Does Slack AI Train on Your Messages? (And an Agent That Doesn't)
Slack Integration

Does Slack AI Train on Your Messages? (And an Agent That Doesn't)

Slack drew fire in 2024 for using customer data to train machine learning features on an opt-out basis, where only a workspace owner could opt out by email. This guide separates Slack’s generative Slack AI (not trained on your messages) from its non-generative ML, shows how to opt out today, and explains how OpenClaw Direct never trains on your Slack messages.

TL;DR
  • Slack’s generative Slack AI is not trained on your messages and needs opt-in consent; its non-generative ML uses your data by default.
  • The only opt-out is an owner-only email to [email protected] with subject “Slack Global model opt-out request” — no settings toggle.
  • The May 2024 backlash (Hacker News + TechCrunch) was about opt-out-by-default and the buried, manual escape hatch.
  • Slack’s clarification is fair: ML uses de-identified/aggregated data and Slack AI’s LLMs aren’t trained on customer data — but the default stayed opt-out.
  • OpenClaw Direct never trains on your messages, encrypts your token in a vault, and deletes inbound logs after 30 days.
OpenClaw Direct Team ·

It depends on which Slack feature you mean, and that nuance is the whole story. Slack says its generative Slack AI add-on uses third-party language models that are not trained on your messages, and that any generative training would require your opt-in. But Slack’s older, non-generative machine learning — the stuff behind search and channel recommendations — analyzes customer data by default, and the only way out is an email from a workspace owner. That opt-out-by-default arrangement is what set off a public fight in May 2024.

TL;DR

Slack’s generative Slack AI is not trained on your messages and needs opt-in consent; its non-generative ML uses your data by default, with an owner-only email opt-out. If you want an agent in Slack that never trains on your messages at all — token encrypted, logs gone in 30 days — see the OpenClaw Direct Slack agent.

The short answer, without the spin

Slack runs two separate things people lump together as “Slack AI.” The first is a set of traditional, non-generative machine learning models that power emoji suggestions, search ranking, and channel recommendations. The second is Slack AI, the paid generative add-on that summarizes threads and answers questions using large language models. They have different data rules, and conflating them is how you end up either needlessly alarmed or falsely reassured.

Per Slack’s privacy principles, the non-generative models analyze customer data — messages, content, and files — but Slack says they work on de-identified, aggregated data rather than reading message content directly. This use is on by default. The generative Slack AI product is the opposite: Slack says it uses third-party LLMs that are not trained on your data, and that it won’t use customer data to train generative models without affirmative opt-in. One system is opt-out, the other opt-in. Same brand, different defaults.

What actually happened in 2024?

In May 2024, a Hacker News thread flagged the wording of Slack’s policy, and TechCrunch reported the backlash on May 17. The complaint wasn’t only that Slack used customer data to train models — it was how. Users were opted in by default, the policy lived buried in legal text, there was no in-app notice and no settings toggle, and the single escape hatch was a manually written email.

And not an email just anyone could send. To opt out, an Org, Workspace, or Primary Owner had to contact Slack’s Customer Experience team at [email protected], include the Workspace or Org URL, and use the exact subject line “Slack Global model opt-out request.” A regular member who cared about their data couldn’t act on their own; they had to find an owner and ask them to send the message. For a lot of teams, that friction meant the default just stayed in place.

Slack’s response was to clarify rather than reverse. It updated its explanation to stress that its ML models don’t access message content directly and that Slack AI’s LLMs aren’t trained on customer data. That’s a fair and real distinction, and worth stating plainly. It also didn’t change the part people objected to: the non-generative training stayed opt-out, and the opt-out stayed an owner-only email.

How to check and change the setting today

There still isn’t a checkbox for this. If you want your workspace out of Slack’s non-generative global model training, the mechanism is the same email:

  • Confirm you’re an Org, Workspace, or Primary Owner — only owners can make the request.
  • Email [email protected] from an address tied to the workspace.
  • Include your Workspace or Org URL so Slack can identify the right account.
  • Use the subject line Slack Global model opt-out request.
  • Wait for Slack’s confirmation email that the opt-out is processed — keep it as your record.

For the generative Slack AI product, the posture is inverted: Slack says it won’t train generative models on your data unless you opt in, so there’s nothing to switch off there by default. If your obligations are strict, don’t take a summary’s word for it — read the current terms and your own DPA, because policies move.

Good to know: “De-identified and aggregated” is not the same as “never touched.” Slack’s non-generative models still analyze customer data to build recommendations; the safeguard is in how the data is processed, not in leaving it alone. If that distinction matters to your compliance team, the owner-only email opt-out is the lever that exists.

Slack ML vs Slack AI vs a hosted agent, side by side

Here’s the honest comparison across the questions that actually decide your risk: does it train on your messages by default, who can opt out, are your keys and tokens encrypted, and how long is data kept.

Question Slack non-generative ML Slack AI (generative) OpenClaw Direct agent
Trains on your messages by default? Yes, on de-identified, aggregated data No — Slack says generative training needs opt-in No, never
Who can opt out? Org/Workspace owner, by email N/A — opt-in only N/A — no training to opt out of
Keys / tokens encrypted? Slack-managed Slack-managed Yes — workspace token in an encrypted vault
Data retention Per Slack’s policy Per Slack’s policy Inbound logs minimized, deleted after 30 days

None of this makes Slack the villain. Its clarification was reasonable and the generative product genuinely keeps your messages out of model training. The friction is real, though: the one place where your data is used by default is also the one place opting out takes an owner and a hand-written email.

OpenClaw Direct’s honest posture

OpenClaw Direct is a dedicated AI agent you talk to inside Slack, and our data rules are short enough to state without a legal appendix. We never train AI models on your Slack messages — not by default, not with opt-in, not at all. Your workspace bot token is stored in a vault, encrypted at rest. Inbound message logs are minimized and deleted after 30 days, so there’s no growing archive of your conversations sitting on our side. And you can bring your own model key, which keeps your prompts flowing through a provider relationship you control.

The agent also sees less than you might assume. It only reads DMs sent to it and channels you explicitly add it to or @mention it in — it never reads channels it hasn’t joined. We publish the details rather than bury them: our security page covers encryption and scopes, the privacy policy covers what we do and don’t keep, and the DPA is there for teams that need one on file. No email to a support alias, no owner-only lever, no default you have to discover after the fact.

Frequently asked questions

Does Slack AI train on your data?

Slack says its generative Slack AI product runs on third-party LLMs that are not trained on your messages, and that generative training needs your opt-in consent. Separately, Slack’s older, non-generative machine learning analyzes customer data for search and recommendations on an opt-out basis. One part is opt-in, the other is opt-out by default.

How do I opt out of Slack AI training?

Only an Org, Workspace, or Primary Owner can do it, and there’s no toggle in settings. They email [email protected] from the workspace, include the Workspace or Org URL, and use the subject line “Slack Global model opt-out request.” Slack confirms by email once it processes the request.

What data does Slack use to train its models?

For its non-generative global models, Slack says it analyzes customer data such as messages, content, and files, but works on de-identified and aggregated data rather than reading message content directly. Its generative Slack AI add-on uses third-party LLMs that Slack says are not trained on customer data.

Was the 2024 Slack AI controversy real?

Yes. In May 2024 a Hacker News post and a TechCrunch report surfaced that Slack used customer data to train machine learning features by default, with an email-only opt-out for owners. Slack then clarified the line between its non-generative ML and its generative Slack AI product.

Does OpenClaw Direct train on my Slack messages?

No. OpenClaw Direct never trains AI models on your Slack messages. Your workspace token is encrypted at rest, inbound message logs are minimized and deleted after 30 days, and you can bring your own model key. The details are on our security page.

Is there a way to run a Slack AI agent that never trains on my data?

Yes. A hosted agent like OpenClaw Direct connects to your workspace without using your messages for training. It only sees DMs sent to it and channels you add it to, stores your token in an encrypted vault, and deletes inbound logs after 30 days.

Want an agent that just never trains on you?

The Slack story is defensible but fiddly: generative AI leaves your messages alone, the older ML doesn’t by default, and the only opt-out is an owner with the right email subject line. If you’d rather not track which system does what, pick a tool with one rule instead of two. OpenClaw Direct never trains on your Slack messages, keeps your token in an encrypted vault, and clears inbound logs after 30 days. Add it to your workspace and read exactly what it keeps.