Skip to content
shuffl

Version 1.16 · Effective

Privacy Policy

This policy explains what Shuffl does with the information in a workspace: who can see it, why it is processed, who else it reaches and how long it is kept.

Most information in Shuffl belongs to the employer that runs the workspace. Shuffl processes it to operate the service on that employer’s instructions. Employment questions about that information, such as why a record exists or who inside the company may read it, are answered by the employer, not by Shuffl.

Who operates Shuffl

Shuffl is operated by Shuffl LLC, 2048 N 78th St, Seattle, WA 98103, United States. This policy covers the Shuffl web application, the Shuffl assistant in a connected Slack workspace, and the API and agent interfaces a workspace enables.

A workspace is created and administered by an employer. For workspace content (employee records, questions, HR conversations and company knowledge), the employer decides what is collected and who may see it, and Shuffl acts on the employer’s instructions. For running and securing the service itself, and for billing where fees apply, Shuffl decides how the information is used.

What Shuffl processes

Shuffl processes the following categories. A workspace may not use every feature, in which case the matching category is empty.

For new Slack assistant turns, Shuffl stores message references and processing metadata instead of question and answer text. It reads the messages from Slack when needed, checks current access, and shows unavailable content when a message cannot be read. Web Chat shows current Slack edits and has no saved transcript fallback. This change does not erase earlier stored Slack conversation text or migration archives.

Product analytics help Shuffl see how the product is used. On its servers, Shuffl records product events, such as a question asked, a document uploaded, a Pulse answered or a setting changed, with the account id, the workspace id, where it happened (web, Slack, API) and a few fixed values such as a count or a yes or no. They never include what anyone wrote: no questions, answers, documents, requests, praise, Pulse answers or scores, names, email addresses or Slack ids.

In the browser, Shuffl loads PostHog, which records the pages visited and the buttons and links used, with the text on screen masked and query strings and fragments removed from every address. It does not record sessions. When a person is signed in, this activity is tied to their Shuffl account id and workspace id, never their name or email address. In the European Economic Area, the United Kingdom and Switzerland, browser analytics start only after the visitor allows them. Elsewhere they are on unless the visitor rejects them, and each browser is asked once.

A person can turn product analytics off for their account in account settings, and a company owner or administrator can turn them off for every workspace in the company in Company settings. Either way no browser analytics load for that person, and their server events count only towards anonymous workspace totals with no account id. The AI usage accounting named above records how much a workspace used and what it cost; it contains no questions, answers or documents.

When a page or API request fails on the server, Shuffl reports the kind of error, the route pattern and where in the code it happened to PostHog. That report contains no error message, address, request contents or information about who made the request.

In a connected Slack workspace, Shuffl counts how that workspace uses the Shuffl app: when its Home tab is opened, which of Shuffl’s buttons are used and which Shuffl forms are submitted. These counts go to PostHog under the workspace, with no Slack user, name, email address or message content, and they do not depend on a browser choice.

  • Account and sign-in information: the email address and credentials used to sign in, active sessions and devices, verification and password-reset tokens, and the sign-in method last used.
  • Employee records: the people record a workspace keeps for each employee, its employment and program history, and the explicit links between that record and a web or Slack identity.
  • Questions and answers: conversations with the assistant, the sources it cited, and the assistant’s record of what it could not answer.
  • HR requests: the message an employee approves for sending, the private drafts an HR responder writes before sending, and the reply that returns to the original conversation.
  • Company knowledge: documents a workspace uploads or imports, the guidance an authorized reviewer approves, every version of that text, the audience and review dates set for it, and the search embeddings derived from published text.
  • Operational records: audit history of who did what in a workspace, API and agent keys issued and the requests made with them, delivery records for email Shuffl sends, stored Slack event payloads used to process incoming activity, and content-free accounting of AI usage and cost. Depending on the event, a Slack payload can include message, profile or channel information.
  • Optional calendar scheduling: the Google account a person connects, its encrypted authorization credential, temporary primary-calendar free/busy intervals, and receipts for invitations the person confirms, including the people invited, time, event identifier and meeting link.
  • Support conversations: messages an account holder sends to Shuffl from in-app support, and the email delivery records for Shuffl’s replies.
  • Sales inquiries: the name, work email, company, team size and message a visitor sends from the contact sales form, which needs no account.
  • Startup program applications: the company, website, founders, funding stage and amount raised, team size, the applicant’s name, role and work email, their answers to the form, and the pitch deck they upload. The form needs no account.

Why Shuffl processes it

Shuffl processes the information above for these reasons:

Where data-protection law asks for a legal basis, the basis follows who is deciding. For workspace content the employer is the one deciding, and Shuffl processes it under its contract with that employer and on the employer’s instructions; the employer establishes its own basis with its people. For the purposes Shuffl decides (keeping accounts secure, operating and debugging the service, accounting for AI usage and cost, and answering support and sales inquiries and reviewing startup program applications), the basis is Shuffl’s legitimate interest in running a secure and reliable service, and its contract with the customer. Where a law obliges Shuffl to keep or produce something, that obligation is the basis.

  • To answer an employee’s question from knowledge their workspace has approved, and to show the sources behind the answer.
  • To carry a request to HR that the employee approved, and to return the reply to the conversation it came from.
  • To keep company knowledge reviewable: versions, audiences, effective and review dates, and who approved what.
  • To authenticate people, keep accounts secure, and enforce the access each person’s workspace gives them.
  • When a person opts in, to suggest call times and send an invitation with a Google Meet link from that person’s own calendar after their confirmation.
  • To operate, debug and keep the service reliable, and to account for AI usage and cost.
  • To answer support requests from the account holder who sent them.
  • To answer a sales inquiry from the person who sent it.
  • To review a startup program application and reply to the person who sent it.
  • To meet legal obligations that apply to Shuffl.

Who else sees it

Inside a workspace, what each person sees follows the access their workspace gives them. An employee’s conversation with the assistant is not shared with HR until the employee approves what to send. A private HR draft is not delivered until an HR responder sends it. Company knowledge is readable by the audience an authorized reviewer set for it.

Outside the workspace, Shuffl relies on the service providers below. Each processes information only to provide its service to Shuffl, under Shuffl’s instructions and its own agreement with Shuffl. Shuffl does not sell workspace information, and does not share it for advertising.

A private HR draft is private from the rest of the workspace; it is not invisible to everyone. A small number of authorized Shuffl personnel can reach workspace content where it is needed to operate the service, to investigate a fault or a security incident, or to meet a legal obligation. That access is limited to the people who need it and is recorded.

When this list changes, Shuffl updates this page and tells workspace administrators, on the notice described under Changes and contact.

Shuffl may disclose information when the law requires it, or to investigate a security incident or abuse of the service. Where Shuffl is legally permitted to tell the affected workspace, it will.

  • Hosting and application delivery, which processes every request to the service.
  • A managed PostgreSQL database, which holds the workspace records described above.
  • An AI gateway, which routes a question and the knowledge retrieved for it to a model provider and returns the answer, routes published knowledge and questions to an embedding provider so knowledge can be found by meaning, and routes messages and chat excerpts to a decision model to classify questions, handle corrections and find related chats.
  • Email delivery, for invitations, verification, notifications, Shuffl’s replies to support conversations and sales inquiries sent to Shuffl.
  • Email hosting for Shuffl’s own mailboxes, where sales inquiries arrive and are answered.
  • Slack, where a workspace has connected it, for the assistant, HR delivery and directory synchronisation.
  • Payment processing, where fees apply, which receives billing identifiers and never workspace content.
  • VercelApplication runtime: United States (Northern California). AI gateway: processing region is not restricted.

    Hosting and application delivery, which processes every request to the service, and the AI gateway that routes questions to a model provider, knowledge text to an embedding provider, and messages and chat excerpts to a decision model to classify questions, handle corrections and find related chats.

  • SupabaseUnited States (Northern California)

    The managed PostgreSQL database that holds each workspace’s records.

  • AnthropicAI inference region is not restricted by Shuffl.

    The model provider currently configured behind the gateway, which composes an answer from the question and the knowledge retrieved for it.

  • Microsoft AzureAI inference region is not restricted by Shuffl.

    Hosts the OpenAI text-embedding-3-small model reached through the Vercel AI Gateway with zero-data-retention routing. It creates search embeddings from published Knowledge text and questions so knowledge can be found by meaning as well as by wording.

  • xAIAI inference region is not restricted by Shuffl.

    The image model (Grok Imagine), reached through the Vercel AI Gateway, which draws pictures people ask for with “Create with Mello” from the supplied name, description and optional idea. Each request asks the gateway to select a provider with a no-retention agreement; that request does not establish the deletion of every copy held by Shuffl or its service providers.

  • TypeSafe AIAI inference region is not restricted by Shuffl.

    The decision model (Jev), reached through the Vercel AI Gateway, which classifies the latest message of a question, including whether it is sensitive or an attempt to manipulate the assistant. It also compares an earlier and a new Slack message to decide whether the new one changes direction, and receives search text with the titles and short opening-message excerpts of chats the person can access to find related chats. Each request asks the gateway to select a provider with a no-retention agreement.

  • ResendUnited States (Northern Virginia)

    Email delivery for invitations, verification, notifications, Shuffl’s replies to support conversations, and sales inquiries from the contact sales form to Shuffl’s sales mailbox.

  • Google WorkspaceUnited States and other Google data centers

    Email hosting for Shuffl’s own mailboxes, including the sales mailbox where contact sales inquiries arrive and are answered, and the mailboxes where Shuffl staff receive notice of new support conversations.

  • SlackUnited States

    Where a workspace has connected it: the assistant, HR delivery and directory synchronisation.

  • StripeUnited States

    Payment processing where fees apply. It receives billing identifiers and never workspace content.

  • PostHogUnited States

    Product analytics: content-free product events tied to an account and workspace id, browser analytics subject to the browser’s choice, workspace-level counts of how the Slack app is used, and content-free server error reports.

Optional Microsoft calendar and Zoom connections

Each person chooses whether to connect their own Microsoft 365 calendar or Zoom account in Your calendar settings. An administrator cannot connect these accounts for another person. Connections use the account matching the person’s work email and are encrypted and restricted to their workspace and employee identity.

Microsoft grants delegated access to the person’s profile and calendar. Calendar read/write permission is broader than Shuffl uses. Shuffl verifies the account’s identity, checks only that account’s aggregate availability, creates the invitation the person confirms, and checks only Shuffl booking records through an exact booking marker. Event contents returned alongside availability are discarded; Shuffl does not use or store their titles, descriptions, attendees or locations. Other people see suggested times and the resulting invitation, never calendar contents.

Zoom grants access to verify the person’s account and create a meeting for that person. It supplies video, while the connected Google or Microsoft calendar supplies availability and sends invitations. Shuffl creates a Zoom meeting only after confirmation and stores its meeting ID and participant join link. It does not retain host start links, enable recording, read recordings or transcripts, or track attendance. If a creation response is lost, Shuffl does not automatically create another Zoom meeting.

After confirmation, the calendar provider receives the selected time and invitees’ work email addresses. Zoom receives the meeting time when Zoom video is selected; the resulting join link is included in the calendar invitation. Availability is used only during the scheduling request. Calendar and meeting information is not sent to AI models, used for advertising, or used to train models. A booking is not evidence that people met.

Disconnecting Microsoft deletes Shuffl’s stored access immediately. Microsoft does not provide a narrow per-app token-revocation endpoint for this flow; remove its remaining consent through Microsoft My Apps. Disconnecting Zoom disables its use, requests revocation and deletes the credential after Zoom confirms. If revocation fails, Shuffl retains the encrypted credential only to retry and shows that disconnect is incomplete. Deleting the Shuffl sign-in or detaching its employee identity immediately erases both stored grants. Existing meetings and invitations remain with their providers; edits and cancellations happen there. Booking receipts remain with the workspace until its records are erased.

Optional Google Drive and Workspace directory connections

Google Drive for Knowledge is an optional connection an administrator authorizes separately from Google sign-in. Shuffl stores the connected account identifier and email address and an encrypted authorization credential. Google’s picker lets the administrator select files; Shuffl reads those files and their metadata, without listing the rest of the Drive or editing the originals. Imported text is saved as a Knowledge draft for an authorized reviewer to check before publication.

Selected-document content can be sent to the AI providers described in this policy to extract text and prepare Knowledge drafts. Published text can be processed for search embeddings and used to answer questions for people allowed to read it, as described under How the assistant uses company knowledge. The imported document text, versions and search indexes are workspace records governed by the retention section below.

Google Workspace directory sync is a separate optional authorization by a Google Workspace administrator. Shuffl uses read-only directory access to retrieve account identifiers, names, primary work email addresses, job titles, departments, manager relationships and suspended or archived account status. It stores an encrypted authorization credential and uses these facts to update workspace employee records and their account links. Imported facts are available to enabled People and assistant features under the workspace’s access rules. This connection does not read personal contacts or calendar contents or change the Google directory.

Disconnecting either connection deletes Shuffl’s stored credential and stops further reads. Disconnecting Drive withdraws the Knowledge sources imported through that connection; their stored drafts and versions are retained. Disconnecting directory sync ends management by that source but retains the imported employee records. Disconnect does not erase these workspace records or the Google originals, and does not revoke the remaining Google authorization; remove that authorization in Google Account settings. The workspace retention and deletion controls described below still apply.

Shuffl’s use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including applicable Limited Use requirements. Document and directory connections do not expand Google sign-in or authorize a personal calendar connection.

Optional Google Calendar scheduling

Calendar access is a separate choice each person makes in Your calendar settings. An administrator cannot connect a calendar on someone else’s behalf. Google asks permission to read availability and manage events on calendars the person owns. That event permission is broader than Shuffl uses: Shuffl checks only primary-calendar free/busy, creates the call the person confirms on their own primary calendar, and checks the status and links of that exact event.

Shuffl does not list calendar events or read their titles, descriptions or attendees, and does not read contacts. Free/busy intervals are used only during the scheduling request and are not stored. Other participants see suggested times, whether some availability is unknown, and the resulting booking; they do not see another person’s calendar contents. Booking or joining a call is not used as evidence that people met.

After confirmation, Google receives the selected time and invitees’ work email addresses to create and deliver the invitation and Google Meet link, or the join link from the person’s separately connected Zoom account. The invitation and conference remain in the Google accounts involved, under their Google settings. Calendar information is not sent to AI models, used for advertising, or used to train models.

Disconnect calendar disables Shuffl’s access, requests revocation from Google, and deletes the stored credential. If Google cannot be reached, Shuffl retains the encrypted credential only to retry revocation and displays that the disconnect is incomplete. Deleting the Shuffl sign-in or detaching its employee identity erases the stored credential immediately; any remaining Google authorization can also be removed in Google Account settings. Existing invitations remain, and edits or cancellations are made in Google Calendar. Booking receipts remain with the workspace until its records are erased.

This optional feature requires fresh, personal authorization; it does not expand an existing Google sign-in or document connection. The Google API Services User Data Policy and Limited Use statement above also applies to this calendar connection.

How the assistant uses company knowledge

When someone asks a question, Shuffl retrieves the company knowledge that person is allowed to read and sends it, with the question and the conversation so far, to an AI model provider to compose an answer. The answer shows the sources it used so the reader can check them.

To find knowledge by meaning as well as by wording, Shuffl sends the text of published knowledge, and each question, to an embedding provider, which returns a numeric representation used only for search. Those representations are kept in Shuffl’s database with the knowledge they came from, and the same access rules decide who can retrieve it.

To decide how to handle a question, Shuffl may send its latest message to a decision model, which returns what kind of question it is and whether it looks sensitive or like an attempt to manipulate the assistant. When someone sends a Slack message while an earlier one is still being answered, Shuffl may send both messages to that model to decide whether the new message changes direction.

To find related chats, Shuffl may send the search text and the titles and short opening-message excerpts of chats the person is allowed to see to the decision model. These decision-model calls do not include retrieved company knowledge or assistant answers. Their operational logs contain decision outcomes, counts and timing rather than the input text.

Models also prepare drafts, extract text from supplied documents and create short conversation titles. Enabled recognition, community and profile features use relevant message text, channel names or profile facts for their task. Requested images use the supplied name, description and optional idea.

When the assistant suggests new guidance worth keeping, that suggestion is a proposal. It becomes company knowledge only after an authorized person approves its exact wording and who may read it.

An answer can be wrong or incomplete, and a general company document cannot establish an individual’s balance, eligibility or entitlement. Shuffl says so in the product and routes those questions to a person.

Shuffl does not use customer content to train models, and does not use one customer’s content to improve the service for another.

For language, decision, image and search-embedding requests, Shuffl asks the AI gateway to select a provider with a no-retention agreement. If no eligible provider is available, the model request fails instead of using an unrestricted provider. Search can still return authorized keyword matches. Earlier embedding requests did not include this restriction; enabling it does not erase copies from earlier requests. It also does not erase Shuffl’s own stored conversations, HR records, knowledge, search embeddings or operational records. Their retention is described below.

How long it is kept

How long each category is kept:

HR proposals, case messages and Knowledge drafts, approved versions and search indexes have separate storage and retention. They can include content obtained or derived from Slack, including content an employee or reviewer approved. Removing stored text from new Slack assistant turns does not remove these records or establish that all Slack data is stored only as references.

Deleting a personal account removes the sign-in, sessions, workspace memberships and the person’s own support conversations with Shuffl, and revokes the keys they issued. It does not delete the employer’s records: the people record, company knowledge, HR history and audit history stay with the workspace, unlinked from the sign-in. An account that a company directory provisions is removed by that directory.

A company owner or administrator can delete a workspace from workspace settings. It stops sending and answering at once. Everything it holds is kept for 30 days, during which a company owner or administrator can restore it and a workspace administrator can still export it. When the 30 days end, Shuffl erases the workspace records automatically, along with the workspace itself and its team memberships. The people keep their own sign-in accounts. The company account, company memberships, shared sign-in and directory configuration, and company billing remain; deleting one workspace does not delete the company or cancel its billing.

A company owner can also delete the company and all its workspaces from Company settings. They stop immediately and remain recoverable for 30 days. An owner can restore them during that period; workspaces return paused. When the period ends, Shuffl erases the company automatically, with its memberships, configuration and workspace content. Personal sign-in accounts and other companies remain. Paid subscriptions must finish cancellation before company deletion.

A confirmed Slack workspace uninstall disables that connection, clears its stored access credentials and queues deletion of linked Slack assistant conversations and event payloads. Reconnecting does not cancel that deletion. This scoped cleanup does not automatically erase all associated HR records, Knowledge, directory fields, recognition, historical archives or provider copies; those require separate handling. It does not delete the employer’s company account or unrelated web records. Slack-associated deletion is separate from the workspace’s 30-day recovery period. Contact privacy@shuffl.ai for a deletion request or help directing it; Shuffl assists the employer with its workspace records.

Backups exist so a fault cannot lose a workspace’s work. They are kept for no more than 30 days, and an erasure is worked through to them within that period, after which no copy of the erased records remains in a backup. A provider that holds a copy to deliver its own service, such as a database backup or an email delivery record, is held to the same ceiling.

  • Company knowledge, including every earlier version, is kept for as long as the workspace keeps it. Versions are retained deliberately, so an answer given in the past can still be explained.
  • Assistant conversations expire 30 days after creation; an expired conversation and its turns are removed. Web conversations continue to store their questions and answers. New Slack assistant turns retain references and processing metadata during that period, with message content read from Slack.
  • HR requests and their messages are kept for as long as the workspace keeps them, because they are the employer’s record of how a case was handled.
  • Audit history is kept for the life of the workspace. It is what makes an access question answerable later.
  • Stored Slack event payloads have no separate age-based deletion schedule. Confirmed uninstall queues removal of the payloads identified with that connection; assistant conversation expiry alone does not remove them.
  • AI usage accounting is kept for 90 days. It is content-free.
  • Support conversations with Shuffl are kept while the account exists, and go when the account is deleted.
  • Sales inquiries are not stored in the Shuffl service. Each one is an email in Shuffl’s sales mailbox, kept while Shuffl is talking with the sender about becoming a customer, and deleted when the sender asks.
  • Startup program applications, pitch deck included, are stored in the Shuffl database and deleted 12 months after Shuffl decides on them. A notice of each one also goes to Shuffl’s sales mailbox. An upload with no application is deleted after a day.

Choices and controls

An employee chooses what a request to HR contains before it is sent; the assistant prepares it, and nothing is shared until the employee approves it.

Privacy preferences let a browser record a choice about analytics. The choice is kept for that browser only and can be changed or cleared at any time. Allowing starts analytics in that browser; rejecting stops them and removes the identifiers they stored. Clearing the choice returns to the default for where the visitor is.

Because most information in a workspace belongs to the employer, who answers a request depends on what is being asked:

Shuffl will help an employer answer a request about its own workspace.

Where Shuffl itself decides how information is used (accounts and sign-in, support conversations, sales inquiries and startup program applications), a person may, under the law that applies to them, ask Shuffl for a copy of their information in a portable form, correct it, erase it, restrict or object to how it is used, and withdraw a consent they gave. Send the request to privacy@shuffl.ai. Shuffl answers within one month, and says why if it cannot do what was asked.

Shuffl makes no decision about a person by automated means that has a legal or similarly significant effect on them. The assistant answers questions and sorts them for routing; decisions about a person’s employment stay with their employer.

A person who thinks their information has been mishandled can complain to the data protection authority where they live or work, and can contact Shuffl first at the address above.

  • See or correct an employee record, or ask why it exists: the employer decides, because the record is theirs.
  • Delete a personal Shuffl account: the person does it themselves, in account settings.
  • Turn product analytics off: the person does it for their account in account settings or for one browser in privacy preferences, and a company owner or administrator can do it for every workspace in the company in Company settings.
  • Export a whole workspace: an administrator does it in workspace settings.
  • Delete a whole workspace: a company owner or administrator does it in workspace settings, and can restore it for 30 days.

Where information is processed

Shuffl’s application runtime and database run in Northern California, and email delivery is configured in Northern Virginia. The AI gateway’s processing region is not restricted, and Shuffl does not restrict AI inference to a particular region. The provider table under “Who else sees it” distinguishes these routes; the application’s location does not establish where AI requests are processed.

Using Shuffl can transfer information to the United States and to other locations used by the AI gateway and model providers. Where the law of the country a workspace or its people are in requires a transfer mechanism, Shuffl relies on the European Commission’s Standard Contractual Clauses, and on the UK Addendum to them for the United Kingdom, and requires the same of the providers listed above.

Changes and contact

This policy carries a version and an effective date, shown at the top of the page. When it changes materially, Shuffl updates both and tells workspace administrators at least 30 days before the change takes effect, unless a change has to be immediate to keep the service safe or lawful.

Questions about this policy go to privacy@shuffl.ai. Questions about information held in a particular workspace go to that employer.