Privacy · last updated 6 August 2026
Who sees what
Five questions, answered in the first sentence each, with the evidence underneath. Nobody is routed anywhere and neither answer has a catch.
01
Who can see how I voted?
One person, ever: the coworker you praised. Not your manager, not your workspace admin, not the person who installed kudoSnap, not the workspace, and not us in any list we could show someone.
And they don't see it automatically — they have to answer a question of their own first. That's deliberate. Wanting to know who noticed you is exactly what makes you stop and notice someone else, and it's the reason the thing works at all.
So “anonymous” isn't quite the right word for it, and we'd rather be precise than flattering: recognition arrives unsigned, and the person who received it can find out who sent it by taking part. What never happens is anyone else seeing it.
How the vote is stored, and what can read it
Votes are stored linked to voter and recipient, because the reveal needs both. What matters is what reads them: no query returns votes by voter, no screen in the product displays them that way, and there is no export — no CSV, no report, no admin download, in any format, to anyone.
Reveals are free once you've answered a poll of your own, so this is a normal part of using kudoSnap rather than a rare event. It only ever runs one direction: someone can learn who praised them. There is no direction in which you can look up how somebody else voted.
02
Can kudoSnap read my Slack messages?
No. We never request the permission that would let us. kudoSnap can see which channels exist and who's in them — that's how it figures out who you actually work with — and it can send you a DM. That's the whole footprint.
All seven permissions, and what each one is for
These are every permission kudoSnap asks for at install. Not the important ones, not a summary: all of them.
| Permission | What it lets us do | What it does not |
|---|---|---|
| channels:read | See which public channels exist and who's in them | Read a single message in any of them |
| groups:read | See who's in a private channel the bot was invited to | Read those messages, or see private channels it wasn't invited to |
| mpim:read | See who's in a group DM the bot is part of | Read those messages |
| users:read | See names, avatars, and timezones from the member directory | See email addresses — that's a separate scope we don't request |
| users.profile:read | Read the department field your Slack admin defined, so recognition can be grouped by team | Read profile fields we don't ask for, or any custom field's history |
| chat:write | Send you a DM and draw the app's Home tab | Post in any channel, public or private |
| team:read | See your workspace's name and email domain | See anything about the individuals in it |
None of them read message content. Reading messages requires a history scope, and there isn't one in this list.
03
What does my company see?
The same thing you see. kudoSnap has one dashboard, it shows patterns rather than people, and anyone in your workspace can sign into it with Slack. There is no admin version with more in it.
This month in your workspace
- of people heard something specific and good about themselves
- 63%of people heard something specific and good about themselves
- answered at least one question
- 71%answered at least one question
- people haven't been recognized yet
- 9people haven't been recognized yet
Most noticed: Connection, then Delivery
Everyone in this workspace can sign in and see this. There is no admin version with more in it.
The real one lives at admin.kudosnap.com. Sign in with Slack — if you're in the workspace, you're in.
What is actually on that dashboard
Five surfaces, and it's worth being specific because “a dashboard” is exactly the kind of word people fill in with the worst version:
- Pulse — how many people got recognized, how many are answering, how quickly, over time. Counts and rates, workspace-wide.
- Culture — which kinds of strengths this workspace notices most. Four categories, no names.
- Departments — the same counts grouped by the department field in Slack, and how recognition moves between teams. This exists, it is not hidden, and it is visible to everyone rather than to managers. It shows team-level totals and never who voted for whom.
- People — profile cards, and only ones their owner chose to publish. Nothing appears here because someone else decided it should.
- Questions — which questions have been asked and how often they get answered.
What isn't there: any view scoped to one manager's reports, any ranking or “most recognized” list, any individual's votes, and any export. There is no manager view — not a setting someone left switched off, but a screen and a query that don't exist. The reasoning is that the moment recognition can be filtered to one person's team, it becomes something you can be measured with, and then nobody answers honestly.
Adding that dashboard required zero additional Slack permissions. It's built entirely from votes people chose to cast inside kudoSnap.
04
What's stored?
Your Slack user ID, your name and avatar as Slack reports them, your timezone, your job title and department if your workspace fills those in, which channels you're in, the questions we sent you, and who you picked.
Every field kept, and the ones we never request
Not your messages — we can't read them. Not your email address — we don't request the scope that returns it, though we do store your workspace's email domain from install. Not anything you typed, because there is nothing to type: every answer is a tap on one of four names.
Timezone is used to send questions during your working hours rather than at 3am. Channel membership is used to work out who you actually work with, so the four names are people you know. Department, when your Slack admin has defined that field, is what makes the team-level view possible.
Subprocessors, retention, and how deletion actually works are on /security.
05
How do I get out of it?
Email hello@kudosnap.com and we'll stop sending you questions. It's a person, not a form, and it takes about a day.
What opting out looks like today, honestly
Being honest about the shape of this: there is no self-serve opt-out button yet. One is being built into the app's Home tab in Slack, and this page will change the day it ships. Until then the email address is the mechanism, and it works — we set a flag on your account and the scheduler skips you from then on.
You may still receive recognition after that, because that's someone else's message to you rather than ours. Say so in the email and we'll stop that too.
Removing the app from the workspace stops everything for everyone, immediately. Erasing what's already stored is a separate step and currently a manual one — /security says exactly how that works, including the part we haven't automated yet.
Check it yourself
Something on this page not match what you're seeing? Tell us at hello@kudosnap.com. The dashboard is at admin.kudosnap.com if you'd rather look for yourself.