Privacy Policy for SmartAdmin / SugarAndSalt

Last updated: July 18, 2026

SugarAndSalt LLC ("SugarAndSalt," "we," "us") provides SmartAdmin / SugarAndSalt, an AI-assisted Slack application that connects an authorized Slack workspace to Salesforce. This policy explains how the application collects, uses, stores, shares, and deletes data.

1. Data we process

We may process:

  • Slack user, workspace, channel, message, and thread identifiers.
  • Slack profile name and email address when needed for account mapping, tenant administration, or support requested by the user.
  • Messages, prompts, files, and thread context sent directly to the app. When needed to answer a request, the app may access messages already present in the same Slack thread.
  • Salesforce OAuth tokens, connected-organization information, metadata, and record data required to perform the user's request.
  • App preferences, selected Salesforce environment, user-provided or interaction-derived dictionaries and context, consent records, license, billing, and usage metadata.
  • Limited security, operational, performance, and error logs.

We do not use Slack content to train a foundation model.

2. How we use data

We use data to:

  • Authenticate Slack and Salesforce connections.
  • Answer user requests and perform supported Salesforce administration tasks.
  • Maintain context within an authorized conversation.
  • Provide account, license, billing, support, security, and abuse-prevention functions.
  • Debug and improve the behavior and reliability of this product as described under "Retention."
  • Send service or product notices only where the user has provided the required consent.

We do not sell Slack message or file content.

3. AI providers and other service providers

To generate an answer, relevant request content may be sent to a third-party AI provider. Providers we may use include OpenAI (ChatGPT), Anthropic (Claude), Google Gemini, and xAI (Grok). The provider used for a given request may change based on product needs, operational settings, or user selection. Google Gemini may also be used for background preference-dictionary consolidation and is not a Vertex AI region-pinned deployment.

Under our paid API configurations, we do not opt in to provider training on customer prompts. Provider-side retention and logging follow each provider's applicable API terms (for example, some providers retain API inputs and outputs for a limited period for abuse monitoring unless a zero-retention option is enabled).

We also use Google Cloud Platform (including Cloud Run, Firestore, Pub/Sub, BigQuery, Cloud DLP, Secret Manager, and security services), Salesforce, and Stripe. Request text may be inspected by Cloud DLP for masking before LLM inference. Slack event payloads may transit Google Cloud Pub/Sub. Each provider processes data under its applicable agreement and privacy terms.

4. Retention

  • Workspace configuration, authorization, preference, and account metadata is retained while the integration is active.
  • Conversation transcripts are not retained in SugarAndSalt application databases. Credit-usage analytics (credits consumed, feature category, Slack thread id, timestamps) are retained without chat body.
  • Short redacted summaries of failed or unsatisfactory interactions may be retained as Salesforce Cases ([ProductSignal] / [System Error]) for product improvement. Preference dictionaries derived from prior interactions may remain until uninstall or a verified deletion request.
  • Temporary attachments and generated working files are used only to process the request and are not intentionally archived as a product feature, though short-lived local or queue copies may exist until cleaned up.
  • Security, consent, billing, support-case, and operational records are retained only as needed for service operation, legal obligations, dispute resolution, and fraud prevention.

When Slack sends an app_uninstalled event, we best-effort delete the Slack installation token, Salesforce connection information and OAuth tokens, license cache, installed-skill settings, and workspace-scoped dictionaries. Uninstalling alone does not immediately delete credit-usage analytics, product-signal or support Cases, AI usage counters, channel environment pins, AI-provider preferences, Master Salesforce tenant/user/consent/support records, Stripe billing records, or temporary working files.

5. Access, transfer, correction, and deletion

A Slack user or workspace administrator may request access, transfer, correction, or deletion by emailing contact@sas-jp.com. We verify the requester's identity and, for a workspace-wide request, administrative authority. Eligible data is deleted within 30 days after verification, except where retention is required for legal, security, billing, dispute-resolution, or fraud-prevention purposes. We will explain any data that must be retained.

Slack also stores messages and files under the workspace's Slack agreement and retention settings. Requests concerning copies held by Slack must be handled through the workspace administrator or Slack.

6. Security and processing location

Our application workloads run primarily in Google Cloud us-central1 in the United States. External providers may process data in other locations permitted by their agreements. We restrict access to authorized identities, separate secrets from application source, encrypt Salesforce authorization tokens at the application layer, rely on Google Cloud encryption at rest, and use TLS 1.2 or newer in transit.

No system is completely secure. Users should avoid sending data that is not needed for their request and should review AI-generated results before applying Salesforce changes.

7. Contact

SugarAndSalt LLC

Email: contact@sas-jp.com

Address: 〒152-0035 東京都目黒区自由が丘1-8-19 メルサⅡ 4F

Contact Information

For inquiries regarding this policy, please contact us at:

SugarAndSalt LLC
Email: contact@sas-jp.com