action ai ("we") is operated by Alexander Macdonald, United Kingdom. For your account, billing and product-telemetry data we are the data controller. For the contact details and notes you choose to store about people you meet, you decide what is recorded — we process that data on your instructions (see section 6). For organisational deployments (team seats), the organisation is the controller and we act as processor under a data processing agreement.
| Data | Purpose | Legal basis |
|---|---|---|
| Account: email, name, sign-in identity (Google OAuth or email) | Creating and securing your account | Contract |
| Your content: people, events, notes (5,000-character cap), tasks, talking points | Providing the product — turning your notes into contacts and follow-ups | Contract |
| Voice recordings (all tiers, including Free) | Transcription only — audio is sent to OpenAI (Whisper) for transcription and is not stored by us (section 3) | Contract |
| Usage counters, abuse-prevention signals (including rate-limit records and referral fingerprints) | Fair-use limits, preventing abuse, keeping the service available | Legitimate interests |
| Error reports (crash data with tokens scrubbed, no personal content) | Fixing bugs | Legitimate interests |
| Support messages you send us | Answering you | Legitimate interests |
| Newsletter email (separate, optional sign-up) | Launch updates and product news | Consent — withdraw any time via unsubscribe |
| Billing (handled by Lemon Squeezy as merchant of record) | Subscriptions | Contract — we never see or store card numbers |
Your account and content are stored in our database hosted by Supabase (on AWS infrastructure). Some of our providers are US companies; transfers outside the UK/EEA are protected by the EU-US Data Privacy Framework and/or Standard Contractual Clauses with the UK International Data Transfer Addendum, as listed below.
| Provider | What they do | Data involved | Transfer safeguard |
|---|---|---|---|
| Supabase | Database, authentication, server functions | Account + your content | DPA; SCCs |
| Anthropic (US) | Note parsing (Claude) | Note text, per request | EU-US DPF + SCCs + UK Addendum |
| OpenAI (US) | Voice transcription (Whisper) — all tiers, including Free | Audio, transient | EU-US DPF; SCCs |
| Netlify (US) | Hosting / CDN | Standard access logs | DPA; SCCs |
| Sentry (US) | Error monitoring | Crash reports — configured to exclude personal data; tokens scrubbed | DPA; SCCs |
| Resend (US) | Transactional email | Email address | DPA; SCCs |
| Lemon Squeezy | Payments (merchant of record) | Billing details — card data never touches us | Merchant-of-record; DPA |
action ai exists to help you remember people you actually met, so the notes you keep contain other people's details. We designed for their rights, not just yours:
Joining an event by code or link works exactly like section 6 above — the people you personally capture there are yours alone, private to your account. The event host never receives your individual contact data, only aggregate counts (how many joined, how many contacts were captured, how many follow-ups resulted). You remain the sole data controller for who you personally meet at an event.
Hosting an event is optional and adds two features, neither of which touches attendee data: a brand kit (logo, colours, an outbound "next edition" link you set yourself), and an optional domain verification for an "Official" badge — either a DNS record or an email to a privileged mailbox (admin@ / postmaster@) at the domain you're verifying. Domain verification processes your own business/domain identity, not any attendee's data, and is logged as its own processing purpose below. Two commitments are enforced by an automated check on every release, not just written here: the outbound event link is never appended with attendee data, and there is no attendee-export feature.
Under UK GDPR you can: access your data (export it any time from Settings), correct it, delete it (Settings → Delete account — immediate, cascading, cloud included), take it with you (the export is machine-readable), object to or restrict processing, and withdraw consent where consent is the basis. To exercise anything you can't do in-app, email contact@actionai.club. You can also complain to the UK regulator, the Information Commissioner's Office.
We use one functional cookie (your session, so returning visitors reach the app) and browser local storage for the app to work offline. No advertising or cross-site tracking cookies.
action ai is a professional networking tool and is not directed at children under 16.
We'll update this page when our practices change and revise the date at the top. Material changes will be flagged in-app.