Privacy Policy
Effective 1 August 2026
BobaTab (“the Service”) is a Slack application operated by KUCODE LLC (“we”, “us”). It lets people in a Slack workspace give each other bobas and spend them on stickers. This policy explains what the Service collects, why, and how to have it removed.
The Service is installed by a Slack workspace administrator on behalf of that workspace. Where the workspace determines how the data is used, the workspace is the data controller and we act as a processor for them.
What we collect
Workspace information
Your Slack workspace ID and name, the ID of the channel the Service posts in, the ID of the person who installed it, and the access token Slack issues at installation. Tokens are encrypted before they are stored.
Profile information
For each person who uses the Service: their Slack user ID, display name, profile image URL, and whether Slack reports them as a workspace administrator or a bot. This is fetched from Slack and refreshed when they sign in.
The Service no longer asks Slack for email addresses. Workspaces that installed while it did may still have addresses stored against their records; those are not used for anything and are removed with the rest of the workspace's data on deletion.
Message content
The Service reads messages in #boba only — the single channel it creates when installed, or joins if a channel by that name already exists — in order to detect when someone gives a boba. It is a member of no other channel and reads none. It cannot read direct messages between people, and it cannot read private channels it has not been added to.
When a message contains a boba, the accompanying text is stored along with the give, so the recognition has a reason attached. Messages that do not contain a boba are processed and discarded, not stored.
Activity information
Records of bobas given and received, sticker packs opened, the stickers they produced, and who each sticker was sent to.
Sign-in
Signing in to the web dashboard uses Slack. We set one cookie (bobatab_session) containing a signed token identifying you to the Service. It is strictly necessary for sign-in and expires after seven days. We do not use advertising or tracking cookies.
Website analytics
Our website uses Vercel Web Analytics to count page views. It does not set cookies, does not identify you, and does not follow you across other websites. It records the page visited, the referring site, and coarse details such as country, browser, and device type. It runs on our website, including the dashboard, and never inside Slack.
How we use it
We use the information above only to:
- record bobas and calculate balances and daily allowances;
- show names and pictures so people can recognise each other;
- deliver stickers;
- authenticate you and confirm administrator status;
- diagnose faults and keep the Service secure.
We do not sell personal information, we do not use it for advertising, and we do not use your messages or activity to train machine learning models.
Who we share it with
We do not share personal information with third parties except the service providers required to run the Service:
- Slack Technologies — the platform the Service operates on.
- Vercel — application hosting.
- Neon — database hosting.
We may also disclose information where required by law, or to protect our rights or the safety of others.
Security
Traffic is encrypted in transit. Access tokens and gift card codes are encrypted at rest using AES-256-GCM. Requests from Slack are verified cryptographically before being processed. Each workspace's data is segregated and access is limited to what the Service needs to function.
No system is perfectly secure, and we cannot guarantee absolute security.
Retention and deletion
Uninstalling the Service does not immediately delete your data. We stop processing and stop recording new activity, but retain existing records so that reinstalling restores everyone's balances rather than erasing the workspace's history.
A workspace administrator can delete everything themselves, without asking us. Sign in with Slack at the web dashboard, open Settings, and use Delete workspace. It takes effect immediately and cannot be undone: the workspace record and every row belonging to it are removed, including people, gives, stickers, shop items and any reward codes. Copies may persist briefly in routine encrypted backups until those expire on their own schedule.
If you would rather we did it, or you no longer have an administrator who can sign in, contact us at kucode8@gmail.com. Individuals who want their own records removed should contact their workspace administrator, who controls the data.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict its processing, and to complain to a data protection authority. Because the Service holds this data on behalf of your employer or workspace, please direct requests to your workspace administrator first; we will assist them in responding.
International transfers
Our providers may process and store information in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for those transfers.
Children
The Service is a workplace tool and is not directed at children. We do not knowingly collect information from anyone under 16.
Changes
We may update this policy. Material changes will be reflected in the effective date above, and where appropriate we will notify workspace administrators.
Contact
Questions or requests: kucode8@gmail.com (KUCODE LLC).