Effective Date: January 8, 2026  ·  Last Updated: August 23, 2026

Privacy Policy

Action (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our workspace collaboration platform and related services — including our built-in AI features, which process workspace content through third-party AI providers as described below, and our API integrations with AI assistants like ChatGPT and Claude.

By using Action, you agree to the collection and use of information in accordance with this policy.


Information We Collect

Information You Provide Directly

When you use Action, you may provide us with:

  • Account Information: Name, email address, profile picture, and authentication credentials when you create an account; phone number if you enable SMS notifications
  • Workspace Content: Tasks, posts, decisions, metrics, channels, and other content you create within your workspaces
  • Communication Data: Comments, votes, and interactions with other workspace members
  • Integration Settings: Configuration data and credentials for the services you connect (messaging, project tools, CRM, and others listed below) and API keys you issue

Information Collected Automatically

When you access Action, we automatically collect:

  • Usage Data: Pages visited, features used, actions taken, and timestamps
  • Device Information: Browser type, operating system, device identifiers
  • Log Data: IP addresses, access times, error logs, and referring URLs
  • API Access Logs: Operations performed via the MCP API, including timestamps and response codes

Information from Third-Party Integrations

When you (or a workspace admin) connect Action to third-party services, we receive data from those services as authorized during the connection flow. Depending on which integrations your workspace enables, this may include:

  • Messaging (Slack, Telegram): Workspace and channel information, user identifiers, and messages in channels you connect
  • Work Tools (Linear, Jira, Asana, monday.com, GitHub, Attio, BambooHR, Stripe): Projects, issues, records, and activity data from the tools you connect, used to compute status and insights — for Stripe, this includes subscription and revenue data and associated customer names and email addresses
  • Directory Providers (Google Workspace, Microsoft 365): Names, email addresses, and basic profile information of members of your organization, when directory sync is enabled
  • Email: Messages sent to your workspace's Action email address, including sender information and attachments
  • Meetings: Audio captured during meeting capture sessions you start, and the resulting transcripts and notes — you are responsible for notifying participants and obtaining any consents required by law before starting a capture
  • AI Assistants (ChatGPT, Claude, Cursor): API requests and operation parameters sent through our MCP server
  • Authentication Providers: Basic profile information from OAuth providers (Google, Microsoft, etc.)

How We Use Your Information

Provide and Improve Our Services

  • Operate and maintain the Action platform
  • Process and fulfill your requests (creating tasks, posting updates, etc.)
  • Enable collaboration features within your workspaces
  • Personalize your experience and provide relevant content

Provide AI Features

Action includes built-in AI features: summaries and highlights, morning briefings, extraction of tasks and decisions from meetings and messages, natural-language parsing, and insights computed from connected tools. To provide these features, relevant workspace content is sent to our AI service providers for processing:

  • Language models (Anthropic): Workspace content relevant to the feature (for example, the updates being summarized, or a meeting transcript being turned into notes) is sent to Anthropic's API to generate the output
  • Text embeddings (OpenAI): Workspace text and search queries are sent to OpenAI's embeddings API to power search and semantic matching
  • Speech-to-text (Deepgram): Audio from meeting capture sessions you start is streamed to Deepgram solely to produce a transcript; we do not store the audio

No training: We do not use your data to train AI models, and we do not grant our AI service providers permission to do so. Data we submit to Anthropic and OpenAI is processed under commercial API terms under which the provider does not use it to train models. Providers may retain submitted data for a limited period under their published data-retention policies (for example, for abuse monitoring).

Enable AI Assistant Integration

  • Process requests from connected AI assistants (ChatGPT, Claude, Cursor)
  • Execute MCP API operations on your behalf
  • Maintain API access logs for security and debugging

Communication

  • Send transactional emails (task assignments, decision notifications)
  • Deliver email digests summarizing workspace activity
  • Notify you of important account or service updates
  • Respond to your support requests

Security and Compliance

  • Detect, prevent, and address fraud, abuse, or security issues
  • Enforce our Terms of Service and other policies
  • Comply with legal obligations

Analytics and Improvements

  • Analyze usage patterns to improve our services
  • Develop new features and functionality
  • Monitor and improve performance and reliability

How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

Within Your Workspace

  • Workspace content (tasks, posts, decisions) is visible to workspace members based on channel membership and permissions
  • Your profile information (name, avatar) is visible to other members of workspaces you belong to

With Service Providers

We work with third-party service providers who assist us in operating our platform:

ProviderPurposeData Shared
SupabaseDatabase, authentication, and file storageAccount data, workspace content
VercelHosting and deliveryRequest logs, technical telemetry
AnthropicAI processing (summaries, briefings, extraction, insights)Workspace content relevant to the AI feature being run
OpenAIText embeddings for search and semantic matchingWorkspace text and search queries
DeepgramMeeting transcription (speech-to-text)Audio from meeting capture sessions you start
PostmarkEmail delivery (outbound and inbound)Email addresses, notification and email content
TwilioSMS delivery and phone verificationPhone numbers, SMS notification content, inbound SMS replies, verification codes
PostHogProduct analytics and session replayProfile identifiers (name, email, workspace), usage events, session replays of app usage (typed input is masked), error reports, and AI usage metadata (model, token counts, latency — not prompt content)
Google AnalyticsWeb analyticsPage views, usage events, and analytics identifiers

We engage these providers under terms that require them to protect your information and restrict their use of it to providing their services (including limited purposes set out in their own terms, such as abuse monitoring).

With AI Service Providers (Built-in AI Features)

As described under “Provide AI Features” above, Action's built-in AI features send relevant workspace content to Anthropic (language models) and OpenAI (embeddings), and meeting audio to Deepgram (transcription). This processing is subject to our no-training commitment: we do not use your data to train AI models and do not grant these providers permission to do so. Submitted data is used to generate the requested output, subject to the provider's data-retention policy.

With AI Assistants You Connect

Separately, you can connect external AI assistants (ChatGPT, Claude, Cursor, and similar tools) to your workspace through our MCP API. When you do:

  • Requests: The assistant sends requests to our API on your behalf, and the content it requests (task lists, post details, search results) is returned into that assistant's conversation context
  • Their terms govern: Once data is returned to an assistant, its handling — including retention and any model-training settings — is governed by your own agreement and settings with that assistant's provider, not by this policy. Review your assistant's data controls before connecting it to sensitive workspaces
  • API Keys: Your Action API key authenticates requests and is never shared with the assistant provider beyond the connection you configure

With Third-Party Tools You Connect

When you connect integrations (Slack, Telegram, Linear, Jira, Asana, monday.com, GitHub, Attio, BambooHR, Stripe, Google Workspace, Microsoft 365, and similar), we exchange data with those services as needed to operate the integration you authorized — for example, reading activity to compute status, or sending notifications into a channel. Each provider's own privacy policy governs its processing of that data. You can disconnect an integration at any time in workspace settings.

Legal Requirements

We may disclose your information if required by law or if we believe disclosure is necessary to:

  • Comply with legal processes or government requests
  • Protect our rights, privacy, safety, or property
  • Prevent fraud or abuse of our services

Business Transfers

If Action is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.


Data Retention

We retain your information for as long as necessary to provide our services and fulfill the purposes described in this policy:

  • Account Data: Retained while your account is active; deleted upon account deletion
  • Workspace Content: Retained while the workspace exists; deleted when the workspace is deleted
  • API Logs: Retained for 90 days for security and debugging purposes
  • Email Delivery Logs: Retained by our email delivery provider for a limited period under its retention policy
  • AI Processing Data: We submit content to our AI service providers under terms that prohibit its use for model training and limit retention to the provider's published data-retention window

You can request deletion of your data by contacting us at privacy@actionhq.ai.


Data Security

We implement appropriate technical and organizational measures to protect your information:

  • Encryption: All data is encrypted in transit (TLS 1.2 or higher) and at rest
  • Access Control: Row-level security ensures users can only access data they're authorized to view
  • API Security: API keys are securely hashed; rate limiting prevents abuse
  • Authentication: Sign-in via Google or Microsoft OAuth — Action never stores your password, and multi-factor authentication is inherited from your identity provider
  • Monitoring: Security logging and audit trails

Despite these measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.


Your Rights and Choices

Access and Portability

You can access your data at any time through the Action interface. Contact us to request a copy of your data in a portable format.

Correction

You can update your profile information and workspace content directly within Action.

Deletion

You can delete:

  • Individual items (tasks, posts, etc.) within the application
  • Your entire account through account settings
  • Request workspace deletion (workspace admins only)

API Access Control

You can:

  • Enable or disable MCP API access for your workspace
  • Toggle read and write operations independently
  • Issue API keys with granular scopes (e.g., read-only metrics)
  • Revoke connected apps and API keys at any time
  • Review an audit log of all API operations

Email Preferences

You can manage email notification preferences in your account settings, including task assignment notifications, decision notifications, and email digest frequency (daily, weekly, or disabled).

Do Not Track

Action does not currently respond to “Do Not Track” browser signals.


Cookies and Tracking Technologies

Action uses the following cookies and similar technologies:

  • Essential Cookies: Authentication and session cookies required to keep you signed in and secure the service. These cannot be disabled
  • Analytics: PostHog (usage events and session replay, as described above) and Google Analytics (page views and usage measurement) set identifiers to understand how the product is used
  • Attribution: A first-touch cookie records how you originally arrived at Action (e.g., campaign parameters)

We do not use third-party advertising cookies. You can limit or clear cookies through your browser settings; blocking essential cookies will prevent sign-in.


International Data Transfers

Action is operated from the United States. If you access our services from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.

We take appropriate safeguards to ensure your information remains protected in accordance with this Privacy Policy.


Children's Privacy

Action is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we learn that we have collected information from a child under 16, we will delete that information promptly.


Third-Party Links and Services

Action may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.


Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on our website
  • Updating the “Last Updated” date at the top of this policy
  • Sending an email notification for significant changes

Your continued use of Action after any changes indicates your acceptance of the updated policy.


Additional Information for AI Assistant Users

ChatGPT and Claude Integration

When you connect Action to AI assistants:

  1. Authentication: You authorize access via OAuth or an API key scoped to your workspace
  2. Data Flow: Your requests go from the AI assistant → Action API → your workspace data → back to the AI assistant
  3. No Training by Us: We do not use your workspace data to train AI models. However, once data is returned into an AI assistant you connect, its handling — including any training settings — is governed by your agreement with that assistant's provider; review the assistant's data controls
  4. Scope Control: You control which operations (read/write) the API can perform, and access is limited to what your own account can see

API Data Minimization

Our API follows data minimization principles:

  • Only requested data is returned
  • Rate limits prevent bulk data extraction
  • All access is logged for audit purposes

Revoking Access

To disconnect an AI assistant:

  1. To revoke an assistant you connected, go to Account → Apps & Integrations and revoke the connected app
  2. Workspace admins can additionally revoke API keys or disable MCP access for the whole workspace under Workspace Settings → Integrations
  3. Revoked credentials immediately stop working

Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

For data protection inquiries or to exercise your rights, email privacy@actionhq.ai with the subject line “Privacy Request.”