Cost Nudge Privacy Policy

Cost Nudge Privacy Policy

Cost Nudge Privacy Policy

Version 1.4 · Effective date: August 25, 2026

Supersedes Version 1.3, effective July 29, 2026.

This policy describes how Cost Nudge Industries, LLC (“Cost Nudge,” “we,” “us”) collects, uses, and shares data in connection with the Cost Nudge service — the end-user component that displays meeting cost, its companion admin dashboard, and the backend services behind them (together, the “Service”).


Summary

This summary is for convenience. The numbered sections below control.

Cost Nudge shows meeting organizers an approximate labor cost for the meetings they schedule, and gives their employer aggregate reporting on meeting cost. It is sold to businesses and installed by an employer’s IT administrator.

  • What we collect from a meeting: attendee email addresses, scheduled duration, start time, and calendar event identifiers — collected when we detect a newly created meeting, normally within seconds or minutes of it being saved.

  • What we do not collect: meeting titles, descriptions, agendas, locations, attachments, notes, chat, or recordings. We do not read email, files, or other workplace content beyond the calendar data described below.

  • What we keep: a per-meeting record containing a cost figure, a count of matched employees, the organizer’s email address, and the meeting’s scheduled time, duration, and calendar identifiers. Section 3.4 lists the full contents. Attendee email addresses are used only momentarily on our servers to compute the cost figure and are not stored in the record.

  • Individual salaries: never uploaded to the Service. Cost is computed from broad salary bands that each Customer defines offline, before any data reaches us — so we never receive an individual’s pay. Cost is shown only for meetings with at least three matched employees, and as an approximate range rather than an exact figure. Together these prevent a cost figure from revealing any individual’s pay.

  • We do not sell personal information, use it for advertising, or use it to train AI or machine-learning models.

  • Your employer controls this data. We process it on their instructions. Requests to access or delete your data should go to your employer first.


1. Scope

This policy covers:

  • The Cost Nudge end-user component, which displays an in-context meeting-cost badge to meeting organizers inside their calendar application. Cost Nudge is currently delivered as a browser extension for Google Chrome. If we add other delivery mechanisms, we will update this policy to describe them, and update the effective date above.

  • The Cost Nudge admin dashboard, used by an organization’s designated administrators to view aggregate meeting-cost analytics.

  • The Cost Nudge backend (Google Cloud Functions and Cloud Firestore), which performs all cost calculations and stores organizational data.

Cost Nudge is a business-to-business product. It is deployed to an organization’s employees by that organization’s IT administrator. If you are an individual employee using the Service because your employer has installed it, your employer’s own privacy notices and policies also apply to you, and your employer controls certain settings and data described below.

This policy does not cover third-party websites, services, or products, including Google Workspace or Stripe, except as described in Section 8 (Data Sharing & Sub-processors).


2. Controller vs. Processor Roles

For data protection purposes, the organization that subscribes to Cost Nudge (your employer, the “Customer”) is the data controller of the meeting, employee, and organizational data processed through the Service. Cost Nudge acts as the Customer’s data processor (or “service provider” under U.S. state privacy laws): we process data on the Customer’s behalf and according to the Customer’s instructions, as reflected in the Customer’s subscription agreement with Cost Nudge.

If you have questions about how your employer uses meeting-cost data, please contact your employer’s IT, People Ops, or Finance team directly. If you have questions about how Cost Nudge itself processes data as a processor, see Section 17 (Contact).


3. Information We Collect

3.1 Organizer identity

When an employee first uses the Service, it authenticates the user against their organization’s workplace account and establishes a signed-in identity through Firebase Authentication. We receive the user’s email address, basic profile information, and a Firebase user identifier. Sign-in through the organization’s existing workplace identity provider is the sole authentication method; Cost Nudge does not create or store passwords.

To do this, the Service requests read-only access to the signed-in user’s calendar — a sensitive Google permission — used solely to detect meetings the user creates for the cost capture described below. It does not request access to Gmail, Drive, or any other Workspace content, and this permission does not allow it to create, modify, or delete calendar events.

3.2 Meeting data captured for newly created meetings

When the Service detects that the signed-in user has created a new meeting, it collects the following fields so that a per-meeting labor-cost estimate can be computed. Detection normally occurs within seconds or minutes of the meeting being saved.

  • Attendee email addresses, as they appear in the meeting’s guest list, so the backend can match them against the Customer’s employee roster and determine whether the meeting meets the eligibility threshold described below. Because eligibility is evaluated on our servers, attendee email addresses are transmitted for every saved meeting, not only those that ultimately qualify.

  • Scheduled meeting duration, scheduled start time, and calendar event identifiers (used to prevent duplicate cost records for the same event).

  • For recurring meetings, recurrence linkage information (a series identifier, whether the event is a recurring instance, and the instance date), so that recurring-series cost attribution can be applied correctly.

  • Organizer email address and Firebase user ID.

What is actually stored, and the eligibility gate. Attendee email addresses are used only transiently, on our servers, to determine how many attendees match active employees in the Customer’s roster. A persistent per-meeting cost record is created only if at least three attendees match active employees (the “eligibility threshold”). If fewer than three attendees match, no cost record is written and no meeting data is retained. When a record is created, it contains only the fields listed in Section 3.4 — it does not contain individual attendee email addresses, individual attendee identities, or attendee RSVP status. Raw attendee email addresses are a one-time matching input and are not written to Cost Nudge’s database.

This capture happens automatically for each qualifying new meeting while a trial or subscription is active. It is not limited to meetings where the cost badge is visibly displayed to the organizer: during the initial baseline period of a trial, the badge is intentionally hidden while capture continues, so that the Customer can compare scheduling behavior before and after the badge is switched on.

3.3 What we do NOT capture

  • Meeting titles, descriptions, agendas, attachments, or locations. Responses from a calendar provider’s API can include such fields, but the Service does not extract, transmit, or store them; they are discarded at the point of detection.

  • Meeting content, notes, chat, or recordings.

  • Email, files, documents, or any other content in the user’s workplace account.

  • Edits or cancellations of existing meetings. In the current release, data capture occurs only on new meeting creation; editing or cancelling a meeting afterward does not update or remove its cost record.

  • Individual employee salaries. See Section 9.

3.4 Cost record fields (what is actually stored per meeting)

Each per-meeting cost record stored in the Customer’s organization data contains: calendar event ID, organization ID, organizer Firebase user ID, organizer email address, calculated cost, display tier, count of matched eligible attendees, scheduled duration, trial phase, capture timestamp, scheduled start time, and — for recurring meetings — recurrence linkage fields. Cost records are immutable once written.

3.5 Live cost preview (badge)

When the Service displays the in-context cost badge to an organizer, it sends attendee email addresses and duration to a separate, read-only backend function that returns only an aggregate total cost, a matched-attendee count, and a yes/no “below threshold” flag. This preview function does not create or store any record; it exists only to render the badge in real time. No individual attendee data and no salary or rate data is returned to the end-user component.

3.6 Employee roster data (provided by the Customer)

Separately from employees’ use of the Service, the Customer’s administrator uploads a file listing the organization’s employees — work email, assigned salary band, a midpoint value, and department — using a Cost Nudge-provided template. From the band midpoint supplied on each employee’s row we also compute and store an hourly rate, as described in Section 9. We record whether each employee is active: everyone in the latest uploaded file is active, and anyone missing from it is marked inactive. Active status is not a column in the file. This roster is used on our servers to match meeting attendees and compute cost. It comes from the Customer, not from individual employees’ use of the Service, and is described here for completeness.

3.7 Account and billing data

If your organization converts from trial to a paid subscription, our payment processor (Stripe) manages billing. Stripe receives only organization-level billing information, such as the organization name and an administrator’s billing contact email. Stripe never receives meeting, attendee, or salary data. Cost Nudge does not receive or store full payment card numbers.


4. How We Use Information

We use the information described in Section 3 solely to:

  • Authenticate users and enforce organization-scoped access to data.

  • Compute and display approximate meeting labor cost to meeting organizers.

  • Compute aggregate, organization-level analytics for the Customer’s admin dashboard.

  • Enforce the eligibility, privacy-tiering, and abuse-prevention rules described in Sections 3.2 and 9.

  • Operate, secure, and troubleshoot the Service.

We do not use meeting or attendee data for advertising, and we do not sell personal information.


5. Use of Data from Calendar Provider APIs

Cost Nudge’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Where the Service uses another provider’s calendar APIs, we apply the same commitments. Specifically:

  1. Limited to user-facing features. We use data obtained through calendar APIs only to provide and improve the meeting-cost features described in this policy.

  2. No transfer for unrelated purposes. We do not transfer this data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets, in which case we will require the recipient to honor this policy.

  3. No advertising. We do not use this data for serving advertising of any kind, including retargeting, personalized advertising, or interest-based advertising.

  4. No human reading. We do not allow humans to read this data unless (a) we have the user’s or the Customer’s explicit consent for specific data, (b) it is necessary for security purposes such as investigating abuse or a suspected incident, (c) it is required to comply with applicable law, or (d) the data has been aggregated and anonymized.

5.1 Artificial intelligence and machine learning

We do not use data obtained through calendar APIs, meeting data, attendee data, employee roster data, or any Customer data to develop, train, retrain, or improve any artificial intelligence or machine-learning model, whether our own or a third party’s. We do not provide such data to any third party for those purposes.


6. Legal Basis

Where applicable data protection law requires a legal basis for processing, Cost Nudge processes personal data as a processor on behalf of the Customer, under the Customer’s instructions and its own legal basis. Questions about the legal basis for a specific organization’s use of Cost Nudge should be directed to that organization.


7. Automated Decision-Making

Cost Nudge does not make automated decisions about individual employees, and it does not produce individual-level output. The Service computes costs and analytics at the meeting and department level only. It does not score, rank, evaluate, or profile individual employees, and it is not designed or intended for use in employment decisions.


8. Data Sharing & Sub-processors

We share data only with service providers necessary to operate the Service, under contractual confidentiality and data-protection obligations:

  • Google Cloud Platform / Firebase (Cloud Firestore, Firebase Authentication, Cloud Functions, Firebase Hosting) — hosting, database, authentication, and compute for the Service. Data involved: all Service data described in Section 3.

  • Stripe — subscription billing. Data involved: organization-level billing and contact information only (see Section 3.7); no meeting, attendee, or salary data.

Changes to sub-processors. We will notify Customer administrators before adding a new sub-processor that processes Customer personal data, so the Customer has an opportunity to object.

The Cost Nudge end-user component contains no third-party analytics code, no advertising code, and no remotely-hosted code. Its network communication is limited to Google’s own services (for sign-in and calendar access) and Cost Nudge’s own backend; it sends no data to any analytics provider or advertiser.

We do not sell personal data, and we do not share data with third parties for their own marketing purposes.

We may disclose information if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of Cost Nudge, our customers, or others.


9. Salary Privacy Safeguards

Cost Nudge is designed so that a cost figure produced by the Service cannot be used to determine any individual employee’s salary or compensation. Three layered safeguards produce this result:

  1. Minimum-attendee threshold. A cost figure is computed and shown only when at least three matched employees are in a meeting, so a cost estimate cannot be attributed to a single individual’s rate.

  2. Salary bands, not individual salaries. Cost is computed from organization-defined salary bands (currently six), using a midpoint value provided on each roster row — never from an individual employee’s actual salary. Each Customer defines its own bands offline, using a Cost Nudge template, and assigns each employee to a band before uploading the roster. The upload carries a midpoint value on each roster row, but has no column for an individual’s salary or hourly rate. If a file includes one anyway, that column is never read — each row is projected onto the four expected columns and nothing else is consulted — and the uploaded file itself is not retained. From the band midpoint you supply for each employee, we compute and store an hourly rate. That rate comes from a band-level figure you chose, not from the employee’s own pay. No individual salary figure is read into or stored in the Service at any point.

  3. A range, snapped outward — never an exact figure. The badge shows the organizer an approximate cost with a range around it, for example ~$150 ($100–$200). Both ends are snapped outward to a fixed grid (currently $25): the low end down, the high end up, and the low end never below $0. Snapping outward is a privacy control rather than a rounding preference. The untouched distance between a meeting’s true low and high is exactly the sum of its attendees’ band widths across the meeting’s hours — so an unsnapped range would let someone read a meeting’s band composition off a single badge with one subtraction. Snapping both ends outward smears that distance across the grid, keeping what a badge can reveal at the level of bands rather than people.

Together these mean a badge is approximate by construction: pay enters only as a band, every figure is a blend of at least three people, and even the blend is shown as a snapped range rather than a number.

The dashboard works differently. Its figures are not snapped to a grid. They are organization- and department-level totals aggregated across many meetings and rounded to whole dollars. Aggregation, not snapping, is what protects individual pay on that surface — the underlying safeguards in points 1 and 2 apply to every record that feeds it.

No hourly rate, salary band midpoint, or per-attendee rate data is sent to or stored in the end-user component; all cost computation happens on our servers.

Administrative access. As with any hosted service, a limited number of Cost Nudge personnel hold administrative credentials to production infrastructure for operations, security, and support. Where that access would involve reading data obtained through calendar provider APIs, it is restricted to the limited circumstances permitted under Section 5(4) above. Because individual salaries are never present in the Service, no level of administrative access can expose an individual employee’s salary.


10. Data Retention

  • Cost records are immutable once written and are retained while the Customer’s subscription or trial is active.

  • When a trial expires without converting to a paid subscription, the badge is switched off and the organization’s data — cost records, employee roster, and salary bands — stays available on the dashboard for 30 days so the organization can review its results, then is permanently deleted.

  • On termination of a Customer’s subscription, the organization’s data — cost records, uploaded employee roster data, and salary bands — is permanently deleted within 15 days. Two things can extend that. The Customer has 10 days after termination to ask us for an export; if it does, we hold that data until the export is delivered, then delete it. And we keep data longer where the law requires.

  • Employee roster data is retained and updated as the Customer uploads new rosters. Records for employees no longer in an uploaded roster are retained for historical reporting but excluded from future attendee matching, until deletion under the termination timeline above.

  • Operational logs. Our cloud provider generates platform-level logs recording information such as request timing, status codes, and originating network address. These logs do not contain meeting, attendee, or salary data. They are retained on the provider’s standard schedule and used only for security and troubleshooting.

  • Customers may request deletion of their organization’s data at any time by contacting us (Section 17), subject to the terms of the Customer’s subscription agreement.


11. Security

We rely on Google Cloud Platform / Firebase infrastructure security, including encryption in transit and at rest and access-controlled service accounts, to protect Service data. Within the Service, access to organizational data is restricted by role-based Firestore security rules: dashboard-level aggregate data is limited to users holding an assigned administrative role (System Admin, People Ops, or Finance) within their own organization, and all cost-record writes are performed exclusively by server-side Cloud Functions — no client application can write cost, employee, or salary-band data directly.

Incident notification. If we become aware of a security incident affecting Customer personal data in the Service, we will notify the affected Customer’s administrators without undue delay, and will provide the information reasonably available to us about the nature of the incident, the data involved, and the steps we are taking in response.

Cost Nudge does not currently hold a formal security certification such as SOC 2, and does not conduct scheduled third-party penetration testing. We will update this section if that changes.


12. Your Rights / Your Organization’s Rights

Because Cost Nudge acts as a data processor for the Customer organization, individual employees who want to access, correct, or delete personal data processed through the Service — such as their own captured meeting data or roster entry — should direct that request to their employer, who controls the data. Where applicable law gives us direct obligations to individuals, or where the Customer directs us to fulfill such a request, we will respond as required by law and by our agreement with the Customer.

Organizations may contact us directly (Section 17) regarding access, export, correction, or deletion of their organization’s data. A Data Processing Addendum is available to Customers on request.


13. Children’s Data

The Service is a workplace tool intended for use by employees of business customers. It is not directed to, marketed to, or knowingly used by children, and we do not knowingly collect personal information from children.


14. International Data Transfers

Cost Nudge stores and processes all Service data on Google Cloud Platform / Firebase infrastructure located in the United States. The Service is offered and distributed only to organizations headquartered in the United States. We do not market the Service outside the United States, and we do not transfer Service data to infrastructure outside the United States.


15. Governing Law

This policy is governed by the laws of the State of Colorado, United States, without regard to its conflict-of-laws provisions.


16. Changes to This Policy

We may update this policy from time to time to reflect changes in the Service or applicable law. We will update the “Effective date” above when we do. Material changes affecting how we process data on behalf of Customers will be communicated to Customer administrators in advance.


17. Contact

Questions about this policy, or about how Cost Nudge processes data as a processor, can be directed to:

Cost Nudge Industries, LLC
Attn: Jonathan Epstein
210 Ken Pratt Blvd Ste 140
Longmont, CO 80501
jonathane@costnudge.com