Privacy Policy

Last updated: August 12, 2026

This policy explains what data Reach collects, how we use it, and the choices you have. We aim to collect only what the service needs to work.

What we collect

Google / Gmail data

If you connect Google, we request the gmail.send scope so Reach can send email as you. We use this access onlyto send the messages you compose or schedule. We do not read your inbox, and Reach's use of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements. Your Google access tokens are stored encrypted at rest, and you can disconnect Google at any time from Settings.

AI features

Reach offers optional AI-assisted features — for example, drafting outreach email and scoring how well your résumé matches a job description. These only run when you use them.

How we use your data

We do not sell your personal data. We do not use your contacts or email content for advertising.

Who we share with (processors)

Your rights & choices

Data retention

We keep your data while your account is active. When you delete your account we delete it immediately — there is no grace period and no recovery. That includes your workspace data (applications, contacts, emails, notes) and the files you uploaded, such as résumés and your profile photo, which are removed from storage rather than merely unlinked. Any active subscription is cancelled at Stripe, and we revoke your Google authorization with Google rather than only discarding our copy of it.

Two narrow exceptions: billing records may be retained where tax and accounting law requires it, and security/audit entries are kept without your identity attached (your account's reference is removed, leaving only the fact that an action occurred).

Security

Data is encrypted in transit (HTTPS) and row-scoped per user, so one account cannot read another's. Provider tokens are encrypted at rest. No system is perfectly secure, but we work to protect your information.

Staff access to your account

A small number of authorised Reach staff can access account data when there is a specific need to: responding to a support request, diagnosing a bug, investigating fraud or abuse, or recovering an account. We do not browse accounts casually, and we do not use your data for any other purpose.

Every such access is recorded in an internal log with the reason for it and who performed it. This access is read-only — staff cannot act as you, and in particular cannot send email from your connected Gmail account. Your Google data is used only as described above and in line with the Limited Use requirements.

Contact

Privacy questions or requests: y.ethanenbus@outlook.com.