ADACTION
DOCK
PrivacyTermsAcceptable useRefunds
Back to product ↗

LEGAL / 01

Privacy
Policy

Effective 2 September 2026
Version 2026-09-02

01 Data we collect02 How we use it03 Website analytics04 Processors05 Retention06 Your rights

MINIMUM CONTEXT / DURABLE EVIDENCE

Your business data stays scoped
to the action you requested.

This Policy explains how RSAngel, operating ActionDock, processes personal information when you visit the site, create a workspace, connect an agent, or use the Service.

01

Data we collect

  • Account and billing data: name, email, workspace, plan, subscription identifiers, billing status, and transaction references. Full payment-card details are handled by the payment provider and are not stored by ActionDock.
  • Authentication data: hashed API keys, hashed dashboard-session tokens, magic-link records, credential names, and security events. Full API keys are shown only when created.
  • Job data: action inputs, supplied business text or structured records, workflow metadata, approval previews, results, errors, evidence, timestamps, and processing usage.
  • Connection data: connection names, HTTPS destinations, method and path policies, runtime write-policy modes, owner-authored reasonableness policies, optional setup-assistant instructions and proposals, documentation source URLs, and encrypted authentication secrets. The stored connection credential is not sent to the setup assistant or runtime AI checker, returned to agents, or displayed after storage. Do not paste other credentials or secrets into instructions, policies, paths, queries, or request bodies.
  • Reports and diagnostics: generated Markdown or JSON reports, callback delivery logs, IP address, request metadata, browser information, and operational logs needed for security and reliability.
  • Website analytics: on tracked public pages, we collect paths and titles, a referrer without query parameters, selected campaign parameters, page type, content progress, pricing and checkout interactions, device and browser information, and approximate location derived by Google Analytics. We do not send names, email addresses, credentials, job content, workspace identifiers, dashboard activity, or arbitrary URL parameters to analytics.
  • Support data: messages and attachments you send to support.
02

How and why we use data

We process data to provide contracted software, authenticate users, execute requested actions, enforce connection and approval policies, preserve job evidence, calculate plan usage, operate billing, prevent abuse, respond to support, comply with law, and improve reliability.

Depending on context and applicable law, our legal bases are performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where required. We do not sell personal information or use customer job content for targeted advertising.

Action inputs may be sent to the configured AI or research provider only when required for the selected action. If you use the optional connection setup assistant, its instruction and non-secret draft fields may also be sent to that provider; a destination-domain documentation search runs only when you select it.

If you enable a runtime reasonableness mode and acknowledge that processing, the exact owner-approved write context and your owner-authored policy are sent to the configured AI provider for an allow-or-reject check. The stored credential is not sent, and the runtime check does not search the web. If the check is unavailable, malformed, or inconclusive, the write is rejected. Deterministic destination, method, public-network and SSRF, approval-binding, and execution-limit checks remain in every mode and do not require model inference. Customers should avoid submitting credentials or unnecessary personal or sensitive data.

Optional voice dictation is handled by the browser's speech-recognition feature. The ActionDock page receives the resulting transcript, not the microphone audio; the browser or operating-system provider may process audio under its own terms. You can always type and edit the instruction, and dictation never submits or saves a connection automatically.

03

Website analytics

Google Tag Manager and Google Analytics load automatically on tracked public pages. Analytics storage is enabled by default. Advertising storage, advertising user data, and ad personalization remain disabled. ActionDock does not use this configuration for targeted advertising.

Analytics runs on public product, documentation, blog, legal, contact, and subscription-checkout pages. It is not included on the workspace dashboard, workspace-claim page, or signed payment-link page. Campaign values are limited to a fixed set of standard advertising parameters and are sanitized before collection; all other query parameters are removed from the reported page URL.

You may contact support@actiondock.app for a privacy request. Browser-level privacy controls may also affect whether analytics requests are delivered.

04

Service providers and transfers

We disclose data only as needed to infrastructure hosting, managed database, AI or research, website analytics, transactional email, observability, customer-support, and payment providers; to professional advisers under confidentiality; or to authorities when legally required. Google processes website analytics under its own terms and applicable data-protection obligations.

Data may be processed outside your country. Where required, we use contractual or other lawful safeguards for cross-border transfers. We do not disclose connection secrets to the calling agent, and we do not permit arbitrary third-party destinations outside a workspace owner’s configured connection.

05

Retention and security

Account, subscription, and financial records are retained for the period required to operate the account and meet legal obligations. Jobs, usage, events, reports, and callback logs follow configured product retention periods and may be deleted sooner by the workspace owner where supported. Backups expire on a rolling schedule.

We use encryption in transit, encrypted connection secrets, hashed authentication tokens, access controls, request limits, destination restrictions, audit records, and monitoring. No system is perfectly secure; report suspected compromise immediately to support@actiondock.app.

06

Your choices and rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent where processing relies on consent; and complain to a data-protection authority. We may verify identity before fulfilling a request.

Workspace owners can revoke API keys, remove reports, delete API connections, remove callbacks, and cancel billing through the dashboard. Contact us for account deletion or a privacy request. We will respond within the period required by applicable law.

ActionDock is intended for business users aged 18 or older and is not directed to children.

07

Controller and contact

RSAngel / ActionDock
Representative: Khan Svetlana
Business Registration Number: 580-50-00933
Address: 충청남도 아산시 신창면 천우물로 22, 101동 603호 (아산 삼부르네상스 더힐)
Email: support@actiondock.app

Material changes will be posted with a new effective date and communicated where required.

RSANGEL / ACTIONDOCK

Privacy Policy · version 2026-09-02

Back to top ↑