Privacy Policy
How Viably collects, uses, and protects your data.
Viably is operated by Supertype Pte. Ltd. · Last updated August 2026.
What we collect
- Slack workspace data: team ID, channel IDs, user IDs, and message content in channels where Viably is invited.
- Usage data: which Powers are enabled, AI model selections, and feature interaction counts.
- Credentials you provide: optional AI provider API keys, stored encrypted at rest.
- Google Calendar data: if you connect your Google account through the Calendar Power: your Google email address, OAuth tokens (encrypted at rest), and the calendar events and free/busy information needed to show your team agenda and schedule meetings.
- Google Search Console data: if you connect a property through the Search Console Power: your Google email address, OAuth tokens (encrypted at rest), and the search performance statistics Google reports for the properties you select (clicks, impressions, average position, and per-URL index status).
Incidental data
Slack payloads delivered to Viably include data we receive but do not intentionally store or use, such as Slack user IDs in slash command payloads, channel IDs, message timestamps, and system metadata. This data flows through our service to process your request but is not retained beyond what is necessary to complete the operation.
What we don't collect
Private DMs or channels Viably hasn't been invited to. We never read messages beyond what is needed to respond to a direct mention or reaction. Via requires explicit user interaction (e.g. @Via summarize this above, or when user uses a 🐛 reaction to file an issue with Viably, or when its in a thread where it was previously mentioned) before it participates.
How we use it
Solely to operate the Powers you enable: answering AI chat messages, tracking issues, syncing medal, relaying webhooks, and so on. We do not sell or share your data with third parties for advertising.
Third-party processors
Certain Powers send data to third-party services to function. You control which Powers are active.
- AI providers: message content for AI chat responses.
- GitHub: issue titles and descriptions when GitHub sync is enabled.
- Stripe: webhook payloads you configure for relay.
- Google Calendar: when you connect your Google account via the Calendar Power, we read (read-only) your calendar events and free/busy times; events you create are written by our service account to a separate shared team calendar.
- Google Search Console: when you connect a property via the Search Console Power, we read (read-only) the search statistics Google already reports for that property. Nothing is sent to Google beyond the read requests themselves.
Google user data
Two Powers use Google APIs, and each is optional. Neither is enabled until you connect an account yourself, and each requests a single read-only scope. We request no other Google scopes at any point.
- View events and free/busy on your calendars (
calendar.readonly): used by the Calendar Power to (1) find open meeting slots across participants when you ask Via to schedule a meeting, and (2) show your upcoming events alongside your Slack tasks and reminders in a unified agenda. - View Search Console data for your verified sites (
webmasters.readonly): used by the Search Console Power to show your own search performance inside Slack and the dashboard: clicks, impressions and average position for the properties you choose, and per-URL index status retrieved through the URL Inspection API so the dashboard can tell you which of your pages Google is indexing.
Both scopes are read-only. Viably never creates or edits events on your personal calendars, and never writes to Search Console: it cannot submit or remove URLs, request indexing, or change any property setting. Events you create from Slack are written by Viably's own service account to a separate shared team calendar maintained for your workspace, never to your personal calendars. For Search Console you may skip OAuth altogether and instead grant Viably's service account restricted access to a single property from within Search Console.
We read only what the feature needs. Viably does not crawl, fetch or store the content of your web pages, and it reads no Google product other than the two named above. Search Console statistics and calendar data are stored per workspace, are never pooled across customers, and are never combined with another workspace's data.
OAuth tokens are encrypted at rest and are transmitted only to Google. Google user data is used solely to provide the user-facing features described above. We do not sell it, we do not use it for advertising, we do not transfer it to third parties, and we do not use it to develop, improve or train generalized AI or machine-learning models. No human at Supertype reads your Google data except with your explicit consent (for example, when you ask us to investigate a support issue), where required for security or to comply with applicable law.
You can disconnect at any time from the Calendar or Search Console Power page. Disconnecting revokes Viably's access and deletes the stored tokens along with the data synced under them. You can also revoke access directly from your Google account permissions page.
Viably's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data retention
Workspace data is retained as long as your Slack app installation is active. Uninstalling Viably from Slack triggers deletion of your workspace's data within 30 days. You can also request immediate deletion by emailing us.
Security
All data is stored in a hosted PostgreSQL database with encryption at rest and in transit. API keys are encrypted before storage. Access is restricted to Supertype engineering staffs that require it to operate the service. We perform regular security audits and vulnerability scans, in line with best practices for SaaS applications of this type.
Your data rights
You have the right to access, transfer, and delete the data Viably holds about your workspace.
- Access: Request what data we hold for your workspace via email.
- Transfer/portability: Request your data in a machine-readable format (JSON).
- Deletion: Uninstalling Viably from Slack triggers automatic deletion within 30 days. For immediate deletion, email us.
- Legal rights: If you are in the EU or California, you may have additional privacy rights under GDPR, CCPA, or similar laws. Contact us to understand your options.
Contact
For questions, data access requests, deletion requests, or GDPR/CCPA privacy rights: [email protected]