Privacy Policy

Last updated: July 14, 2026

This policy explains what data Jukebot collects when a Slack workspace installs and uses it, why we collect it, and the choices and rights you have over it.

Jukebot ("we", "us", "our") is operated from the United Kingdom. For the purposes of UK GDPR and, where applicable, EU GDPR, the operator of Jukebot is the Data Controller for the data described below.

Data We Collect

From Slack

When Jukebot is installed on a workspace, we receive and store:

  • The workspace's Slack team ID and name;
  • The Slack user ID and display name of whoever installs Jukebot, and of any workspace member who adds a track or reacts to one;
  • The ID of the channel linked to Jukebot's shared playlist;
  • A bot access token that lets Jukebot post messages and read events (like reactions) in that channel.

Workspace members who haven't added a track or reacted to one aren't in our database at all — searching and browsing within Slack doesn't require any data collection on our end.

From Spotify

Only the workspace's installer connects a Spotify account, to manage the shared playlist on the whole team's behalf. From that one account, we receive and store their Spotify user ID, display name, email address, and OAuth access/refresh tokens. We don't request or store Spotify playback history, saved libraries, or anything beyond what's needed to search for tracks and manage the shared playlist.

Playlist activity

As the shared playlist is used, we store which tracks are added (track name, artist, Spotify track ID, album artwork URL, who added it, and when) and which emoji reactions members leave on them. This powers features like /jukebot top and the team's activity history.

How We Use It

  • To operate the core service — searching Spotify, adding tracks to the shared playlist, and posting confirmations back to your channel;
  • To power engagement features built on reaction data, such as the /jukebot top leaderboard and Jukebot Rewind;
  • To recover gracefully from Slack-side changes, such as the linked channel being archived or Jukebot being removed from it;
  • To send operational messages via Slack DM — onboarding steps, reconnect prompts if Spotify access is lost, and similar. We don't send you marketing email, and won't email you at all unless you contact us first;
  • To understand aggregate usage across workspaces (for example, how many workspaces are active in a given week) so we can improve the product. This is done at an aggregate level internally and isn't shared outside the company.

We do not use Slack or Spotify data to train machine learning or AI models.

Legal Basis for Processing

Under UK/EU GDPR, our basis for processing the data described above is performance of a contract — installing Jukebot and using its features is how you request the service, and this data is what's needed to provide it. Operational messages (onboarding, reconnect prompts, and similar) are part of that same contractual relationship, not separate consent-based marketing.

Who We Share It With

  • Spotify, to search their catalog and manage the shared playlist, via the installer's connected account;
  • Slack, to post messages and receive events, via Jukebot's bot connection to your workspace;
  • Fathom Analytics, to understand website usage — see "Cookies" below for what this does and doesn't involve;
  • Our infrastructure and hosting providers, who store and process data on our behalf and under our instructions, and aren't permitted to use it for their own purposes.

We don't sell personal information, and we don't share it with anyone else for their own marketing or advertising purposes.

We may also disclose data where required by law, to respond to a valid request from a court or public authority, or to protect our rights, users, or the public from harm. If Jukebot's ownership changes — for example, if it's sold or merged into another business — your data may transfer as part of that deal; it would remain subject to a privacy policy at least as protective as this one.

Retention and Deletion

If a workspace uninstalls Jukebot from Slack, we delete everything we hold about that workspace — the Spotify connection, and the playlist, track, and reaction history built up while it was installed — as part of handling the uninstall event. We don't keep it around after that point.

Uninstalling Jukebot removes our access to your Spotify account, but doesn't itself revoke the authorization on Spotify's side. If you'd like to fully remove Jukebot's access from your Spotify account too, you can do so from Spotify's own connected apps settings.

While a workspace is still installed, you can ask us to delete your data at any time — see "Your rights" below.

Your Rights

Wherever you're based, you can contact us at help@getjukebot.com to:

  • Ask what data we hold about you or your workspace;
  • Ask us to correct inaccurate data;
  • Ask us to delete your data;
  • Object to, or ask us to restrict, how we're using your data;
  • Request a copy of your data in a portable format.

If you're in the UK or EU, you also have the right to complain to your local data protection authority — the ICO in the UK — if you're unhappy with how we've handled your data.

If you're a California resident, you have equivalent rights under the CCPA to know what personal information we collect, request its deletion, and opt out of its sale. We do not sell personal information as defined by the CCPA.

Security

We take reasonable technical and organizational measures to protect the data described above, including encrypting Spotify and Slack tokens at rest and restricting access to production data. No method of transmission or storage is completely secure, and we can't guarantee absolute security.

Cookies

The only cookie the getjukebot.com website sets is a strictly necessary session cookie, used to keep the Spotify/Slack sign-in flow working and to protect against cross-site request forgery.

We use Fathom Analytics to understand how the website is used. Fathom is privacy-focused and doesn't use cookies or store any persistent identifier about you — it can't track you across visits or across other websites, so there's nothing to ask your consent for.

International Transfers

Our infrastructure providers may process and store data outside the country where your workspace is based, including outside the UK or EEA. Where that happens, we take reasonable steps to ensure it's protected to a standard consistent with this policy.

Children's Privacy

Jukebot is a workplace tool used through an organization's Slack workspace and isn't directed at children. We don't knowingly collect personal data from anyone under 16.

Changes to This Policy

We may update this policy from time to time. If we make a material change, we'll update the "Last updated" date above and, where appropriate, let you know via Slack or email.

Contact Us

Questions about this policy, or want to exercise any of the rights above? Get in touch: