Privacy
This covers the free hosted instance and this website. If you self-host Morgenruf, you are the data controller and this policy does not apply to your deployment.
Effective date: April 5, 2026 · Last updated: October 1, 2026
The hosted Morgenruf Slack app and the website at morgenruf.dev are operated by Anmol Nagpal ("we", "our", "us"). This policy explains what personal data we collect, why, how we protect it, and your rights.
1. Who We Are
Morgenruf is an open-source Slack app for standups, coffee chats, kudos and celebrations. The hosted service is operated by Anmol Nagpal, in Canada. It is sponsored and hosted by CloudDrove, which runs the servers and the database in a Canadian data centre and is listed as a sub-processor in section 5. Source code is available at github.com/morgenruf/morgenruf under the MIT license.
Privacy inquiries, including requests to access, transfer or delete your data: [email protected]
2. Data We Collect
| Data | Source | Purpose |
|---|---|---|
| Slack workspace ID and name | Slack OAuth | Identify your workspace |
| Slack bot token | Slack OAuth | Authenticate API calls |
| Slack user IDs and display names | Slack API | Send DMs, display in dashboard |
| Email addresses | Slack API (users:read.email) | Stored with the member record. Emailed only as described under "Email addresses" below |
| User timezones | Slack API | Schedule standups correctly |
| Standup responses (text) | Users via bot DM | Core functionality |
| Standup configuration | Admin via dashboard | Core functionality |
| Kudos messages | Users via Slack | Kudos/recognition feature |
| Mood ratings (optional) | Users via bot DM | Mood analytics |
| Polls: question, options, the channel and who started it; votes | Users via Slack | Polls feature |
| Pulse check-in counts (how many people picked each value), and while a check-in is open, who has answered (not what) | Users via bot DM | Pulse feature, if a workspace admin turns it on |
| Member profile: birthday (day and month only, never the year), start date, role, location, "ask me about", and whether the member opted out of celebrations | The member, or a workspace admin (form or CSV import) | Celebrations, and the features that read the profile |
We do not read Slack channel messages. The only messages Morgenruf receives are direct messages sent to the Morgenruf bot, and the only other conversations it looks at are the coffee chat group messages it opens itself (see "Data we receive but do not use" below). We do not collect payment information.
Email addresses
Morgenruf asks Slack for the users:read.email permission, so Slack gives it the email address on each member's Slack profile, including the person who installed the app. These addresses are stored with the member record.
- The person who installed Morgenruf is emailed only after they opt in inside Slack, by pressing the "Email me setup tips" button. That covers a welcome email, one check-in a week later, a weekly standup digest on Sundays and a note if the app is removed. Nothing is sent to them before that. They can withdraw at any time, from the unsubscribe link in any email, from the "Stop setup emails" button on the Morgenruf Home tab, or by writing to [email protected], and we stop emailing them.
- Everybody else's address is never emailed by us, and no address is used for marketing, sold, or shared with anybody outside the sub-processors in section 5.
- The standup digest email, if a workspace admin turns it on, goes to the address that admin types into the standup settings.
- When Morgenruf is installed, the installing person's name, email address, job title and timezone are posted once to a private Slack channel the operator reads, so a new install does not go unnoticed. Nobody outside the operator sees it.
Data we receive but do not use
Slack sends Morgenruf some data it has no use for. It is discarded, not stored:
- Direct messages to the bot that are not a command (such as
helporkudos @name) or an answer to a standup the bot asked are ignored and not stored. So are the events Slack sends for the bot's own messages and for edits and deletions. - @-mentions of the bot in a channel: Slack delivers the message text, and Morgenruf replies with a fixed pointer to its help. The text is not read, used or stored.
- Coffee chat group messages: to avoid nudging a pair who are already talking, Morgenruf checks whether anybody has written in the group message it opened for them. It looks only at whether a message exists. What was said is not read or stored.
- Slack profiles: when Slack returns a member's profile, Morgenruf keeps the name, display name, email address, timezone and profile photo link. The rest (such as phone number and status) is dropped. The one exception is the install notice described above, which includes the installer's job title.
- Channel joins: when someone joins a channel the bot is in, Morgenruf records them as a member (name, email address and timezone, as above) and sends a welcome DM only if that channel runs a standup, a coffee chat or celebrations. Nothing else about the channel is kept.
Polls and pulse
- Named polls store who voted for what, and show it on the poll message.
- Anonymous polls store each vote under a code made from the voter's Slack ID and a random key for that poll. While the poll is open, the code only lets Morgenruf know a person already voted, so they can change their vote. When the poll closes, the key is deleted, and nobody, us included, can tell who cast which vote. The key is never written to backups.
- Results hidden until close are not shown anywhere, in Slack or the dashboard, before the poll closes.
- Pulse answers are never stored one by one. Morgenruf keeps only how many people picked each value. While a check-in is open, it also keeps who has answered (not what), so it can remind people once; when the check-in closes, that list is deleted and only the counts stay. The list is never written to backups.
- Pulse results show only after a check-in closes, and only as team figures: an average from 5 answers, the breakdown and eNPS from 10. There is no free text and no view of one person's answers, for admins or anybody else.
- On the hosted service, Morgenruf runs the servers, so while a check-in is open someone with direct access to the database could in principle work out the most recent answer. Once it closes, nothing that links an answer to a person remains.
Member profiles
Each member can keep a short profile. It holds a birthday as a day and month only; the year is never stored, and a full date in an imported file has its year removed before it is saved. It also holds a start date (with its year, because anniversaries count years), a role, a location, an "ask me about" line, and an opt-out flag for celebrations.
- The member can see and edit their own profile, clear their own dates, and opt out of celebrations at any time. Opting out keeps the dates but stops anything being posted about them.
- Workspace admins can see every profile, edit any of them, and import birthdays and start dates for the workspace from a CSV file. An import does not overwrite a profile the member filled in themselves unless the admin chooses to.
- Celebrations admins, if a workspace admin appoints one, see the list of celebrations due in the next 30 days.
- If Celebrations is turned on, birthdays and work anniversaries are posted in the channel the workspace chooses, for members who have not opted out. The post names the person and does not include a year of birth.
- Profiles can also be read through the MCP server with an API key, which only a workspace admin can create.
When a member leaves the workspace, their profile is deleted 30 days later. If they return within those 30 days, it is kept. Uninstalling Morgenruf removes every profile along with the rest of the workspace's data (see section 9).
Self-hosted: If you self-host Morgenruf, you are the data controller. We have no access to your data. It stays entirely on your infrastructure.
3. How We Use Your Data
- Deliver standup prompts to team members at scheduled times
- Post formatted standup summaries to your Slack channel
- Display analytics (participation, history) in the web dashboard
- Email setup tips to the person who installed Morgenruf, only after they opt in inside Slack
- Send the standup digest email to the address a workspace admin sets, if they turn it on
- Post birthdays and work anniversaries to the channel your workspace chooses, if Celebrations is turned on
- AI standup summaries are not part of the hosted service. They exist only on self-hosted installs whose operator configures their own OpenAI or Anthropic key (see section 5)
- Debug errors and maintain service reliability via Sentry
We do not use your data for advertising, profiling, or selling to third parties. We never use Slack data to train AI or machine learning models, and the hosted service does not send it to any AI provider.
4. Legal Basis for Processing (GDPR)
For users in the EEA, we process data under the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Delivering standup prompts and summaries | Performance of contract (Art. 6(1)(b)) |
| Analytics and dashboard | Legitimate interests (Art. 6(1)(f)) |
| Website and product usage counts | Legitimate interests (Art. 6(1)(f)) |
| Standup digest email | Performance of contract / Legitimate interests |
| Setup tips email to the installer | Consent (Art. 6(1)(a)), given in Slack and withdrawable at any time |
| Security logging | Legitimate interests |
5. Third-Party Services
Always Active
| Sub-processor | Purpose | Location |
|---|---|---|
| Slack Technologies | Slack API, message delivery | USA/EU |
| CloudDrove | Database and application hosting, on servers CloudDrove operates in a Canadian data centre | Canada |
| Resend | Transactional email delivery | USA |
| Netlify | Website hosting | USA |
| Cloudflare | CDN, and privacy-preserving page view counts (no cookies, no cross-site tracking) | USA |
| Sentry | Error monitoring (no standup content) | USA |
| PostHog | Product and website analytics. Site pages are counted without cookies. Product events are counted per workspace and carry no Slack user ID and no standup content | USA |
Not used by the hosted service
Morgenruf can talk to a few more services, but only on a self-hosted install whose operator configures them with their own account. The hosted service has none of them configured and sends them nothing.
| Service | What it would do on a self-hosted install |
|---|---|
| OpenAI or Anthropic | AI standup summaries, using the operator's own API key. The hosted service does not send any data to an AI provider. |
| Zoom | Optional. Booking a meeting for a coffee chat pair, using the operator's own Zoom app. |
6. Data Retention
| Data type | Retention period |
|---|---|
| Standup responses | 90 days (auto-deleted) |
| Analytics aggregates | 12 months |
| Website and product usage events | 12 months |
| Slack tokens | Until you uninstall Morgenruf |
| Member profiles | Until 30 days after the member leaves the workspace, or until you uninstall Morgenruf |
| Member records (name, email address, timezone) | Until you uninstall Morgenruf |
| Email opt-in and unsubscribe records | Until you uninstall Morgenruf. An unsubscribe is kept so that it keeps holding |
| Workspace history (install and removal dates, how many people, which features were used; no names, emails, Slack IDs or message text) | Kept after you uninstall, so we can see where teams get stuck during setup |
| Request / error logs | 30 days |
| Email send logs | 90 days |
7. Security
- All data in transit is encrypted via TLS/HTTPS
- Slack bot tokens are stored encrypted at rest (AES-256)
- Sessions are backed by Redis with expiry
- Signing secret validation on every Slack event
- Access to production systems is restricted to authorised contributors
- Periodic security reviews of infrastructure
8. Your Rights
Depending on your location, you may have the right to: access, rectify, erase, receive a portable copy (CSV export available in dashboard), restrict processing, or object to processing. EEA users may also lodge a complaint with their national data protection authority.
To exercise any right, email [email protected] with your Slack workspace ID. No account is needed. We will respond within 30 days. In particular:
- Access: ask for a copy of the personal data we hold about you or your workspace.
- Transfer: ask for that data in a machine-readable format (CSV or JSON). Workspace admins can also export standup history as CSV from the dashboard at any time.
- Deletion: ask for your data, or your whole workspace's data, to be deleted. See section 9 for the ways to do it.
- Correction: members can edit their own profile in Slack, and we will correct anything else on request.
9. Data Deletion
- Uninstall Morgenruf from Slack (Manage Apps → Remove Morgenruf). Personal data and content (member records, standup answers, kudos, coffee chats, tokens) are deleted within 7 days of the uninstall, usually within a day. Only the workspace history listed in section 6 is kept.
- Immediate deletion: Email [email protected] with your Slack team ID. A single member can ask for just their own data to be deleted the same way, with their Slack user ID.
- Self-hosted: Drop your database or use the provided cleanup script.
10. International Data Transfers
The hosted service runs in Canada, on servers CloudDrove operates. Some sub-processors in section 5 (Slack, Resend, Sentry, PostHog, Netlify and Cloudflare) are in the USA, so data they handle is transferred there. For EEA/UK users, Canada has an EU adequacy decision, and for the US sub-processors we rely on Standard Contractual Clauses (SCCs) and the adequacy frameworks of those sub-processors. You can request transfer mechanism details at [email protected].
11. Children's Privacy
Morgenruf is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us data, please contact [email protected].
12. Changes to This Policy
We may update this policy for product changes or legal requirements. For material changes, workspace admins will be notified via Slack DM at least 14 days before the change takes effect. Continued use constitutes acceptance. The latest version is always at morgenruf.dev/privacy.
13. Contact
- Privacy: [email protected]
- General support: [email protected]
- GitHub Issues: github.com/morgenruf/morgenruf/issues
This policy applies to the hosted cloud service. If you self-host Morgenruf, you are the data controller and this policy does not apply to your deployment.