Privacy & Cookie Policy

Last Updated: February 1, 2026

This Privacy & Cookie Policy explains how act3.app ("we," "us," or "our") collects, uses, protects, and shares your personal information when you use our services.

Contact:
Email: privacy@act3.app

1. Information We Collect

We collect only the information necessary to provide our services:

Account Information: Email address, password, and login credentials

Profile Information: Name, profile photos, and other information you choose to add

User Content: Stories, text documents, photos, videos, audio recordings, and other content you create or upload

Collaboration Data: Contributor email addresses and shared content

Call Data: Audio and video call recordings when you use our communication features and permit recording

Payment Information: Processed securely by Stripe (we do not store full credit card details)

Technical Data: IP address, device type, browser information, and usage analytics

Marketing Data: When you consent to marketing cookies, we collect information about your interaction with our website and advertisements, including pages visited, links clicked, and ad engagement

2. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain our services

  • Create and manage your account

  • Enable collaboration between you and contributors

  • Process payments securely

  • Facilitate audio/video calls and recordings

  • Improve our features and user experience

  • Provide customer support

  • Protect against fraud and abuse

  • Comply with legal obligations

  • Show you relevant advertisements (with your consent)

  • Measure marketing campaign effectiveness (with your consent)

We do not sell your personal data for monetary consideration. However, when you consent to marketing cookies, we may share certain data with advertising partners, which may constitute "sharing" under California law. You can opt out at any time.

3. AI Processing & Automated Decision-Making

We may use AI systems to help organize, summarize, or enhance your content. Your private content is never sold or used to train public AI models.

Automated Processing: We do not use automated decision-making (including profiling) that produces legal effects or similarly significantly affects you. Any AI features are tools to assist you in creating and organizing your content, with you maintaining full control.

Opt-Out: You may opt out of any future AI training by contacting privacy@act3.app.

4. Call Recording Notice

When you use audio or video call features, calls may be recorded and stored using Agora, our real-time communications provider.

  • Recordings are used only for features you request (such as playback, review, or transcription)

  • Recordings are protected with appropriate security measures

  • You are responsible for ensuring you have legal permission to record all participants in your jurisdiction

5. How We Share Your Information

We share your information only in the following circumstances:

Service Providers:

Stripe – Payment processing and fraud prevention

Supabase – Database hosting and user authentication

Agora – Real-time audio/video services and call recordings

Cloud Storage Providers – Secure content storage

Analytics Providers – Service improvement and usage insights (when you consent to analytics cookies)

Advertising Partners (with your consent):

Google Ads – Targeted advertising and campaign measurement

Meta (Facebook) – Targeted advertising and conversion tracking

[Other advertising platforms you use] – Marketing and retargeting

These providers are contractually bound to protect your data. Advertising partners may use your data only in accordance with their privacy policies and applicable law.

Legal Obligations: We may disclose your information when required by law, court order, or to protect our rights and safety.

Business Transfers: If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

6. Cookies

What Are Cookies?

Cookies are small text files stored in your browser that allow act3.app or third parties to recognize you.

  • First-party cookies: Set by act3.app

  • Third-party cookies: Set by our service providers and advertising partners

  • Session cookies: Deleted when you close your browser

  • Persistent cookies: Remain until they expire or you delete them

Cookie Categories

When you visit act3.app, you'll see a cookie consent banner with the following categories:

Strictly Necessary Cookies (Always Active)
These cookies are essential for the website to function and cannot be disabled.

Functional Cookies (Optional)
These cookies enable enhanced functionality and personalization, such as remembering your preferences.

Analytics Cookies (Optional)
These cookies help us understand how visitors use our site so we can improve it. All analytics data is anonymized.

Marketing Cookies (Optional)
These cookies track your activity to show you relevant advertisements and measure marketing campaign effectiveness. We use marketing cookies from the following providers:

  • Google Ads

  • Meta (Facebook Pixel)

  • [Add other marketing platforms you use]

You can opt out of marketing cookies at any time through your cookie preferences or by visiting our Do Not Sell or Share My Personal Information page.

Cookies We Use

Screenshot of a table listing cookies with columns for Cookie Name, Purpose, Duration, Type, and Category. Examples include session_id for maintaining logged-in sessions, auth_token for account authentication, csrf_token for security, and tracking cookies like _ga and _gid for Google Analytics.

How We Use Cookies

Strictly Necessary Cookies are used to:

  • Keep you logged in

  • Maintain secure sessions

  • Process payments

  • Enable essential site features

  • Prevent fraud and abuse

  • Ensure reliable service delivery

Analytics Cookies (with your consent) help us:

  • Understand how visitors use our site

  • Identify popular features and content

  • Improve user experience

  • Track website performance

Marketing Cookies (with your consent) enable us to:

  • Show you relevant advertisements on other websites

  • Measure the effectiveness of our marketing campaigns

  • Retarget visitors who have shown interest in our services

  • Track conversions and ROI from advertising

We do not use cookies for cross-site tracking without your consent.

Third-Party Cookies

Our service providers and advertising partners may set cookies to enable:

Essential Services:

  • Secure payment processing (Stripe)

  • Fraud protection (Stripe)

  • Seamless audio/video experiences (Agora)

Marketing Services (with your consent):

  • Targeted advertising (Google, Meta)

  • Conversion tracking and attribution

  • Audience building and retargeting

  • Campaign performance measurement


Managing Cookies

You can control cookies in several ways:

Cookie Preference Center:
Click "Manage Preferences" in our cookie banner or visit your account settings to enable or disable optional cookies at any time.

Browser Settings:
Configure your browser to block or delete cookies:

Global Privacy Control (GPC):
We honor Global Privacy Control signals. If your browser sends a GPC signal, we will automatically disable optional cookies including marketing cookies.

Note: Disabling strictly necessary cookies will prevent essential features (including login and payments) from working properly. Disabling marketing cookies will not affect your ability to use our services, but you may see less relevant advertisements.

7. Legal Basis for Processing (EEA/UK Users)

Under GDPR, we process your data based on:

  • Contract Performance: Providing the services you've requested

  • Legitimate Interests: Security, fraud prevention, service reliability, and analytics

  • Legal Obligations: Compliance with applicable laws

  • Consent: Marketing cookies, targeted advertising, and optional data processing

Your Rights Under GDPR

You have the right to:

  • Access your personal data

  • Correct inaccurate data

  • Delete your data (right to be forgotten)

  • Restrict or object to processing

  • Data portability (receive your data in a portable format)

  • Withdraw consent at any time (including marketing cookie consent)

  • Object to direct marketing and profiling

  • Lodge a complaint with your supervisory authority

Supervisory Authority:
If you are in the EEA or UK and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection authority:

To exercise your rights, contact privacy@act3.app.

8. California Privacy Rights (CPRA)

California residents have the right to:

  • Know what personal information we collect and how it's used

  • Request access to their data

  • Request deletion of their data

  • Correct inaccurate data

  • Opt out of the sale or sharing of personal information

  • Limit the use of sensitive personal information

  • Non-discrimination for exercising privacy rights

Opt Out of Targeted Advertising {#opt-out}

act3.app does not sell personal information for monetary consideration. However, when you consent to marketing cookies, we share certain information with advertising partners for targeted advertising purposes, which may constitute "sharing" under California law.

California residents can opt out by:

  1. Clicking "Manage Preferences" in our cookie banner and disabling marketing cookies

  2. Visiting our [Do Not Sell or Share My Personal Information] page

  3. Enabling Global Privacy Control (GPC) in your browser - we automatically honor GPC signals

  4. Contacting us at support@act3.app with "Opt-Out Request" in the subject line

Categories of Information Shared for Advertising: When you consent to marketing cookies, we may share:

  • Browsing activity and pages visited

  • Device information and IP address

  • Engagement with our website and advertisements

  • Email address (hashed for matching purposes)

Response Time: We will respond to verified requests within 45 days.

To exercise your rights, contact support@act3.app with "California Privacy Request" in the subject line.

9. Children's Privacy

Our services are not intended for children under 13. We do not knowingly collect information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at support@act3.app, and we will delete it promptly.

10. Data Retention

We retain your personal data only as long as necessary to:

  • Provide our services

  • Comply with legal obligations (typically 7 years for financial records)

  • Resolve disputes

  • Enforce our agreements

Account Deletion: When you delete your account, we will delete or anonymize your personal data within 30 days, except where we must retain it for legal, tax, or regulatory reasons.

Content Backups: Content may remain in backup systems for up to 90 days after deletion.

Marketing Data: If you opt out of marketing cookies, we will stop collecting new marketing data immediately. Historical marketing data may be retained for up to 26 months for analytics purposes, then deleted.

11. Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption: Data encrypted in transit (TLS/SSL) and at rest (AES-256)

  • Access Controls: Role-based access and multi-factor authentication for staff

  • Secure Infrastructure: Hosting with enterprise-grade security providers

  • Regular Audits: Security assessments and vulnerability testing

  • Employee Training: Staff trained on data protection and privacy

  • Incident Response: Procedures in place to respond to security incidents

No system is 100% secure, but we are committed to protecting your data to the best of our ability.

12. Data Breach Notification

In the unlikely event of a data breach that affects your personal information, we will:

  • Notify affected users within 72 hours of discovering the breach (as required by GDPR)

  • Inform relevant authorities as legally required

  • Provide details about what information was affected and what steps we're taking

  • Offer guidance on protecting yourself from potential harm

Notifications will be sent via email to the address associated with your account.

13. International Data Transfers

Your information may be processed and stored in countries outside your own, including the United States. When we transfer data internationally, we use appropriate safeguards to protect your information:

  • Standard Contractual Clauses (SCCs) approved by the European Commission

  • Adequacy Decisions for transfers to countries with adequate data protection

  • Additional Security Measures including encryption and access controls

By using our services, you consent to the transfer of your information to these countries.

Note for EEA/UK Users: Some of our advertising partners (Google, Meta) may transfer your data internationally when you consent to marketing cookies. These partners use appropriate safeguards including SCCs and adequacy decisions.

14. Data Protection Officer

For questions about how we handle your data or to exercise your privacy rights, you may contact our Data Protection team at:

Email: support@act3.app
Subject Line: "Data Protection Inquiry" or "Privacy Rights Request"

We will respond to all requests within 30 days (45 days for California requests).

15. Changes to This Policy

We may update this Privacy & Cookie Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How We Notify You:

  • Post the updated policy on our website with a new "Last Updated" date

  • For significant changes (such as adding new data uses or partners), send email notification to registered users

  • Display a notice on the website or within the service

  • Request renewed consent for marketing cookies if changes affect how we use them

Your continued use of act3.app after changes take effect constitutes acceptance of the updated policy. We encourage you to review this policy periodically.

16. Contact Us

For questions, privacy requests, or to exercise your rights, please contact us at:

Email: support@act3.app
Response Time: Within 30 days

For specific requests, please include:

  • Your full name and email address associated with your account

  • Clear description of your request

  • Any relevant details to help us verify your identity