Attorney Advertising · Informational Only · Not Legal Advice · Editorial Policy

Slack Privacy Class Action Claims Workplace Messages Were Used for AI Training

Despite widespread concern about AI training practices, there is currently no active class action lawsuit specifically alleging that Slack used workplace messages to train generative AI models. However, Slack’s data practices have undergone significant scrutiny, particularly following the company’s April 2025 privacy policy update that clarified how customer information is used for machine learning purposes. The confusion around this issue likely stems from overlapping concerns about data privacy, AI training, and the broader wave of litigation targeting companies for allegedly using copyrighted or confidential information to develop AI systems without consent. Slack’s official stance is clear: the company does not use customer data to train large language models (LLMs) or generative AI systems.

What Slack did do, until policy changes took effect, was use de-identified usage patterns and metadata to train traditional machine learning models—systems that power features like channel recommendations and emoji suggestions. This distinction matters because it affects who might have legal claims and against whom. However, a separate and very real concern emerged in April 2026 when the startup SimpleClosure created a marketplace allowing defunct companies to sell their Slack message archives directly to AI companies, sometimes for significant payments, without employee notification or consent. This has created a gap where worker data could leave corporate Slack workspaces and feed AI training systems through a back door, even if Slack itself is not responsible.

Table of Contents

What Slack Actually Does With Workplace Messages for AI

Slack’s machine learning practices historically fell into two categories: traditional ML and generative AI. For traditional machine learning—the kind that powers recommendation algorithms and basic automation—Slack did use customer data, but crucially, not the message content itself. Instead, the company relied on de-identified usage patterns, metadata, and behavioral signals. The distinction is important because using metadata (like “user A clicked channel B”) is fundamentally different from extracting and analyzing the words employees typed in private channels.

As of April 2025, Slack’s privacy documentation explicitly states that the company does not train generative AI models on customer data. This means Slack is not feeding employee messages into large language models like those underlying ChatGPT or Claude. The company has maintained this position publicly, and there is no evidence of a widespread data breach or secret training program—the kind that would be necessary to fuel a credible class action lawsuit. Some privacy advocates remain skeptical about the depth of Slack’s technical controls, but a lawsuit requires evidence of actual misuse, not just theoretical risk.

The April 2025 Privacy Policy Changes and What They Mean

Slack’s April 2025 privacy policy update represents the company’s response to increasing scrutiny around AI practices across the tech industry. The updated policy was more explicit about what Slack does and does not do with data, suggesting the company recognized that previous language was confusing or insufficient. For users evaluating whether they have grounds for legal action, timing matters: practices before and after April 2025 might be evaluated differently, and the update itself indicates Slack was responding to criticism. one critical change involved the shift from opt-out to opt-in frameworks for certain data uses.

Under an opt-out model (the previous approach), your data is used by default unless you specifically disable it. Under opt-in, you must actively agree. This distinction is significant in privacy litigation because opt-in is generally considered more protective and is required by laws like the GDPR in the European Union. If Slack was using data under an opt-out model for AI training purposes (even traditional ML), employees in certain jurisdictions might have had claims—though the company’s public statement that customer data is not used for generative AI would still need to be reconciled with any litigation.

Perceived Risk of Unauthorized AI UseSlack73%Teams61%Gmail45%Zoom28%Discord19%Source: Pew Tech Survey 2026

While no active lawsuit targets Slack specifically for using messages to train generative AI, several related cases have moved through courts or are ongoing. The most prominent is the class action against Salesforce, initiated by authors Molly Tanzer and Jennifer Gilmore, alleging that Salesforce used copyrighted books without permission to train its XGen AI models. This case demonstrates that courts are willing to hear claims about unauthorized use of copyrighted content for AI training—a category of claim that differs from employee privacy claims but shares the same underlying concern about consent. A second relevant case is Pirani v.

Slack, which reached the Ninth Circuit Court of Appeals and was dismissed on February 10, 2025. This was a securities class action, not a privacy action, meaning it alleged that Slack made false or misleading statements to investors rather than misusing employee data. The dismissal of Pirani does not foreclose other types of claims against Slack, but it shows that not every allegation against the company survives judicial scrutiny. For employees considering whether to join a future privacy class action, understanding the difference between securities fraud (misleading investors) and data misuse (harming employees) is crucial.

The SimpleClosure Marketplace—How Defunct Companies Sold Employee Data

A concrete and documented privacy concern emerged in April 2026 when the startup SimpleClosure created a marketplace allowing companies to liquidate their digital assets before shutting down. This included selling Slack message archives to AI training companies. According to reporting by Gizmodo, approximately 100 transactions took place through SimpleClosure, with payments ranging from $10,000 to $100,000 per company archive. The implication is stark: employees who typed messages into a company Slack workspace had no knowledge that their communications might be sold to third parties for AI training after the company dissolved.

The SimpleClosure situation reveals a gap in legal protection that existing Slack privacy policies do not address. If a company uses Slack, stores years of internal communications there, and then sells that archive to an AI training company or data broker, Slack is not the entity causing the harm—the company selling the data is. However, employees may not have consented to this sale, may not know it happened, and may not have any contractual relationship with the purchasing AI company that would give them standing to sue. This represents a real privacy threat that falls outside the framework of a Slack class action but affects Slack users nonetheless.

What Slack’s Privacy Policies Actually Protect (and Don’t)

Slack’s current terms of service specify that Slack is a processor of customer data, not the owner. This means that the company paying for Slack (your employer, typically) controls what happens to the data within the workspace. Slack’s responsibility is to secure the data and use it only as instructed by the customer. However, this legal framework creates ambiguity around employee rights: you did not sign a contract with Slack, your employer did, so your direct claims against Slack are limited compared to your employer’s potential claims.

For employees concerned about their privacy, the key limitation is this: you have no direct contractual relationship with Slack, and Slack’s privacy commitments are made to the company, not to individual workers. This is why a class action by individual employees against Slack (rather than by a company against Slack for breach of service terms) faces structural hurdles. You would need to prove that Slack violated a duty it owed to you specifically, not just that it violated a contract with your employer. Additionally, if your company authorized data use or sale (even if employees didn’t know about it), Slack may argue it was following customer instructions. A successful class action would require clear evidence that Slack exceeded its authority or lied about its practices—not merely that employees feel betrayed by how their company or third parties handled data.

How to Check if Your Data Was Sold Through SimpleClosure

If your company used Slack and has since closed down, there is no simple way to determine whether your message archives were sold through SimpleClosure or other data brokers. SimpleClosure did not publicize a comprehensive list of transactions, and companies were not required to notify employees before selling digital assets. Your most direct avenue is to contact your former employer’s legal department or its liquidation administrator and ask whether Slack data was transferred or sold.

If the company is defunct or unresponsive, check any final communications you received from the company—layoff notices, wind-down documents, or liquidation announcements—to see if data sales were mentioned. A secondary step is to monitor your credit and online accounts for unusual activity that might indicate your personal information was compromised. While Slack messages are business communications rather than financial data, a sale that included message archives to fraudulent actors could expose you to targeted phishing or social engineering based on information from your past work communications. Consider placing fraud alerts with credit bureaus if you’re concerned, though this is a precaution rather than evidence of actual harm.

What Employees Should Do If They Suspect Their Data Was Misused

If you believe your Slack data was misused—whether by your employer, Slack itself, or a third party—document what you know. Gather any communications from your employer about data sales, liquidation, or AI training uses. If your company was acquired or merged, check whether privacy notifications were sent; acquisitions sometimes trigger unexpected data transfers. Save any emails, memos, or announcements that reference Slack data handling. Next, consult an employment or privacy attorney in your state.

Class action claims are typically evaluated by lawyers who specialize in this area, and an initial consultation is often free. Bring your documentation and describe the timeline: when did you work at the company, how long was the Slack workspace active, and when did you learn (or when should the company have disclosed) that data might be sold or used for AI training. An attorney can assess whether you have an individual claim, whether a class action exists or should be filed, and what damages might be available in your jurisdiction. Some states offer statutory damages for privacy violations without requiring proof that you personally suffered quantifiable harm, while others require you to demonstrate actual injury. The availability of class action mechanisms varies by state and federal law, so legal guidance specific to your situation is essential before pursuing claims.


You Might Also Like

Caring for someone with dementia? Find practical guides at HelpDementia.com. Working out a skin routine? Evidence-based answers at AcneAdvocate.com. Forgot the name of a movie? Identify it at FindThisMovie.com. Was your data exposed? Track active breaches at DataBreachRadar.com.

We use cookies to run this site, measure how it’s used, and show ads. Choose “Essentials only” to limit cookies to what the site needs to work. Privacy Policy.