Skip to content

Software companies

Can you still export Slack data for AI after the 2025 API terms change?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Slack data can still be used for AI work, but usually not by pulling it through Slack's API. Slack's 2025 API terms bar outside apps from training large language models on API data, and law-firm commentary reads them as also barring bulk export and persistent copies. A workspace owner's native export falls under the customer agreement instead.

Key takeaways

  • Slack's 2025 API terms restrict what apps do with API-accessed data, including training large language models.
  • A workspace owner's native export is governed by the Slack customer agreement, not by the developer terms.
  • Query-in-place access, such as a real-time search API, can serve an internal assistant but does not create a licensable dataset.
  • An outside AI developer should receive a prepared, scoped delivery, never an app or token on your workspace.
  • Every AI tool already connected to Slack deserves an audit against the current terms before any licensing plan.

What does the 2025 revision mean for LLM training?#

The 2025 revision of Slack's API terms means that data an app reads through Slack's APIs should stay out of large language model training. Slack's API Terms of Service say a provider of an app offered for use outside its own organization may not use API Data to train a large language model, and may not bulk export message and file data unless an additional agreement expressly allows it.

According to a Hunton Andrews Kurth client alert, the revised terms took effect on May 29, 2025 and prohibit bulk exporting data accessible through Slack's APIs, creating persistent copies, archives, indexes or long-term data stores, and using such data in large language models. Slack's developer changelog says the clarifications applied immediately to new apps and from June 30, 2025 to existing apps. The direction was set earlier: in December 2024 Slack updated its App Developer Policy to make explicit that using data to train an LLM is prohibited.

The restriction is written for developers, meaning the vendors and contractors whose apps call the API. Because the training ban is framed around apps offered outside the provider's own organization, a tool your own engineers built for your own workspace may be treated differently, so have counsel read the live text rather than assuming either way. On its face the change does not rewrite the customer agreement under which a workspace owner exports its own history, and that split is the key to every AI question a CTO now faces about Slack.

Terms get revised and summaries drift. Read the current Slack API Terms of Service, your customer agreement and the terms of each connected app, and treat secondary coverage, this article included, as a guide to what to look for rather than the text itself.

Which AI goals still work, and through which route?#

Most AI goals involving Slack still work, but each now has one sensible route and one route to avoid. The useful question is not whether Slack data can be used for AI, but which AI use and which access path.

Trade-press coverage of the change, including Cloud Wars, reported that companies would instead have to use Slack's new Real-Time Search API. Under Slack's API terms, providers using that API or the Data Access API may not keep persistent copies, archives or indexes of other organizations' API Data. That path answers questions inside the workspace without building a copy, which suits an internal assistant. It does not produce a dataset a company can scope, prepare and license.

Which AI goals still work, and through which route?
AI goalRoute that fitsRoute to avoidRules that govern the route
Internal assistant that answers questions from SlackQuery-in-place access approved for the workspace, such as a real-time search APICopying channel history into a separate vector store through the APISlack API terms and app approval
Fine-tuning a company model on internal discussionsOwner-level export reviewed by counselAn API connector that pulls history into a training pipelineCustomer agreement, employee notices and privacy laws that may apply
Licensing Slack-derived records to an outside developerOwner-level export, scoped and prepared, delivered under a licenseGiving the developer an app or token on your workspaceCustomer agreement, license terms, employee and customer obligations
Backup and legal holdNative export, or the Discovery API on eligible Enterprise plansTreating a backup vendor's copy as an AI datasetCustomer agreement and the vendor contract

Audit the AI tools already connected to Slack#

An audit of AI tools already connected to Slack is the first practical step, because many companies installed assistants, summarizers and search tools before the terms changed. Each tool either reads in place, copies history, or feeds a model, and only the first fits comfortably with the revised terms.

The audit often turns up a forgotten connector that has been copying channels for a long time. Finding it before a licensing conversation is far better than having a licensee find it during diligence.

  • Pull the list of installed apps and custom integrations from the workspace admin settings.
  • For each one, record whether it reads messages through the API, stores copies, or sends content to a model provider.
  • Ask each vendor, in writing, to explain its access model under the revised API terms.
  • Find internal scripts and retrieval pipelines your own engineers built against the API.
  • Pause any pipeline that fine-tunes on or embeds Slack history until counsel has reviewed it.
  • Record the outcome, so a later licensee can see that no API route was used to build the dataset.

Does the LLM restriction stop you licensing your own export?#

The LLM restriction in Slack's API terms does not by itself decide whether a company may license its own owner-level export, because that export sits under the customer agreement. What decides it are the rights inside the archive: who wrote the messages, what they were told, and whose confidential information appears.

Those rights are assessed deal by deal with counsel. In practice the answer is a narrow scope: engineering, incident and support escalation threads that link to Jira issues or tickets, with direct messages, shared channels and sensitive channels left out. Employee notices and privacy laws that may apply shape how far even that scope can go.

One rule follows directly from the API terms: a licensee should never be given an app, bot or token on your workspace. Deliver a prepared export instead, so the licensee never touches the API and the developer terms never come into play for it.

Which Slack-derived records do AI developers ask about?#

AI developers ask about Slack-derived records that show work moving from problem to outcome, usually after those threads are joined to the systems of record they mention. The raw channel matters less than the linked package built from it.

Joining is mostly mechanical. Threads that cite Jira keys, pull request numbers or ticket IDs can be matched to those records, and threads that cite nothing usually add little once the linked ones are in place.

Which Slack-derived records do AI developers ask about?
Slack-derived recordWhat makes it usefulPreparation it needs
Incident threads joined to postmortemsReal-time diagnosis followed by a written cause and fixRemove customer names, hostnames and credentials
Design debates linked to Jira epicsShows trade-offs and the decision that followedRemove roadmap items not yet released
Review side discussions linked to pull requestsExplains why a change took the shape it didRemove personal remarks and author identities where required
Support escalations linked to ticketsConnects a customer symptom to the engineering answerStrip customer content and account details
Release coordination threadsCaptures sequencing, rollback calls and sign-offsRemove partner and customer commitments

Illustrative: a construction software company redirects its Slack AI plans#

Illustrative: a fictional construction project management software company has a head of AI who connected a third-party tool to Slack so support macros could be drafted from past escalations. The tool copies history through the API and fine-tunes a small model on it.

After reading the revised API terms, the CTO pauses the pipeline and splits the goals. The internal assistant moves to query-in-place access that reads Slack without keeping a copy. Separately, the workspace owner plans a native export of incident and escalation channels for a possible license, with counsel reviewing the customer agreement and employee notices first.

The exported threads are matched to Jira issues and Zendesk tickets by the keys mentioned in them. Direct messages and the shared channels with general contractors never leave Slack. The company starts a fit check describing the linked package, without sending a file.

Where SourceX fits for Slack-derived records#

SourceX scopes Slack material from exports the company itself controls. The fit check collects metadata, such as channel families, years of history and the systems threads link to, and nothing is shared during that initial assessment.

In the SourceX five-step transaction, Rights reviews the Slack agreement, employee notices and customer obligations, Preparation removes personal and confidential details, and the supplier approves every step. The SourceX Evidence Packet records how the export was produced and which channels were approved, so a licensee can see how the dataset was built.

Frequently asked questions

Does the LLM restriction stop us training our own model on our own export?

The API terms speak to data accessed through the API, so an owner-level export generally falls under your customer agreement instead. That does not settle the question: employee notices, confidentiality duties and privacy laws that may apply still govern internal training. Have counsel read the agreement's data use terms and your notices before any fine-tuning.

Is a real-time search API a way to build a training dataset?

No. Query-in-place access exists so an approved app can answer questions from Slack content without keeping a copy. Using it to assemble a stored corpus would defeat its purpose and likely run into the same API limits. Datasets for licensing come from owner-level exports.

Can an AI developer we license to connect to our workspace directly?

Avoid it. A licensee's app on your workspace would be bound by Slack's API terms, which bar apps offered outside their own organization from training LLMs on API data. A prepared, scoped export delivered under the license keeps the licensee away from the API and gives you control over exactly what leaves.

Do our internal AI assistants need to change?

Possibly. Assistants that read Slack in place may be fine, while ones that copy history into their own store or send it to a model provider for training deserve review against the current terms. Ask each vendor in writing, and check pipelines your own engineers built.

What if retention settings already deleted older messages?

Then that history is gone, and it should not be rebuilt from screenshots or personal copies. Work with what the retention settings preserved, and record the policy in the scope so any licensee understands the coverage window and why it ends where it does.

Sources

  • Slack's API Terms of Service state that a provider of an application offered for use outside its own organization may not use API Data to train a large language model, and may not bulk export Slack message and file data except where an additional agreement expressly allows it. Source
  • Third-party providers using the Data Access API and Real-Time Search API may not keep persistent copies, archives, indexes, or long-term data stores of other organizations' API Data. Source
  • According to Hunton Andrews Kurth, Salesforce modified the Slack API Terms of Service, effective May 29, 2025, to prohibit bulk exporting, persistent copies, archives, indexes or long-term data stores, and usage of such data in large language models. Source
  • Slack's developer changelog announced API Terms of Service clarifications that took effect immediately for new apps and on June 30, 2025 for existing apps. Source
  • In December 2024 Slack updated its App Developer Policy, making explicit that the use of data to train an LLM is prohibited. Source
  • Trade-press coverage reported that companies would have to use Slack's new Real-Time Search API instead of bulk export via the API. Source
  • Slack's Discovery APIs allow eligible Slack customers to use third-party applications to export, retain, or archive messages and files; the Discovery API is listed under Slack's top Enterprise tier. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify