Privacy notice
Quorum measures what meetings cost and recommends which of them need fewer people live. It reads calendar metadata and attendance records for the employees of the workspace that installed it. This page states exactly what is collected, what is never collected, who it is shared with, and how long it is kept.
What Quorum reads
| Data | Why | Source |
|---|---|---|
| Meeting title, start and end time, recurrence, join URL | To deduplicate every invitee’s copy into one canonical meeting and price it | Microsoft Graph, Google Calendar |
| Invitee list and RSVP status | To compute planned cost — scheduled duration × each invitee’s cost band | Microsoft Graph, Google Calendar |
| Join and leave times per participant | To compute attended cost, the number the whole product turns on | Teams, Google Meet, Zoom |
| Employee name, work email, role, department | To attribute cost to a team and match a Slack account | Your CSV import, or discovered from invites |
| Cost bands (an hourly rate per band, and which band a person is in) | The only input that turns hours into money | You, in Settings — never inferred, never fetched from a payroll system |
| Conversation volume — counts only | To tell when a written thread has cost more than the meeting that would have settled it. The number of messages, the number of participants, and when it started and last moved — never the text. | GitHub signed webhooks and count-only GraphQL queries for the configured repository. Other conversation sources are not currently available. |
| Transcript speaker segments — off by default | Speaker-time evidence for recommendations. Only if an admin enables transcript analysis. | The meeting platform’s own API — no bot joins your calls |
What Quorum never does
- It never evaluates an individual. Audits and recommendations operate at organization, team, and meeting-series level. Authorized admins and team managers can also view named calendar commitments and factual participation for workload planning. Meet-derived attendance is excluded from these person views. There is no per-person score, ranking, or productivity metric, and no feature may add one. Google’s Meet API terms prohibit using that data for performance tracking, and Quorum enforces the same rule product-wide for every provider.
- It never joins your calls. Attendance comes from the platform’s own join/leave records. No recording bot appears in the participant list.
- It excludes sensitive meetings at ingestion, not in the UI. A meeting whose title or description matches 1:1s, performance reviews, compensation, promotion, termination, disciplinary matters, PIPs, HR cases, medical, legal privilege, grievances, or interviews is reduced to a time-and-duration shell before it is stored. It never gains participants, attendance, cost, AI output, or artifacts.
- It never sends sensitive-meeting content to a model. Excluded meetings have no content to send.
- It never reads message bodies, documents, or email. The Slack scopes are limited to posting messages, opening DMs, reading user emails for account matching, and the slash command. Conversation tracking counts messages without reading them: on GitHub it takes the comment counter the API already returns, and no comment body is ever fetched or stored.
- It never counts messages per person. A thread is expensive because of its size and duration, not because of who posted most. There is no per-person message figure anywhere in the product, and the data model has nowhere to put one.
Automated decisions
Quorum produces recommendations; a human makes every decision. An AI recommendation and an organizer’s decision are stored as separate records and are never merged. Nothing in an employee’s calendar changes unless the meeting organizer acts on it themselves. Cost, health scores, and savings are deterministic code — no model is involved in any number.
Retention
Retention is enforced by a daily job, not promised in a document. Your workspace sets the windows in Settings; the defaults are:
- Meetings, attendance and conversation volume — 365 days by default (configurable 30–3650). Anything older than the window is deleted, along with its participants, attendance, recommendations, and decisions.
- Transcripts — 30 days by default (configurable 7–365), deliberately the shortest window because it is the most sensitive artifact.
- Sign-in links expire after 15 minutes, are single-use, are stored only as a SHA-256 hash, and are purged a day after expiry.
Reducing a retention window takes effect on the next daily sweep, and the Settings page shows the configured window. Ask an administrator to review exports before reducing it.
Enquiries and change tracking
Sales enquiries contain the contact details and message you submit. They are used to handle the request, stored in an operator queue, and forwarded to the configured sales inbox when delivery is available. Database copies are deleted by the daily sweep after 90 days; forwarded email copies require the operator’s mailbox retention policy.
Series change plans store the owner, target date, implementation date and administrative confirmation note. Plans and their decision audit records follow the workspace meeting-retention window. Do not include private meeting content or employee assessments in these notes.
Access and deletion
Workspace admins can export people and meeting data as CSV at any time from the People and Meetings screens. To delete a person’s data ahead of the retention window, or to delete an entire workspace, ask your administrator to coordinate a verified deletion request with the service operator. There is currently no self-service workspace deletion button. The operator must verify the scope, complete deletion and provide confirmation, including the applicable backup-retention schedule.
Where data goes
The full list of third parties that receive any data, and what each one receives, is on the Security & sub-processors page.