Privacy Policy
Last updated: August 1, 2026
1. What we collect
By design, we deliberately collect as little as possible:
- Team roster: email address and job title for each person you add — we do not store real names.
- Salary bands: the hourly-rate ranges you configure for cost calculations, not individual salaries.
- Calendar data: read-only meeting metadata (title, time, duration, attendee emails, attendance status) from the Google Calendar account you connect. We request the minimum OAuth scopes needed for this and never modify your calendar.
- Account info: handled by our authentication provider (Clerk) — your email and login credentials never touch our servers directly.
- Billing info: handled entirely by Stripe — we never see or store your card details.
- Slack digest (optional): if you configure a Slack webhook URL, we send it aggregate weekly summaries only — never per-attendee or salary detail.
2. How we use it
We use this data solely to compute and display meeting-cost estimates, generate reports and shareable report cards, send the optional Slack digest, and — with your consent via the anonymized industry-benchmark feature — contribute to and compare against aggregate statistics that never expose any single organization's data (aggregates are only published once at least 5 distinct organizations contribute to a given comparison group).
3. How we protect it
- OAuth tokens (Google Calendar) are encrypted at rest (AES-256), never stored in plaintext.
- We store email + job title only — never full names — for people on your roster.
- Webhook payloads and secrets are never logged.
- Public share links (report cards) show blurred figures by default and reveal no attendee-level detail.
- Access to your organization's data is scoped to members of that organization.
4. Third parties we rely on
Clerk (authentication), Stripe (billing), Google (calendar access, via OAuth you grant and can revoke at any time), Resend (transactional email), Cloudflare R2 (file storage for generated reports), and, if you enable it, Slack (webhook delivery) and Sentry (error monitoring — optional, no payload data). Each processes only what's necessary to provide their part of the Service, under their own privacy terms.
5. Data retention and deletion
We retain your organization's data for as long as your account is active. If you want your organization's data deleted — including revoking calendar access and removing stored roster/meeting data — contact us at the address below and we'll process the request. You can revoke Google Calendar access at any time from your Google account settings or from Unsymetriq's integration settings.
6. Your choices
- Disconnect your Google Calendar integration at any time from Settings.
- Remove or reassign anyone on your roster at any time.
- Public report-card links can be regenerated; the old link stops working.
7. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
8. Contact
Questions about this policy or a data request? Email plentythings3@gmail.com.