Skip to content

Actionbox legal

Privacy Policy

This notice explains what Actionbox collects, why it is used, what is shared with service providers, and how to control or delete your information.

Last updated

September 5, 2026

Contact

info@actionbox.cloud

01

Scope and roles

This Privacy Policy describes how Suson Sapkota, operating Actionbox ("Actionbox", "we", "us", or "our") handles information in the hosted Actionbox Service at actionbox.cloud and api.actionbox.cloud, related clients, SDKs, CLI tools, documentation, integrations, and any mobile application that Actionbox makes available.

Actionbox acts as a Data Controller for account, billing, and direct website visitor data. For Customer Content submitted via the API or dashboard (such as Action titles, descriptions, and callback payloads), the customer acts as the Data Controller and Actionbox acts as a Data Processor under applicable privacy laws.

02

Information we collect

Depending on how you use Actionbox, we may collect the following categories of information:

  • Account and identity information: your email address, display name, Google or Apple account subject identifier, account creation time, and sign-in or account-linking events. Google and Apple provide the identity fields needed for OAuth sign-in; Actionbox does not need your provider password.
  • Session and device information: hashed server-side session records, session creation/expiry/revocation times, last-seen timestamps, device name, platform and operating-system family, app version, an Actionbox-generated device registration identifier, and Firebase Cloud Messaging or Apple Push Notification service token data needed for native notifications.
  • Workspace and integration data: Source names, slugs, default priorities, hashed Source API keys and safe key prefixes, key creation and last-used times, Action titles and descriptions, options, typed interaction definitions, responses, metadata, timestamps, status changes, and source relationships.
  • Callback and delivery data: callback URLs, signed webhook delivery records, delivery status, HTTP status, retry history, error codes, and timestamps. Callback URLs are supplied by the customer and may identify a customer's infrastructure.
  • Technical and security information: request IDs, request paths and methods, response status, timing, rate-limit counters, application logs, browser or reverse-proxy logs, and information needed to detect abuse, troubleshoot failures, and protect the Service.
  • Product analytics and acquisition information: page and route views, referrer host/path, UTM and campaign fields, coarse interaction events, normalized error and performance signals, and the Actionbox user identifier after sign-in. We do not send raw Action content, Source tokens, passwords, OAuth secrets, callback URLs, or copied code to product analytics providers.
  • Billing and transaction records: transaction identifiers, subscription status, billing country or postal code, currency, and invoice history provided by our Merchant of Record. Actionbox does not collect, process, or store raw payment card numbers or CVV codes.
03

How we use information and AI policy

We use information only to provide, authenticate, maintain, secure, and improve the hosted Service, deliver signed callbacks, enforce workspace boundaries, measure reliability, and respond to support requests.

Zero AI model training: We will never sell your personal information or Customer Content, nor will we use your Action titles, descriptions, metadata, code snippets, form inputs, or decision outcomes to train artificial intelligence or machine learning models.

  • provide, authenticate, maintain, and improve the hosted Service;
  • create, display, resolve, expire, reconcile, and audit Actions and their events;
  • deliver and retry signed callbacks and native notification hints;
  • secure accounts, enforce Source and workspace isolation, rate-limit abuse, investigate incidents, and protect the availability of the Service;
  • measure onboarding, documentation usefulness, product adoption, reliability, and acquisition so we can make product decisions; and
  • respond to support, privacy, security, and legal requests.
04

Google and Apple sign-in

Production sign-in uses Google OAuth and may also use Sign in with Apple. When you choose a provider, it sends Actionbox the identity information required to verify the flow, including a provider subject identifier, verified email status, and a display name when available. Actionbox stores the verified subject so later sign-ins can be linked to the same Actionbox account.

Actionbox does not receive or store your Google or Apple password. Google and Apple may process your information under their own terms and privacy policies. Apple may provide a private relay email address instead of your personal address.

05

Mobile devices, local data, and notifications

Any iOS or Android application that Actionbox makes available stores the Actionbox session token and account email in platform-protected storage such as the Apple Keychain or Android encrypted storage. It may also store an Actionbox-generated device identifier, local preferences, and a minimized Action list in the application's private sandbox for offline orientation. That cache may include an Action title, status, priority, environment, timestamps, assignment, and Source name, but excludes descriptions, responses, receipts, comments, context, option values, and arbitrary metadata. Signing out or completing account deletion clears the local session, account email, registered device identifier, and cached Action list.

Any mobile application that Actionbox makes available requests network access and asks for notification permission when you enable push. It does not request access to your camera, microphone, contacts, precise location, photos, SMS, or call history. Operating-system and app-store services may independently collect diagnostic or download information under their own notices.

Actionbox sends push notifications through Firebase Cloud Messaging and, for Apple devices, Apple Push Notification service. Hidden previews are the default and send generic visible text plus the Action identifier and event type needed to refresh authoritative state. If you choose title-only or full previews, the relevant Action title and, for full previews, description may pass through those providers and appear on a lock screen. You can change the preview setting in Actionbox or disable notification permission in device settings. Signing out removes the local registration and, when the Service is reachable, revokes that registered device server-side.

Any mobile application that Actionbox makes available sends allowlisted service and product events to the Actionbox API, such as platform and app version, screen or feature use, search length and result count, refreshes, push hints, and decision type. These events may be forwarded to PostHog as described below. They exclude raw search text and Action titles, descriptions, response values, comments, callback URLs, credentials, and arbitrary metadata, and are not used for advertising or cross-app tracking.

06

Product analytics: PostHog and Google Analytics

Actionbox uses PostHog, configured for the EU PostHog host, to understand how the public site, documentation, dashboard, CLI, SDKs, API, and any mobile application that Actionbox makes available are used. This may include page views, acquisition fields such as UTM parameters and referring host, coarse country or region derived by the provider, client platform and version, button and navigation events, feature adoption, documentation section selection, normalized API failures, and performance signals. Signed-in product events are associated with an opaque Actionbox user identifier; Actionbox does not attach the account email or display name to the PostHog person profile.

Actionbox also uses Google Analytics for privacy-filtered page and route measurement on the website, documentation, blog, and dashboard. Advertising storage, ad personalization, Google signals, and user-ID reporting are disabled in this integration. Query parameters and Actionbox resource identifiers are excluded from the page location sent by the dashboard.

When you voluntarily send product feedback from the signed-in dashboard, Actionbox stores the category, message, a generalized page route, limited display context, your account, and workspace so the feedback can be reviewed and acted on. Feedback text is not sent to product analytics providers.

Browser text and element attributes are masked. Documentation search text and copied code are not sent as raw values. Backend analytics uses an allowlist and excludes Action titles, descriptions, response values, form values, option labels, callback URLs, Source tokens, session tokens, passwords, OAuth secrets, APNs tokens, and arbitrary Action metadata. Analytics is best-effort and does not block the Service.

Browser analytics is disabled until you choose Allow. You can choose Necessary only without affecting sign-in or core product functions, and Do Not Track remains respected. One saved choice applies across the website, documentation, blog, and dashboard. After making a choice, use the Privacy choices link to change or withdraw your consent at any time. Declining before an opt-in prevents browser analytics initialization; turning it off later stops further collection and resets the current PostHog browser identity.

The browser analytics choice applies to PostHog and Google Analytics running in the website, documentation, blog, and dashboard. Any iOS or Android application that Actionbox makes available does not embed those browser libraries; its limited allowlisted events are sent to the Actionbox API as service telemetry and may be forwarded server-side to PostHog. Stop using or sign out of such an application to stop new account-linked mobile events, and use the deletion process below for retained account data.

07

Cookies and local storage

The dashboard uses a secure, HttpOnly Actionbox session cookie so browser JavaScript cannot read the session token. Short-lived, signed OAuth state cookies protect Google and Apple authorization flows. These cookies are necessary for sign-in and security rather than advertising.

If you opt in, browser analytics may use first-party cookies or local storage for Google Analytics and PostHog identifiers, attribution state, and your saved analytics choice. Choosing Necessary only before opting in prevents those browser analytics libraries from initializing; turning analytics off later disables further collection. Disabling necessary cookies can prevent sign-in from working.

08

When information is shared

We share information only as needed to operate, secure, support, and improve the Service, or when required by law. Current categories of recipients include:

  • Google and Apple, for OAuth authentication and identity verification;
  • Google Firebase Cloud Messaging and Apple Push Notification service, for optional mobile notification registration and delivery;
  • our authorized Merchant of Record (such as Paddle or Lemon Squeezy) for processing payments, calculating applicable taxes, and generating compliance invoices;
  • hosting, database, queue, backup, email, monitoring, and network providers that help run Actionbox;
  • PostHog and Google Analytics, for the privacy-filtered analytics described above;
  • your own callback or webhook destination when you configure one; and
  • law enforcement, regulators, professional advisers, or other parties when disclosure is required or reasonably necessary to protect rights, safety, security, or the Service.
09

Retention and deletion

We retain account, Source, Action, event, webhook, device, and security records while needed to provide the Service, maintain an audit trail, resolve disputes, prevent abuse, comply with legal obligations, and recover from failures. Source API keys and user sessions are stored in hashed form where applicable; raw Source keys are shown only at creation or rotation.

Authenticated account owners can export their current account data from Settings or with `GET /v1/account/export`. They can permanently delete the account and its tenant-scoped records with Delete account in the mobile application or dashboard, or with `DELETE /v1/account` after sending the exact confirmation `DELETE ACTIONBOX ACCOUNT`; the session is revoked when deletion completes. Source revocation remains available when an integration should be disabled without deleting the workspace.

Signing out or uninstalling a mobile application is not an account-deletion request and does not remove hosted records. If you no longer have access to the application or dashboard, email info@actionbox.cloud from the account email with the subject "Account deletion" to initiate a deletion request without reinstalling the application.

Deletion removes account-scoped records from the live database. Backups, limited security records, legal holds, and provider-managed analytics may remain until their configured retention windows expire or be retained where law requires. Do not use Actionbox for information subject to a fixed deletion deadline or customer-specific data-processing agreement unless we have agreed that requirement in writing.

10

Security

Actionbox uses controls appropriate to the current low-volume MVP, including HTTPS at the public edge, secure HttpOnly SameSite cookies, origin checks for browser mutations, hashed credentials, scoped authorization, rate limiting, callback URL validation, request IDs, restricted metrics, non-root containers, backups, and privacy-filtered analytics.

Security is a shared responsibility. Protect your Google or Apple account, Source tokens, callback endpoints, exported data, and internal systems. No security control can eliminate every risk, and no transmission or storage system is guaranteed to be completely secure.

11

Your choices and privacy requests

Depending on where you live and how privacy law applies, you may have rights to request access to, correction of, deletion of, or information about personal data associated with your account. For authenticated access and deletion, use the dashboard Settings controls (or equivalent controls in any mobile application that Actionbox makes available), GET /v1/account/export, or DELETE /v1/account with the exact confirmation described above; for requests that cannot be completed through the Service, contact info@actionbox.cloud with the account email, the request you are making, and enough detail to verify and process it. Do not include passwords, Source tokens, OAuth secrets, or Action content that is not necessary for the request.

We may need to verify your identity, protect another person's information, preserve records required for security or law, or apply lawful exceptions before completing a request. We aim to acknowledge privacy requests within 7 days and complete verified requests within 30 days unless applicable law permits or requires a different period.

12

Children and international processing

Actionbox is intended for developers and operators aged 18 or older, not children. Do not use the Service if you cannot enter a binding contract where you live.

Actionbox and its providers may process information in countries other than where you live. Those countries may have different privacy laws; we use providers and contractual safeguards appropriate to the hosted beta and will provide additional data-processing terms only by written agreement.

13

Changes and contact

We may update this Privacy Policy as the Service, providers, analytics configuration, or legal requirements change. The updated date at the top of this page identifies the current version. Material changes will be communicated through the Service or the account contact information we have.

For privacy questions, requests, or concerns, contact info@actionbox.cloud. For security vulnerabilities, use the same address and avoid sending secrets or personal data in the initial report.

Questions about this policy?

Contact the Actionbox team.

Suson Sapkota, operating Actionbox maintains these policies for the hosted Actionbox service.

Email info@actionbox.cloud