Privacy policy
Last updated July 11, 2026
ActionOwl, formerly named BriefOwl and currently served at briefowl.io, is operated by Maivor AB, Sweden (the data controller). Contact: daniel@maivor.ai. The current private alpha reads connected measurement data and does not write to your site, source accounts, CMS, or code repository.
Account data
When you create an account we store your email address and authentication credentials, handled by Supabase Auth. We use your email to sign you in and to deliver the product (for example your weekly brief). We do not sell personal data, and we do not send marketing email without a separate, explicit opt-in.
Google data (Search Console and Analytics)
If you connect Google, ActionOwl requests two read-only scopes: Search Console (webmasters.readonly) and Google Analytics (analytics.readonly). We use this access for one purpose: pulling the performance data of the sites you select so the product can write your briefs and raise findings. We store the OAuth refresh token encrypted in Supabase Vault, and we store the generated briefs plus the aggregated metrics they are built from. You can remove a Google connection in Connections. That removes the local connection and its stored credential; it does not revoke the grant in your Google account. Revoke that separately in your Google account’s security settings if you want both sides removed.
ActionOwl’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, and never read by humans except with your permission for support, for security, or where the law requires it.
Bing credential
You may add a Bing Webmaster Tools API key. The service verifies the key with Bing and stores it encrypted in Supabase Vault. Bing site binding, scheduled ingestion, and Brief evidence are not implemented in the current alpha. You can remove the stored key in Connections.
How Briefs are written
The written analysis in a brief is produced by a large language model (Anthropic’s Claude, via API). The model receives pre-computed site-level metrics and supporting dimensions needed for the Brief, such as counts, page paths, search queries, and deltas. It does not receive your account password or raw visitor-level event rows. Under Anthropic’s commercial API policy, retained API data is not used for model training without express permission.
Analytics on this website
The public website at briefowl.io uses Google Analytics 4 to count visits — only with your consent. No tracking loads before you choose, the data is routed through our own domain, and declining changes nothing about how the site works. Change your mind any time:
Processors
The service uses Supabase (database, authentication, and encrypted secret storage), Vercel (hosting), Google (connected APIs and consent-gated website analytics), Anthropic (Brief synthesis), and Microsoft Bing when a Bing API key is verified. Some providers may process data outside the EEA. Where required, Maivor uses the provider’s data-processing terms and applicable transfer safeguards.
Cookies
Two kinds: a strictly necessary session cookie that keeps you signed in (no consent required), and optional analytics cookies that exist only if you allow them in the banner.
Retention and deletion
Account data, Briefs, and imported site data remain until you ask us to delete them. Archiving a site hides it from active views but is not deletion. Removing a connection removes its local binding and triggers credential cleanup; provider-side authorization must be revoked with that provider. To delete your account and its data, email daniel@maivor.ai. We complete verified deletion requests within 30 days.
Your rights
Under the GDPR you can request access, correction, deletion, restriction, or a portable copy of your personal data, and you can object to processing. Write to daniel@maivor.ai. You can also lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten, imy.se).