Last updated: 2026-05-24
WeekHaven is the data controller for personal data collected through this service. We are incorporated in the United States and can be reached at support@weekhaven.com .
We collect the following categories of personal data:
When you connect your Slack account to WeekHaven, we request the following OAuth user-token scopes on your behalf:
channels:read — enumerate the public channels you are a member ofchannels:history — read message history from those public channelsim:read — enumerate your direct message conversationsim:history — read message history from direct message conversations you explicitly includeusers:read — resolve Slack user IDs to display names so that message metadata is human-readableWe request a user token (xoxp-*) via user_scope, not a bot token. This means the token operates with your personal permissions — it can only access channels and DMs that you yourself can access. We do not request any bot scopes.
During a weekly review generation, WeekHaven fetches messages from your joined public channels (all, unless you narrow the selection in Settings) and from direct message conversations that you explicitly include. Messages are fetched over a bounded recency window (the period covered by your current review).
For each message we read, we extract only a lightweight metadata recordin memory: the channel or DM name, the sender's display name, the message timestamp, and a preview of the message text capped at 200 characters. We never read the full message body beyond that 200-character cap. We skip bot messages, system events (channel joins/leaves, topic changes, etc.), and empty messages.
These previews are processed in memory only and passed directly to the AI inference provider that generates your weekly review. They are not written to any WeekHaven database table and are discarded as soon as the review is generated. Only the AI-generated review summary is persisted (see Retention, below).
Your Slack user token is stored encrypted at rest in our database (connected_accounts table, via Supabase). The encryption key is held separately from the data store. Slack user tokens do not expire by default; they remain active until you revoke access.
Raw Slack message previews are not retained. They live only in memory during a single review generation and are discarded once the review is produced. The weekly review summary that we generate from those previews is retained until you delete your WeekHaven account. Once you disconnect your Slack account, no further data is fetched and your stored Slack token is removed.
You can disconnect your Slack account at any time from Settings → Connections inside WeekHaven. You can also remove WeekHaven from your Slack workspace by navigating to Slack → Settings & administration → Manage apps and revoking the app. Either action immediately invalidates the stored token and stops any further data collection.
We share data with the following categories of sub-processors:
All sub-processors are contractually bound to process data only as instructed and to maintain appropriate security measures.
Depending on your jurisdiction (including under GDPR and CCPA), you have the right to:
To exercise any of these rights, email us at support@weekhaven.com . We will respond within 30 days.
For privacy questions or data requests, contact: support@weekhaven.com .