Security and procurement
Clear answers before you bring recognition into Slack
Review the permissions Karl requests, the information used to provide the service, and how to request current procurement materials for your team.
Slack-authorized access
Karl uses Slack OAuth and the permissions shown during install to support kudos, values, leaderboards, and recognition messages.
Stripe-handled billing
Payment details are tokenized by Stripe. Karl keeps the billing identifiers needed to manage the workspace subscription.
Procurement support
Contact us for the current data-processing, subprocessor, privacy, and security materials your review requires.
Slack permissions
Access is visible during installation
Slack presents the requested scopes to the workspace admin before approval. The current modern Karl install uses the following scopes:
app_mentions:read
Respond to mentions of Karl.
channels:read
Identify channels where Karl is invited.
chat:write
Post recognition and help messages.
commands
Support Slack slash commands.
im:history / im:write
Support direct-message help flows.
reactions:read / reactions:write
Support recognition reactions.
users:read / users:read.email
Identify workspace members for recognition and account support.
Information Karl uses to provide the service
Workspace and account information: Slack workspace identity, the installing user, and member information needed to make recognition work.
Recognition activity: kudos, values, reactions, channel context, and team settings needed to show recognition in Slack and the dashboard.
Billing information: Stripe customer, subscription, invoice status, and limited payment-method details such as brand and last four digits for account management.
Acquisition data: anonymous attribution fields such as landing page, campaign parameters, and an attribution session used to measure install and trial conversion. This is kept separate from the dashboard's team-facing response.
Frequently asked questions
What Slack permissions does Karl request?+
The current modern install requests permissions for app mentions, reading channels, posting messages, slash commands, direct-message history and writing, reactions, and reading users and user email addresses. Slack shows the final permission screen before an admin approves the install.
Does Karl store payment card numbers?+
No. Upgrade and payment-method forms use Stripe.js to tokenize card details. Karl stores the Stripe customer and subscription identifiers needed to show billing status and manage access.
How can procurement request security documents?+
Email support@trykarl.com with your company, the documents you need, and your target timeline. We can coordinate current privacy, data-processing, subprocessor, and security-questionnaire requests.
Ready to review Karl with your team?
Start with the 30-day free trial, or contact us for procurement questions before installation.
