Privacy Policy
Effective date: September 10, 2026
This Privacy Policy explains how NudgeForge, operated by CompilerFlow ("CompilerFlow," "we," "us"), collects, uses, and protects information when you visit this website, start a trial or subscription, or use the NudgeForge Chrome extension, desktop application, and hosted backend.
1. Information We Collect
- Account & billing data: your email address and subscription details. Payment card details are collected and held by our payment processor, Paddle, not by CompilerFlow.
- Call transcript data: when the extension or desktop app is active on a Google Meet call, the live captions of that call (speaker labels and spoken text) are sent to our hosted backend to generate suggestions and, if enabled, to store call history.
- Call recordings: on plans where recording is enabled, the audio, video, and/or screen of the call is captured and stored so you can review and share it.
- Knowledge-base content: the battlecards, product docs, and other files you upload to ground the AI suggestions.
- Usage & log data: IP address, app version, connection events, and error logs, collected automatically for security, reliability, and support.
2. How We Use Information
- To provide, maintain, and support the Service and its AI features (see Section 3);
- To store and display your call history, transcripts, and recordings back to you;
- To process subscriptions and prevent fraud and abuse;
- To respond to support requests;
- To comply with legal obligations.
We do not use your call transcripts, recordings, or knowledge-base content to train our own models, and we do not sell personal data.
3. AI Processing
Nudges and call summaries are generated by third-party large language model providers, currently OpenAI and Google (Gemini). When a suggestion is generated, the relevant transcript text, recent conversation context, and matching excerpts from your knowledge base are transmitted to the configured provider to produce a response. OpenAI and Google both state that data submitted through their API/enterprise tiers is not used to train their models by default. CompilerFlow may change which provider is used, including on a per-customer basis.
4. Sharing & Disclosure
We share information with: (a) subprocessors that host our infrastructure, process payments (Paddle), or provide AI processing (OpenAI, Google), each under contractual confidentiality obligations; (b) law enforcement or regulators where required by law; and (c) a successor entity in the event of a merger, acquisition, or asset sale, subject to the same protections described here.
5. International Data Transfers
Our hosted backend infrastructure is currently located in the United States. If you are located in the United Kingdom, the European Economic Area, or another jurisdiction with data-transfer restrictions, your information will be transferred to and processed in the United States, and by the AI providers named in Section 3 in the regions they operate. We rely on Standard Contractual Clauses or equivalent safeguards with these providers where applicable.
6. Data Retention
Account and workspace data is retained for as long as your organization maintains an active subscription. Transcripts and recordings are retained according to your plan's retention window; you can delete individual sessions at any time. On cancellation, we delete or anonymize Customer Data within a reasonable period unless a longer retention is required by law.
7. Your Rights
Depending on your location, you may have rights under data protection law (including the UK and EU GDPR where applicable) to access, correct, export, or delete personal data we hold about you, and to object to or restrict certain processing. To exercise these rights, email hello@compilerflow.com. We will respond within one month of a verified request, extendable as permitted by law. You also have the right to lodge a complaint with your local data protection authority.
8. Security
We apply industry-standard technical and organizational measures to protect information from unauthorized access, alteration, or disclosure, including TLS encryption in transit and encryption of sensitive fields at rest, with per-customer data isolation on the hosted backend. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, communicated by email or in-product.
10. Contact Us
For privacy questions or data requests, contact hello@compilerflow.com.