Security
Security and data handling
We look after your company's conversations, so we publish where the data lives and who can read what.
- Storage
- Servers in Japan (Tokyo)
- AI training
- Never with customer data
- Answer scope
- Sources: only what the asker can read
01Where data is stored and processed
- Messages, files, and the bot's records
- Servers in Japan (Tokyo)
- Email to admins
- United States (Resend)
- Network transit
- Cloudflare
02Who can read what
- 01
The bot reads only channels it has joined
It joins public channels automatically and posts a notice when it does. Admins can switch off any channel in the admin console. It reads a private channel only when that channel's owner or an admin adds the bot.
- 02
It never reads DMs between people
The only DMs it processes are the ones sent to the bot: questions and commands.
- 03
Answer sources come only from what the asker can read
Answers cite only messages from channels the person asking can read. Other managers' DMs with the bot are never used. When admins set up sharing between managers, managers in a sharing group or joined by a reporting line (above, below, or under the same manager) also receive items from other managers' channels (the AI's one-line summary, owner, due date and status). Briefs bring only the items that concern that manager, and decisions a manager in the channel chose to pass on. Items from a private channel are shared only if an admin switches that channel on, and the bot tells the channel. Original messages and links are never shared.
- 04
Questions stay out of the admin console
The admin console shows only how many questions each manager asked.
- 05
Anyone can check
Anyone can DM the bot “channels” to see which channels it reads.
03How it's protected
- Traffic is encrypted with TLS. The servers expose no inbound ports (Cloudflare Tunnel).
- Each company's keys and tokens are stored encrypted.
- Backups are encrypted before they are stored.
- Members' private keys stay on their own PCs; the operator never holds them. A lost key can't be recovered, so an admin replaces the member with a new key.
04Retention and deletion
- Messages are kept for as long as your contract runs.
- After the contract ends, chat keeps working for 30 days. Then access stops, Matin's copies are deleted, and the server data is fully deleted within the period set in the terms.
- Encrypted backups keep deleted data for up to 5 weeks.
05Telling employees
Before you start, we ask you to tell employees what the bot reads and why. We give you a notice template for this.
The terms of service and privacy policy are shown when you create your workspace, and you agree to them there.