Privacy
ActionConfirm is designed data-minimal: we keep only what the confirmation workflow needs, and we keep it protected.
What we store
- Organizer account: your Google user ID and email (encrypted at rest), so we can remember your documents and batches.
- Per-document records: the document ID and title, the extracted action items, and each item’s assignee and due date as written in your notes.
- Recipient emails: stored encrypted, plus a one-way keyed hash used for delivery status and attribution. They are never logged and never appear in analytics.
- Recipient responses: the response type, any correction text, and an optional note. Exactly what the recipient chose to send you.
- Email delivery state: per-item delivery status (accepted / delivered / failed / unknown) from our email provider, so your status view is truthful.
What we never store
- Your Google OAuth or refresh tokens. They flow straight to Google within a single request and are never persisted or logged.
- The content of your document beyond the action-items section you ask us to process.
- Recipient links or tokens. Only one-way hashes are stored. The links themselves exist only in the sent email.
- Any recipient data in analytics or admin surfaces (hashed pseudonymous identifiers only).
Third parties
- Google APIs. Reading the action-items section and writing the confirmed-results section, always at your explicit action.
- Resend. Delivering confirmation request emails.
Your control
- Deleting a confirmation batch deletes its items, links, and responses.
- Nothing is sent and nothing is written to your document without an explicit click.
- To request account/data deletion, see Support.