Effective Date: January 8, 2026 · Last Updated: August 23, 2026
Privacy Policy
Action (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our workspace collaboration platform and related services — including our built-in AI features, which process workspace content through third-party AI providers as described below, and our API integrations with AI assistants like ChatGPT and Claude.
By using Action, you agree to the collection and use of information in accordance with this policy.
Information We Collect
Information You Provide Directly
When you use Action, you may provide us with:
- Account Information: Name, email address, profile picture, and authentication credentials when you create an account; phone number if you enable SMS notifications
- Workspace Content: Tasks, posts, decisions, metrics, channels, and other content you create within your workspaces
- Communication Data: Comments, votes, and interactions with other workspace members
- Integration Settings: Configuration data and credentials for the services you connect (messaging, project tools, CRM, and others listed below) and API keys you issue
Information Collected Automatically
When you access Action, we automatically collect:
- Usage Data: Pages visited, features used, actions taken, and timestamps
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP addresses, access times, error logs, and referring URLs
- API Access Logs: Operations performed via the MCP API, including timestamps and response codes
Information from Third-Party Integrations
When you (or a workspace admin) connect Action to third-party services, we receive data from those services as authorized during the connection flow. Depending on which integrations your workspace enables, this may include:
- Messaging (Slack, Telegram): Workspace and channel information, user identifiers, and messages in channels you connect
- Work Tools (Linear, Jira, Asana, monday.com, GitHub, Attio, BambooHR, Stripe): Projects, issues, records, and activity data from the tools you connect, used to compute status and insights — for Stripe, this includes subscription and revenue data and associated customer names and email addresses
- Directory Providers (Google Workspace, Microsoft 365): Names, email addresses, and basic profile information of members of your organization, when directory sync is enabled
- Email: Messages sent to your workspace's Action email address, including sender information and attachments
- Meetings: Audio captured during meeting capture sessions you start, and the resulting transcripts and notes — you are responsible for notifying participants and obtaining any consents required by law before starting a capture
- AI Assistants (ChatGPT, Claude, Cursor): API requests and operation parameters sent through our MCP server
- Authentication Providers: Basic profile information from OAuth providers (Google, Microsoft, etc.)
How We Use Your Information
Provide and Improve Our Services
- Operate and maintain the Action platform
- Process and fulfill your requests (creating tasks, posting updates, etc.)
- Enable collaboration features within your workspaces
- Personalize your experience and provide relevant content
Provide AI Features
Action includes built-in AI features: summaries and highlights, morning briefings, extraction of tasks and decisions from meetings and messages, natural-language parsing, and insights computed from connected tools. To provide these features, relevant workspace content is sent to our AI service providers for processing:
- Language models (Anthropic): Workspace content relevant to the feature (for example, the updates being summarized, or a meeting transcript being turned into notes) is sent to Anthropic's API to generate the output
- Text embeddings (OpenAI): Workspace text and search queries are sent to OpenAI's embeddings API to power search and semantic matching
- Speech-to-text (Deepgram): Audio from meeting capture sessions you start is streamed to Deepgram solely to produce a transcript; we do not store the audio
No training: We do not use your data to train AI models, and we do not grant our AI service providers permission to do so. Data we submit to Anthropic and OpenAI is processed under commercial API terms under which the provider does not use it to train models. Providers may retain submitted data for a limited period under their published data-retention policies (for example, for abuse monitoring).
Enable AI Assistant Integration
- Process requests from connected AI assistants (ChatGPT, Claude, Cursor)
- Execute MCP API operations on your behalf
- Maintain API access logs for security and debugging
Communication
- Send transactional emails (task assignments, decision notifications)
- Deliver email digests summarizing workspace activity
- Notify you of important account or service updates
- Respond to your support requests
Security and Compliance
- Detect, prevent, and address fraud, abuse, or security issues
- Enforce our Terms of Service and other policies
- Comply with legal obligations
Analytics and Improvements
- Analyze usage patterns to improve our services
- Develop new features and functionality
- Monitor and improve performance and reliability
How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
Within Your Workspace
- Workspace content (tasks, posts, decisions) is visible to workspace members based on channel membership and permissions
- Your profile information (name, avatar) is visible to other members of workspaces you belong to
With Service Providers
We work with third-party service providers who assist us in operating our platform:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, authentication, and file storage | Account data, workspace content |
| Vercel | Hosting and delivery | Request logs, technical telemetry |
| Anthropic | AI processing (summaries, briefings, extraction, insights) | Workspace content relevant to the AI feature being run |
| OpenAI | Text embeddings for search and semantic matching | Workspace text and search queries |
| Deepgram | Meeting transcription (speech-to-text) | Audio from meeting capture sessions you start |
| Postmark | Email delivery (outbound and inbound) | Email addresses, notification and email content |
| Twilio | SMS delivery and phone verification | Phone numbers, SMS notification content, inbound SMS replies, verification codes |
| PostHog | Product analytics and session replay | Profile identifiers (name, email, workspace), usage events, session replays of app usage (typed input is masked), error reports, and AI usage metadata (model, token counts, latency — not prompt content) |
| Google Analytics | Web analytics | Page views, usage events, and analytics identifiers |
We engage these providers under terms that require them to protect your information and restrict their use of it to providing their services (including limited purposes set out in their own terms, such as abuse monitoring).
With AI Service Providers (Built-in AI Features)
As described under “Provide AI Features” above, Action's built-in AI features send relevant workspace content to Anthropic (language models) and OpenAI (embeddings), and meeting audio to Deepgram (transcription). This processing is subject to our no-training commitment: we do not use your data to train AI models and do not grant these providers permission to do so. Submitted data is used to generate the requested output, subject to the provider's data-retention policy.
With AI Assistants You Connect
Separately, you can connect external AI assistants (ChatGPT, Claude, Cursor, and similar tools) to your workspace through our MCP API. When you do:
- Requests: The assistant sends requests to our API on your behalf, and the content it requests (task lists, post details, search results) is returned into that assistant's conversation context
- Their terms govern: Once data is returned to an assistant, its handling — including retention and any model-training settings — is governed by your own agreement and settings with that assistant's provider, not by this policy. Review your assistant's data controls before connecting it to sensitive workspaces
- API Keys: Your Action API key authenticates requests and is never shared with the assistant provider beyond the connection you configure
With Third-Party Tools You Connect
When you connect integrations (Slack, Telegram, Linear, Jira, Asana, monday.com, GitHub, Attio, BambooHR, Stripe, Google Workspace, Microsoft 365, and similar), we exchange data with those services as needed to operate the integration you authorized — for example, reading activity to compute status, or sending notifications into a channel. Each provider's own privacy policy governs its processing of that data. You can disconnect an integration at any time in workspace settings.
Legal Requirements
We may disclose your information if required by law or if we believe disclosure is necessary to:
- Comply with legal processes or government requests
- Protect our rights, privacy, safety, or property
- Prevent fraud or abuse of our services
Business Transfers
If Action is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
Data Retention
We retain your information for as long as necessary to provide our services and fulfill the purposes described in this policy:
- Account Data: Retained while your account is active; deleted upon account deletion
- Workspace Content: Retained while the workspace exists; deleted when the workspace is deleted
- API Logs: Retained for 90 days for security and debugging purposes
- Email Delivery Logs: Retained by our email delivery provider for a limited period under its retention policy
- AI Processing Data: We submit content to our AI service providers under terms that prohibit its use for model training and limit retention to the provider's published data-retention window
You can request deletion of your data by contacting us at privacy@actionhq.ai.
Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption: All data is encrypted in transit (TLS 1.2 or higher) and at rest
- Access Control: Row-level security ensures users can only access data they're authorized to view
- API Security: API keys are securely hashed; rate limiting prevents abuse
- Authentication: Sign-in via Google or Microsoft OAuth — Action never stores your password, and multi-factor authentication is inherited from your identity provider
- Monitoring: Security logging and audit trails
Despite these measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
Your Rights and Choices
Access and Portability
You can access your data at any time through the Action interface. Contact us to request a copy of your data in a portable format.
Correction
You can update your profile information and workspace content directly within Action.
Deletion
You can delete:
- Individual items (tasks, posts, etc.) within the application
- Your entire account through account settings
- Request workspace deletion (workspace admins only)
API Access Control
You can:
- Enable or disable MCP API access for your workspace
- Toggle read and write operations independently
- Issue API keys with granular scopes (e.g., read-only metrics)
- Revoke connected apps and API keys at any time
- Review an audit log of all API operations
Email Preferences
You can manage email notification preferences in your account settings, including task assignment notifications, decision notifications, and email digest frequency (daily, weekly, or disabled).
Do Not Track
Action does not currently respond to “Do Not Track” browser signals.
Cookies and Tracking Technologies
Action uses the following cookies and similar technologies:
- Essential Cookies: Authentication and session cookies required to keep you signed in and secure the service. These cannot be disabled
- Analytics: PostHog (usage events and session replay, as described above) and Google Analytics (page views and usage measurement) set identifiers to understand how the product is used
- Attribution: A first-touch cookie records how you originally arrived at Action (e.g., campaign parameters)
We do not use third-party advertising cookies. You can limit or clear cookies through your browser settings; blocking essential cookies will prevent sign-in.
International Data Transfers
Action is operated from the United States. If you access our services from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
We take appropriate safeguards to ensure your information remains protected in accordance with this Privacy Policy.
Children's Privacy
Action is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we learn that we have collected information from a child under 16, we will delete that information promptly.
Third-Party Links and Services
Action may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the updated policy on our website
- Updating the “Last Updated” date at the top of this policy
- Sending an email notification for significant changes
Your continued use of Action after any changes indicates your acceptance of the updated policy.
Additional Information for AI Assistant Users
ChatGPT and Claude Integration
When you connect Action to AI assistants:
- Authentication: You authorize access via OAuth or an API key scoped to your workspace
- Data Flow: Your requests go from the AI assistant → Action API → your workspace data → back to the AI assistant
- No Training by Us: We do not use your workspace data to train AI models. However, once data is returned into an AI assistant you connect, its handling — including any training settings — is governed by your agreement with that assistant's provider; review the assistant's data controls
- Scope Control: You control which operations (read/write) the API can perform, and access is limited to what your own account can see
API Data Minimization
Our API follows data minimization principles:
- Only requested data is returned
- Rate limits prevent bulk data extraction
- All access is logged for audit purposes
Revoking Access
To disconnect an AI assistant:
- To revoke an assistant you connected, go to Account → Apps & Integrations and revoke the connected app
- Workspace admins can additionally revoke API keys or disable MCP access for the whole workspace under Workspace Settings → Integrations
- Revoked credentials immediately stop working
Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
- Email: privacy@actionhq.ai
- Support: support@actionhq.ai
For data protection inquiries or to exercise your rights, email privacy@actionhq.ai with the subject line “Privacy Request.”