privacysecurity

Your Boss Can Read Your Slack DMs. So Can Slack.

Files and photos shared in Slack DMs feel private. They're not. Here's who can access them, under what conditions, and what to do about it.

It starts with something small. You need to share a contract with a colleague, so you drop it in a Slack DM — faster than email. Or you send yourself a photo through a private channel to get it from your phone to your laptop. Or you paste in account credentials, thinking a direct message is a reasonable safe space.

These feel like private actions. In most workplaces, on most Slack plans, they aren’t.

Who Can Read Your Slack DMs

The answer depends on your Slack plan, but it’s less private than most people assume.

Standard and Pro plans: Workspace owners and admins can request a data export that includes public channels. Private channels and DMs are not included in standard exports — but with a formal legal request (such as a court order), Slack can provide this data.

Business+ plans: Workspace owners can export data from any channel or conversation — including direct messages and private channels — without requiring a legal request. This is an administrative feature, and it doesn’t require notifying the employees whose messages are being exported.

Enterprise Grid: Admins have extensive access and monitoring capabilities, including the ability to use Slack’s Discovery API to search, export, and audit all messages and files across the organization.

NBC News has reported that Slack’s terms give employers the ability to “read private DMs without telling workers” — this isn’t a loophole or a rarely-used edge case. On paid plans, it’s a documented administrative feature.

Slack itself makes this clear in its privacy FAQ: “Slack respects our customers’ rights to manage their own data.” The “customer” is your employer. You, as an employee, are a user of the customer’s workspace.

What Slack the Company Can Access

Beyond your employer’s access, Slack itself has access to the data you store in its system.

Slack encrypts data in transit and at rest, using AES-256 encryption. This protects against external attackers intercepting data. It does not prevent Slack as a service provider from accessing the data it stores — the encryption keys are held by Slack, not by users.

Slack’s privacy policy describes using data for purposes including product improvement, trust and safety, and abuse detection. Slack also uses machine learning on message content and file data for features like search, summarization, and smart notifications.

For most purposes, Slack’s own access to content is less practically concerning than employer access. But it’s worth knowing that “encrypted” in this context means protected from third-party interception, not inaccessible to Slack.

The Specific Problem With Personal Files

People send personal files through Slack for understandable reasons. It’s convenient, it’s where work already happens, and DMs feel private in the same way a conversation in a private office feels private.

The files that end up in work Slack accounts tend to be exactly the kind of content people would least want their employer to access:

  • Tax documents or financial statements sent to a financial advisor colleague
  • Medical information shared with an HR contact or trusted coworker
  • Legal documents shared while navigating a personal situation
  • Photos sent to yourself to move between devices
  • Sensitive personal communications carried out “privately” via DM

All of this content lives in your employer’s workspace. On Business+ and Enterprise plans, your employer has administrative access to it. On all plans, Slack the company has access to it as a service provider.

Editing and Deleting: What It Actually Does

A common assumption is that editing a Slack message or deleting it protects you retroactively. This is not accurate.

Slack retains message history according to the workspace’s retention policy, which is set by the workspace admin — typically your employer. If retention is set to indefinite (common on paid plans), deleted messages may still exist in Slack’s system. Slack’s admin export tools can access message history regardless of whether users have deleted their copy.

The message you deleted from your view may still be in the workspace’s archived data.

What “Workspace” Actually Means

The fundamental issue is ownership. When you use a company-managed Slack workspace, you’re operating inside an infrastructure your employer pays for and controls. The terms you agreed to when joining Slack were between Slack and your employer. Your employer’s rights to that workspace — and the data in it — flow from that contract.

This is legally standard and not deceptive. US law generally permits employers to monitor communications on company systems with appropriate notice. The EU and UK have similar frameworks requiring notice but permitting monitoring. The issue isn’t that employers are doing something wrong — it’s that most employees have a fundamentally incorrect mental model of what “private DM” means inside a company-owned workspace.

What This Means for Personal Documents

The practical implication is straightforward: a company-managed Slack account is not an appropriate place to store or transmit personal files and documents.

This isn’t about distrust of your employer. It’s about using tools for what they’re designed for. Work collaboration platforms are designed and contractually structured around your employer being the customer. Your personal documents, photos, and communications are personal — and they belong in systems where you are the customer, where the terms protect your content, and where your employer is simply not a party to the agreement.

For personal file sharing and storage that genuinely is private — content you wouldn’t want an admin to see, content that has nothing to do with work — the appropriate place is a personal account on a service you control independently of your employment.

Teams: The Same Picture

Microsoft Teams follows a structurally similar model. Teams data is stored in Microsoft 365, which an organization’s IT admins can access through Microsoft’s compliance and eDiscovery tools.

Teams messages are indexed by Microsoft Purview (formerly Microsoft Compliance Center), allowing admins to run content searches across private chats, channel messages, and files. On enterprise plans, admin access is comprehensive.

If anything, Teams is used in more sensitive organizational contexts — healthcare, legal, government — which increases the value of understanding its access model clearly.

Cloud Personal File Storage: A Different Relationship

The distinction worth drawing isn’t between “good apps” and “bad apps.” It’s between apps where your employer is the customer and apps where you are.

When you’re the customer:

  • The terms of service run between you and the service provider
  • Your employer has no administrative access because your employer has no account
  • Deletion is governed by the service’s stated policy toward users, not your employer’s retention settings
  • Privacy policy obligations run to you

daftei is an example of this structure. The account is yours — not your employer’s. The files you store there are governed by terms between you and daftei. GDPR and CCPA compliance obligations run to you as the user. Your employer doesn’t have a seat at the table because they don’t have an account in the workspace.

The practical difference: a photo you send through your personal daftei account to share between your phone and laptop is accessible to you, and not to your employer’s IT admin, your company’s compliance team, or anyone who might later receive an export of your workplace’s Slack data.

Signals That Your Current Setup Has the Wrong Boundary

If any of these apply, you’re storing personal content in the wrong place:

  • You’ve sent tax documents, paystubs, or insurance cards through Slack DM
  • You use Slack or Teams to “move files between devices” for personal content
  • You’ve discussed medical, legal, or financial matters through work messaging apps
  • You store passwords, 2FA backup codes, or personal login credentials in Slack

None of these are catastrophizing scenarios. They’re patterns that indicate personal and professional storage have blurred in a direction that puts personal content inside employer-controlled infrastructure.


The convenience of work messaging tools makes them a natural default for file sharing. The access model that governs those tools makes them a poor choice for personal content. Knowing the difference — and keeping personal files in systems where you’re actually the customer — is a practical privacy decision that doesn’t require technical sophistication, just a clear mental model of whose system you’re operating in.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts