1. Scope
This Privacy Policy applies to the ActionClip macOS app, the ActionClip website, licensing and update services, support chat, and related services operated under the ActionClip name.
ActionClip is the controller of information described in this policy unless a third-party service, such as Lemon Squeezy, processes information under its own terms and privacy policy.
2. What stays on your Mac
Most ActionClip features run locally. Depending on the features you use, the app may store the following on your Mac:
- Settings, onboarding state, enabled actions, custom actions, action groups, usage counters, and other preferences.
- Recent action history and result previews used by the in-app Recent Actions view.
- Temporary clipboard data needed to complete copy, paste, replace, and selection-recovery flows.
- Your AI provider keys, Microsoft Translator key, and redeemed license code in the macOS Keychain.
- A randomly generated anonymous install identifier in app preferences.
ActionClip does not create an ActionClip account or collect your Mac serial number, network MAC address, or another hardware-derived device identifier. Settings remain local unless a user with an eligible multi-Mac plan explicitly enables iCloud Sync and chooses the categories to sync.
Deleting the ActionClip app may not delete preferences or Keychain items because macOS stores them separately from the app bundle. You can remove local preferences and Keychain entries separately if you want a complete reset.
3. Selected text and online actions
Reading selected text requires macOS Accessibility permission. ActionClip uses that permission to detect your selection and show actions nearby. Selected text is not uploaded merely because the widget appears.
Local actions
Copy, paste, text transforms, local JavaScript, supported Apple Intelligence actions, Ollama Local actions that use a loopback server, and other on-device features process text on your Mac.
Your own provider keys
If you enable online actions and configure OpenAI, Anthropic, Google, Microsoft, OpenRouter, Ollama Cloud, or another supported provider, the text and instructions needed for the action are sent to that provider. Provider keys are stored in the macOS Keychain and are used only to make the requests you initiate. If you connect OpenAI with a ChatGPT or Codex account, its connected-account credentials remain on that Mac and are not included in iCloud Sync.
Temporary AI and demo translation
If you use Temporary AI without your own provider key, the prompt and selected text are sent through ActionClip's backend and then to the configured AI service. Demo translation similarly sends the text needed for translation through ActionClip's backend to Microsoft Translator.
In ActionClip 2.3.0, online Edge voices for Say are enabled by default for new installs and once on upgrade. Later opt-outs are retained. When you run Say with Edge voices and Allow online actions enabled, the text to be spoken is sent directly to Microsoft for speech generation. This does not upload text in the background. Disable Edge voices in Speech voices settings or disable online actions to use local speech. Translation and OCR playback remain local.
If you submit a custom action to Marketplace review, its configuration, examples, listing details, author display name, and review contact email are sent to ActionClip's review service and a private Discord review channel. License credentials verify submission eligibility and are not published. Review status and listing metadata are retained to show your submission history. Remove passwords, tokens, private text, and customer data before submitting. Submission is optional and does not automatically publish the action.
ActionClip's backend does not store Temporary AI prompts, selected text, translation text, or outputs in its product database and does not include them in analytics, logs, or operational notifications. The external provider may process request content under its own terms and privacy policy. Avoid submitting confidential, regulated, or highly sensitive information to an online action unless you are comfortable with the selected provider's practices.
4. Optional iCloud Sync
Users with an eligible multi-Mac plan can choose to keep selected ActionClip items up to date on Macs signed in to the same iCloud account. Sync is off until you enable it. You can independently choose Actions & Groups, Popup Behavior, Appearance, Action Defaults, and Provider API Keys.
Selected sync items are stored in your private iCloud database. Provider API-key sync is off by default; when enabled, supported provider keys are encrypted before upload. Connected ChatGPT or Codex accounts, local AI settings, recent action history, macOS permissions, selected text, clipboard contents, and device-specific options are not synced.
Custom actions, groups, action order, and built-in or custom icon overrides can be included under Actions & Groups. Turning off a category stops future synchronization for that category, but disabling sync is not a substitute for deleting records already stored by iCloud. iCloud availability, storage, retention, account controls, and deletion are also governed by your Apple account and Apple's policies.
iCloud Sync is a convenience feature, not a backup service. Keep separate copies of important custom actions and settings.
5. Anonymous product events
ActionClip sends limited product events to help understand whether the app is working. These events use the same random install identifier used for trials and licensing. The backend stores a keyed hash of that identifier rather than the original value.
Events may include app installation and opening, onboarding completion, action category or built-in action slug, custom-action type, success or failure state, coarse input-size and latency buckets, provider route, app version, and macOS version. When you add an action from the Marketplace, ActionClip may also send that action's stable public identifier. The backend combines it with the keyed hash of the existing random install identifier to count at most one installation per action for that app installation, even if the action is later removed and added again. It does not send the action's name, configuration, or selected text for this count.
Events may also include a coarse app-signature classification, such as an official release, development build, recognized third-party signature, unsigned app, or failed or unavailable validation. Events may also include a versioned indicator score, a fixed list of findings, and whether the checks completed. The checks inspect only ActionClip's own bundle for a recognized signing certificate, a known added library name or matching library contents, missing hardened runtime, signature failure, and an App Store receipt. This helps estimate use of modified copies. Certificate contents, certificate or file fingerprints, signer names, file paths, library contents, and additional device identifiers are not sent. These observations are reported by the app and do not establish where a download came from. A score of zero does not establish that an app is safe or unmodified.
Product events are designed not to contain selected text, prompts, outputs, clipboard contents, source app or window names, URLs, commands, email addresses, API keys, tokens, or secrets. First-install and onboarding milestones, and positive modified-copy indicators reported on app launch, may generate a private operational notification for the ActionClip team.
6. Purchases and licenses
Payments are handled by Lemon Squeezy, which acts as merchant of record and processes payment, tax, receipt, refund, and checkout information under its own policies.
When you start a purchase from the ActionClip website, the site may attach DataFast's random visitor and session identifiers to the Lemon Squeezy checkout. This lets DataFast associate the resulting payment with website information such as the traffic source or campaign that led to the purchase. These identifiers do not contain selected text, prompts, clipboard contents, payment-card details, or other content processed by the ActionClip app.
If you visit through an affiliate referral link, the website stores rj_refid, rj_tid, and rj_program for up to 30 days in first-party cookies and local storage. It sends the referral ID, click ID, optional source label, landing URL, and referrer URL to RefJam, and passes the same three attribution keys to Lemon Squeezy during checkout. This is used only to attribute referrals, calculate commission, and operate the affiliate dashboard. It is separate from DataFast website analytics and from ActionClip's macOS app analytics, and it does not send selected text, app content, prompts, API keys, local files, or a new device identifier.
When you purchase ActionClip as a gift, ActionClip collects the recipient's name and email address, your display name, the selected plan, and any optional message you write. These details are sent to Lemon Squeezy as checkout custom data and are processed by Resend to send the recipient their license. ActionClip's gifting database stores only order and license-key identifiers, plan, delivery status, retry state, and timestamps; it does not store the recipient's name or email, your message, or the raw license code. Resend necessarily receives those delivery details and the raw license code to send the gift.
For licensing and support, ActionClip may receive and store purchaser email, license-recovery requests, order and product identifiers, plan, price and currency, refund status, license-key identifier, activation status, and timestamps. When you redeem a license in the app, ActionClip also asks where you first heard about the app and stores the option you choose; if you choose Other, it stores the short explanation you enter. This answer is used to understand how customers discover ActionClip, is included with the successful redemption event sent to a private Discord channel, and may appear with its activation time in ActionClip's authenticated private analytics dashboard. It is not included in public license responses or logs. The backend stores a hash and short suffix of a redeemed license code, not the raw code. The raw redeemed code remains in your Mac's Keychain and is sent only when needed to redeem, validate, or remove that Mac's activation.
After a completed live purchase, ActionClip uses the purchaser email supplied by Lemon Squeezy to send one transactional thank-you email through Resend. The email includes download, guides, support, and Discord community links. ActionClip records the order identifier and delivery status to prevent duplicates and support retries; the delivery queue and operational logs do not contain the purchaser email or message body. The message has no tracking pixel and does not subscribe the purchaser to marketing email. Gift recipients continue to receive a separate license-delivery email.
Purchase, redemption, and license-recovery events may create a private operational notification containing the plan or recovery request and purchaser email so the ActionClip team can identify and support the purchase. A full refund, chargeback, revoked key, or removed activation may return the app to the Free plan.
7. Website, contact, and forum information
When you visit ActionClip websites or backend services, hosting and security providers may process ordinary request information such as IP address, user agent, requested page, and timestamp. The site does not use advertising trackers. Embedded media, fonts, or linked services may make their own network requests.
The ActionClip website uses DataFast for website traffic analytics, attribution, and crawler traffic measurement. For ordinary visits, DataFast may use cookies and process IP addresses and website-usage information such as page visits, traffic sources, and download-link clicks. When a known AI assistant, search engine, or model-training crawler requests the site, server-side tracking may send DataFast the crawler's user agent, source IP address, requested public page, response status, and timestamp. This website analytics does not receive selected text, prompts, outputs, clipboard contents, or other content processed by the ActionClip app.
The landing page embeds a testimonial wall from Senja. Loading or interacting with the embed may send Senja ordinary request, device, usage, and tracker information under its own policy. The testimonial embed does not receive selected text or other content processed by the ActionClip app.
The website includes Crisp for support chat. Crisp may use cookies or similar browser storage and process ordinary request information, chat messages, contact details you provide, and conversation metadata under its own policy. If you use the ActionClip Forum, your posts, votes, profile information, and other activity are processed by UserJot and may be publicly visible.
If you apply to the ActionClip affiliate program, the application form collects the name, email address, publishing channels, public channel or profile links, approximate audience size, and optional notes you provide. The website validates those details through ActionClip's Cloudflare-hosted endpoint and forwards them to a private Discord channel so the application can be reviewed and answered. Affiliate application details are not made public.
When you explicitly submit a custom action for Marketplace review, the app sends a review package to ActionClip's Cloudflare-hosted endpoint and forwards it to a private Discord channel. The package contains the action's name, description, prompt, URL, code, script, template, configuration, optional embedded icon, examples, requirements, reviewer notes, the display name and contact email you enter, the app version, and a submission identifier. ActionClip checks your live paid license for this request; it sends the Keychain-held license code and activation identifiers to the review endpoint for validation, but does not save the raw code with the submission. A private database stores the submission identifier, license-key identifier, action name, category, summary, pending/accepted/rejected status, optional rejection note, and timestamps so you can see review progress. This information is used for manual review and is not published automatically. ActionClip does not add your selected text, API keys, or analytics identifier to the package; examples or other text that you deliberately enter in the submission form are included.
8. How information is used
ActionClip uses information to:
- Provide, secure, troubleshoot, and improve the app and website.
- Run user-requested online actions and enforce temporary-service limits.
- Validate licenses, manage activation limits, process refunds, deliver transactional purchase emails, and provide purchase support.
- Respond to support, privacy, and legal requests.
- Review affiliate applications, contact applicants, and operate the affiliate program.
- Review custom actions submitted for possible publication in the ActionClip Marketplace and contact their creators about the review.
- Prevent abuse, fraud, security incidents, and unauthorized license use.
- Comply with applicable legal and accounting obligations.
Where required by law, processing is based on providing the service or fulfilling a purchase, ActionClip's legitimate interests in operating and securing the product, consent for optional features, or compliance with legal obligations.
9. Sharing and service providers
ActionClip does not sell personal information or use it for targeted advertising. Information is shared only as needed with service providers, when you direct ActionClip to an external provider, to comply with law, to protect users and the service, or as part of a business transfer subject to appropriate safeguards.
Current service categories include:
- Cloudflare for website, backend, update hosting, security, and database infrastructure.
- Apple iCloud for optional synchronization available with eligible multi-Mac plans through the user's private iCloud database.
- DataFast for website traffic analytics, attribution, and crawler traffic measurement.
- RefJam for affiliate click and purchase attribution, commission calculation, and the partner dashboard.
- Senja for the embedded testimonial wall.
- Lemon Squeezy for checkout, payments, taxes, refunds, receipts, license events, and gift-checkout custom data.
- Resend for purchaser thank-you emails and recipient gift emails.
- OpenRouter and its model providers for Temporary AI requests.
- Microsoft Translator and user-selected AI providers for online actions.
- Crisp for support chat, UserJot for the forum, and Discord for private operational notifications, affiliate applications, and Marketplace action reviews.
10. Retention
Local information remains on your Mac until you remove it, reset the app, or macOS removes it. Keychain items and preferences can remain after the app itself is deleted. Items you elect to sync may remain in your private iCloud database until they are deleted through the app, your iCloud account, or Apple's retention processes.
Backend trial, analytics, license, purchase, security, and support records are retained for as long as reasonably needed to operate the service, honor purchases, prevent abuse, resolve disputes, meet accounting or legal obligations, and protect ActionClip and its users. Information may be deleted or de-identified when it is no longer needed.
Affiliate applications and Marketplace review submissions may remain in ActionClip's private service records for as long as reasonably needed to review the submission, contact the submitter, document a publishing decision, prevent abuse, and resolve disputes.
11. Security and international processing
ActionClip uses reasonable technical and organizational safeguards, including HTTPS, restricted service credentials, keyed hashing of install identifiers, sanitized analytics fields, Keychain storage for sensitive local credentials, private CloudKit records for iCloud Sync, and encryption of provider API keys before they are uploaded when key sync is enabled. No system can guarantee absolute security.
Service providers may process information in countries other than where you live. Where required, ActionClip relies on provider safeguards and lawful transfer mechanisms.
12. Your choices and rights
You can disable online actions, use Apple Intelligence or Ollama Local when available, turn iCloud Sync off or choose its categories, leave provider API-key sync disabled, remove provider keys, disconnect a ChatGPT or Codex account, remove a redeemed license from a Mac, or stop using external services. You may also request access, correction, deletion, restriction, objection, or portability where applicable law provides those rights.
To make a privacy request, use ActionClip Chat Support. Include enough information to identify the relevant purchase or support record. ActionClip may need to verify your request and may retain information when legally required.
13. Children
ActionClip is a general productivity tool and is not directed to children under 13. If you believe a child has provided personal information through ActionClip, contact us so the request can be reviewed.
14. Changes and contact
This policy may be updated when ActionClip's features, service providers, or legal obligations change. The effective date at the top will be updated, and material changes will be communicated where required.
Questions about this policy can be submitted through Chat Support.