Privacy
What the service needs to know to run the game.
This is a plain-language privacy baseline for the hosted service. It explains the kinds of data Trustactic may handle when a workspace installs the Slack app, runs games, manages billing, or contacts support.
Field note
Who is responsible for the service
Trustactic is the product brand for this hosted Slack application and its related web surfaces. The final legal controller, contracting entity, registered address, and governing-law details still need to be published before the first paid sale. For privacy questions, access requests, deletion requests, or complaints, use the contact route and select Privacy. We may ask for enough workspace or billing context to verify the request without asking you to send secrets or private game-state details.
Field note
What we collect
- Slack workspace, team, channel, and installation identifiers.
- Slack user identifiers and display names where needed to run the game.
- Game/session metadata needed to operate Hidden Roles, such as phases, actions, votes, missions, and event history.
- Billing and subscription metadata from Stripe.
- Contact/support submissions and operational logs used to run and debug the service.
Field note
Player-created content
Player names, mission answers, votes, reactions, and discussion events may be stored with the workspace game record. During an active Hidden Roles game, player-authored channel messages and app mentions from the game channel are captured with their Slack event metadata and payload so the service can preserve operational context and support a future AI reader. Slack reaction events received for an installed workspace may also be stored; when a reaction matches a captured game message it is linked to that game, and unmatched reactions may remain workspace-scoped. DMs, bot messages, edits, deletes, and unrelated message channels are excluded by the current message capture path. Raw discussion capture is not currently presented as host history and is not required to resolve the game rules. Trustactic does not apply a vocabulary filter to ordinary player content. Workspace administrators should tell players when a game is being run and should not use the product to collect sensitive information that the game does not need.
Field note
Why we use it
- Install and operate the Slack app.
- Run the game, assign roles, process actions, and announce outcomes in Slack.
- Provide console/admin, billing, public-safe room history, and support surfaces.
- Protect hidden game state, investigate failures, and maintain service reliability.
Field note
Slack and hidden-state boundaries
The service uses hidden role and game-state data to run the game correctly. That data should not be exposed to ordinary players through browser surfaces. The browser exists for installation, billing, public-safe room history, and support rather than player gameplay.
Field note
Billing and support providers
We rely on Slack for gameplay delivery, Stripe for billing, Supabase for hosted data storage, Vercel for application hosting, and operational tools needed to monitor and support the service. These providers may process information in the regions and under the terms that apply to their services. Trustactic does not sell player or workspace data and does not use game content for advertising.
Field note
Cookies and analytics
The webapp uses necessary cookies for Slack OAuth state, secure console sessions, checkout, and security controls. Production pages may use privacy-conscious Vercel Analytics to understand aggregate page usage. We do not use advertising cookies or cross-site ad profiles. You can read or clear browser cookies through your browser controls; clearing session cookies may require you to sign in or authorize again.
Field note
Retention and deletion
Installation records, game history, captured discussion events, and operational logs are retained while needed to operate the service, provide billing and support, investigate failures or abuse, and satisfy legal or accounting duties. Trustactic has not published a fixed retention schedule or promised automatic anonymization for every record yet; deletion and access requests are handled through operational review while the retention process is completed. If you need access, correction, export, deletion, or uninstall-related help, use the contact route.
Field note
Privacy requests
Select Privacy in the contact form and include the workspace name, the request you are making, and a reply address. We will verify the requester before disclosing or deleting workspace information. This public baseline does not promise a data-processing agreement or customer-specific privacy terms; those questions require separate legal review before a paid enterprise arrangement.