Slack permissions and message access
The Commissioner requests these bot permissions when a workspace installs it:
channels:history: receive public-channel message events and look up threads in channels the bot has joined.files:read: download submitted photos and retrieve file information for judging and appeals.chat:write: post rulings, replies, and league announcements.users:read: look up member display names and check workspace-admin status for officer actions.commands: respond to/standings,/newseason, and/halloffame.
This version handles public channels, not private-channel or direct-message events. Slack sends message events from public channels the bot belongs to, not only spider posts. The app examines those events for image submissions, appeals, and commands; unrelated messages are not added to the league record. Invite the bot only to channels intended for league play.
Photos and AI processing
The app downloads a submitted image from Slack using the workspace’s bot token. It normally orients and resizes the original photo, with a Slack-thumbnail fallback. It sends image content and the adjudication instructions to Anthropic’s Claude API to identify and score the find. An unclear photo can trigger a second AI request with an enlargement.
Appeals can send the original photo, a new evidence photo, and relevant details of the previous AI ruling. The AI request builder does not intentionally include the workspace’s bot token, member name, or Slack member ID. Anything visible in a submitted photo can nevertheless reach the AI provider. Keep people, private documents, and other sensitive material out of the frame.
There is no model-training workflow in this application. That does not establish Anthropic’s account-specific training, feedback, or retention settings. This page makes no guarantee of zero provider retention or exclusion from every provider training use; the operator must confirm the applicable account terms and settings.
What is stored
The application stores workspace-separated records in Netlify Blobs:
- Installation records: the workspace ID and name, bot access token and bot user ID, installer/commissioner ID, install time, and appointed officers.
- League records: member IDs and display names (or real names when no display name is set), submission IDs and timestamps, AI findings and scores, appeal status and grounds, and Slack file IDs and private image/thumbnail URLs used to retrieve evidence again.
- Season and operations records: the latest league channel, daily usage counters, season/reset information, archived champion and podium records, and event IDs used to deduplicate Slack retries.
The application code does not persist downloaded photo bytes in Blobs; it keeps Slack file references instead. Photos and the bot’s posted replies also remain subject to the workspace’s own Slack settings.
Retention and logs
Each league save keeps at most the most recent 500 submissions. Starting a new season clears the active submissions after recording the season’s champion and podium. Daily usage accounting replaces older usage counters when a new ruling is recorded.
The code does not set a time-based expiry for installation records, league records, season archives, or deduplication markers. There is no automatic purge schedule for those records. Function code logs errors and warnings, including provider error text; hosting services may also keep operational request logs. Log retention and backup/deletion timelines are not established by this repository.
Uninstalling is not full deletion
When a verified Slack app_uninstalled or tokens_revoked event reaches the app, it deletes the workspace’s installation record, including its stored bot token. That handler does not delete the league record, season archives, or event-deduplication records. Reinstalling can therefore restore access to retained league history.
A member can ask the bot to withdraw their own find in its thread. That removes matching active league entries; it does not erase season archives, Slack photos or messages, provider records, or logs. Deleting a Slack message alone is not an application-data deletion request.
For a broader deletion request, use the support contact route and identify the workspace and records concerned. There is no automated full-deletion endpoint or guaranteed deletion turnaround in this version.
The website and questions
The install flow uses a short-lived, secure, HTTP-only cookie to check the OAuth response. The static pages request fonts from Google Fonts; the optional dues link opens Stripe. The page code does not include a website analytics script. This describes the checked-in application, not every hosting-provider setting or third-party service policy.
Spider League is published by Coast Studio. For privacy questions or help with a request, start with Support.