← bleeper

Privacy

Last updated 27 July 2026

This page describes how Bleeper actually works, written and checked against the software itself. It has not yet been reviewed by a lawyer. If you need contractual certainty before adopting Bleeper, ask us — we would rather answer the question than have you rely on wording we drafted ourselves.

What Bleeper stores

Bleeper runs incidents in Slack and keeps the record of them. Concretely, we store:

  • Your account: name, email address, and login credentials or the Google account you signed in with. Also which organization you belong to and your role in it.
  • Your organization: its name, plan, the incident types and severity levels you configure, and your reminder settings.
  • Incidents: title, severity, type, status, when it opened and resolved, and the Slack channel it ran in.
  • Timeline messages. When you run /incident update, the text you write is stored. When someone reacts to a Slack message with 📌, Bleeper reads that message and stores its text as a follow-up. Message content is stored, not just referenced.
  • Follow-ups: their text, owner, status, and any linked GitHub or Linear issue.
  • Not the rest of the conversation. The incident page can show what was said in the incident’s Slack channel. Those messages are read from Slack each time you open that tab and are never stored by Bleeper, not even cached — so your own Slack retention rules keep governing them. Only members of a private incident’s channel can read its conversation here.
  • Slack identifiers: your workspace id and the user ids of people who take part in incidents. We look up display names and email addresses from Slack to show names instead of raw ids, and to work out who may see a private incident. These are cached for about a day.
  • Credentials for connected tools: the Slack bot token created when you install the app, and access tokens for GitHub or Linear if you connect them.

We do not store card details. Payments are handled entirely by Creem, and card data never reaches our servers.

What we don't do with it

We don’t sell it, we don’t share it with advertisers, and neither we nor Cloudflare use your incident content to train machine-learning models.

AI features

Paid workspaces can have Bleeper draft postmortems, follow-ups and stakeholder updates. Where that happens, the incident material is processed by Cloudflare Workers AI — the same infrastructure Bleeper already runs on, not a separate AI vendor. Cloudflare does not train models on it, and nothing sent for a draft is kept afterwards: the drafts themselves are stored, the material they were written from is not.

An admin chooses what those features may read, under Settings → General → AI access. There are three settings and the default is the middle one:

  • Off — nothing is sent, and no AI feature runs.
  • Bleeper’s records only (default) — timeline entries, follow-ups and incident details. Never the conversation.
  • Records and the incident channel — also the messages and files in each incident channel, including private incidents.

Free workspaces have every AI feature switched off regardless of this setting, and upgrading to a paid plan does not change it — reading the channel is always something somebody has to turn on.

Who else processes it

Bleeper is a small system with a short list of sub-processors:

  • Cloudflare — hosting, databases, caching, outbound email (sign-in links and invitations), and the AI features above.
  • Slack — where incidents actually run.
  • Creem — payments, as merchant of record, for paid plans only.
  • GitHub and Linear — only if an admin connects them, and only for the follow-ups mirrored there.

Bleeper runs on Cloudflare’s network and its databases are not pinned to a single region by default, so your data may be stored or processed outside your own country.

Private incidents

An incident marked private opens an invite-only Slack channel, is never mirrored to an issue tracker, and on the dashboard is visible only to organization owners and admins plus the people in that Slack channel. It still counts toward aggregate statistics like mean time to resolve — the numbers include it, the details don’t.

How long we keep it

While your organization exists, its incident history is kept indefinitely — that’s the point of a postmortem record. If you want it gone sooner, an admin can delete the organization.

When an organization is deleted, its incidents, timelines and follow-ups are destroyed after a 30-day grace period. The grace period exists so an accidental deletion can be undone. Account records tied to the organization are removed immediately. Cached Slack display names and email addresses expire on their own within about a day.

Backups and logs may briefly retain traces after that window; logs are kept short and contain identifiers, not incident content.

Getting your data out

Any owner or admin can export everything their workspace holds as a single JSON file from Settings → General, at any time, with no request to us. That is also the fastest answer to a subject access request. If you need something the export doesn’t cover, ask.

Cookies

Bleeper sets a cookie to keep you signed in, and short-lived cookies during the Slack, GitHub and Linear connect flows to protect against request forgery. There are no advertising or analytics cookies.

Your rights and contact

Depending on where you live you may have rights to access, correct, export or delete your personal data. The export and organization-deletion controls above cover most of these directly. For anything else — including questions about this policy — contact us and we will answer.