Legal · Privacy Notice

Privacy Notice

What we collect when you join the waitlist, where it is stored, how long we keep it, and how to have it deleted.

Last updated September 2026 Data controller CloudsCockpit Inc. Applies to Waitlist signup

Your email, and little else

We store your address, which form you used, a timestamp, a keyed hash of your IP, and your browser's user-agent string. Nothing more.

Held only until you activate

Waitlist data exists to activate your account. Once activated, your data moves to the AWS stack described below.

Deletion on request

Email legal@actionboard.ai and we will remove your entry.

This notice describes how CloudsCockpit Inc. (“we”, “us”) handles personal data collected through the ActionBoard.ai waitlist form. It covers the pilot preview only. It does not describe data you later upload into pods or labs once you hold an account — that is governed by the Terms of Service and the Security Policy.

01 Scope

ActionBoard.ai is in pilot preview and is not generally available. The only personal data we collect from the public site is what you submit to the waitlist form. There are no analytics trackers, advertising pixels, or third-party cookies on these pages.

02 What We Collect

When you submit the waitlist form, we record exactly five fields:

  • Email address The address you type. This is the only field you supply directly, and the only one that identifies you by name.
  • Signup source Which of the two entry points you used — the profile builder form or the platform preview call-to-action. Stored as profile_builder or platform_preview.
  • Timestamp The UTC date and time of your submission.
  • Keyed hash of your IP address Your IP is never stored in readable form. We store an HMAC-SHA256 of it, keyed with a secret that lives only in our server environment. This lets us rate-limit abuse without holding your address. It is pseudonymised, not anonymised: it cannot practically be reversed without the secret, but two submissions from the same network still produce the same value.
  • User-agent string The browser and operating-system identifier your browser sends with every web request, retained for abuse diagnosis.

We do not collect your name, employer, job title, phone number, or location, and the form does not ask for them.

03 Why We Collect It

  • To contact you about access The email address exists so we can invite you when a place opens in the pilot.
  • To prevent abuse The keyed IP hash and user-agent support rate limiting and spam detection. The form is also protected by Cloudflare Turnstile, a bot check that runs when you submit.
  • To understand which entry point works The signup source tells us which part of the site brought people in. It is never used to build a profile of you.

We do not sell this data, rent it, share it with advertisers, or use it to target advertising anywhere.

04 Where It Is Stored

Your data lives in two distinct places depending on whether you have activated an account.

  • Before activation — Cloudflare D1 Waitlist entries are stored in a Cloudflare D1 database, reachable only by our server-side function. Cloudflare acts as our infrastructure provider and processes this data on our behalf. Traffic to the site and the form is served over TLS.
  • After activation — AWS Cognito and encrypted RDS When you activate an account, identity and authentication are managed by AWS Cognito, and your account data is held in an encrypted AWS RDS database. From that point your data is governed by the controls described in the Security Policy.

The waitlist database and the account database are separate systems. Joining the waitlist does not create an account, and no AWS record exists for you until you activate one.

05 How Long We Keep It

  • If you activate an account Your waitlist entry has served its purpose and is removed once activation completes. Your account data then persists for as long as you hold the account.
  • If you never activate We delete waitlist entries that have not been activated within 24 months of signup.
  • Rate-limiting records The short-lived records used to throttle repeat submissions expire automatically within minutes and are not retained.

You do not have to wait for either period to elapse — you can ask us to delete your entry at any time, as described below.

06 Processors & Sharing

We share waitlist data with no one for their own purposes. Two infrastructure providers process it on our behalf, under contract and on our instructions:

  • Cloudflare Hosts the site, serves the waitlist function, stores the D1 database, and runs the Turnstile bot check on the form.
  • Amazon Web Services Provides Cognito identity services and the encrypted RDS database, which hold your data only after you activate an account.

We may disclose data where we are legally required to do so. If that ever happens, we will tell you unless we are prohibited from doing so.

07 Access & Deletion

You can ask us at any time to tell you what we hold about you, correct it, or delete it entirely. Email legal@actionboard.ai from the address you signed up with, or tell us which address to look up. We will respond within 30 days.

Deleting your waitlist entry removes you from the invitation list. If you later want access, you are welcome to sign up again.

08 Contact

ActionBoard.ai is operated by CloudsCockpit Inc. For anything relating to this notice or your data: