Privacy policy
Last updated: October 4, 2026
Spinny (“the app”) is a Slack app operated by Byungdon Yoon (“we”). This policy explains what the app collects when a Slack workspace installs it, why, how long it is kept and how to have it deleted.
Installation
When a workspace installs the app, Slack gives us the following, and we store it:
| Data | Why |
|---|---|
| Workspace ID and name, Enterprise Grid org ID (if any) | To know which installation a request belongs to |
| Bot access token, bot user ID, app ID, granted scopes | To post and update game messages in your workspace |
| Slack user ID of the person who installed the app, and the install time | To answer support questions about an installation |
Games
Each game started with /spinny is stored with:
| Data | Why |
|---|---|
| The channel ID and name, the game’s title, mode and number of winners | To show the game on the web and in the channel’s list of past games |
| Each player’s Slack user ID, display name and profile photo URL, as they were when the game was set up | To draw the wheel with names and photos and to show the result |
| Who set the game up and who spun it (user ID, name, photo URL), when, and whether it was spun in Slack or on the web | To show who spun and when |
| The result, and the ID of the Slack message that shows the game | To update that message with the result |
A game is deleted automatically 90 days after it was set up. Deletion runs in the background and may take a few more days to complete; a game past its 90 days is never shown in the meantime.
Usage counts
For each workspace and month, we keep how many games were played and the Slack user IDs of the people who spun, to count how many people use the app. We use these to plan limits and pricing. They are kept while the app is installed.
Who can see a game
The web pages ask you to sign in with Slack. A game, and a channel’s list of past games, is shown only to people signed in from the same workspace. Anyone from that workspace who has a game’s link can open it, including a game from a private channel.
Signing in sets a cookie in your browser with your workspace ID, user ID, name and photo URL. It is signed so it cannot be altered, lasts 7 days, and is removed when you sign out. We do not keep a copy on our servers.
What we read but do not store
To set up a game, the app reads whether each player is a deactivated account and (only when you click “Add all channel members”) the member list of that channel. The app does not read message history, does not export your data, and does not use any Slack data to train machine learning models.
Where it is kept
Everything above is kept in Amazon DynamoDB in the AWS Seoul region (ap-northeast-2), encrypted at rest. Access tokens are never written to logs. Error logs are kept in Amazon CloudWatch for 30 days to diagnose failures; they do not contain tokens.
Sharing
We do not sell or share your data. Amazon Web Services hosts the app as our infrastructure provider; no other third party receives data from it.
Deletion
When you uninstall the app, Slack notifies us. We delete the installation record, including the token, right away, and then every game and usage count of your workspace. Encrypted point-in-time backups expire on their own within 35 days. To ask for deletion or a copy of what we hold about your workspace, email us at the address below; we answer within 2 business days.
Changes
If this policy changes, we update the date at the top of this page. Material changes are also noted on the support page.
Contact
Email support@example.com.