ActionRail Privacy Notice
Last updated: July 20, 2026
This notice explains how ToolJet Solutions, Inc. ("ToolJet", "we", "us") handles information for the ActionRail website, documentation, Cloud early-access waitlist, and optional product telemetry. It supplements the ToolJet Privacy Policy. ToolJet is the operator of ActionRail and the controller of the information described here.
ActionRail's open-source runtime executes inside your application or environment. The data that remains in your environment is controlled by you and is not covered by this notice.
Information we collect
| Context | Information | Why we use it |
|---|---|---|
| Website and documentation | Standard request information processed by our hosting providers, such as IP address, browser or user-agent information, requested URL, and request time | Deliver and secure the website, diagnose failures, and prevent abuse |
| Consent-based website analytics | Pages viewed, referral source, coarse browser and device information, and interactions with selected documentation, GitHub, and Cloud-access links | Understand documentation use and improve the ActionRail launch experience |
| Cloud early-access waitlist | Name, work email, company, optional use-case description, submission source, and notice version | Manage the waitlist, understand expected use cases, prevent duplicate submissions, and contact you about ActionRail Cloud |
| Optional product telemetry | Random installation and event identifiers; ActionRail component and version; Python major/minor version; operating-system family; SDK mode; and aggregate agent and action counts | Measure adoption, identify compatibility issues, and improve ActionRail |
| Direct communications | Information you include when you email or otherwise contact us | Respond to your request and maintain the resulting business communication |
What optional telemetry does not contain
ActionRail's telemetry contract does not accept names, email addresses, company names, agent or tool names, tool arguments, prompts, rule definitions, Source credentials, Source responses, individual decisions, or audit records. Unknown telemetry fields are rejected by the receiving service.
Telemetry can be disabled by setting ACTIONRAIL_TELEMETRY_DISABLED=1. See
Anonymous usage telemetry for the exact events
and configuration.
Website analytics choices
ActionRail uses Google Analytics only after you select Accept analytics. Before consent, the Google Analytics script is not loaded and no analytics request is sent to Google. We configure analytics without advertising storage, advertising personalization, or Google Signals. Analytics events do not include waitlist form contents, prompts, tool arguments, Source data, or Console data.
Your choice is stored locally in your browser. Global Privacy Control and an enabled browser Do Not Track signal are treated as a declined choice by default. You can change the choice using Analytics settings in the website footer. Declining after previously accepting disables further analytics and removes ActionRail's accessible Google Analytics cookies from the browser.
Legal bases
Where a legal basis is required, we process information as necessary to take steps you request before receiving a service, for our legitimate interests in operating, securing, and improving ActionRail, to comply with law, and with consent where applicable. You can withdraw consent where consent is the basis for processing, without affecting earlier processing.
How we share information
We disclose information only as needed to operate ActionRail, comply with law, protect rights and security, or complete a business transaction. Service providers may process information on our behalf, including Google Analytics for consent-based website measurement, Google Cloud/Firebase for the public Hub and waitlist storage, and the providers that host the documentation and source repository. We do not sell ActionRail waitlist information, website analytics, or optional product telemetry.
External websites linked from the documentation apply their own privacy notices.
Retention
- Raw optional telemetry partitions expire after 180 days.
- Google Analytics event-level and user-level data is retained for no more than 14 months, subject to Google Analytics deletion and aggregation behavior.
- Cloud waitlist submissions are scheduled for deletion after 24 months, unless an active business relationship or legal obligation requires longer retention.
- Operational and security logs are retained according to the configured policies of the relevant hosting provider and only for as long as reasonably necessary for security and reliability.
- Business communications may be retained as needed to respond, maintain records, and meet legal obligations.
Your choices and rights
You may decline website analytics or disable optional product telemetry at any time. You may also ask to access, correct, or delete waitlist information, or object to or restrict certain processing where applicable. Applicable law may provide additional rights, including the right to complain to a data-protection authority.
Send requests to hello@tooljet.com. We may need to verify your identity before completing a request.
International processing and security
ToolJet and its providers may process information in countries other than where you live. We use safeguards required by applicable law for international transfers. We use administrative, technical, and organizational measures designed to protect information, but no online service can guarantee absolute security.
Children
ActionRail is a developer and business product and is not directed to children under 13. Do not submit information about a child through the waitlist or support channels.
Changes and contact
We may update this notice as ActionRail develops. We will change the date above and provide additional notice when required. Questions can be sent to hello@tooljet.com.