Privacy notice
Privacy
How SuiteAction handles your data, and the exact Google access it asks for.
Last updated 26 August 2026
You connect SuiteAction to Claude (or another AI assistant) as a connector; then you connect a Google account and it edits the Sheets, Docs and Slides you point it at. Everything described below about your Google account data applies from the moment you connect a Google account.
Who we are
SuiteAction is operated by Metro Stack Limited, a company registered in England and Wales (company number 17195789), registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Metro Stack Limited is the data controller for the personal data described on this page. For anything on this page, contact support@suiteaction.dev.
SuiteAction is not intended for children. We do not knowingly collect data from anyone under 18; if you believe a child has signed up, email us and we will delete the account.
What we collect, and why
If you join the waitlist: your email address — that is all we require. Optionally, you can tell us which of Sheets, Docs or Slides matters most, whether $29 a month would be worth it, which AI tool you use, and one task you want automated. We also record which page you arrived on and, if you came from an advert or another site, where from.
We use this to email you when the product launches and to decide what to build first. The lawful basis is your consent — which you can withdraw at any time with the unsubscribe link — and our legitimate interest in developing a product people asked for.
When you join, we email you a confirmation (from
hello@updates.suiteaction.dev) with an unsubscribe link. If it does
not arrive, check your spam folder, or email
support@suiteaction.dev and we
will remove you. You will also be emailed once when the product launches.
If you connect a Google account: that gives SuiteAction permission to read and edit your Google Sheets, Docs and Slides so it can carry out the instructions you give it. So you can see what was done and so we can investigate problems, we keep a log for 90 days of each change made — the tool used, the file it acted on and, for a sharing action, who it was shared with — never the contents of your files. The lawful basis is performance of a contract — it is the service you are asking for.
If you connect an AI assistant: we record which assistant you connected and when it was last used, and store its sign-in tokens as one-way hashes, so the connection keeps working and you can see and revoke it. The lawful basis is performance of a contract.
If you create an account: we store the email address you sign in with — from your GitHub sign-in, or the emailed sign-in link you use when connecting SuiteAction from an AI assistant — and, from GitHub, your name. We use these to create the account and contact you about it. We also store a record that your email was verified, any API keys you create (kept as a one-way keyed hash — only the first few characters stay readable, so you can tell your keys apart), a per-action usage count that meters your plan, and, if you start a free trial, a hashed record of it so the same person cannot take repeated free trials. To keep the account secure we also record the IP address and browser you sign in from — kept while your session is active (up to 30 days) and for up to 30 days after it expires (even if you sign out sooner), so we can answer questions about past sign-ins — and keep short-lived counts of failed sign-in attempts by IP. The lawful basis is performance of a contract, and our legitimate interest in keeping the service secure.
Google user data
SuiteAction's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- For access to your files we request exactly these Google scopes, and no broader file scopes (connecting your Google Workspace additionally uses the standard sign-in scopes
openid,userinfo.emailanduserinfo.profileto read basic identity — your name and email — to label the connected account):https://www.googleapis.com/auth/spreadsheetshttps://www.googleapis.com/auth/documentshttps://www.googleapis.com/auth/presentationshttps://www.googleapis.com/auth/drive.file
- We request no restricted Drive scope — SuiteAction cannot browse or read your Drive at large.
- Your file content is used only to carry out the instruction you gave. It is not used to train any model, is not sold, and is not shared with anyone except the Google API the request is bound for and the AI assistant you connected, which receives the results of the requests it makes on your behalf and processes them under its own terms.
- Your access and refresh tokens are stored encrypted. We do not read your documents — except where you explicitly ask us to, where it is necessary to investigate abuse or a security problem, or where the law requires it. The service decrypts your credentials in order to use them on your behalf, which is not the same thing as being unable to.
- Disconnecting your Google account cuts off access at once; we delete the stored tokens once Google confirms the revocation.
Images you give SuiteAction to insert
When you ask SuiteAction to place an image into a Slide or Doc, you can provide it in four ways: upload a file in the dashboard; hand it to the AI assistant you connected, which sends it to us directly; open a one-time upload link we generate and drop a file onto it (that link works without signing in, so treat it like a password — anyone you forward it to could upload a file to your account during its ~30-minute life, and we keep the record of the link for about a day after it expires); or give the address of an image already online, which our server then fetches on your behalf (the site hosting that image sees the request coming from our server). To insert it, SuiteAction:
- stores the image, and a record of its file name, size, type and pixel dimensions, briefly on our servers (DigitalOcean, London) — at most about 24 hours, after which it is deleted automatically (a copy of that small record — never the image itself — can persist in our encrypted database backups for up to 30 days);
- strips camera and location metadata (EXIF/GPS) from the image before storing it;
- serves it from a temporary, unguessable web link so that Google (or whichever tool inserts it) can fetch the image and copy it into your file. That link is unauthenticated by design — anyone who has the exact link could load the image during the ~24-hour window — so it is used only for images you chose to upload for insertion, and it expires. Google copies the image into your file at insert time, so your file keeps working after the link expires.
The image is used only to carry out the insert you asked for. It is not used to train any model, is not sold, and is not shared with anyone except the tool that inserts it (for example, Google) and the AI assistant you connected. You can delete an uploaded image at any time from the dashboard, and closing your account deletes any you have stored. The lawful basis is performance of a contract — it is the insert you asked for.
Files you export
When you ask SuiteAction to export a Google file to another format (PDF, Excel, PowerPoint, CSV and so on), it produces that copy and stores it briefly on our servers (DigitalOcean, London) so you can download it — at most one hour, and usually deleted within minutes of your download — served from a temporary, unguessable, single-use link (with a short ~90-second grace after the first fetch, so a chat app's link preview does not consume your download). Closing your account deletes any pending export. The lawful basis is performance of a contract — it is the export you asked for. This export copy is the only case where the content of one of your Google files rests on our servers (an image you upload for insertion is the other short-lived case, described above), and only for that short window; everywhere else we pass your file content straight to and from Google without keeping it.
Where your data goes
Our servers and database (DigitalOcean) are in London, with encrypted backups stored in Frankfurt (in the EEA, covered by the UK's adequacy regulations). Our website host (Netlify), our email provider (Resend), Google, and our payment processor (Stripe) are in the United States, so some of your data is transferred outside the UK. Those transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on the UK Extension to the EU–US Data Privacy Framework where the provider is certified under it. You can ask us for a copy of the safeguard we rely on.
The AI assistant you connect may also be outside the UK — for example Claude's operator, Anthropic, is in the United States. Sending it the results of the requests you asked it to make is necessary to provide the service you requested, and the assistant then handles that data under its own terms.
How long we keep it
Each kind of data has its own life:
- Waitlist entry — until launch plus twelve months. If you unsubscribe we stop emailing you and keep the entry marked as opted out, so we never contact you again; ask us and we delete it entirely.
- Google tokens — while your account is connected; deleted once Google confirms the revocation, including after you close your account (until Google confirms, the encrypted token is held only so we can complete the revocation).
- AI-assistant connection record — which assistant you connected, when it was connected and last used, and hashed sign-in tokens; kept until you disconnect it or close your account, and its expired tokens are cleared as they age out.
- Images you upload to insert — at most about 24 hours, then deleted automatically; sooner if you delete them from the dashboard or close your account.
- Files you export — at most one hour, usually deleted within minutes of your download.
- Sign-in identity and hashed API keys — deleted when you close your account.
- Sign-in security records (the IP address and browser you signed in from) — up to 30 days after your session expires (a session lasts at most 30 days, even if you sign out sooner); failed-sign-in counts are short-lived.
- The 90-day action log — detached from you when you close your account and deleted as it ages out.
- Usage totals — kept for six years after the relevant tax year, as UK company and tax law requires, against the billing record with your name and email removed; if you ever subscribed, we also keep the payment reference our accountants need. The lawful basis is compliance with a legal obligation.
- A hashed trial record — which no one else can link back to you — kept to stop repeat free trials, for as long as we offer free trials.
The opt-out record and the trial record are kept under our legitimate interest in honouring unsubscribes and preventing free-trial abuse.
Who else sees it
The services that handle some of your data (the first three act only on our instructions; Google, Stripe and the AI assistant also act under their own terms, as noted):
- Netlify hosts the public website and passes your waitlist signup through to our API, so it sees the IP address of visitors and the details you submit in transit.
- DigitalOcean runs our servers and database.
- Resend sends our email.
- Google sees three things: the API requests made on your behalf, which it handles under its own terms; the internal spreadsheet where we keep the waitlist; and, on some advertising and landing pages that load Google fonts, the IP address of visitors to those pages.
- Stripe, our payment processor, handles your payment details when you subscribe — founder subscriptions are open now; general subscriptions open at launch. For payment data Stripe acts as an independent controller under its own privacy policy.
- The AI assistant you connected receives the results of your requests and processes them under its own terms.
Visitors' IP addresses are processed only transiently, to serve and secure the site, under our legitimate interest. We do not sell personal data and we do not share it for advertising.
Cookies and local storage
The public site sets no cookies and uses no third-party analytics or advertising trackers. If you sign in to the dashboard we set one strictly necessary session cookie to keep you signed in; it identifies your session and nothing else, plus a short-lived security cookie during the sign-in handshake itself, which is deleted as soon as sign-in completes. The site also keeps a few small values in your browser's local storage: one records how you first arrived (a timestamp, the landing page, any campaign tags and, if you came from another site, its address), and — only if you have been given a password for a restricted area of the site — two remember that entry and when it expires. If you use the dashboard it also keeps a couple of set-up flags in your browser, which identify nothing. The arrival record stays until you clear it; the restricted-area values are removed automatically when they expire. None of it is shared.
How we protect it
Data travels over TLS, and your Google tokens are stored encrypted; API keys are kept only as one-way hashes; each customer's requests to Google run in isolation from every other customer's; and backups are encrypted before they leave our servers. No system is invulnerable and we do not claim ours is — if a personal-data breach occurs we will notify the Information Commissioner's Office within 72 hours unless it is unlikely to pose a risk, and tell you without undue delay, along with what we are doing about it, if it is likely to put you at high risk. We make no automated decisions about you that have a legal or similarly significant effect, and we do not profile you.
Your rights
Under UK GDPR you can ask for a copy of your data, ask us to correct or delete it, object to how we use it, ask us to restrict it, or ask for a portable copy in a machine-readable format. Email support@suiteaction.dev and we will respond within one month. If you are not satisfied you can complain to the Information Commissioner's Office.
To delete everything, close your account from the dashboard (or email us and we will close it for you) — the “How long we keep it” list above says what is removed and what little survives.
Changes, and if we ever close down
If this page changes materially we will say so here, and we will email anyone on the waitlist or with an account whose data is affected. If Metro Stack Limited ever shuts down, we will email you, delete the stored tokens and personal data, and your files are unaffected — they live in your Google Drive, not with us.