Privacy policy

This policy explains what information is collected when you use the website at actionbrain.ai and the service at app.actionbrain.ai, what we do with it, and what rights you have. It covers the whole service and everyone who uses it.

The short version

  • We do not sell information and we never hand it to advertisers.
  • Every business's data is completely separate from every other business's.
  • Anything that arrives through a Google or Microsoft connection is used only to give you the service, and never to train general artificial intelligence models.
  • We do not store card details.

Who is responsible

The service is operated by Shopy Partners, of 3 Derech HaHadarim, Ganei Tikva, Israel. For any privacy question, and to exercise any right: orel@actionbrain.ai.

What is collected

What you give us

  • Your name, your business name, an email address and a phone number, when you open an account or send a form from the site.
  • Your website address, when you ask us to build a chat from it.
  • Content you upload: documents, files and text you add to your knowledge base.

What is collected automatically

  • What a browser sends anyway, and the server's own security log. The site carries no measurement tools. The detail is on the cookies page.
  • Activity logs in the service, for security and for finding faults: who signed in, when, and from which address.

What arrives from the systems you connect

When you connect a system — conversations, messages, invoices, customers, a product catalogue or files — information comes in under the permission you granted, and only from the systems you chose. Nothing arrives from a system you did not connect, and nothing beyond the permission you gave.

Signing in with Google and with Microsoft

You can sign in to the service with a Google or Microsoft account, and you can connect a mailbox. Those are two different things, with two different permissions.

Signing in

When you sign in we receive your name, your email address, your profile picture and the unique identifier of that account. It is used to recognise you and to open or find your account — and for nothing else.

Connecting a mailbox

We read the mailbox an employee has connected themselves — and we store what we read. That is what the service is: the correspondence becomes your business's knowledge base, held on our servers, and your assistant answers out of it.

From each message we store the subject, the sender, the recipients and the copies, the time it was sent, and the message body. We record whether a message had attachments, but we do not store the contents of attachments. We do not access calendars, contacts, or Drive files.

A connected mailbox reads the last 90 days of mail by default, and that window can be set separately for each connection.

Derived data is stored too: the correspondence becomes conversations kept for your business, a search index, and the knowledge base the assistant answers from. Counts and summaries built from it — how many conversations there were, what customers ask about most — are stored alongside and used only to show you your own numbers.

All of it — the raw information and the derived — is used only to provide the service to you. It is never pooled with another business's data, never turned into a shared or anonymised data set, and never used to improve the service for anybody else.

What we are not allowed to do with it, and do not do

  • We do not sell it, and we do not pass it to anyone for advertising or marketing.
  • We do not use it to train general artificial intelligence models — not ours, and not any provider's.
  • We do not let a person read it, except in narrow cases: with your explicit permission, to deal with a fault you reported, where the law requires it, or for security.

ActionBrain's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The same rule applies to information received from Microsoft.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Google user data — raw or derived — is not used to develop, improve or train any AI/ML model, ours or a provider's, and is not transferred to any service that would. It is not used for targeted advertising, it is not used for credit or lending decisions, and it is not sold to any party.

You can disconnect at any time — from inside the service, or from the security settings of your Google or Microsoft account. When a mailbox is disconnected we withdraw the permission at Google and erase the stored access keys immediately. The conversations already built from that mailbox stay as your business's own records until you delete the connection itself, and at that point our stored copy of the Google data goes with it.

What the artificial intelligence does with your information

  • To answer a question, analyse a conversation or suggest knowledge, the relevant content is sent to an AI model provider we work with. Today those providers are OpenAI and Anthropic, through their paid APIs. The providers permitted to process content derived from Google Workspace are limited to those whose published terms prohibit using API data to train or improve models; we record that check per provider with the date the terms were read, and the limit is enforced by the application rather than left to configuration.
  • Your content is not used to train those providers' models, or anybody else's.
  • The system answers from your own knowledge base. When there is no answer there, it says so rather than inventing one.
  • You decide what enters the knowledge base on its own and what waits for someone in your business to approve it.

Why the information is used

  • To give you the service and run your account — that is performing our agreement with you.
  • To support you when you contact us.
  • To keep the system secure and prevent misuse — our legitimate interest, and every other customer's.
  • To meet obligations the law places on us, including tax and invoicing.
  • To send service messages. Marketing email is sent only with consent, and every message carries a way to stop it.

Payments

We do not store card details and we have no access to them. Payment is handled by a licensed processor that meets the payment card industry security standard (PCI-DSS), and it is the one that receives the card. From us it receives what a charge needs: a name, an email address and the plan. We keep the invoices and the record of the transaction, as the law requires.

Who the information is shared with

We use providers to run the service. Each gets access only to what its work requires, and each is bound to confidentiality and to protecting the information. These are the kinds of provider:

  • Hosting and infrastructure — the providers that hold the database and the file storage, and the one that runs the application itself. We will name them on request, at orel@actionbrain.ai.
  • AI model providers — for answering, analysing and suggesting knowledge, and only in order to run the features of the business whose information it is.
  • Payments and billing — as set out above.
  • Email and support — for service messages and for handling enquiries.
  • Protection against automated submissions — Cloudflare, on the forms on this site, to confirm that the person filling one in is a person. Details in the cookie notice.

Beyond those, information goes to an outside party only where the law requires it, or to defend a legal claim. It is not sold. It does not go to data brokers or to advertisers. It is not used for targeted advertising, and it is not used for credit or lending decisions.

Where it is kept

  • Enquiries sent from this website are stored on a server in Nuremberg, Germany, inside the European Union.
  • The service's own data is held with established infrastructure providers. The locations are available on request, at orel@actionbrain.ai.
  • Some providers may process information outside those places. Where that happens the transfer is made under a recognised legal mechanism, and the provider is held to the same standard of protection.

How long it is kept

  • An enquiry sent from the site — up to 24 months, then deleted.
  • Account data and content you uploaded — while the account is active, and up to 30 days after it closes.
  • Backups — encrypted, and held by our infrastructure provider.
  • Invoices and payment records — seven years, as tax law requires.
  • Security logs — up to 12 months.

Something deleted can still sit inside a backup until that backup is rotated out. It is not restored into the service and it is not used for anything.

How it is protected

Google user data is held in a PostgreSQL database and, for large items, in object storage, both with an established infrastructure provider, and with a separate database and separate storage for each environment. Both are encrypted at rest with AES-256 and reached only over an encrypted connection. The encryption keys are held per project inside hardware security modules certified to FIPS 140-2, and the daily backups inherit the same encryption.

The access keys that let us keep reading a mailbox are encrypted a second time, on their own, before they are written down. The key that unlocks them exists only in the running application, which is a different system from the database — never in the database, never in a backup, and never in our source code. A copy of the database is therefore not enough to read a single mailbox.

Every table holding customer information is separated at the database level by organisation, and no query the application makes runs with a permission that could cross that line. One business's information is never pooled with another's.

Access inside our own team is limited by role and by need, and it is logged. No system is completely immune, so it matters that you protect your own sign-in details and turn on two-step verification wherever you can.

If a security incident occurs that could affect you, we will tell you and the relevant authority as the law requires, without undue delay.

Your rights

Under Israel's Privacy Protection Law, and under the GDPR for anyone in the European Union, you have the right:

  • To see the information held about you.
  • To have information that is wrong corrected.
  • To have information deleted, subject to what the law requires us to keep.
  • To export your business's data in a form that can be read.
  • To object to certain processing, or ask that it be restricted.
  • To withdraw consent to marketing email.

To exercise a right, write to orel@actionbrain.ai. We will confirm who you are and come back with an answer within 30 days. If that answer does not satisfy you, you can complain to the Israeli Privacy Protection Authority, and anyone in the European Union can complain to their own supervisory authority.

Information about your own customers

When you connect a system, information about your customers comes in through it. For that information you are the one in control, and we act only on your instructions. Telling your customers, and getting whatever consents you need from them, is your responsibility. If your business needs a data processing agreement, we are glad to sign one — write to us.

Children

The service is built for businesses, not for children. We do not knowingly collect information about anyone under 16. If such information reaches us, we delete it.

Changes to this policy

We update this policy from time to time. A material change is published on the site before it takes effect, and account holders are told about it.

Last updated: 25 September 2026. For privacy questions and requests: orel@actionbrain.ai.