Slack data to train MentionDraft or third-party models. See also the AI disclaimer.

How long we keep it

  • Style cards — until you ask us to delete them. They can be rebuilt on a draft, not only about every 30 days.
  • Drafts — we store the incoming text and the generated draft until you ask us to delete them. Uninstalling the Chrome extension does not erase them.
  • Extension sessions — hashed tokens, until you disconnect or request deletion. Uninstalling the extension does not by itself erase the server session.

Access, export, and deletion

Email talakraft@talakraft.com from the Slack account you use with MentionDraft. We will confirm what we store, export drafts and style cards on request, and delete stored data for your user id.

If you are in the EEA/UK, you may have GDPR rights (access, rectification, erasure, restriction, portability, objection). You may lodge a complaint with your local supervisory authority.

If you are a California resident, we do not sell or share personal information as defined by CCPA/CPRA.

Subprocessors

  • Railway — hosts the backend and database volume.
  • Cloudflare — CDN and DNS for mentiondraft.talakraft.com.
  • OpenAI — generates drafts from the prompt we send.
  • Slack — source of events; destination of the Chrome side panel session.
  • Polar Software Inc. — merchant of record and authorized reseller for paid subscriptions (payment, invoices, VAT/sales tax). Polar is an independent controller for payment data you enter at Polar checkout.

International transfers

OpenAI and Polar process data in the United States. For EEA/UK users, we rely on those providers' published transfer mechanisms. TODO: counsel should name the exact transfer tool later — this page does not claim a specific instrument.

Lawful basis

We process Slack identifiers, open-conversation content, style cards, drafts, and sessions to perform the contract of providing drafts after you connect Slack. We process operational logs (HTTP metadata, no message bodies) for our legitimate interests in running and securing the service. Polar Software Inc. is an independent controller for payment data you enter at Polar checkout.

Security

Production APIs require either a Slack-connected extension session or an operator key. Slack Events require Slack's signing secret. Extension sessions are hashed at rest. We will notify affected users if we become aware of a breach involving Slack user data.

Children

MentionDraft is for workplace Slack use. It is not directed at children under 16.

Chrome Web Store Limited Use

The use of information received from Google APIs (and user data this extension collects) adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Changes

We will update this page when collection or processors change. If collection or sharing practices change after you install, we will notify you in the Chrome extension UI before the new practice applies.

MentionDraft
Privacy Terms AI Disclaimer Support

© 2026 Talakraft. All rights reserved.