Privacy Policy
Last Updated: November 25, 2025
1. Introduction
Welcome to Plug and AI ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your data. This Privacy Policy explains how we collect, use, and protect your information when you use our Slack application and services.
2. Information We Collect
Slack Data
- Messages: We process messages where our bot is mentioned or direct messages sent to the bot to generate AI responses. Message content is stored only in-memory during processing and is never saved to our database or file system.
- User and Team Information: We store your Slack Team ID, User ID, and Team Name to manage your account and billing.
- Files: If you upload images for vision analysis, they are processed entirely in-memory and then discarded. We never save your files or images to our servers, database, or persistent storage.
Usage Data
We track API usage (token counts, model selection) to calculate costs and bill your workspace appropriately.
Billing Information
All payments are processed securely by Stripe. We do not store your credit card information. We only retain a record of your credit balance and transaction history.
3. How We Use Your Information
- To provide the AI chat service and generate responses.
- To maintain conversation context within Slack threads.
- To process payments and manage your credit balance.
- To improve the performance and reliability of our service.
4. Data Sharing and Third Parties
Zero Data Retention (ZDR)
Our Commitment (Plug and AI)
We maintain a strict Zero Data Retention policy for your message content:
- No Logging: We do not log or persistently record your messages, prompts, or AI responses.
- No Training: We do not use your data, messages, or interactions to train AI models.
- In-Memory Only: We do not persistently store your conversation history or message content in our databases. Messages are processed solely in-memory to generate a response and provide conversational context, then discarded.
Third-Party Providers (OpenRouter & Model Providers)
Third-party AI providers (OpenRouter and downstream model providers) may or may not comply with Zero Data Retention policies independently. To help protect your privacy:
- ZDR Enabled by Default: We enforce OpenRouter's Zero Data Retention setting by default on all requests. This instructs OpenRouter and downstream providers not to store your data or use it for training.
- User Control: You may disable ZDR in your settings if you wish to use models that do not support this feature. Disabling ZDR means your data may be subject to the standard data retention policies of OpenRouter and the underlying model providers.
Note: While we enforce ZDR settings, we cannot guarantee compliance by third-party providers. Please review their respective privacy policies.
We do not sell your data. We share data only with the following necessary service providers:
AI Model Aggregation
We utilize OpenRouter as our exclusive gateway to access various AI models. When you interact with our service, your message content is transmitted to OpenRouter, which routes it to the model provider of your choice.
🤖 Multiple LLM Providers
Our service supports 300+ AI models from multiple providers including OpenAI, Anthropic, Google, Meta, Mistral, and others. The specific model used depends on your preference settings or explicit selection.
For detailed information about the following policies, you must consult OpenRouter's documentation and each model provider's respective policies:
- LLM model(s) being used: See OpenRouter Models
- LLM data tenancy policy: Varies by provider — review each provider's terms
- LLM data residency policy: Varies by provider — data may be processed in different regions
- LLM retention settings: See OpenRouter ZDR documentation and individual provider policies
We enable Zero Data Retention (ZDR) by default, but ultimate compliance depends on the model provider. Users requiring strict data governance should review provider-specific policies before use.
⚠️ Important Chain of Responsibility Notice
Our service acts as an interface between your Slack workspace and OpenRouter. By using our service, you acknowledge and agree to the following data processing chain:
- Plug and AI (Us): We process your request and securely forward it to OpenRouter.
- OpenRouter: Acts as an aggregator and forwarder. Please review OpenRouter's Privacy Policy. We do not control, are not responsible for, and do not account for OpenRouter's privacy practices or data handling.
- Model Providers: OpenRouter forwards your request to the specific underlying model provider you select (e.g., OpenAI, Anthropic, Google, etc.). Each of these providers has their own separate privacy policies and data retention practices.
Disclaimer: We expressly disclaim liability for the privacy practices, security standards, or data handling of OpenRouter and any downstream model providers in this chain. You utilize these third-party services at your own risk and are encouraged to review the privacy policies of the specific AI models and aggregators involved.
Infrastructure & Payments
- Heroku (Salesforce, Inc.): We use Heroku for application hosting.
- Cloudflare: We use Cloudflare for database services and CDN.
- Stripe: We use Stripe for secure payment processing.
- Slack: As a Slack app, all interactions occur within the Slack platform.
5. Data Retention
We retain account and transaction records (billing data) as long as your account is active.
6. Your Rights
You can request the deletion of your data by contacting us. Slack workspace administrators can uninstall the app at any time, which revokes our access to your workspace.
7. Contact Us
If you have any questions about this Privacy Policy, please visit our Support page.