Privacy Policy

    Last Updated: 18 July 2026

    1. Introduction

    This Privacy Policy explains how ActionList ("we," "our," or "us"), the operator of the ActionList platform and the ActionList.io domain, based in Victoria, Australia, collects, uses, stores, transfers, and protects information in connection with the ActionList platform, including the website, web application, and iOS mobile application ("the Service").

    For the purposes of data protection laws that use these terms (such as the EU and UK GDPR), the operator of ActionList is the data controller of personal information processed through the Service. Contact details are in Section 18.

    2. Scope

    This Policy applies to all users worldwide who access or interact with the Service, including visitors, registered users, and organisations. It covers all versions of the Service, including web, mobile (iOS and Android), and any beta or experimental features.

    3. Information We Collect

    We collect data directly from you, automatically through system operations, and from third parties you choose to connect. This may include:

    3.1 Personal and Account Information

    • Name, email address, password (stored as a secure hash), and other account credentials
    • Communication details (support requests, feedback, inquiries)
    • Profile settings or usage preferences
    • Billing and subscription status (payments are processed by Apple or other payment providers; we do not receive or store full card numbers)

    3.2 Technical and Usage Data

    • Device identifiers, IP addresses, browser type, operating system
    • Pages visited, actions performed, and timestamps
    • Cookies, session data, and analytics identifiers
    • Crash reports and diagnostic data

    3.3 Uploaded and Generated Data

    • Tasks, notes, goals, habits, calendar events, focus sessions, and other content you create
    • Files, inputs, or data you upload or generate within the Service
    • Metadata and derived insights created by your activity

    3.4 Third-Party Sources

    • Information from services you choose to connect (e.g., Google Calendar, Apple), limited to what is needed to provide the integration

    4. How and Why We Use Information (Legal Bases)

    We process your information for the following purposes. Where the EU or UK GDPR or a similar law applies, the legal basis for each purpose is indicated:

    1. Operating and providing the Service — creating your account, storing and syncing your tasks and content, providing subscribed features (performance of a contract)
    2. Authentication and account security (performance of a contract; legitimate interests in securing the Service)
    3. Analytics and Service improvement — understanding how features are used, fixing crashes and errors (legitimate interests; consent where required for non-essential cookies or SDKs)
    4. Communications — service updates, security notices, support responses (performance of a contract; legitimate interests); marketing communications only with your consent, which you may withdraw at any time (consent)
    5. Fraud and abuse prevention, and enforcement of our Terms of Service (legitimate interests; legal obligation)
    6. Improving features using anonymised and aggregated data, including statistical analysis and improvement of AI-assisted features (legitimate interests) — see Section 11
    7. Complying with legal and regulatory obligations (legal obligation)

    We use anonymised and aggregated data — data that can no longer reasonably identify you — for analytics, product improvement, and business intelligence. Personally identifiable information is not shared publicly and is not sold.

    5. Data Sharing and Disclosure

    We do not sell your personal information, and we do not share it with third parties for their own advertising purposes.

    5.1 Sub-processors

    We share data with vendors who process it on our behalf to run the Service. Each acts as a sub-processor under contractual data-processing obligations and may only use your data to provide their service to us:

    • Supabase — database hosting, authentication, and file storage
    • Sentry — error monitoring and diagnostics
    • Mixpanel — product analytics and usage measurement
    • Anthropic — AI assistant and AI-assisted features
    • OpenAI — AI-assisted features
    • Resend — transactional and marketing email delivery
    • Stripe — payment and subscription processing
    • Google — calendar integration and Sign in with Google
    • Apple — Sign in with Apple and App Store billing

    5.2 Legal and Security Obligations

    We may disclose information where required to comply with law or valid legal process, to protect our rights, prevent fraud, or protect the safety of users or the public.

    5.3 Business or Ownership Changes

    In the event of a business restructure, merger, acquisition, sale, or other transfer of all or part of the Service, your data may be transferred as part of that transaction. We will notify you of any such change and of any choices you have, as required by applicable law. References to "ActionList," "we," "our," and "us" in this Policy include our successors and assigns.

    6. Cookies and Tracking

    We use cookies and similar technologies to keep you signed in, store preferences, and analyse Service usage. Where required by law (including in the EU/EEA and UK), we will request your consent before setting non-essential cookies or analytics identifiers, and you may withdraw that consent at any time. You may also disable cookies in your browser, though some features may not function correctly.

    7. Data Storage, Retention and Deletion

    We store data using reputable infrastructure providers (such as Supabase and its underlying cloud providers). We retain personal information only as long as necessary for the purposes described in this Policy, to comply with legal obligations, or to resolve disputes. Anonymised or aggregated data may be retained for statistical purposes.

    Account deletion: You can delete your account at any time from within the app or by emailing us. When your account is deleted, your personal information and content are deleted or anonymised within a reasonable period, except where retention is required by law. Residual copies in routine backups are removed as backups rotate.

    Export: You can export your data from the Service. We recommend keeping your own backups of important data.

    8. Data Security

    We implement reasonable technical and organisational security measures appropriate to the nature of the data we hold, including encryption in transit, hashed credentials, access controls, and reliance on audited infrastructure providers. No system can be guaranteed to be completely secure, and we encourage you to use a strong, unique password and to keep your credentials confidential.

    9. International Data Transfers

    Your information may be transferred to, stored in, or processed in countries other than your own — including Australia, the United States, Singapore, and the European Union — where our infrastructure providers operate.

    Where we transfer personal information from a jurisdiction that restricts international transfers (such as the EU/EEA, UK, or ASEAN jurisdictions with transfer rules), we rely on appropriate safeguards, such as transfers to countries with adequacy decisions, standard contractual clauses entered into by our infrastructure providers, or other mechanisms recognised by applicable law.

    10. Your Rights

    Subject to applicable law, you may request:

    • Access to the personal information we hold about you
    • Correction of inaccurate information
    • Deletion of your information
    • Export of your data in a portable format
    • Objection to or restriction of certain processing
    • Withdrawal of consent where processing is based on consent (without affecting prior processing)

    To exercise any right, contact info@actionlist.io. We may verify your identity before acting. We will respond within the timeframe required by your local law and in any case within 30 days (extendable where the law permits for complex requests, in which case we will tell you). Exercising your rights is free of charge except where the law allows a reasonable fee for manifestly excessive requests.

    10.1 Australia

    We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles to the extent they apply to us. If you believe we have mishandled your information, please contact us first; if you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

    10.2 European Economic Area and United Kingdom

    If you are in the EEA or UK, you have the rights listed above under the GDPR / UK GDPR, including the right to lodge a complaint with your local supervisory authority (or the UK Information Commissioner's Office). Where we rely on legitimate interests, you may object at any time; where we rely on consent, you may withdraw it at any time. We do not use your personal information for automated decision-making that produces legal or similarly significant effects.

    10.3 United States

    If you are a resident of California or another US state with a comprehensive privacy law, you have the rights of access, deletion, correction, and portability described above. We do not sell or share your personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA), and we do not use sensitive personal information for purposes requiring a right to limit. We will not discriminate against you for exercising your rights. You may designate an authorised agent to submit requests on your behalf.

    10.4 Singapore and Other ASEAN / Asian Jurisdictions

    If you are in Singapore, Malaysia, Thailand, Indonesia, the Philippines, Japan, South Korea, or another jurisdiction with data protection legislation (such as the Singapore PDPA), we handle your personal data in accordance with the consent, purpose-limitation, protection, and access/correction obligations of your local law. You may withdraw consent to processing by contacting us, in which case we may be unable to continue providing the Service to you.

    11. AI, Analytics, and Automation

    The Service is built around artificial intelligence, and AI processing is a core and necessary part of how the Service operates. When you use the Service, content you submit—which may include tasks, habits, reminders, notes, instructions, and chat content—is transmitted to third-party AI service providers, currently including Anthropic and OpenAI, and to other AI service providers that we may engage from time to time, so they can process your requests and generate responses. These providers process information on our behalf under applicable contractual data-processing, confidentiality, and security terms. We select AI providers whose applicable commercial terms do not permit content submitted through their APIs to be used to train their general-purpose AI models by default, unless training has been expressly enabled or consented to. We do not opt in to provider model training or knowingly submit identifiable personal content as provider feedback without appropriate notice or consent. AI service providers may temporarily retain submitted content and related technical information for service delivery, security, abuse prevention, legal compliance, and other purposes permitted under their applicable terms and data-retention policies. The providers used, processing locations, retention periods, and technical arrangements may change over time. Because AI processing is fundamental to the Service, you cannot use the Service without your content being transmitted to one or more AI service providers. If you do not agree to this processing, you should not use the Service. We may use information that has been aggregated or de-identified so that it no longer reasonably identifies you to analyse, maintain, and improve the Service. We do not use identifiable personal content to train our own or third-party AI models without your consent.

    AI-generated outputs may be inaccurate, incomplete, or unsuitable for your purposes. Verify AI-generated content before relying on it.

    12. Children's Privacy

    The Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will delete it promptly. If you believe a child has provided us personal information, contact us at info@actionlist.io.

    13. Third-Party Services You Connect

    If you connect third-party services (such as Google Calendar or Apple services) to ActionList, those services' own privacy policies govern their handling of your data. We only access the data needed to provide the integration you requested, and you can disconnect an integration at any time.

    14. Data Breach Notification

    We maintain procedures for detecting, assessing, and responding to data breaches. If a data breach occurs that is likely to result in serious harm or risk to you, we will notify you and the relevant regulator as required by applicable law — including the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth) and, where the GDPR applies, notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

    15. Changes to This Policy

    We may revise this Policy from time to time. If we make material changes to how we handle your personal information, we will notify you by email or in-app notice before the changes take effect and, where required by law, seek your consent. The "Last Updated" date at the top indicates the current version.

    16. Governing Law

    This Policy is governed by the laws of Victoria, Australia. This does not deprive you of the protection of mandatory data protection laws of your country of residence or your right to complain to your local data protection authority.

    17. No Fiduciary Duty

    Nothing in this Privacy Policy creates a fiduciary relationship between you and ActionList. You remain responsible for your own decisions regarding your data, including maintaining backups of important content.

    18. Contact

    Data Controller / Operator: ActionList (ActionList.io), Victoria, Australia
    Email: info@actionlist.io
    Privacy complaints (Australia): Office of the Australian Information Commissioner — oaic.gov.au