Effective September 21, 2026 · v2026-09-21.1

Privacy Policy

What ActVox stores, who else sees it, how long we keep it, and what you can do about it. Written from what the product actually does.

Who we are and how to reach us

ActVox LLC (trading as ActVox Research, "ActVox", "we") is responsible for the personal data described here. Our address is 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, United States.

For anything in this policy — a question, a request to see or delete your data, or a complaint — write to support@actvox.com. support@actvox.dev reaches the same team. We answer privacy requests from that inbox; there is no separate form to fill in.

This policy covers our marketing site at actvox.com, the ActVox application at os.actvox.com, and the API at api.actvox.com that connected apps such as ChatGPT use.

What we collect

Your account. Sign-in is handled by Clerk. Clerk holds your credentials, and your name, profile picture and phone number if you gave them. Our own database stores only your Clerk user id and your email address, plus what you fill in about your business: business name, logo, website address, industry, location and brand colours, along with preferences such as language and default platforms. If you sign in with a social account, we receive the identifier and email address that provider releases to Clerk — we do not receive your password.

Your workspace. Everything you or the agent create in a workspace: pages and their revision history, databases, whiteboards, uploaded files, chat threads and messages, calendar entries and content drafts, knowledge-base sources together with the text extracted from them, generated images and videos along with the prompts used to make them, and the workspace memory the agent keeps so later conversations have context. Page editing is collaborative, so we also store the incremental edit log that makes real-time editing work.

Reports. The web address you submit for analysis, the page text we fetch from it, the public information we find about that business and its competitors, and the report we generate from all of it. If you ask for a report before creating an account, we keep it against a temporary session so you can claim it later.

Connected accounts. If you connect Google Search Console, LinkedIn, Instagram/Meta or Telegram, we store the access credentials that connection issues, plus what the connection returns or sends — for example Telegram messages, or the post you publish.

Payments. We never see or store your card details — Stripe handles payment (Clerk did so for subscriptions started before September 2026). What we keep is the record of the transaction: the payment identifier, the plan or credit pack, the amount, the email address used to pay, and the resulting credit movements in your wallet.

Referrals. If you arrive through an affiliate link, or join our affiliate programme, we send your email address, your name and your account identifier to Affonso, which runs the programme and calculates commission. We do not send Affonso anything you create in ActVox.

How the product is used. Error reports, agent-run records, and — only if you allow analytics — product analytics. See Cookies, analytics and traces.

How we use it

  • To run the workspace, agent and reports you ask for. This is the bulk of it.
  • To sign you in and keep your account and your organisation's data separated and secure.
  • To bill you correctly, apply your plan's allowance, and meet our accounting and tax obligations.
  • To find and fix faults — error reports and agent traces are how we tell a broken feature from a bad prompt.
  • To understand which parts of the product are used, if you have allowed analytics.
  • To send you transactional email: a finished report, an organisation invitation, a notification you asked for.

We do not sell your personal data, and we do not license your workspace content to anyone for advertising or for training their models.

AI processing, and who else sees your content

ActVox is an AI product. To produce anything, the relevant part of your content has to be sent to a model or research provider. These are the providers that actually receive content, and what each one gets:

ProviderWhat we sendWhy
xAI (Grok)Page text we fetched, your business profile, your chat messages and the drafts being worked onThe main model behind the report pipeline and the workspace agent
Anthropic (Claude)Video script drafts, in-app support conversations, and images you attach to chatLong-form drafting, the support assistant, and reading images so the agent can use them
OpenAIKnowledge-base text (to build search embeddings), voice notes you record, and some image generation promptsSearch over your knowledge base, speech-to-text, image generation
Google (Gemini)Image generation promptsGenerating images, as an alternative to xAI
fal.aiVideo prompts and any source image you supplyGenerating video
TavilySearch queries built from your business details and report inputsWeb research inside reports and chat
Firecrawl, and Jina Reader as a fallbackThe web address to read — not your workspace contentFetching the text of a page you asked us to analyse
Google PlacesA business name and location queryGoogle Business Profile analysis
ApifyPublic social profile addressesReading public social profiles for the social and competitor analysis

Each provider handles what we send under its own agreement with us, and each keeps its own logs on its own schedule. We do not control those retention periods and we do not state them here as if we did.

Underneath all of this, Clerk provides sign-in, Stripe processes payments, Convex stores the database and your uploaded files, Resend sends transactional email, and PostHog and LangSmith receive the telemetry described below.

Connecting ChatGPT and other apps

You can connect ChatGPT (and, in future, other assistants) to ActVox. A connection is always bound to one workspace you pick during setup. It cannot reach your other workspaces, and it cannot reach an organisation workspace unless you are an admin of that organisation.

The first connection is read-only. Reading means the connected app can retrieve, from that one workspace: your page tree and page contents, search results, content drafts, reports and report sections, your knowledge-base text and the search results over it, your business profile, brand and design settings, workspace instructions, strategy and personas, database rows, and whiteboard elements. It cannot read your chat history with the ActVox agent, your stored credentials, or any other workspace.

Permission to change things is separate and requires you to approve it explicitly on a consent screen. Some actions cost credits from your wallet — refreshing a report, and adding or restoring a knowledge source, because those fetch the public web. Some actions are deliberately not available to a connected app at all: creating or revoking share links, and publishing or unpublishing content, because sending something to a real audience stays a human decision.

Revoking a connection is not the same as deleting data. Revoking stops the app from making any further request — the next call is refused — and it disables the keys behind that connection. It does not delete the ActVox records the connection created, and it cannot recall anything the app already received. Content that ChatGPT has read is in your ChatGPT conversation history, which is governed by OpenAI's terms, not ours.

You can see, pause, resume and revoke every connection in the app under Settings → Connections. We keep a record of each connection and a log of the calls it made — the method, the tool name and the result, never the content — so you and we can audit what happened. That log survives revocation on purpose.

When your work becomes visible to others

Nothing you create is public by default. Three things can change that, and all three are actions you take:

  • Making a report public. You can turn a report into a public page. Until you do, its full content requires your account.
  • Creating a share link. A share link is visible to anyone holding the URL unless you restrict it to your organisation. You can revoke it. Shared payloads are scrubbed of file identifiers and of anything that looks like an email address before they leave.
  • Publishing. Posting to LinkedIn, Instagram or Telegram only happens when you ask for it.

One thing to know about report links: even before you make a report public, anyone who has that report's identifier can see a limited preview of it — the business name, industry and description, and the headline scores. This exists so a report can be opened and claimed before signing up. The full report is not included. If a report's preview should not be seen at all, delete the report.

Inside an organisation, workspaces belong to the organisation and every member with access can see them. What you write in an organisation workspace stays with the organisation if you leave it.

Cookies, analytics and traces

The full inventory is in the Cookie Policy. In summary:

Product analytics (PostHog). Analytics starts switched off and captures nothing at all — no cookie, no network request — until you allow it. In the EU, EEA, UK and Switzerland it stays off until you accept. Elsewhere it runs under a notice you can turn off at any time, and a Global Privacy Control signal from your browser turns it off everywhere without you clicking anything. When it is on, it records page views and clicks, and may record a masked session replay in which text you type into inputs is hidden. If you are signed in, your Clerk id, email address and name are attached. Two places send text you wrote: the report feedback comment box and the in-app survey. On the app-connection consent screens nothing is captured at all. On sign-in and sign-up, page views are still recorded — we need them to know how many people complete signing up — but the web address is cut back to the path, so nothing carried in it reaches analytics, and no session replay is recorded there.

Agent traces (LangSmith). Agent runs are traced so we can debug them. Identifiers and secrets are always stripped out — email addresses, record identifiers, tokens and API keys are replaced before the trace is sent. Beyond that there is a setting that controls how much is sent, and at the level production runs by default the text of the prompts and the model's replies is included. We can run a stricter level that sends no content at all, so please assume the text is included. Your workspace, account and conversation are identified only by irreversible pseudonyms, so a trace cannot be traced back to you from inside LangSmith. Metadata is restricted to a fixed list of technical fields; anything else is dropped.

Error reports. Unhandled errors are captured with a stack trace so we can fix them. Because this is how we keep the service working and secure, it is not switched off by an analytics choice.

Page performance. We measure page speed with a cookieless measurement that sets nothing on your device and does no cross-site tracking.

How long we keep things

Some things are deleted automatically on a schedule the product actually runs:

WhatDeleted after
Generated image variants you did not select or use7 days
Reports created without an account and never claimed7 days
The workspace activity feed30 days
Archived image history on a report90 days
Expired app-connection codes1 day past expiry
Expired app-connection tokens30 days past expiry
Agent change proposals you neither accepted nor rejected7 days
Pending agent approvals24 hours
Workspace memory entries that carry an expiryat their expiry

Everything else — pages and their revision history, chat messages, report sections, knowledge-base text, uploaded files, connected-account messages — is kept for as long as the workspace exists, because it is your work and deleting it on a timer would be wrong. You control it: deleting a page, report or draft moves it out of the way, and "Delete forever" removes it. Deleting a workspace removes its contents.

We do not publish a fixed retention period for operational logs and traces, because the providers that hold them set their own schedules and we would be quoting a number we do not control.

What deleting your account actually removes

You can delete your account from your account settings. When you do, we receive the deletion and remove your personal workspaces together with everything inside them — pages, chats, reports, uploads, knowledge base, connected-account credentials — then remove your API keys, then remove your user record.

Being precise about what that does not cover, because the difference matters:

  • Organisation workspaces. They belong to the organisation, not to you. Deleting your account removes your access, not the organisation's data. An organisation owner deletes the organisation, which removes its workspaces.
  • Billing records. Payments, credit transactions and usage metering — including the email address used to pay — are kept so we can meet accounting and tax obligations and settle any dispute about a charge.
  • Your cookie-consent record. It is the evidence of the choice you made, so deleting it would destroy the proof that we honoured it.
  • Product feedback you sent us, and the audit log of any app connections you made.
  • Backups and provider copies. Our infrastructure providers keep operational backups, and the providers listed above keep their own logs. Copies can persist there for a period set by them, not by us.

If you want any of the retained records reviewed or removed where we are able to, write to support@actvox.com and we will tell you what we can and cannot do, and why.

Your choices

  • Get a copy of your work. In the app, Settings → General → Privacy and data → Export workspace data downloads a file containing that workspace's pages, agent memory, chat threads and messages, content drafts and reports. It covers one workspace at a time and tells you if it had to truncate a very large group. For anything it does not cover, ask us.
  • Correct it. Profile fields, business details and everything you created are editable in the app.
  • Delete it. Per item, per workspace, or your whole account, as described above.
  • Change your cookie choice. On actvox.com use "Cookie settings" in the footer or the button on the Cookie Policy. In the app use Settings → General → Privacy and data. Your choice is stored per site, so setting it in one place does not set it in the other.
  • Turn off analytics with a browser signal. We honour Global Privacy Control everywhere, not only in California.

Depending on where you live you may also have the right to object to or restrict processing, to receive your data in a portable form, or to complain to a data protection authority. Send any of those to support@actvox.com. If you are in the EEA, the UK or Switzerland you may also complain to your local supervisory authority.

Where your data is processed

ActVox LLC is a United States company, and the providers listed in this policy are predominantly United States providers. If you use ActVox from outside the United States, your data is transferred there. Where the law of your country requires a transfer safeguard, we rely on the standard contractual protections in our agreements with those providers.

Children

ActVox is a tool for businesses and is not intended for children. You must be at least 18 to hold an account. We do not knowingly collect personal data from children; if you believe a child has given us data, write to us and we will remove it.

Changes to this policy

When this policy changes we update the effective date at the top. If a change materially affects what we do with your data, we will tell you in the product before it takes effect. If a change alters what we store on your device, you will be asked for your cookie choice again.