← BobaTab

Privacy Policy

Effective 1 August 2026

BobaTab (“the Service”) is a Slack application operated by KUCODE LLC (“we”, “us”). It lets people in a Slack workspace give each other bobas and spend them on stickers. This policy explains what the Service collects, why, and how to have it removed.

The Service is installed by a Slack workspace administrator on behalf of that workspace. Where the workspace determines how the data is used, the workspace is the data controller and we act as a processor for them.

What we collect

Workspace information

Your Slack workspace ID and name, the ID of the channel the Service posts in, the ID of the person who installed it, and the access token Slack issues at installation. Tokens are encrypted before they are stored.

Profile information

For each person who uses the Service: their Slack user ID, display name, profile image URL, and whether Slack reports them as a workspace administrator or a bot. This is fetched from Slack and refreshed when they sign in.

The Service no longer asks Slack for email addresses. Workspaces that installed while it did may still have addresses stored against their records; those are not used for anything and are removed with the rest of the workspace's data on deletion.

Message content

The Service reads messages in #boba only — the single channel it creates when installed, or joins if a channel by that name already exists — in order to detect when someone gives a boba. It is a member of no other channel and reads none. It cannot read direct messages between people, and it cannot read private channels it has not been added to.

When a message contains a boba, the accompanying text is stored along with the give, so the recognition has a reason attached. Messages that do not contain a boba are processed and discarded, not stored.

Activity information

Records of bobas given and received, sticker packs opened, the stickers they produced, and who each sticker was sent to.

Sign-in

Signing in to the web dashboard uses Slack. We set one cookie (bobatab_session) containing a signed token identifying you to the Service. It is strictly necessary for sign-in and expires after seven days. We do not use advertising or tracking cookies.

Website analytics

Our website uses Vercel Web Analytics to count page views. It does not set cookies, does not identify you, and does not follow you across other websites. It records the page visited, the referring site, and coarse details such as country, browser, and device type. It runs on our website, including the dashboard, and never inside Slack.

How we use it

We use the information above only to:

We do not sell personal information, we do not use it for advertising, and we do not use your messages or activity to train machine learning models.

Who we share it with

We do not share personal information with third parties except the service providers required to run the Service:

We may also disclose information where required by law, or to protect our rights or the safety of others.

Security

Traffic is encrypted in transit. Access tokens and gift card codes are encrypted at rest using AES-256-GCM. Requests from Slack are verified cryptographically before being processed. Each workspace's data is segregated and access is limited to what the Service needs to function.

No system is perfectly secure, and we cannot guarantee absolute security.

Retention and deletion

Uninstalling the Service does not immediately delete your data. We stop processing and stop recording new activity, but retain existing records so that reinstalling restores everyone's balances rather than erasing the workspace's history.

A workspace administrator can delete everything themselves, without asking us. Sign in with Slack at the web dashboard, open Settings, and use Delete workspace. It takes effect immediately and cannot be undone: the workspace record and every row belonging to it are removed, including people, gives, stickers, shop items and any reward codes. Copies may persist briefly in routine encrypted backups until those expire on their own schedule.

If you would rather we did it, or you no longer have an administrator who can sign in, contact us at kucode8@gmail.com. Individuals who want their own records removed should contact their workspace administrator, who controls the data.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict its processing, and to complain to a data protection authority. Because the Service holds this data on behalf of your employer or workspace, please direct requests to your workspace administrator first; we will assist them in responding.

International transfers

Our providers may process and store information in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for those transfers.

Children

The Service is a workplace tool and is not directed at children. We do not knowingly collect information from anyone under 16.

Changes

We may update this policy. Material changes will be reflected in the effective date above, and where appropriate we will notify workspace administrators.

Contact

Questions or requests: kucode8@gmail.com (KUCODE LLC).


Back to BobaTab