Legal
Privacy Policy
Last updated: 17 July 2026
Contents
- 1. Introduction
- 2. The personal information we collect
- 3. How we collect personal information
- 4. Why we collect, hold, use and disclose your information
- 5. Disclosure to service providers
- 6. Disclosure to overseas recipients
- 7. Cookies, analytics and tracking
- 8. Direct marketing
- 9. AI and automated processing
- 10. Security of your information
- 11. Retention and deletion
- 12. Access and correction
- 13. Children
- 14. Third-party links and services
- 15. Notifiable data breaches
- 16. Changes to this Policy
- 17. How to contact us or make a complaint
1. Introduction
This Privacy Policy explains how Ask Solz Pty Ltd, trading as Actuant (we, us, our) collects, holds, uses and discloses personal information. We are an “APP entity” and are bound by the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). Where we handle the personal information of individuals in other jurisdictions, additional laws may apply.
This Policy applies to our website, applications, APIs and related services (the Service). Actuant is a launch and growth copilot: you give us the URL of an app you have built, and the Service audits it for launch readiness, can propose fixes through GitHub pull requests, submits it to launch directories on your behalf, helps you set up waitlists, analytics and payments, and shows you traffic, sign-up and revenue signal across your apps. By using the Service, you consent to the collection, use and disclosure of your personal information as described here. If you do not agree, please do not use the Service.
2. The personal information we collect
Personal information is information or an opinion about an identified, or reasonably identifiable, individual. The kinds of personal information we collect include:
- Account information — name, email address, password (stored hashed by our authentication provider), organisation/workspace details and profile information;
- Billing information — plan, billing contact, and transaction records. Card details are collected and processed directly by our payment provider; we do not store full card numbers;
- Customer Data — the app URLs you submit for scanning, the results of those scans, repository contents we access when you connect GitHub, the product details you provide for directory submissions (names, descriptions, screenshots, links), waitlist sign-ups collected through your pages, and the analytics and revenue data processed to build your signal dashboard, any of which may contain personal information about you or third parties that you choose to process;
- Connection tokens — OAuth access tokens for the third-party services you connect (such as GitHub and Stripe), which we request with the least privilege needed and store in encrypted form;
- Usage, device and log data — IP address, device and browser information, pages and features used, events, timestamps, referring URLs and diagnostic data, collected automatically;
- Cookies and similar technologies — see section 7; and
- Communications — records of your correspondence with us, including support requests and survey responses.
We do not seek to collect sensitive information (such as health or biometric information). Please do not submit sensitive information through the Service unless strictly necessary; if you do, you consent to us handling it to provide the Service.
3. How we collect personal information
We collect personal information:
- directly from you — when you register, submit an app URL for scanning, configure a launch, communicate with us, or otherwise use the Service;
- automatically — through cookies, analytics and server logs as you use the Service, and through the scans, directory submissions and analytics integrations you set up; and
- from third parties — such as our authentication provider, payment provider, GitHub (when you authorise repository access), and the analytics and payment integrations you connect to your apps.
Where it is reasonable and practicable, we collect personal information directly from you. If we collect information about you from a third party, we take reasonable steps to ensure you are made aware of this Policy.
4. Why we collect, hold, use and disclose your information
We handle personal information for purposes including to:
- provide, operate, maintain and secure the Service and your Account;
- run the launch-readiness scans, AI-assisted fixes, directory submissions, waitlists and signal dashboards you set up;
- process payments, manage subscriptions and prevent fraud;
- provide customer support and respond to your enquiries;
- understand and improve the Service, including through analytics and product research;
- send you service, security and administrative messages (which you cannot opt out of while you hold an Account);
- send you marketing communications where permitted (see section 8);
- detect, investigate and prevent misuse, security incidents and breaches of our terms; and
- comply with our legal obligations and enforce our legal rights.
We will only use or disclose your personal information for a purpose for which it was collected, a related purpose you would reasonably expect, a purpose you have consented to, or as otherwise permitted or required by law.
5. Disclosure to service providers
We disclose personal information to trusted third-party service providers (sub-processors) who help us operate the Service, under arrangements that require them to protect the information. These currently include, among others:
- Authentication — Clerk (user accounts, sign-in, verification emails);
- Hosting and infrastructure — Vercel (application hosting) and Neon (Postgres database hosting);
- Payments — Stripe (billing for your subscription, and Stripe Connect where you choose to accept payments in your own apps through the Service);
- Product analytics — PostHog (see section 7);
- Email — Resend (transactional and marketing email);
- Code hosting — GitHub (when you authorise repository access via OAuth so the Service can open pull requests on your repositories); and
- AI model providers — the model providers that power AI features (routed via OpenRouter), which process the scan results and content submitted to them to generate audits and proposed fixes.
We may also disclose personal information to: the launch directories you direct us to submit your app to (limited to the product details you provide for the submission); our professional advisers; a potential or actual purchaser in connection with a sale or restructure of our business; and law enforcement, regulators or others where required or authorised by law.
6. Disclosure to overseas recipients
Some of our service providers store or process personal information outside Australia. In particular, several providers listed above are located in, or store data in, the United States and may process data in other countries depending on the provider and the integrations you use. By using the Service you acknowledge and consent to your personal information being disclosed to, and stored or processed by, recipients located overseas.
We take reasonable steps to ensure overseas recipients handle your personal information consistently with the APPs, including through contractual protections. However, you acknowledge that, where you consent to overseas disclosure, APP 8.1 may not apply and we may not be accountable under the Privacy Act for how an overseas recipient handles your information, and you may not be able to seek redress under the Privacy Act.
7. Cookies, analytics and tracking
We use cookies and similar technologies. Strictly necessary cookies are required to run the Service (for example, to keep you signed in and to keep the Service secure) and are always on. We also use analytics cookies (via PostHog) to understand how the Service is used and how to improve it.
Analytics is enabled by default on an opt-out basis. You can opt out of analytics at any time through the privacy controls in the Service or your browser settings, or by contacting us at privacy@actuant.dev. If you opt out, we will stop setting and reading analytics cookies for your device.
8. Direct marketing
We may send you marketing communications about Actuant where you have consented or where the law otherwise permits. Every commercial electronic message we send will identify us and include a functional unsubscribe facility, consistent with the Spam Act 2003 (Cth). You can opt out at any time by using the unsubscribe link or by contacting us, and we will action your request promptly (and in any event within the period required by law). Opting out of marketing will not stop service or transactional messages.
9. AI and automated processing
Actuant uses AI to audit your apps and to propose fixes. When you submit an app URL for scanning or connect a GitHub repository, the relevant content (which may include personal information) is processed by AI models to generate audit findings, proposed code changes and other output (AI Output). Proposed code changes are delivered as GitHub pull requests for you to review — the Service does not push changes to your repositories without a pull request. AI Output may be inaccurate; you are responsible for reviewing it before acting on it (see our Terms of Service).
Where we use a computer program to make, or to do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect your rights or interests, and personal information is used in that program, we will describe that use here in accordance with the Privacy Act. We do not currently use automated decision-making of that kind to make significant decisions about individuals without human involvement; if this changes, we will update this Policy.
10. Security of your information
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include encryption of stored connection tokens, least-privilege scopes for the services you connect, encryption in transit, access controls, and use of reputable infrastructure providers. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Retention and deletion
We retain personal information for as long as it is needed to provide the Service, for the purposes described in this Policy, and to meet our legal, accounting and record-keeping obligations. When personal information is no longer needed, we will take reasonable steps to destroy or de-identify it. You may request deletion of your Account and associated data as described below, subject to information we are required or entitled to retain.
12. Access and correction
You may request access to, or correction of, the personal information we hold about you by contacting our Privacy Officer using the details below. We will respond within a reasonable period. We may need to verify your identity, and in limited circumstances permitted by the APPs we may decline a request, in which case we will give you reasons. We do not generally charge for access requests, but may charge a reasonable, non-excessive fee for retrieval and supply in some cases.
13. Children
The Service is not intended for, and may not be used by, anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.
14. Third-party links and services
The Service may link to, or interact with, third-party websites and services that we do not control, including GitHub, Stripe, the launch directories your app is submitted to, and the analytics tools set up for your apps. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to read their privacy policies.
15. Notifiable data breaches
If we become aware of a data breach involving personal information that is likely to result in serious harm, we will assess and respond to it in accordance with the Notifiable Data Breaches scheme under the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.
16. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, where changes are material, take reasonable steps to notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
17. How to contact us or make a complaint
If you have a question, an access or correction request, or a complaint about how we handle your personal information, please contact our Privacy Officer at privacy@actuant.dev. We will acknowledge and investigate your complaint and aim to respond within a reasonable time.
If you are not satisfied with our response, you may complain to the OAIC at www.oaic.gov.au.
Ask Solz Pty Ltd, trading as Actuant — Privacy Officer, privacy@actuant.dev.