Privacy policy
Last updated August 28, 2026
ActionOwl, served at actionowl.io and formerly named BriefOwl, is operated by Maivor AB (org. no. 559539-4726), Sparrgrensgatan 10, 416 54 Göteborg, Sweden — the data controller. Contact: daniel@maivor.ai. The current private alpha reads connected measurement data and the public pages of the sites you connect. ActionOwl does not write to your site, source accounts, CMS, or code repository unless you explicitly accept the exact Action and separately approve its immutable execution preview. In the bounded GitHub pilot, ActionOwl may then create one new branch, commit the approved change to one bounded file, and open one draft pull request in the selected repository; it does not merge, deploy, or modify workflows.
Account data
When you create an account we store your email address and authentication credentials, handled by Supabase Auth. We use your email to sign you in and to deliver the product (for example your weekly brief). We do not sell personal data, and we do not send marketing email without a separate, explicit opt-in.
SEO sprint inquiries
When you ask about an SEO evidence-to-action sprint, Maivor AB stores the email address you provide, a source-page label and the latest request time in Supabase. We use these details and your subsequent correspondence to handle your inquiry and discuss whether the sprint is suitable. Microsoft 365 handles our business email. Our lawful basis is our legitimate interest in responding to business inquiries you initiate (GDPR Article 6(1)(f)). We do not subscribe you to a newsletter or send unrelated marketing.
We retain inquiry information while needed to handle your request. We remove it from active records when the inquiry closes, unless specific information remains necessary for an agreed service or a legal obligation. Inquiry closure and deletion are handled manually. You can object to this processing or request deletion by emailing daniel@maivor.ai.
Google data (Search Console and Analytics)
If you connect Google, ActionOwl requests two read-only scopes: Search Console (webmasters.readonly) and Google Analytics (analytics.readonly). We use this access for one purpose: pulling the performance data of the sites you select so the product can write your briefs and raise findings. We store the OAuth refresh token encrypted in Supabase Vault, and we store the generated briefs plus the aggregated metrics they are built from. You can remove a Google connection in Connections. That removes the local connection and its stored credential; it does not revoke the grant in your Google account. Revoke that separately in your Google account’s security settings if you want both sides removed.
ActionOwl’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, and never read by humans except with your permission for support, for security, or where the law requires it.
Who we share, transfer, or disclose Google user data to
We do not sell Google user data. We do not share, transfer, or disclose it to any third party except the five service providers below. Each acts as our processor under terms that limit its use of the data to delivering and securing the service:
- Supabase (database, authentication, and encrypted secret storage) — stores the Search Console and Analytics metrics imported for your sites, the Briefs and recommendations written from them, and your Google OAuth refresh token, held encrypted in Supabase Vault.
- Vercel (application hosting) — runs the application servers and scheduled jobs, so Google user data passes through Vercel’s compute while a Brief is being generated. Vercel does not retain it as a data set of its own.
- Anthropic (Claude API, used to write the analysis) — receives the pre-computed facts a Brief is built from: site-level metric totals and week-over-week deltas, page paths, and search-query terms. It never receives your OAuth token or your credentials. Under Anthropic’s commercial API terms this data is not used to train models. When optional Company Research is enabled for a site, Anthropic also receives a bounded first-party read of up to 12 publicly reachable pages from that site to produce a cited, display-only Company Profile. It receives no login-protected page, OAuth token, account password, or raw visitor-level event row. Anthropic’s standard API retention deletes inputs and outputs within 30 days, subject to safety, legal, or separately agreed exceptions; covered Fable requests are retained for 30 days for safety review. Commercial API inputs and outputs are not used for model training unless Maivor explicitly opts in.
- OpenAI (OpenAI Ireland Ltd for EEA customers; API validation) — when this validation is enabled, independently reviews proposed Actions and Deep Dive claims. It receives the minimised evidence needed for that review: site-level metric totals and deltas, page paths, search-query terms, and public-page metadata. It never receives OAuth tokens, account passwords, or raw visitor-level event rows. OpenAI states that API data is not used to train its models unless the customer explicitly opts in. ActionOwl disables Responses API storage; under OpenAI’s standard data controls, prompts and responses may nevertheless remain in abuse-monitoring logs for up to 30 days.
- Resend (transactional email delivery, when Brief email is enabled for your account) — receives your email address and the summary carried in the message: the site domain, the one-line health figure, and up to three recommended-action titles. It does not receive the underlying data set.
Beyond those providers, Google user data is transferred only in the narrow cases the Google API Services User Data Policy permits: with your explicit consent, to comply with applicable law or valid legal process, or as part of a merger or acquisition after we have notified you and you have consented. It is never shared for advertising, personalisation, credit assessment, lending, or any other purpose unrelated to producing the features you asked for. These providers are established in or may process data outside the EEA, including in the United States. Maivor relies on each provider’s data-processing agreement and the transfer safeguards it commits to (standard contractual clauses and, where applicable, the EU–US Data Privacy Framework).
How we protect your data
Credentials and connected-source data are protected by specific technical measures, not a general promise:
- Encrypted in transit. The site and every API call are served over HTTPS/TLS only. Plain HTTP is redirected, and the domain is sent with HTTP Strict Transport Security (two-year max-age). Our calls out to Google, Supabase, Anthropic, OpenAI, and Resend are TLS-encrypted.
- Sensitive credentials encrypted at rest. Your Google OAuth refresh token and any Bing API key are never written to ordinary application tables. They are stored encrypted in Supabase Vault; the database keeps only a reference id, and the plaintext exists transiently in server memory for the length of a single provider call. The remaining data is encrypted at rest by Supabase’s managed Postgres.
- Access control at the row. Every workspace-scoped table has PostgreSQL row-level security enabled, so a signed-in session can read only rows belonging to a workspace it is a member of. The database functions that can decrypt a stored credential are revoked from every browser-reachable role and callable only by server-side code holding the service-role key, which is never shipped to the browser.
- Least privilege by scope. We request read-only Google scopes and therefore cannot write to, modify, or delete anything in your Search Console or Analytics property.
- Minimised before analysis. Prompts sent to language models carry pre-computed aggregates, page paths, and query terms — never your credentials, and never raw visitor-level event rows.
- Restricted human access. No one at Maivor AB reads your Google user data as a matter of routine. Administrative access to production systems is limited to authorised Maivor AB personnel, and a person looks at your data only with your permission for support, where it is necessary to investigate a security or abuse problem, or where the law requires it.
- Deleted on disconnect. Removing a connection triggers deletion of its stored credential from the Vault, so the encrypted token stops existing on our side.
- Breach notification. If a personal-data breach occurs, we notify the Swedish supervisory authority within 72 hours where the GDPR requires it, and notify you directly where the breach is likely to result in a high risk to you.
Bing credential
You may add a Bing Webmaster Tools API key. The service verifies the key with Bing and stores it encrypted in Supabase Vault. Bing site binding, scheduled ingestion, and Brief evidence are not implemented in the current alpha. You can remove the stored key in Connections.
Reading your public pages
To state a page’s current title or description, check whether a change went live, and look for things like a missing contact form or internal link, ActionOwl fetches a small number of your site’s public pages each week using an identified crawler (user agent “ActionOwlBot”). Only publicly reachable content is read — never login-protected areas — and the extracted details (titles, headings, links) are stored with the recommendations they support.
How Briefs and recommendations are written
The written analysis in a Brief, the suggested texts in recommendations (for example an improved page title), and the automated review of those recommendations are produced by large language models accessed by API. Anthropic’s Claude writes the analysis. When OpenAI validation is enabled, OpenAI independently reviews certain proposed Actions and Deep Dive claims. The models receive pre-computed site-level metrics and supporting dimensions — counts, page paths, search queries, deltas — and the public page content described above. They do not receive your account password or raw visitor-level event rows. What you see in the product is machine-generated analysis, and every claim is tied to the measured data it came from. Under Anthropic’s commercial API policy, retained API data is not used for model training without express permission. OpenAI states that API data is not used for training unless the customer opts in; its standard abuse-monitoring logs may retain prompts and responses for up to 30 days even though ActionOwl disables Responses API storage.
Analytics on this website
With your consent, Google Analytics 4 records website visits, completed forecast and ROI calculations, and successful request submissions. Our custom event parameters contain only a source-page label—not your email address, calculator inputs or calculated results. GA4 also processes its standard website-visit data.
Analytics loads only after you allow it, and requests are routed through our domain. Declining does not affect the calculators or request form. You can withdraw consent at any time using “Reset cookie choice”.
Processors
The service uses Supabase (database, authentication, and encrypted secret storage), Vercel (hosting), Google (connected APIs and consent-gated website analytics), Anthropic (Brief synthesis), OpenAI (independent Action and Deep Dive validation), Resend (transactional email), and Microsoft Bing when a Bing API key is verified. GitHub is used for ActionOwl’s internal connected-execution pilot. ActionOwl reads the selected repository to build an immutable preview and, only after separate owner approval, may create one new branch, commit the approved change to one bounded file, and open one draft pull request. It does not merge, deploy, modify workflows, or receive Google user data. The integration is dormant unless the relevant GitHub executor flags are explicitly enabled. Some providers process data outside the EEA, mainly in the United States. Where required, Maivor relies on the provider’s data-processing terms and applicable transfer safeguards. For Google user data specifically, the recipients and what each one receives are set out above under “Who we share, transfer, or disclose Google user data to.”
Cookies
Two kinds: a strictly necessary session cookie that keeps you signed in (no consent required), and optional analytics cookies that exist only if you allow them in the banner.
Retention and deletion
Account data, Briefs, recommendations and their history, and imported site data remain until you ask us to delete them. Archiving a site hides it from active views but is not deletion. Removing a connection removes its local binding and triggers credential cleanup; provider-side authorization must be revoked with that provider. To delete your account and its data, email daniel@maivor.ai. We complete verified deletion requests within 30 days.
Your rights
Under the GDPR you can request access, correction, deletion, restriction, or a portable copy of your personal data, and you can object to processing. Write to daniel@maivor.ai. You can also lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten, imy.se).