Privacy Policy
Your privacy matters deeply to us. This policy explains what information we collect, how we use it, and your rights. We keep things simple and transparent.
1. Who we are
- Cleo Mare, sole proprietor based in Israel
- Contact: actionboard.app@gmail.com
- Developer of Tidy Nook AI
2. Information we collect
- Email address (for your account)
- Display name (chosen by you)
- Photos you upload (for AI analysis only)
- Usage data (which features you use)
- Device info (iOS version, device type)
- Crash reports (to fix bugs)
3. What we don't collect
- Your location
- Your contacts
- Your photos stay private — not shared or stored beyond analysis
- No health data
- No biometrics
- We never sell your data
4. How we use your data
- To provide the AI analysis service
- To authenticate your account
- To process your subscription
- To improve the app
- To send essential service emails only
5. Third-party processors
We use these services, all GDPR-compliant:
- Supabase — database and authentication
- Anthropic — AI analysis (Claude)
- Apple — payments and app distribution
- RevenueCat — subscription management
All have signed Data Processing Agreements (DPAs) under GDPR Article 28.
6. Data retention
- Account data: as long as you have an account
- Analysis history: stored locally on your device
- Logs: 30 days
- Payment records: 7 years (tax law)
- After account deletion: 30 days then permanent deletion (90 days for backups)
7. Your rights (GDPR)
You have the right to:
- Access your data
- Correct inaccurate data
- Request deletion
- Export your data
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
To exercise these rights, email actionboard.app@gmail.com.
8. Your rights (CCPA — California)
California residents have additional rights:
- Right to know what we collect
- Right to delete
- Right to opt out of data sale (we don't sell)
- Right to non-discrimination
9. Children's privacy (COPPA)
- The app is not directed at children under 13
- We do not knowingly collect data from minors
- If you believe your child provided data, please contact us
10. International data transfers
Your data may be processed outside your country. We use Standard Contractual Clauses (SCCs 2021/914) for EU transfers.
11. Security
- All data encrypted in transit (TLS 1.2+)
- All data encrypted at rest
- Limited employee access
- Regular security audits
- 72-hour breach notification (GDPR Art. 33)
12. Changes to this policy
We may update this policy. We'll notify you of material changes — just check the "Last Updated" date at the top.
13. Contact
Questions? Email actionboard.app@gmail.com.
Have questions about this page?
actionboard.app@gmail.com