Privacy Policy
Last updated: August 17, 2026
This Privacy Policy explains what personal information ActionKeeper collects, how and why we use it, who may receive it, how long we keep it, and the choices and rights available to you.
It is intended to be readable and specific. It applies to ActionKeeper at actionkeeper.app and related services operated by LeaderPath, LLC ("ActionKeeper," "we," "us," or "our").
Two kinds of people, two different relationships
This matters more here than in most privacy policies, so it comes first.
If you are a provider — a speaker, trainer, coach, consultant, facilitator, or organization with a subscription — you chose ActionKeeper, you have an account, and we generally determine how and why we process your provider account, billing, security, and service-use information. For that information, LeaderPath, LLC generally acts as the business or controller under applicable privacy law.
If you are a participant — someone enrolled in a program by a provider — the provider generally decides why you are enrolled, what program information is collected, and how that information is used in the program. For participant program data that we process on the provider's instructions, the provider generally acts as the business or controller and ActionKeeper generally acts as its service provider or processor. We may act independently for limited operational purposes such as account security, fraud prevention, legal compliance, and protecting the service.
The exact legal roles can depend on the circumstances and applicable law. Section 9 explains the participant relationship in practical terms.
1. What we collect
From providers
| What | Why |
|---|---|
| Name and email address | To create your account and sign you in |
| Business name, role, website, support email, time zone, and country | To provide your public-facing branding, program defaults, support, and account administration |
| Logo and profile photograph, if you upload them | To display them to your participants |
| Material you upload — books, workbooks, guides, transcripts, and similar content | To provide your program and ground the AI coach in your work |
| Program and cohort content you create | To run your programs |
| Billing and transaction identifiers received from Stripe | To manage your subscription, payments, accounting, and fraud prevention |
| Sign-in times, device/session information, and security events | To secure the account, prevent abuse, troubleshoot, and show account activity |
| Support communications and information you choose to send us | To respond to requests, troubleshoot, and improve support |
From participants
| What | Why |
|---|---|
| First and last name and email address | To enroll you, identify your program account, and send program communications |
| Commitments and action steps you write | To provide the program and show your progress |
| Weekly check-in answers and reflections | To provide the program and support follow-through |
| Self-rated scores, where the program asks for them | To show progress over the program |
| Messages exchanged with the AI coach | To provide the AI coaching feature and let you review your conversation history |
| Email delivery events — such as sent, delivered, bounced, and opened | To operate program email, troubleshoot delivery, and stop sending to addresses that repeatedly fail |
| Basic service, session, and security information | To authenticate you, protect the service, prevent abuse, and troubleshoot technical issues |
We do not require participants to provide payment information, precise location data, advertising identifiers, biometric information, or health information as part of ordinary use. Providers should not design programs to solicit sensitive personal information unless they have determined that doing so is lawful and appropriate and have made any required disclosures or obtained any required consent.
Because commitments, reflections, and AI-coach messages are free-text fields, a participant may voluntarily include health information, personal circumstances, or other sensitive information even though ActionKeeper does not ask for it. Please do not submit sensitive information that is not necessary for the program.
What we do not do
ActionKeeper does not currently use advertising trackers, behavioral-advertising pixels, session-recording tools, or third-party analytics tools such as Google Analytics or Meta Pixel in the core service.
We use cookies or similar local technologies that are necessary to authenticate users, maintain sessions, protect security, and operate requested features. We do not currently use them for cross-context behavioral advertising. If our practices materially change, we will update this Policy and provide any notice or consent mechanism required by applicable law.
2. How we use personal information
- Provide, operate, maintain, and support ActionKeeper and its program features.
- Authenticate users, manage accounts and subscriptions, process billing-related records, and prevent fraud.
- Enable providers to create programs, enroll participants, send program communications, and view the information made available to them through the service.
- Provide AI-coaching functionality using the participant's message and relevant provider-supplied material.
- Protect the security, integrity, availability, and lawful use of the service.
- Respond to support requests, investigate technical problems, and enforce our Terms of Service.
- Comply with law, lawful process, and obligations that apply to us.
- Generate service-level operational information that does not identify an individual, where permitted by law.
3. What we do not use your data for
- We do not sell your personal information.
- We do not share personal information for cross-context behavioral advertising and do not use personal information for targeted advertising.
- We do not use your uploaded provider material to train generalized AI models, ours or anyone else's.
- We do not use participant content to train generalized AI models.
- We do not share one provider's proprietary program material with another provider.
- We do not read participant content in the ordinary course of operating the platform, except as described in Section 7 for support, security, abuse prevention, legal compliance, or other limited operational reasons.
- We do not use participant information to make decisions producing legal or similarly significant effects about employment, credit, housing, insurance, or other eligibility.
4. Who else may process or receive your information
ActionKeeper relies on service providers to operate the platform. Our current key service providers include:
| Service | What it does | Where |
|---|---|---|
| Supabase | Database, authentication, file storage, and related infrastructure | Primarily United States |
| Vercel | Hosting, application delivery, and content delivery | United States and global edge infrastructure |
| Resend | Transactional and program email delivery | United States |
| Stripe | Payment processing and related billing services; payment-card details are provided to Stripe rather than stored by us | United States and other locations used by Stripe |
| Anthropic | AI model services used by the AI coach | United States and other locations used to provide the service |
| Voyage AI | Creates searchable representations of provider-uploaded material used to retrieve relevant passages | United States and other locations used to provide the service |
The specific vendors, hosting locations, and subprocessor arrangements may change as the service evolves. We require service providers to process personal information only for authorized purposes and subject to contractual protections appropriate to the service they provide.
AI service providers receive only the information reasonably needed to generate or retrieve a response for the feature being used, such as the participant's message and relevant passages of provider material. Under our current service arrangements, provider-uploaded material and participant content are not used by these AI service providers to train generalized models for their own purposes.
We may also disclose personal information when reasonably necessary to comply with law or lawful legal process; protect the rights, safety, security, or property of ActionKeeper, our users, or others; investigate fraud, abuse, or security incidents; or complete a merger, financing, acquisition, reorganization, or sale of all or part of our business, subject to applicable law.
ActionKeeper is operated from the United States, and personal information may be processed or stored in the United States. If information is transferred from another country, the laws of the destination may differ from those in your country. Where applicable law requires a specific transfer mechanism or contractual safeguard, we will use an appropriate mechanism before making a transfer that requires it.
5. How long we keep information
| Data | Kept for |
|---|---|
| Provider account and active provider content | While the account is open; after account closure, generally up to 30 days in active systems before deletion, subject to legal, security, backup, and accounting exceptions |
| Participant program data | While the relevant program and provider account remain active, then generally subject to the provider account's deletion schedule or the provider's lawful instructions |
| Test sandboxes | 30 days, then archived or deleted according to the applicable test environment process |
| Email delivery records | Generally 12 months |
| Security and audit records | Generally 24 months, or longer if reasonably necessary to investigate or document a security or legal matter |
| Billing, transaction, tax, and accounting records | For the period required or reasonably necessary for accounting, tax, fraud-prevention, dispute, and legal-compliance purposes |
| Backups | Retained according to our infrastructure provider's backup schedule; deleted information may remain in encrypted or access-restricted backups until those backups are overwritten or expire |
Deletion from the live service does not necessarily remove every residual copy immediately. Information may remain temporarily in backups, logs, or records we must retain for security, fraud prevention, accounting, dispute resolution, or legal compliance. We do not restore deleted information from backup except where reasonably necessary for disaster recovery, security, or legal obligations.
6. Your choices and privacy rights
Depending on your relationship with ActionKeeper and the law that applies to you, you may have rights to:
- Access or confirm whether we process personal information about you.
- Correct inaccurate personal information.
- Delete personal information, subject to lawful exceptions.
- Obtain a portable copy of certain information where required by law or where the product provides an export feature.
- Opt out of certain processing such as sale, targeted advertising, or certain profiling where those activities occur and applicable law gives you that right.
- Appeal a refusal to act on a privacy request where applicable law provides an appeal right.
- Exercise privacy rights without unlawful discrimination or retaliation.
Providers can manage much of their account and program information from within the service. Participants should generally submit program-data requests to the provider who enrolled them because that provider ordinarily controls the program data. You may also contact us, and we will either respond directly where appropriate or route the request to the relevant provider.
To make a privacy request, email info@actionkeeper.app. We may need to verify your identity or authority before completing a request. We aim to respond within 30 days, but some laws allow a different response period or an extension in appropriate circumstances.
ActionKeeper does not currently sell personal information, share personal information for cross-context behavioral advertising, or use personal information for targeted advertising. If those practices change, we will update this Policy and provide any legally required opt-out method.
California, Texas, and other U.S. state privacy laws may provide additional rights if their applicability thresholds and other requirements are met. This Policy is intended to describe our actual practices regardless of whether a particular state privacy law applies to a specific user.
7. Who can see what
This is the section participants care about most, so it is specific.
| The provider who enrolled you | Your employer or client organization | ActionKeeper | |
|---|---|---|---|
| Your name and email | Yes | Depends on how the organization or provider enrolled you | Yes, as needed to operate the service |
| Your commitments and action steps | Yes | Not through ordinary reporting; reporting is generally aggregated | Only as described below |
| Your check-in answers and reflections | Yes | Not through ordinary reporting; reporting is generally aggregated | Only as described below |
| Your conversations with the AI coach | No through ordinary provider features | No through ordinary organization reporting | Processed by ActionKeeper and its authorized service providers to provide and protect the feature; limited human access may occur as described below |
| Whether you are completing check-ins | Yes | May be shown in aggregate or program-level reporting, depending on program configuration | Yes, as needed to operate the service |
Standard reporting to a client organization is designed to show participation totals and common themes across a cohort rather than attribute individual reflections to named participants. A provider is responsible for telling participants if a particular program is configured differently or if the provider separately exports and uses information outside ActionKeeper.
ActionKeeper personnel do not routinely read participant content. Authorized personnel may access customer or participant content when reasonably necessary to provide support requested by a customer, investigate security or abuse, maintain service integrity, comply with law, or protect users or the service. Access is limited to authorized personnel and is logged or otherwise controlled where supported by our systems.
8. Security
- Sign-in uses a secure link sent to the user's email account. Users are responsible for protecting access to that email account.
- Two-factor authentication is available to providers and is required for platform administrators.
- Data separation between providers is enforced using database access controls designed to prevent one provider from accessing another provider's data.
- Sign-in attempts, verification attempts, and registration are rate-limited or otherwise protected against abuse.
- Data is encrypted in transit using industry-standard encrypted connections, and our infrastructure providers provide additional security controls for stored data.
No online service can guarantee absolute security. We maintain administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, alteration, or disclosure, and we review those safeguards as the service evolves.
ActionKeeper has not completed a SOC 2 audit or equivalent independent security certification as of the date of this Policy. We will not represent otherwise unless and until that changes.
9. If you are a participant
- Somebody enrolled you. A provider — such as a speaker, trainer, coach, facilitator, consultant, or organization — is using ActionKeeper to follow up after a program or learning experience. Program communications identify the provider responsible for the program.
- Your commitments, check-in responses, and other program information are generally visible to the provider who enrolled you. Standard organization-level reporting is designed to use totals and themes rather than identify who wrote a particular reflection.
- Your AI coach conversations are not visible to the provider or your employer through ordinary product features. They are still processed by ActionKeeper and authorized AI service providers to operate the feature, and limited human access may occur for the reasons described in Section 7.
- You can stop optional program emails using the preferences or unsubscribe controls provided in those messages. Certain strictly necessary service or security messages may still be sent when appropriate.
- You can request access, correction, or deletion as described in Section 6. Because the provider generally controls participant program data, we may need to coordinate the request with that provider.
- AI safety features may be designed to recognize some language associated with crisis or urgent situations and may present emergency or crisis resources when triggered. These automated safeguards cannot identify every crisis, are not monitored in real time, and are not a clinical or emergency service.
10. Children and minors
ActionKeeper is not designed for or directed to children or minors under 18. Providers must not knowingly enroll anyone under 18. We do not knowingly collect personal information from children under 13, and if we learn that we have done so without legally valid authorization, we will take reasonable steps to delete it as required by law.
If you believe a person under 18 has been enrolled or that we have collected information from a child, contact us at info@actionkeeper.app.
11. Changes to this Policy
We may update this Policy as our service, vendors, legal obligations, or privacy practices change. If a change materially affects how we use personal information or materially reduces a user's rights, we will provide notice appropriate to the change, which may include email or an in-product notice. The "Last updated" date at the top identifies the current version.
12. Contact
LeaderPath, LLC, a Texas limited liability company
3526 Lakeview Pkwy, Ste. B-104, Rowlett, TX 75088
