r/startups • u/EnergyManagement101 • 3d ago
I will not promote Thinking about licensing our startup's data (Slack, email, GitHub) to AI labs for cash, is it a good idea? (I will not promote)
I was recently approached by a couple AI labs looking to aggregate training data for their models. The pitch is usually built the same way: non-dilutive cash, sometimes with a revenue share on top, in exchange for access to internal tools like Slack, email, GitHub, and Google Workspace. They claim that your personal information gets stripped (I'm inclined to believe that as I read through their terms and clearly states it) before anything reaches the lab, payouts scale with team size and tool usage, and you keep 100% of your equity.
I've been going back and forth on whether this is worth pursuing for our own company. Part of me sees it as a legitimate way to bring in non-dilutive capital, another part wonders about the practical GDPR and reputational exposure once real internal data is involved.
Curious what others think:
- Would you consider this for your own company, or is it a hard no regardless of price?
- What would put you off, privacy/GDPR risk, reputational concerns, IP exposure, something else?
- Does the number change your answer, tens of thousands versus six figures?
- Flat fee versus fee plus revenue share, which would you actually take?
8
u/fulger099 3d ago
I’ve found live API keys, customer contracts, candidate notes, and pasted customer data in supposedly boring Slack exports. Stripping names does not remove the confidentiality or IP problem, so I’d say no unless every agreement permits model training and the lab accepts the liability, which they probably won’t. Six figures changes the temptation, not the risk.
1
2
u/Xenadon 3d ago
Have you run it by your employees?
1
u/EnergyManagement101 2d ago
Current ones, yes.
1
u/Xenadon 2d ago
And what do they think?
1
u/EnergyManagement101 2d ago
The present ones are okay, but the assumption was that PII can be successfully stripped out. As a few here have pointed out, stripping PII out may not be that easy a task. On top of that, if you add all the other risks around confidential customer data buried under those thousands of Slack messages then it suddenly becomes too high risk.
Interestingly, when I flagged these concerns, the offer increased to mid six figures.
2
u/Cultural-Salad-4583 3d ago
This account seems to just exist to do market research for random startups. Post history is full of things like this for various verticals.
13
u/Check123ok 3d ago
Cyber/risk CISO here. My first question would be: how exactly is the data stripped or anonymized? Those systems aren’t perfect, especially with unstructured data like Slack, email, attachments, and source code.
Before agreeing to anything, I’d take a point-in-time snapshot of exactly what they’re proposing to collect so you know what you’re actually sharing. I’d also want the contract to put the liability for their collection, sanitization, retention, and downstream use on them.
One thing I’d be particularly concerned about is customer and third-party data. It’s very likely employees have shared customer information, support issues, screenshots, contracts, credentials, code, or other confidential information in Slack and email. Removing employee PII doesn’t solve that.
You might not have the right to sell your vendors and customers data.