Sign in
๐Ÿ”’ Security & privacy

Built to ask for as little as possible

Trombingo requests the minimum Slack permissions it needs, keeps almost nothing, and protects what little it stores.

๐Ÿ”‘

Sign in with Slack (OpenID Connect)

Authentication goes through Slack's standard OpenID Connect flow. We never see or store your Slack password.

๐ŸŽฏ

Least-privilege scopes

The bot uses a single lightweight users:read permission to list workspace members. Sign-in requests only your basic identity and email.

๐Ÿ–ผ๏ธ

Nothing scraped, nothing hoarded

Profile photos and names are fetched live from Slack at game time and shown only to run the round โ€” not archived.

๐Ÿ”

Encrypted secrets

Slack bot tokens are encrypted at rest, and all traffic is served over HTTPS.

๐Ÿ‡ช๐Ÿ‡บ

EU hosting

The app and its database run in the EU (France region), on Fly.io with a managed Neon PostgreSQL database.

๐Ÿ—‘๏ธ

Automatic deletion

Uninstalling Trombingo from a workspace notifies us instantly and deletes that workspace's data โ€” players, scores, games, and tokens.

What we store

  • โ€ข Your Slack user & workspace IDs, name, and email, to identify you and link your workspaces
  • โ€ข Game scores, to power the leaderboards
  • โ€ข An encrypted bot token per workspace, to fetch members at game time

What we don't

  • โœ“ No copies of profile photos
  • โœ“ No message or channel access
  • โœ“ No selling or sharing of your data

Responsible disclosure

Found a security issue? We appreciate responsible disclosure. Email contact@trombingo.com with the details and we'll respond as quickly as we can.

๐Ÿฅธ

Ready to test your memory?

See how many teammates you can name before the clock runs out.