Privacy & Cookie Policy
Last Updated: February 1, 2026
This Privacy & Cookie Policy explains how act3.app ("we," "us," or "our") collects, uses, protects, and shares your personal information when you use our services.
Contact:
Email: privacy@act3.app
1. Information We Collect
We collect only the information necessary to provide our services:
Account Information: Email address, password, and login credentials
Profile Information: Name, profile photos, and other information you choose to add
User Content: Stories, text documents, photos, videos, audio recordings, and other content you create or upload
Collaboration Data: Contributor email addresses and shared content
Call Data: Audio and video call recordings when you use our communication features and permit recording
Payment Information: Processed securely by Stripe (we do not store full credit card details)
Technical Data: IP address, device type, browser information, and usage analytics
Marketing Data: When you consent to marketing cookies, we collect information about your interaction with our website and advertisements, including pages visited, links clicked, and ad engagement
2. How We Use Your Information
We use your information to:
Provide, operate, and maintain our services
Create and manage your account
Enable collaboration between you and contributors
Process payments securely
Facilitate audio/video calls and recordings
Improve our features and user experience
Provide customer support
Protect against fraud and abuse
Comply with legal obligations
Show you relevant advertisements (with your consent)
Measure marketing campaign effectiveness (with your consent)
We do not sell your personal data for monetary consideration. However, when you consent to marketing cookies, we may share certain data with advertising partners, which may constitute "sharing" under California law. You can opt out at any time.
3. AI Processing & Automated Decision-Making
We may use AI systems to help organize, summarize, or enhance your content. Your private content is never sold or used to train public AI models.
Automated Processing: We do not use automated decision-making (including profiling) that produces legal effects or similarly significantly affects you. Any AI features are tools to assist you in creating and organizing your content, with you maintaining full control.
Opt-Out: You may opt out of any future AI training by contacting privacy@act3.app.
4. Call Recording Notice
When you use audio or video call features, calls may be recorded and stored using Agora, our real-time communications provider.
Recordings are used only for features you request (such as playback, review, or transcription)
Recordings are protected with appropriate security measures
You are responsible for ensuring you have legal permission to record all participants in your jurisdiction
5. How We Share Your Information
We share your information only in the following circumstances:
Service Providers:
Stripe – Payment processing and fraud prevention
Supabase – Database hosting and user authentication
Agora – Real-time audio/video services and call recordings
Cloud Storage Providers – Secure content storage
Analytics Providers – Service improvement and usage insights (when you consent to analytics cookies)
Advertising Partners (with your consent):
Google Ads – Targeted advertising and campaign measurement
Meta (Facebook) – Targeted advertising and conversion tracking
[Other advertising platforms you use] – Marketing and retargeting
These providers are contractually bound to protect your data. Advertising partners may use your data only in accordance with their privacy policies and applicable law.
Legal Obligations: We may disclose your information when required by law, court order, or to protect our rights and safety.
Business Transfers: If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
6. Cookies
What Are Cookies?
Cookies are small text files stored in your browser that allow act3.app or third parties to recognize you.
First-party cookies: Set by act3.app
Third-party cookies: Set by our service providers and advertising partners
Session cookies: Deleted when you close your browser
Persistent cookies: Remain until they expire or you delete them
Cookie Categories
When you visit act3.app, you'll see a cookie consent banner with the following categories:
Strictly Necessary Cookies (Always Active)
These cookies are essential for the website to function and cannot be disabled.
Functional Cookies (Optional)
These cookies enable enhanced functionality and personalization, such as remembering your preferences.
Analytics Cookies (Optional)
These cookies help us understand how visitors use our site so we can improve it. All analytics data is anonymized.
Marketing Cookies (Optional)
These cookies track your activity to show you relevant advertisements and measure marketing campaign effectiveness. We use marketing cookies from the following providers:
Google Ads
Meta (Facebook Pixel)
[Add other marketing platforms you use]
You can opt out of marketing cookies at any time through your cookie preferences or by visiting our Do Not Sell or Share My Personal Information page.
Cookies We Use
How We Use Cookies
Strictly Necessary Cookies are used to:
Keep you logged in
Maintain secure sessions
Process payments
Enable essential site features
Prevent fraud and abuse
Ensure reliable service delivery
Analytics Cookies (with your consent) help us:
Understand how visitors use our site
Identify popular features and content
Improve user experience
Track website performance
Marketing Cookies (with your consent) enable us to:
Show you relevant advertisements on other websites
Measure the effectiveness of our marketing campaigns
Retarget visitors who have shown interest in our services
Track conversions and ROI from advertising
We do not use cookies for cross-site tracking without your consent.
Third-Party Cookies
Our service providers and advertising partners may set cookies to enable:
Essential Services:
Secure payment processing (Stripe)
Fraud protection (Stripe)
Seamless audio/video experiences (Agora)
Marketing Services (with your consent):
Targeted advertising (Google, Meta)
Conversion tracking and attribution
Audience building and retargeting
Campaign performance measurement
Managing Cookies
You can control cookies in several ways:
Cookie Preference Center:
Click "Manage Preferences" in our cookie banner or visit your account settings to enable or disable optional cookies at any time.
Browser Settings:
Configure your browser to block or delete cookies:
Global Privacy Control (GPC):
We honor Global Privacy Control signals. If your browser sends a GPC signal, we will automatically disable optional cookies including marketing cookies.
Note: Disabling strictly necessary cookies will prevent essential features (including login and payments) from working properly. Disabling marketing cookies will not affect your ability to use our services, but you may see less relevant advertisements.
7. Legal Basis for Processing (EEA/UK Users)
Under GDPR, we process your data based on:
Contract Performance: Providing the services you've requested
Legitimate Interests: Security, fraud prevention, service reliability, and analytics
Legal Obligations: Compliance with applicable laws
Consent: Marketing cookies, targeted advertising, and optional data processing
Your Rights Under GDPR
You have the right to:
Access your personal data
Correct inaccurate data
Delete your data (right to be forgotten)
Restrict or object to processing
Data portability (receive your data in a portable format)
Withdraw consent at any time (including marketing cookie consent)
Object to direct marketing and profiling
Lodge a complaint with your supervisory authority
Supervisory Authority:
If you are in the EEA or UK and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection authority:
To exercise your rights, contact privacy@act3.app.
8. California Privacy Rights (CPRA)
California residents have the right to:
Know what personal information we collect and how it's used
Request access to their data
Request deletion of their data
Correct inaccurate data
Opt out of the sale or sharing of personal information
Limit the use of sensitive personal information
Non-discrimination for exercising privacy rights
Opt Out of Targeted Advertising {#opt-out}
act3.app does not sell personal information for monetary consideration. However, when you consent to marketing cookies, we share certain information with advertising partners for targeted advertising purposes, which may constitute "sharing" under California law.
California residents can opt out by:
Clicking "Manage Preferences" in our cookie banner and disabling marketing cookies
Visiting our [Do Not Sell or Share My Personal Information] page
Enabling Global Privacy Control (GPC) in your browser - we automatically honor GPC signals
Contacting us at support@act3.app with "Opt-Out Request" in the subject line
Categories of Information Shared for Advertising: When you consent to marketing cookies, we may share:
Browsing activity and pages visited
Device information and IP address
Engagement with our website and advertisements
Email address (hashed for matching purposes)
Response Time: We will respond to verified requests within 45 days.
To exercise your rights, contact support@act3.app with "California Privacy Request" in the subject line.
9. Children's Privacy
Our services are not intended for children under 13. We do not knowingly collect information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at support@act3.app, and we will delete it promptly.
10. Data Retention
We retain your personal data only as long as necessary to:
Provide our services
Comply with legal obligations (typically 7 years for financial records)
Resolve disputes
Enforce our agreements
Account Deletion: When you delete your account, we will delete or anonymize your personal data within 30 days, except where we must retain it for legal, tax, or regulatory reasons.
Content Backups: Content may remain in backup systems for up to 90 days after deletion.
Marketing Data: If you opt out of marketing cookies, we will stop collecting new marketing data immediately. Historical marketing data may be retained for up to 26 months for analytics purposes, then deleted.
11. Data Security
We implement industry-standard security measures to protect your information, including:
Encryption: Data encrypted in transit (TLS/SSL) and at rest (AES-256)
Access Controls: Role-based access and multi-factor authentication for staff
Secure Infrastructure: Hosting with enterprise-grade security providers
Regular Audits: Security assessments and vulnerability testing
Employee Training: Staff trained on data protection and privacy
Incident Response: Procedures in place to respond to security incidents
No system is 100% secure, but we are committed to protecting your data to the best of our ability.
12. Data Breach Notification
In the unlikely event of a data breach that affects your personal information, we will:
Notify affected users within 72 hours of discovering the breach (as required by GDPR)
Inform relevant authorities as legally required
Provide details about what information was affected and what steps we're taking
Offer guidance on protecting yourself from potential harm
Notifications will be sent via email to the address associated with your account.
13. International Data Transfers
Your information may be processed and stored in countries outside your own, including the United States. When we transfer data internationally, we use appropriate safeguards to protect your information:
Standard Contractual Clauses (SCCs) approved by the European Commission
Adequacy Decisions for transfers to countries with adequate data protection
Additional Security Measures including encryption and access controls
By using our services, you consent to the transfer of your information to these countries.
Note for EEA/UK Users: Some of our advertising partners (Google, Meta) may transfer your data internationally when you consent to marketing cookies. These partners use appropriate safeguards including SCCs and adequacy decisions.
14. Data Protection Officer
For questions about how we handle your data or to exercise your privacy rights, you may contact our Data Protection team at:
Email: support@act3.app
Subject Line: "Data Protection Inquiry" or "Privacy Rights Request"
We will respond to all requests within 30 days (45 days for California requests).
15. Changes to This Policy
We may update this Privacy & Cookie Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
How We Notify You:
Post the updated policy on our website with a new "Last Updated" date
For significant changes (such as adding new data uses or partners), send email notification to registered users
Display a notice on the website or within the service
Request renewed consent for marketing cookies if changes affect how we use them
Your continued use of act3.app after changes take effect constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
16. Contact Us
For questions, privacy requests, or to exercise your rights, please contact us at:
Email: support@act3.app
Response Time: Within 30 days
For specific requests, please include:
Your full name and email address associated with your account
Clear description of your request
Any relevant details to help us verify your identity