AI you switch on, in one conversation, on purpose
Every AI feature here is off by default, quarantined to a clearly-labelled conversation, and gated behind a consent step the server actually enforces.
The boundary is cryptographic, not a checkbox
The assistant is a real account with an empty public key. Your device therefore cannot derive a key to encrypt to it. Talking to the assistant is not "encryption turned off" — it is a conversation that was never encryptable in the first place, and the client knows it.
- Voice is kept out of that conversation altogether, so no recording of anyone can reach it
- The app shows an open-lock badge wherever end-to-end encryption is absent by design
- A green padlock on an unencrypted conversation is worse than no padlock at all
Consent that the server enforces
The first message any individual sends to the assistant is refused with an explicit consent requirement, and the refusal explains what accepting means. It is per-user, because those are that person's words, not their employer's.
- It will not switch on until that person has said yes — and we enforce that, rather than a pop-up the app could skip
- Org admins must separately enable the feature, behind their own acknowledgement in the console
- Both the org setting and the per-user consent are recorded in the audit log
How this differs from the category
The usual arrangement is that switching on AI means letting a company read everything across your whole account. Ours only sees the one conversation you deliberately open with it.
- On-device transcription is the AI feature we lead with, and it preserves end-to-end encryption entirely
- The assistant is the one place content is readable, and it is labelled everywhere it appears
- We do not currently offer AI summaries of your channels, and we will not add them silently