Skip to content

Software companies

Slack channels vs private channels vs DMs: what can be licensed?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Public channels are usually the most practical Slack history to license, once personal and confidential details are removed. Private channels are reviewed one by one, and direct messages are typically excluded because employees treat them as private. Workspace settings, employee notices, customer contracts and applicable law decide the final scope, assessed deal by deal with counsel.

Key takeaways

  • Public channels, private channels and direct messages carry different expectations and get different default treatment.
  • Public work channels are the usual starting point; direct messages are usually left out.
  • Private channels for HR, legal, leadership and deals are excluded; private project channels may be reviewed one by one.
  • Shared channels with customers or partners involve another company's people and often its confidential information.
  • What an owner can export depends on the Slack plan and settings, so confirm access before scoping.

Public channels, private channels and DMs at a glance#

Public channels, private channels and direct messages differ in who could see them when they were written, and that difference drives the typical approach to licensing. Treat the table as a starting position for counsel, not a conclusion.

Public channels, private channels and DMs at a glance
Slack spaceWhat it usually holdsTypical approachMain questions for counsel
Public channelsEngineering, incident, release, support escalation and product discussion visible to the whole workspaceCandidate for licensing after personal and confidential details are removed; social channels excludedDo employee notices and policies cover this use? Do channels hold customer confidential information?
Private channelsLeadership, HR, legal, deal rooms, sensitive customer matters, and project work kept private by habitExcluded by default; individual project channels may be reviewed and includedIs any content privileged, about personnel or covered by an NDA? Did members expect limited access?
Direct messages and group DMsOne-to-one and small-group conversations, often mixing work and personal topicsTypically excludedIs there any reason to depart from exclusion, and could consent realistically be obtained?

Why public channels are the usual starting point#

Public channels are the usual starting point because they were written for a workspace-wide audience and tend to hold the work itself: engineers debugging an outage, product managers debating a release, support escalating a customer problem. That is the content AI developers value, because it shows how a software company reasons through real decisions.

Public does not mean clean. Work channels still contain names, email addresses, customer account details, links to internal documents and the occasional personal remark. Preparation removes or replaces those details, and social channels for hobbies, celebrations or announcements are usually dropped, since they add privacy exposure without much value.

Scope by channel purpose rather than channel count. A short list of well-used engineering and support channels with long histories makes a stronger package than every public channel in the workspace.

Private channels: reviewed one by one#

Private channels are reviewed one by one because the label covers very different content, from board discussions to a project team that never made its channel public. Start from metadata, such as channel name, stated purpose, membership and date range, before anyone reads messages.

Privilege deserves particular care. Sharing attorney-client communications with a third party can put privilege at risk, so any channel where counsel gives advice is a strong candidate for exclusion regardless of its other content.

  • Typically excluded: HR, people operations, compensation, performance and investigations.
  • Typically excluded: legal channels and any channel where counsel gives advice.
  • Typically excluded: board, leadership, fundraising, M&A and deal rooms.
  • Usually excluded: channels about named customer escalations that hold confidential customer information.
  • Possible candidates: project, engineering and on-call channels made private by habit, after review and notice to members.

Direct messages: why they are usually excluded#

Direct messages are usually excluded because employees treat them as private conversation, even on company systems. They mix work with health, family, complaints about colleagues and job searches, and separating the two reliably at scale is not realistic.

A workplace policy may say the company can access messages on its systems. That access is usually framed around security, investigations and legal holds, which is different from licensing content to an outside party. Consent from each employee, including people who have left, is rarely practical, so for most companies the risk of including direct messages outweighs their value.

Messages between a person and an app, such as monitoring alerts or deploy notifications, raise fewer personal concerns. They are usually easier to collect from the system that sent them than from Slack, though, so they rarely justify reaching into the direct message space.

Shared channels and guest accounts#

Shared channels and guest accounts bring other organizations into the record, which usually takes that content out of scope. Channels shared with customers, partners or vendors contain their employees' messages and often their confidential information, governed by your contracts and NDAs with them.

Guests and single-channel members raise the same issue inside your own workspace. Where a public channel includes contractor or customer guests, their messages are usually removed even if the channel itself stays in scope.

The legal review generally looks at a set of documents and settings rather than a single rule, because no one law answers what Slack history can be licensed. Which laws may apply depends on where employees live, what the content includes and which contracts are in place.

Record the outcome at the channel level, with the reason for each inclusion or exclusion. That record answers later questions from employees, customers or an acquirer's diligence team, and it lets the scope be checked again if a policy or law changes during the license term.

  • The Slack plan and export settings: what owners can export, and whether private channels and DMs are reachable at all. Check your plan and Slack's current documentation.
  • The terms that govern extraction: Slack's export tools, API and app terms can limit how data pulled through them is stored or used, so check the current terms before choosing a method.
  • Retention settings and any legal holds, since held data must be preserved unchanged.
  • Employee handbook, acceptable-use and electronic communications policies, and privacy notices given to employees.
  • Privacy laws that may apply to employee information, such as the California Consumer Privacy Act for California staff where the business is covered, and the GDPR for staff in the EU.
  • Works council, union or consultation obligations where employees are represented.
  • Customer contracts, NDAs and data processing agreements covering information discussed in Slack.
  • Privilege and confidentiality obligations tied to legal, board and deal discussions.

Illustrative: a B2B analytics software company scopes its Slack history#

Illustrative: a fictional company sells production analytics software to manufacturers and has used Slack since its founding. Its plan and settings allow workspace owners to export both public and private channel history.

The general counsel and the CTO start from a channel list with names, purposes and date ranges. Public engineering, incident, release and support escalation channels go into scope, while social and announcement channels are dropped. Private channels for leadership, people operations, legal and finance are excluded without reading them. A small group of private project channels is reviewed, and those without personnel or customer-confidential content are included after members are told. Direct messages and every channel shared with customers stay out.

Before any export, the company updates its employee notice to describe the use. The final scope, a channel-level list with the reason for each decision, becomes part of the release record.

How SourceX approaches workplace chat#

SourceX treats workplace chat as one of the more sensitive record types and scopes it channel by channel within the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. The initial assessment works from a description of the workspace, such as the plan, channel types and date ranges, and never from message content.

Preparation removes names, contact details and customer identifiers. The SourceX Evidence Packet records the channel scope, the privacy record and the release authorization, and the company approves each step. The content is licensed, not sold.

Frequently asked questions

Does the company own what employees write in Slack?

Work messages on company systems are generally company records, but ownership is not the only question. Employee privacy expectations, notices, workplace policies and applicable law also shape what can be licensed, and they can point in a different direction. Treat ownership as the starting point of the review, not the answer.

Should we tell employees before licensing Slack history?

A clear notice is usually advisable, and in some situations it may be required. The notice describes what is in scope, what is removed and why. Counsel can advise whether notice alone is enough for your workforce and locations, or whether other steps apply.

Can former employees' messages be included?

Messages from former employees in public work channels are usually treated like current employees' messages: in scope if the channel is, with names and contact details replaced. Former employees cannot easily be asked for consent, which is one more reason direct messages stay out.

What about files and links shared in Slack?

Files are reviewed separately from messages. They may be customer documents, third-party reports or personal files, and links usually point to documents stored elsewhere. Most scopes cover message text only, with files excluded or added through their own review.

Do retention settings affect what we can license?

Yes. Messages deleted under a retention policy are generally gone, and data under a legal hold must be preserved as is. Check retention settings before scoping, and never change them to tidy up history without legal sign-off.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify