> action ai

Privacy Policy

Last updated: 24 July 2026 · Contact: contact@actionai.club

1 · Who we are

action ai ("we") is operated by Alexander Macdonald, United Kingdom. For your account, billing and product-telemetry data we are the data controller. For the contact details and notes you choose to store about people you meet, you decide what is recorded — we process that data on your instructions (see section 6). For organisational deployments (team seats), the organisation is the controller and we act as processor under a data processing agreement.

2 · What we collect, why, and on what legal basis

DataPurposeLegal basis
Account: email, name, sign-in identity (Google OAuth or email)Creating and securing your accountContract
Your content: people, events, notes (5,000-character cap), tasks, talking pointsProviding the product — turning your notes into contacts and follow-upsContract
Voice recordings (all tiers, including Free)Transcription only — audio is sent to OpenAI (Whisper) for transcription and is not stored by us (section 3)Contract
Usage counters, abuse-prevention signals (including rate-limit records and referral fingerprints)Fair-use limits, preventing abuse, keeping the service availableLegitimate interests
Error reports (crash data with tokens scrubbed, no personal content)Fixing bugsLegitimate interests
Support messages you send usAnswering youLegitimate interests
Newsletter email (separate, optional sign-up)Launch updates and product newsConsent — withdraw any time via unsubscribe
Billing (handled by Lemon Squeezy as merchant of record)SubscriptionsContract — we never see or store card numbers

3 · The AI processing, plainly

4 · Where your data lives, and transfers

Your account and content are stored in our database hosted by Supabase (on AWS infrastructure). Some of our providers are US companies; transfers outside the UK/EEA are protected by the EU-US Data Privacy Framework and/or Standard Contractual Clauses with the UK International Data Transfer Addendum, as listed below.

Sub-processors

ProviderWhat they doData involvedTransfer safeguard
SupabaseDatabase, authentication, server functionsAccount + your contentDPA; SCCs
Anthropic (US)Note parsing (Claude)Note text, per requestEU-US DPF + SCCs + UK Addendum
OpenAI (US)Voice transcription (Whisper) — all tiers, including FreeAudio, transientEU-US DPF; SCCs
Netlify (US)Hosting / CDNStandard access logsDPA; SCCs
Sentry (US)Error monitoringCrash reports — configured to exclude personal data; tokens scrubbedDPA; SCCs
Resend (US)Transactional emailEmail addressDPA; SCCs
Lemon SqueezyPayments (merchant of record)Billing details — card data never touches usMerchant-of-record; DPA

5 · How long we keep things

6 · Notes about other people — how we've designed for this

action ai exists to help you remember people you actually met, so the notes you keep contain other people's details. We designed for their rights, not just yours:

7 · Events: hosting and attending

Joining an event by code or link works exactly like section 6 above — the people you personally capture there are yours alone, private to your account. The event host never receives your individual contact data, only aggregate counts (how many joined, how many contacts were captured, how many follow-ups resulted). You remain the sole data controller for who you personally meet at an event.

Hosting an event is optional and adds two features, neither of which touches attendee data: a brand kit (logo, colours, an outbound "next edition" link you set yourself), and an optional domain verification for an "Official" badge — either a DNS record or an email to a privileged mailbox (admin@ / postmaster@) at the domain you're verifying. Domain verification processes your own business/domain identity, not any attendee's data, and is logged as its own processing purpose below. Two commitments are enforced by an automated check on every release, not just written here: the outbound event link is never appended with attendee data, and there is no attendee-export feature.

8 · Your rights

Under UK GDPR you can: access your data (export it any time from Settings), correct it, delete it (Settings → Delete account — immediate, cascading, cloud included), take it with you (the export is machine-readable), object to or restrict processing, and withdraw consent where consent is the basis. To exercise anything you can't do in-app, email contact@actionai.club. You can also complain to the UK regulator, the Information Commissioner's Office.

9 · Security

10 · Cookies and local storage

We use one functional cookie (your session, so returning visitors reach the app) and browser local storage for the app to work offline. No advertising or cross-site tracking cookies.

11 · Children

action ai is a professional networking tool and is not directed at children under 16.

12 · Changes

We'll update this page when our practices change and revise the date at the top. Material changes will be flagged in-app.