Privacy Policy

Last updated: 16 July 2026

Who we are

Actions (actions-app.com) is operated by NGJB Limited, a company registered in England and Wales, trading as “Actions”. Actions turns your meetings into organised, actionable work: our meeting assistant joins calls you choose, captures the transcript, and uses AI to extract action items, summaries, and projects.

This policy explains what personal data we collect, why, who we share it with, and the choices you have. It is written to meet our obligations under the UK GDPR and the Data Protection Act 2018. For privacy questions, contact privacy@actions-app.com.

1. Information we collect

Account information. When you sign in with Google or Microsoft, we receive your name, email address, and profile picture. If you sign up with email and password instead, we collect only your email address and a securely hashed password.

Google user data. With your explicit consent on the Google consent screen, we request the following Google OAuth scopes — and no others:

  • Basic profile (openid, email, profile) — to create and sign you into your account.
  • Google Calendar events, read-only (calendar.events.readonly) — to detect your upcoming meetings so that (a) they appear in your Actions calendar and (b) our meeting assistant can join the meetings you have chosen to record. This does not permit access to calendar lists or calendar settings.
  • Google Meet space settings (meetings.space.settings) — to enable automatic transcription/recording artefacts for Google Meet meetings you host.

We do not request access to Google Drive, Gmail, your contacts, or your files. We never modify or delete your calendar events — our calendar access is read-only.

Microsoft user data. If you connect a Microsoft account instead, we request read-only access to your Outlook calendar (Calendars.Read) for the same meeting-detection purpose.

Meeting content. When our meeting assistant joins a meeting (visible to all participants as a named attendee), we collect the recording and transcript of that meeting, and metadata such as title, time, and participants. You can also upload transcripts or record voice notes manually.

Billing information. If you subscribe to a paid plan, payment is handled by Stripe. Card details go directly to Stripe — we never see or store full card numbers. We store your organisation name, subscription tier, and Stripe customer identifiers.

Usage and device data. Standard log data (IP address, browser type, feature usage) collected automatically to secure and improve the service.

2. How we use your data

  • Calendar data is used only to identify meetings, display them to you, and schedule the meeting assistant to join meetings you have selected. We do not use calendar data for advertising or profiling.
  • Meeting transcripts are processed by AI (Google Gemini) to generate action items, summaries, talking points, and project suggestions — the core user-facing features of Actions.
  • Account data is used to operate your account, authenticate you, provide support, and send transactional emails (such as invitations and notifications).
  • Billing data is used to manage subscriptions and comply with tax and accounting law.

We do not sell personal data, and we do not use your data for third-party advertising.

3. Google API Services User Data Policy (Limited Use)

Actions' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google user data to provide or improve the user-facing features described in this policy.
  • We do not transfer Google user data to third parties except as necessary to provide these features (see “Who we share data with” below), to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
  • We do not use or transfer Google user data for serving advertisements.
  • We do not allow humans to read Google user data unless (a) we have your affirmative agreement for specific data, (b) it is necessary for security purposes such as investigating abuse, (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymised.
  • We do not use Google user data — including Google Calendar data and Google Workspace content — to develop, improve, or train generalised artificial intelligence or machine-learning models.

4. AI processing of your content

Transcript text is processed by Google Gemini to produce action items, summaries, and suggestions. This output is generated by AI and may contain errors; it is always presented in the product as AI-generated. Our AI processing is engaged under terms which do not permit your content to be used to train generalised AI models, and we do not train our own models on your content.

The meeting assistant is always a visible, named participant in any meeting it joins, so that everyone on the call can see that the meeting is being captured.

5. Who we share data with

We share personal data only with service providers who process it on our behalf, under written data-processing terms, solely to provide the service:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting and delivery.
  • Recall.ai — operates the meeting assistant. Recall.ai receives your calendar authorisation solely to detect and join the meetings you have selected and to return recordings and transcripts to us. Recall.ai uses vetted transcription sub-processors.
  • Google (Gemini API) — AI extraction of action items, summaries, and embeddings from transcript text.
  • Stripe — payment processing.
  • Resend — transactional email delivery (e.g. invitations, notifications).

Within your own organisation's workspace, teammates can see the meetings, tasks, and projects that belong to that organisation, subject to access controls. We never share your data across different customers' organisations. We may also disclose data where required by law, to protect our rights, or in connection with a merger or acquisition (with prior notice where Google user data is involved).

6. Data storage and security

Your data is stored in Supabase (PostgreSQL) and protected by access controls, including Row-Level Security policies. Connections use TLS encryption in transit and our hosting providers encrypt data at rest. OAuth credentials are restricted to backend services and are not made available through the browser application. Access to production systems is restricted, and we will notify you and the UK Information Commissioner's Office of a qualifying personal-data breach where required by law.

7. Data retention and deletion

We keep your data while your account is active, subject to legal and operational retention requirements. You can delete individual meetings and their transcripts in the product. Self-service account deletion is not currently available in Settings. To request deletion of your account or organisation data, email privacy@actions-app.com. We will verify your identity and complete verified requests without undue delay and in any case within one month, as required by UK GDPR. We will explain any information we must retain, such as billing records required by tax and accounting law.

8. Revoking access

You can disconnect your calendar at any time from Settings, which stops all future calendar reads and meeting joins. You can also revoke Actions' access to your Google account directly at myaccount.google.com/permissions (or your Microsoft account at account.live.com/consent/Manage).

9. International transfers

Where personal data is transferred outside the UK/EEA (for example, to a US-based provider), we rely on appropriate safeguards including the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with technical measures such as encryption in transit and at rest.

10. Your rights

Under the UK GDPR you have the right to access, rectify, erase, restrict, or object to our processing of your personal data, the right to data portability, and the right to withdraw consent. Exercise these by emailing privacy@actions-app.com. Where your data appears in another organisation's meetings, that organisation is the data controller and we act as its processor under our Data Processing Agreement; we will assist them in responding to your request. You may also complain to the Information Commissioner's Office, though we would appreciate the chance to resolve concerns first.

11. Cookies

We use only essential cookies and local storage for authentication and session management. We do not use third-party advertising or tracking cookies. Any analytics use privacy-respecting tools that do not track individuals across sites.

12. Children

Actions is a workplace tool intended for users aged 18 and over. We do not knowingly collect data from children.

13. Changes to this policy

We may update this policy from time to time. We will update the “last updated” date above and notify you of material changes by email or in the product before they take effect.

14. Contact

Privacy questions or requests: privacy@actions-app.com
NGJB Limited (trading as Actions), registered in England and Wales.