What is on your screen
CRM records, page text, form values, typed content, passwords, cookies, authentication tokens, clipboard contents, downloads, and browsing history.
PRIVACY, IN PLAIN ENGLISH
Nudge remembers the timer without snooping through sensitive work. Here is exactly what the product uses, what it does not read, and what choices stay under your control.
CRM records, page text, form values, typed content, passwords, cookies, authentication tokens, clipboard contents, downloads, and browsing history.
Your chosen client, project, task, notes, timer timestamps, duration, enabled website hostname, account identity, and workspace records you intentionally create.
01
The extension uses the hostname of a work site you turn on so it knows where you have chosen to show Nudge. It can use temporary mouse, scroll, focus, and visibility timestamps to detect inactivity and ask whether you are still working.
Because you can add a website domain, Chrome may describe the permission as the ability to read and change data on that site. Nudge uses the permission to display and operate its own timer interface. It does not read the site’s records or content and does not use Salesforce OAuth or the Salesforce API.
02
Without an account, timer entries, settings, labels, tasks, and handoffs remain in browser storage on that device. When you sign in and enable private sync, Nudge encrypts the client, project, task, notes, and entry details in your browser before sending them to the sync service.
The service also stores the encrypted entry, start and end timestamps, duration, and a technical entry identifier required to synchronize devices and detect conflicts.
03
When you use the workspace, Nudge stores the records you intentionally create: organizations, team members, clients, projects, tasks, time reviews, retainers, updates, requests, decisions, comments, files, and access settings.
Private workspace records and time capture are available only to authorized consultants and internal team members.
Clients receive access only to their organization’s portal and information intentionally made client visible.
Database row-level security and organization-level portal entitlements enforce these boundaries. Internal users can preview the client experience without changing it.
04
The public Nudge website uses Google Analytics and first-party product events to understand which pages, campaigns, and product journeys are useful. This can include page and section views, buttons selected, video interactions, FAQ opens, campaign parameters, approximate device and browser information, and non-personal answers to the workflow diagnostic. Google Analytics may use cookies or similar technologies according to your browser settings.
If you submit the early-access form, Nudge stores the contact and business information you provide, your consent, page and campaign attribution, product interest, diagnostic answers and recommendation, sections viewed, and general context such as language, time zone, and mobile, tablet, or desktop viewport. These details are connected to your lead only after you choose to submit the form.
After a successful submission, Nudge stores your first name and an opaque visitor identifier in first-party cookies for up to one year, plus your form details and diagnostic choices in browser storage. This greets you, restores your assessment, and prefills later forms on that browser. These values are used for personalization and lead context, not third-party advertising or covert fingerprinting.
06
07
Nudge uses encrypted transport, role-based access, database row-level security, organization isolation, audit history for sensitive access changes, and client-side encryption for optional private time-entry sync.
Information is retained for as long as needed to provide the service, maintain security and legitimate business records, meet legal obligations, or resolve disputes. No security system can guarantee absolute protection, so please use a strong account password and keep recovery keys private.
08
Privacy should be easy to ask about. Contact Nudge for questions, access requests, corrections, or deletion requests.
hello@crmhacker.com →