Skip to content

Systems and records

Slack Connect channels: whose data is it when you export?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

In a Slack Connect channel, your company controls the messages its own people post, but messages from the other organization are best treated as third-party content. Having a copy in your export is not permission to use it. Before shared channels leave Slack for licensing or any outside use, exclude external messages or get written permission.

Key takeaways

  • A Slack Connect export can hold another company's messages, but possessing a copy does not grant rights to use them.
  • Treat messages, files and canvas edits authored by external organizations as third-party content: exclude them or get written permission.
  • Your own employees' messages in shared channels can still carry a partner's confidential information through quotes, pricing and roadmaps.
  • Preservation and use are separate questions: a shared channel may be kept for a legal hold and still be excluded from licensing.
  • Scope shared channels one by one and log each decision, so a reviewer can trace why content was kept or removed.

Who owns the messages in a Slack Connect channel?#

Messages in a Slack Connect channel come from more than one organization, so no single company holds clean rights to the whole conversation. Your company generally controls what its own employees write, under its employment policies and its Slack agreement. The partner, customer or vendor on the other side generally controls what its people write.

The copy sitting in your workspace is what makes this confusing. Both sides usually see the shared history, and your admin exports may include it, but a copy made for collaboration is not a license to reuse. Counsel usually reads a shared channel the way it reads an email thread with a customer: you can keep it as a business record, and you need a separate basis to use the other side's words for anything new.

Who owns the messages in a Slack Connect channel?
Content in the channelAuthored byDefault treatment outside Slack
Messages from your employeesYour organizationUsually yours to review for use, subject to confidentiality checks
Messages from external membersThe other organizationThird-party content: exclude or get written permission
Slack Connect direct messages with external peopleBoth organizationsTreat like a shared channel; whether DMs appear in your export depends on plan and permissions
Files uploaded by external membersThe other organizationExclude; files often carry their own confidentiality markings
Canvases or lists edited by both sidesMixedExclude unless every contributing organization agrees
App and bot posts from the partner's integrationsThe other organization's systemsExclude; they can expose the partner's internal data
Your replies that quote partner textMixedRemove the quoted text or exclude the thread

What does a Slack Connect export actually contain?#

A Slack Connect export contains whatever your plan, export type and admin permissions allow, which is why two companies can get very different files for the same channel. Slack offers different export options on different plans, from public channel exports to fuller exports and API-based tools on enterprise plans. Read Slack's current help pages for your plan before assuming what the file holds.

Once you have the export, inspect the file rather than the Slack interface. Message records carry user and workspace (team) identifiers, and those are how you separate internal authors from external ones; display names alone are not reliable, because external people can share a first name with your staff. External participants' names, titles and email addresses may also appear, and they are personal data about people who are not your employees and never received your workforce privacy notice.

  • Step 1: list every shared channel and the external organizations connected to each one.
  • Step 2: export a small test set and confirm how external authors are identified in the file.
  • Step 3: build an allowlist of your own users and workspace identifiers, and flag everything else as external.
  • Step 4: check files, canvases and app posts separately, since a message-only review misses them.
  • Step 5: log the export date, plan, export type and the person who ran it.

Which agreements decide what you can do with shared-channel content?#

The agreements with the other organization decide what you can do with its content, more than Slack's own terms do. For B2B software companies the most common case is a shared support channel with a customer, and the customer contract usually defines confidential information broadly enough to cover what the customer types into that channel.

Slack's terms set the platform rules, and your workforce notices cover your own employees; neither replaces the contract with the counterparty. Where a customer agreement limits use of customer data to providing the service, licensing that customer's messages to a third party usually needs fresh consent. Privacy laws, including US state privacy laws and GDPR where European participants are involved, may also apply to external participants' personal data, and they are assessed deal by deal with counsel.

Which agreements decide what you can do with shared-channel content?
DocumentWhat to look for
Customer master agreement or order formDefinitions of customer data and confidential information; permitted use; any aggregation or de-identification rights
NDA with a partner or vendorWhether chat messages count as disclosures; return or destroy duties when the relationship ends
Slack Connect invitation and channel settingsWhich organization created the channel and who can manage or export it
Employee handbook and workforce privacy noticeWhether staff were told work messages may be reviewed and used beyond daily operations
Data processing agreementWhether you act as a processor of the customer's personal data in that channel

How do retention settings work when two companies share a channel?#

Retention in a Slack Connect channel depends on how each organization's settings apply, and the outcome may not match what either side expects. Slack documents how message and file retention interacts across connected organizations; read that page next to your own retention configuration before you rely on a shared channel as a record.

Two practical risks follow. Your export may be missing partner messages that the partner's settings removed, so threads look one-sided. Or your export may still hold partner content that the partner assumed was gone, which matters if an NDA required return or destruction at the end of the engagement.

Legal holds add a third layer. A hold can require you to preserve a shared channel, partner messages included, for a dispute. That duty to preserve does not make the content available for licensing or analytics, so keep the held copy separate and labeled so a later export does not sweep it in.

Should you exclude, ask permission or de-identify external messages?#

Exclusion is the default for external messages, because it removes the third-party rights question instead of managing it. Permission is the path when the content is valuable and the relationship allows a direct ask. De-identification alone rarely settles the question, since the substance of a message, such as a price, a defect or a roadmap date, can stay confidential after names are removed.

Record the decision for each channel, not just the overall policy. A short log with the channel name, connected organizations, decision and reason is what a reviewer or a buyer will ask for later.

Should you exclude, ask permission or de-identify external messages?
SituationDefault decisionReason
Partner messages discussing pricing, roadmaps or defectsExcludeConfidential substance survives name removal
Customer support channel where the contract permits de-identified useCounsel review, then possibly include in de-identified formThe answer depends on exact contract wording
Partner gives written consent for a defined scopeInclude within that scope onlyConsent should name the channels, period and purpose
Channel dominated by external authorsExclude the whole channelYour remaining replies lose meaning without the other side
Internal-only channel discussing a shared channelReview as internal contentStill check for pasted partner messages and screenshots

Illustrative: a vertical SaaS company with customer channels#

Illustrative: a fictional route-planning software company for regional distributors runs premium support through Slack Connect channels with its larger customers, plus internal channels where support engineers escalate problems to the product team. The general counsel is asked whether the support history can go into a data licensing review.

A test export shows that most shared channels mix customer dispatch staff, the company's support engineers and customer-owned bots. Counsel excludes every shared channel, because the customer agreements limit use of customer data to providing the service. The internal escalation channels stay in scope, with a review pass that strips pasted customer messages and screenshots.

The result is a smaller but cleaner package: internal diagnosis, engineering discussion and resolution notes linked to Jira issues, with a channel-by-channel log of what was excluded and why. Two customers are later asked for written consent, and their channels are reconsidered only after they reply.

How SourceX handles shared channels#

Shared channels are settled at the second stage of the SourceX five-step transaction (Supply, Rights, Preparation, Approval, Delivery), before any redaction work begins. During the fit check a company describes its Slack setup in metadata only, such as whether shared channels exist and what they are used for; no messages change hands.

When a package moves forward, its SourceX Evidence Packet notes which shared channels were left out and on what basis, alongside provenance, permitted use and the privacy record. The supplier signs off on the final scope before delivery.

Frequently asked questions

Does removing the partner's name make their messages usable?

Usually not on its own. Confidentiality attaches to the information, not just the name, so a message about a supplier's pricing or a customer's outage can stay confidential after names are stripped. De-identification helps with personal data, but the contract with the other organization still decides whether the content can be used.

Are our employees' messages in shared channels fully ours to use?

They are generally company records, but two checks remain. Your employees often quote or summarize the partner's information, which carries the partner's confidentiality with it. And your workforce notices and policies shape how staff messages can be used, which is a separate question from the partner's rights.

Can we keep shared channels for a legal hold but leave them out of licensing?

Yes, and that is a common setup. Preservation duties and permission to use are separate questions. Keep the held material in a labeled, access-controlled location, and filter later exports by channel ID rather than by name, since channel names can change over time.

What if the other company leaves or disconnects the channel?

A disconnect changes who can post and see new activity, but it does not settle rights to the history you already hold. Check Slack's documentation for what each side keeps after a disconnect, then apply the same rule: external messages remain third-party content unless the other organization agrees otherwise.

Who should approve including external messages?

Counsel should review the underlying contract, and the person who owns the relationship, often an account executive or a business leader, should confirm the request is appropriate. Get the other organization's consent in writing, with the channels, date range and purpose spelled out.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify