Privacy Policy

Last updated: July 13, 2026

Sterling (“Sterling,” “we,” “us”), a product of Divine Leader, LLC, provides a Slack-native AI assistant that connects to your business tools and performs work inside Slack. This Privacy Policy explains what we collect, how we use it, and the choices you have. It covers both our website and the Sterling application you install in Slack.

1. Sterling for Slack — data we process

When you install Sterling in your Slack workspace, we process Slack data solely to provide the assistant's functionality:

  • Messages directed to Sterling — direct messages and channel mentions you send to the bot, plus the recent thread history needed to maintain conversational context.
  • User profile basics — your Slack user ID and display/real name, used to address you and route approvals.
  • Workspace metadata — your Slack team ID, team name, and the bot installation token Slack issues during authorization.
  • Action & audit records — a log of requested actions and permission decisions, with sensitive values redacted.
  • Connected-app data — when you authorize integrations (e.g. Shopify, Klaviyo, Google Workspace), Sterling accesses only the data needed to perform the tasks you request, within the scopes you grant.

2. Where your data is stored

Workspace data is stored in Google Cloud Firestore (region us-east1), logically isolated per workspace by Slack team ID so one workspace can never read another's data. Application secrets and connection tokens are held in Google Secret Manager, never in source code, and sensitive text is redacted before it is written to our audit logs.

3. How we use your data

We use the data above only to generate responses, execute actions you approve, maintain conversation context, provide billing and usage accounting, and operate and secure the service. We do not sell your data, and we do not use the contents of your Slack messages or connected-app data to train third-party AI models.

4. AI disclosures

  • Model used — Sterling generates responses with Google Gemini, accessed through the Google Gemini API.
  • LLM data retention — message content is sent to the model only to generate a response. It is not used to train models. Google may retain API inputs and outputs for a limited period for abuse monitoring under its Gemini API terms; Sterling's own storage of conversation context follows the retention rules in Section 6.
  • LLM data tenancy — Sterling is a multi-tenant service with per-workspace logical isolation by Slack team ID. Your workspace's data is never used in, or exposed to, another customer's requests.
  • LLM data residency — inference and storage run on Google Cloud infrastructure in the United States (Firestore region us-east1).
  • Accuracy — AI-generated output can be inaccurate or incomplete. Review important results before relying on them; access to actions that change data in your connected tools is controlled by per-user permission levels set by your workspace admins.

5. Sharing

We do not sell or rent personal information. We share data only with:

  • Infrastructure & AI subprocessors — Google Cloud (hosting and database), Google Gemini API (model inference), Composio (integration connections and execution), Stripe (billing), and Vercel (website hosting), each processing data only to provide their service to us.
  • Growth & support vendors — Sequenzy (onboarding and lifecycle email to the installing admin), Rewardful (affiliate referral attribution), Meta Conversions API (ad attribution using SHA-256-hashed identifiers only — never message content), and Tawk.to (live chat on our website, for site visitors who use it).
  • Legal authorities — when required by law or to protect rights and safety.

6. Retention & deletion

When you remove Sterling from your Slack workspace, we immediately delete the stored bot token and stop accessing your workspace, and we automatically delete the rest of your workspace data — conversation history, user profiles, onboarding records, and logs — 14 days after uninstall (the grace period exists so nothing is lost if you reinstall). You may also request immediate deletion at any time by emailing us at the address below; we will delete it within 14 days, except where retention is required by law. Aggregated, non-identifying usage statistics may be retained.

7. Security

We apply encryption in transit, per-workspace isolation, secret management, redaction of sensitive values in logs, and human-approval gates on actions that change data. No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard safeguards.

8. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at the address below.

9. Children's privacy

Sterling is a business product and is not intended for individuals under 18. We do not knowingly collect personal information from children.

10. Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the “Last updated” date. Continued use of the service after changes constitutes acceptance of the updated policy.

11. Contact us

Questions about this Privacy Policy or your data? Email hello@sterlingcoworker.com.