← Back to Keep the Thread
Privacy Policy
Effective: March 2026 · Last updated: August 15, 2026
Summary: Keep the Thread processes Slack and Asana API responses on the live request path to return tool results and AI-generated continuity reports. We do not log or retain Slack messages, Asana task or project content, files, prompts, or generated reports after the request. We store encrypted connector credentials, limited connection metadata, account state, workflow configuration that an operator explicitly saves, content-free outcome metadata, and consented proof submissions.
Buyer review: For the controls and procurement summary, use /security. This page remains the detailed privacy and data-handling reference.
1. Who We Are
Keep the Thread, whose current technical runtime is Slack MCP Cloud, is operated by Rêvasser Labs ("we", "us"). Contact: privacy@revasserlabs.com.
2. What We Collect
- Slack credentials: Slack OAuth tokens or, when you deliberately use the legacy fallback, Slack session tokens (
xoxc- and xoxd-). Persistent credentials are encrypted at rest using AES-256-GCM; legacy fallback credentials may instead be held in ephemeral memory.
- Asana credentials and connection metadata: Asana OAuth access and refresh tokens are encrypted at rest using AES-256-GCM. We also store granted scopes, token expiry, the authorized account GID and display name, and visible workspace GIDs and names so the connector can show its bounded connection state. We do not store the Asana client secret in account records or expose any OAuth token to the browser.
- API key: Your bearer token (
stmh_ prefix) used to authenticate MCP requests.
- Billing data: Stripe handles all payment processing. We receive your Stripe customer ID, plan type, and subscription status. We never see or store credit card numbers.
- Usage metrics: Request counts per billing period (month), stored for rate limiting and billing. No Slack message content or Asana task content is included.
- Saved workflow configuration: Profile name, workflow kind, channel identifiers, optional priority-person identifiers, focus, cadence, IANA timezone, Slack delivery channel, and encrypted downstream webhook configuration when an authenticated operator explicitly saves them.
- Workflow operations measurement: Tenant identifier, tool name, workflow kind, success or failure outcome, bounded error code, plan, and duration. These records never include Slack messages, prompts, generated briefs, channel identifiers, or webhook URLs; they also exclude Asana task or project content and Asana source identifiers.
- Customer proof submissions: Workflow kind, display name, role, optional company or team name, a customer-written quote, and an operational outcome. Submission requires explicit publication consent and a content-boundary confirmation; nothing is public until operator approval.
- Website analytics: Cloudflare Web Analytics records aggregate page-view and visit metrics on the hosted website. This applies to the public web pages only and is separate from Slack MCP request handling.
- Hosted funnel events: The hosted web pages record limited first-party funnel events such as pricing visits, deployment review clicks, checkout starts, checkout completes, setup starts, token-connect success, usage dashboard opens, billing portal opens, and Gemini configuration views. These events are used to understand product funnel performance, not Slack message content.
3. What We Do NOT Collect
- Slack message content, files, or attachments after the live request
- Asana task descriptions, comments, attachments, or project content after the live request
- Channel names, user-profile details, or workspace metadata outside identifiers explicitly saved in a workflow profile
- Search queries or search results after the live request
- Ad-tech cookies or cross-site tracking identifiers that follow you across sites
- Message analytics, prompt logging, or Slack-content telemetry outside the live request path
4. How Connected Data Flows
When you invoke an MCP tool, the hosted worker:
- Authenticates your bearer token against our tenant database
- Retrieves only the encrypted connector credential needed for that request
- Calls the Slack or Asana API on your behalf within the tool's documented boundary
- Returns the direct tool response or validated continuity report to your MCP client
Slack API response data and, for the cross-tool discrepancy report, selected Asana project and incomplete task fields are processed by the requested tool and Cloudflare Workers AI during the live request. Slack message content, Asana task or project content, prompts, and generated reports are not logged, cached, or retained by Keep the Thread after the request or scheduled delivery finishes.
The first Asana continuity contract reads one selected project, limits task retrieval to one page of at most 100 incomplete tasks, and performs no external writes. It does not create, update, complete, or delete Asana tasks, and it does not post to Slack.
5. Connector Credential Storage
- Official OAuth: Slack and Asana OAuth credentials are encrypted with AES-256-GCM using a key stored in Cloudflare environment secrets, then written to a tenant-bound Cloudflare D1 record. OAuth app secrets remain server-side.
- Legacy Slack ephemeral mode: Slack session credentials are held in worker memory only. They are lost on worker restart or cold start. No credential database write occurs.
- Legacy Slack persistent mode: Slack session credentials are encrypted and stored only after explicit consent (
consent_persistent_storage: true).
6. Data Retention
Asana task or project content is not retained after a live tool request. The connection metadata described above is retained only while the connector remains connected.
- Connector credentials: Stored until you disconnect the connector or delete your account. Disconnecting Asana asks Asana to revoke the refresh token before the local encrypted record is deleted. Ephemeral legacy Slack credentials are lost on worker restart.
- Usage records: Retained for the current billing period plus one prior month for dispute resolution.
- Billing data: Retained by Stripe per their privacy policy.
- Hosted funnel events: Retained only for product analytics and conversion reporting, separate from Slack request traffic and message handling.
- Workflow profiles: Retained until the account is deleted or an authenticated removal request is completed.
- Workflow outcome events and schedule receipts: Bounded operational metadata is retained for product measurement, reliability review, and conversion analysis; Slack content, Asana task or project content, and generated reports are excluded.
- Customer proof: Private submissions remain non-public unless approved. Approved proof remains public until consent is withdrawn or the record is removed.
7. Data Sharing
We do not sell, rent, or share your data with third parties except:
- Stripe: Payment processing only.
- Cloudflare: Infrastructure provider (Workers, D1, AI, and Web Analytics for the hosted site). Subject to Cloudflare's privacy policy.
- Slack: Your credentials are used to authenticate API requests to Slack on your behalf.
- Asana: Your OAuth credentials are used to authenticate read-only API requests to Asana on your behalf.
- Operator-configured downstream service: When you explicitly configure and invoke webhook delivery, the generated workflow payload is sent to that public HTTPS endpoint. The destination's own privacy terms apply.
- Law enforcement: Only if required by valid legal process.
8. AI-Augmented Tools
6 tools (slack_catch_me_up, slack_triage, slack_smart_search, slack_workflow_brief, continuity_shadow_report, continuity_asana_discrepancy_report) use Cloudflare Workers AI to process selected Slack messages and, for the discrepancy report only, selected Asana task and project fields. This processing happens within Cloudflare's infrastructure during the request and is not retained by Keep the Thread.
9. Security
- All traffic over HTTPS/TLS
- Slack and Asana OAuth tokens encrypted at rest (AES-256-GCM)
- Bearer tokens are cryptographically random, scoped per tenant
- No plaintext credentials in logs or responses
- Worker runs on Cloudflare's global edge network with DDoS protection
- Cloudflare Web Analytics is limited to aggregate website metrics and does not change MCP token or message handling
10. Website Analytics and Funnel Measurement
The hosted marketing and account pages use two separate measurement layers:
- Cloudflare Web Analytics: aggregate page-view and visit metrics for hosted pages.
- First-party funnel events: product-site events such as pricing visits, deployment review clicks, checkout starts, checkout completes, setup starts, token-connect success, account views, billing portal opens, and Gemini CLI documentation/config views.
These measurements apply to the hosted web surfaces. They do not add Slack message retention, Asana task-content retention, connected-content telemetry, or prompt logging to the MCP request path.
11. Workflow Operations Measurement
Workflow operations measurement is separate from website analytics. It records which hosted workflow tool ran, the selected workflow kind, success or failure, a bounded validation or delivery error code, the current plan, and duration. It is used to improve onboarding, reliability, scheduling, and the Free-to-paid path. It excludes Slack messages, Asana task or project content, prompts, generated reports, source identifiers, priority-person identifiers, and webhook URLs.
12. Your Rights
Regardless of your location, you can at any time:
- Disconnect credentials: Remove Slack or Asana access via the setup page or authenticated API
- Delete your account: Contact us to permanently delete all stored data
- Export your data: Request a copy of all data we hold about you
- Revoke access: Revoke the app in Slack or Asana, or rotate legacy Slack session tokens, to invalidate stored access
For EU/EEA residents (GDPR): You have the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data. We process data under legitimate interest (service delivery) and contract performance. To exercise these rights, contact privacy@revasserlabs.com. We respond within 30 days.
For California residents (CCPA): You have the right to know what personal information we collect, request deletion, and opt out of sale. We do not sell personal information. To exercise these rights, contact privacy@revasserlabs.com.
Data breach notification: In the event of a data breach affecting your personal data, we will notify affected users within 72 hours of discovery via the email address associated with your account or Stripe subscription.
13. Children's Privacy
Keep the Thread is not directed at individuals under 18. We do not knowingly collect data from minors.
14. Changes
We may update this policy. Material changes will be posted here with an updated effective date. Continued use after changes constitutes acceptance.
15. Contact
Questions about this privacy policy: privacy@revasserlabs.com