Effective Date: January 8, 2026 · Last Updated: January 8, 2026
Privacy Policy
Action (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our workspace collaboration platform and related services, including our API integrations with AI assistants like ChatGPT and Claude.
By using Action, you agree to the collection and use of information in accordance with this policy.
Information We Collect
Information You Provide Directly
When you use Action, you may provide us with:
- Account Information: Name, email address, profile picture, and authentication credentials when you create an account
- Workspace Content: Tasks, posts, decisions, metrics, channels, and other content you create within your workspaces
- Communication Data: Comments, votes, and interactions with other workspace members
- Integration Settings: Configuration data for connected services (Slack, email, API keys)
Information Collected Automatically
When you access Action, we automatically collect:
- Usage Data: Pages visited, features used, actions taken, and timestamps
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP addresses, access times, error logs, and referring URLs
- API Access Logs: Operations performed via the MCP API, including timestamps and response codes
Information from Third-Party Integrations
When you connect Action to third-party services, we may receive:
- Slack: Workspace ID, channel information, and user identifiers for connected Slack workspaces
- AI Assistants (ChatGPT, Claude): API requests and operation parameters sent through our MCP server
- Authentication Providers: Basic profile information from OAuth providers (Google, GitHub, etc.)
How We Use Your Information
Provide and Improve Our Services
- Operate and maintain the Action platform
- Process and fulfill your requests (creating tasks, posting updates, etc.)
- Enable collaboration features within your workspaces
- Personalize your experience and provide relevant content
Enable AI Assistant Integration
- Process requests from connected AI assistants (ChatGPT, Claude, Cursor)
- Execute MCP API operations on your behalf
- Maintain API access logs for security and debugging
Communication
- Send transactional emails (task assignments, decision notifications)
- Deliver email digests summarizing workspace activity
- Notify you of important account or service updates
- Respond to your support requests
Security and Compliance
- Detect, prevent, and address fraud, abuse, or security issues
- Enforce our Terms of Service and other policies
- Comply with legal obligations
Analytics and Improvements
- Analyze usage patterns to improve our services
- Develop new features and functionality
- Monitor and improve performance and reliability
How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
Within Your Workspace
- Workspace content (tasks, posts, decisions) is visible to workspace members based on channel membership and permissions
- Your profile information (name, avatar) is visible to other members of workspaces you belong to
With Service Providers
We work with third-party service providers who assist us in operating our platform:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database and authentication | Account data, workspace content |
| Vercel | Hosting and delivery | Request logs, analytics |
| Postmark | Email delivery | Email addresses, notification content |
| Slack | Integration | Workspace and channel data |
These providers are contractually obligated to protect your information and use it only for the purposes we specify.
With AI Assistant Providers
When you use Action through AI assistants:
- Requests: Your API requests are processed through our servers; we do not share your workspace data directly with OpenAI, Anthropic, or other AI providers
- API Keys: Your API key authenticates requests but is not shared with AI providers
- Content: The specific content you request (task lists, post details) is returned through the AI assistant interface
Legal Requirements
We may disclose your information if required by law or if we believe disclosure is necessary to:
- Comply with legal processes or government requests
- Protect our rights, privacy, safety, or property
- Prevent fraud or abuse of our services
Business Transfers
If Action is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
Data Retention
We retain your information for as long as necessary to provide our services and fulfill the purposes described in this policy:
- Account Data: Retained while your account is active; deleted upon account deletion
- Workspace Content: Retained while the workspace exists; deleted when the workspace is deleted
- API Logs: Retained for 90 days for security and debugging purposes
- Email Delivery Logs: Retained for 30 days
You can request deletion of your data by contacting us at privacy@actionhq.ai.
Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest
- Access Control: Row-level security ensures users can only access data they're authorized to view
- API Security: API keys are securely hashed; rate limiting prevents abuse
- Authentication: Multi-factor authentication support via Supabase Auth
- Monitoring: Security logging and anomaly detection
Despite these measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
Your Rights and Choices
Access and Portability
You can access your data at any time through the Action interface. Contact us to request a copy of your data in a portable format.
Correction
You can update your profile information and workspace content directly within Action.
Deletion
You can delete:
- Individual items (tasks, posts, etc.) within the application
- Your entire account through account settings
- Request workspace deletion (workspace admins only)
API Access Control
You can:
- Enable or disable API access for your workspace
- Control read/write permissions for API operations
- Revoke API keys at any time
- Limit API access to public channels only
Email Preferences
You can manage email notification preferences in your account settings, including task assignment notifications, decision notifications, and email digest frequency (daily, weekly, or disabled).
Do Not Track
Action does not currently respond to “Do Not Track” browser signals.
International Data Transfers
Action is operated from the United States. If you access our services from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
We take appropriate safeguards to ensure your information remains protected in accordance with this Privacy Policy.
Children's Privacy
Action is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we learn that we have collected information from a child under 16, we will delete that information promptly.
Third-Party Links and Services
Action may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the updated policy on our website
- Updating the “Last Updated” date at the top of this policy
- Sending an email notification for significant changes
Your continued use of Action after any changes indicates your acceptance of the updated policy.
Additional Information for AI Assistant Users
ChatGPT and Claude Integration
When you connect Action to AI assistants:
- Authentication: You provide an API key that authenticates requests to your workspace
- Data Flow: Your requests go from the AI assistant → Action API → your workspace data → back to the AI assistant
- No Training: Your workspace data is not used to train AI models; it is only used to fulfill your specific requests
- Scope Control: You control which operations (read/write) and channels the API can access
API Data Minimization
Our API follows data minimization principles:
- Only requested data is returned
- Sensitive fields can be excluded
- Rate limits prevent bulk data extraction
- All access is logged for audit purposes
Revoking Access
To disconnect an AI assistant:
- Go to Workspace Settings → MCP API
- Disable the API or regenerate your API key
- The previous key will immediately stop working
Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
- Email: privacy@actionhq.ai
- Support: support@actionhq.ai
For data protection inquiries or to exercise your rights, email privacy@actionhq.ai with the subject line “Privacy Request.”