Privacy Policy
Last updated October 7, 2026
This privacy policy explains how Hop On, a Slack app made by Intrepide
("we", "us"), accesses, uses, shares, protects, retains and deletes your data, including
Google user data. Hop On adds a /meet command to Slack that creates a Google
Meet meeting on your Google account and posts the join link to your Slack conversation. This
policy covers the Hop On app and the website at hopon.intrepide.ai. The rest of intrepide.ai is
covered by the Intrepide privacy policy.
1. Google user data we access
When you click Connect Google, Hop On asks for one Google permission (OAuth scope):
https://www.googleapis.com/auth/meetings.space.created, which lets the app create
Google Meet meeting spaces and manage only the meetings that Hop On itself created. With it we access:
- An OAuth refresh token and short-lived access tokens that Google issues so Hop On can act on your behalf.
- Details of the meetings Hop On creates for you: the meeting link
(for example
https://meet.google.com/abc-defg-hij), the meeting code, and the meeting space ID, as returned by the Google Meet API.
Hop On does not access your name, email address, profile photo, contacts, calendar, Gmail, Drive, other meetings, meeting recordings, transcripts or participants, or any other Google user data.
2. How we use Google user data
We use Google user data only to provide Hop On's user-facing feature: each time you type
/meet (including right after you first connect, to start the meeting you asked for),
we use your token to create a new meeting on your Google account and post that meeting's join
link to the Slack conversation where you typed the command. We do not use Google
user data for any other purpose. Specifically, we do not use it:
- for advertising, including targeted, personalized or interest-based advertising;
- to sell to or share with data brokers or information resellers;
- to determine credit-worthiness or for lending purposes;
- to develop, improve or train generalized or non-personalized artificial intelligence or machine-learning models. Hop On does not use Google Workspace API data, or any other Google user data, to develop, improve, or train AI or ML models.
No person at Intrepide reads Google user data, except with your explicit permission (for example, when you ask us for support), when needed for security purposes such as investigating abuse, or to comply with the law.
3. How we share, transfer or disclose Google user data
We do not sell, rent or share Google user data. It is disclosed only:
- To Slack, at your request. The meeting link Hop On creates is posted to the Slack
conversation where you typed
/meet, so the people in it can join. This is the purpose of the app. - To our hosting provider, Cloudflare, Inc. Hop On runs on Cloudflare Workers, and your encrypted token is stored in Cloudflare Workers KV. Cloudflare processes this data only to host the app on our behalf.
- When required by law, such as to comply with a valid legal process.
4. How we protect Google user data
- Your Google refresh token is encrypted with AES-256-GCM before it is stored. The encryption key is kept as a separate secret and is never stored alongside the data.
- All traffic between Slack, Google, your browser and Hop On uses HTTPS (TLS).
- Every request from Slack is checked against Slack's signing secret, and the Google connection link is signed and expires after 10 minutes, so only you can link your Google account to your Slack user.
- Tokens are never written to logs. Access to the production systems and their secrets is limited to Intrepide administrators.
5. Retention and deletion of Google user data
- How long we keep it: your encrypted refresh token is kept only while your Google account is connected to Hop On. Access tokens are used immediately and never stored. Meeting links and codes are not stored by us; they exist only in your Slack conversation and your Google account.
- Delete it yourself, any time: type
/meet disconnectin Slack. We immediately delete your stored token and revoke it at Google. - Revoke from Google: remove Hop On at myaccount.google.com/permissions. The token stops working right away.
- Uninstall: when a Slack workspace uninstalls Hop On, we automatically delete every stored token for that workspace and revoke them at Google.
- Ask us: email alex@intrepide.ai and we will delete your data within 30 days.
Limited Use
Hop On's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data we receive from Slack
- On install: the workspace ID and name, which we store to know the app is installed. Slack also issues an access token; we discard it and never use it.
- On each
/meet: the workspace ID, your Slack user ID, the channel ID, any text after the command, and a one-time reply URL. We use these only to answer that command. We store your workspace ID and user ID to remember which Google token is yours. We do not store channel IDs or message text.
Hop On's only Slack permission is commands. It cannot read messages, files, or
member lists.
Cookies, logs and fonts
The app sets one short-lived cookie during "Add to Slack" to protect the install against forgery. It expires after 10 minutes. There are no analytics or advertising cookies. Our hosting provider keeps short-lived request and error logs (timestamps, paths, status codes) for debugging and security; these never contain tokens. These pages load fonts from Google Fonts, which receives your IP address as part of serving them.
Children
Hop On is intended for workplace use and is not directed at children under 13.
Changes to this policy
If this policy changes, we will update the date above. If we change how Hop On uses Google user data, we will update this policy before the change takes effect and ask for your consent again where required.
Contact
Intrepide · alex@intrepide.ai · intrepide.ai