Privacy Policy
Last updated: August 12, 2026
This policy explains what data Reach collects, how we use it, and the choices you have. We aim to collect only what the service needs to work.
What we collect
- Account: your email address and authentication identity (managed by Supabase Auth; Google/LinkedIn if you sign in with them).
- Your workspace data: job applications, company folders, contacts, interactions, tags, notes, and any résumé you upload.
- Email you send: recipients, subject, body, and engagement with outreach you send through Reach — whether a message was opened, whether links in it were clicked, and whether any document you shared was viewed. To show you that engagement we record the approximate time, device and location of those opens and clicks. This is standard email-tracking behavior; if you email contacts in the EU, local rules on tracking may apply to you as the sender.
- Billing: subscription status. Card details are handled by Stripe — we never see or store your full card number.
- Usage: which pages of Reach you open, roughly how long you spend on each, and which features you use. This is tied to your account and used only to work out which parts of Reach are worth building on. It records page names and feature names only — never the contents of a page, and never what you type into a search box.
Google / Gmail data
If you connect your Google account, Reach requests a single Gmail scope, gmail.send. Because this is the data Google holds us most strictly to, here is exactly what happens to it.
- What we access.
gmail.sendis write-only. The only Gmail operation Reach performs is sending a message you wrote. We never read, search, download, or store your existing email — no inbox, no sent mail we did not send, no drafts, threads, labels, or Google Contacts. Reach makes no other Gmail API call. - How we use it. Solely to deliver messages you composed and chose to send, from your own address so they arrive as coming from you: a message to a contact you selected, the same message personalized to several contacts you selected (capped at 100 per send, and only ever contacts already in your own account), or a calendar invite to someone you scheduled a meeting with. If you schedule a send for later, delivery happens at the time you set. Reach never picks recipients for you and never sends anything you did not write and confirm.
- Who we share it with. Nobody. The message goes to Google for delivery and to the recipient you chose. We do not sell it, transfer it to any third party, use it for advertising, or use it to train any model — including our own. This is narrower than our general AI settings: email you send through Gmail is never used for training, whether or not you have opted in.
- How we protect it. Your Google tokens are encrypted at rest and never exposed to the browser. Everything moves over HTTPS, and your data is row-scoped per account so no other user can reach it. Sending is refused outright unless your stored authorization actually carries the
gmail.sendscope. - How long we keep it, and how it is deleted. Reach does keep the messages it sent for you — recipient, subject, body, and send time — so you can see your sent history in the Email tab and so scheduled sends can run. This is our copy of mail you sent through Reach; it is not access to your Gmail account. Delete an email in Reach and its content goes with it. Delete your account and all of it is removed immediately, with no grace period, and we revoke Reach's Google authorization with Google rather than only discarding our copy. You can disconnect Google at any time in Settings, which stops all sending and leaves your existing Gmail untouched.
Reach's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI features
Reach offers optional AI-assisted features — for example, drafting outreach email and scoring how well your résumé matches a job description. These only run when you use them.
- PII is stripped before anything is sent.Email addresses and phone numbers in your content are replaced with placeholders before it goes to the AI model, and restored only in what's shown back to you. If your content contains a Social Security number or a credit card number, we refuse to send it — the request is blocked, not redacted.
- Processing is US-hosted only.AI features run on DeepSeek open-weight models through a US-based inference provider (currently DeepInfra) — never DeepSeek's own China-hosted API. Your content is never sent to infrastructure we can't make retention commitments about.
- Your résumé file never leaves your browser. For résumé-matching features, the file is parsed locally in your browser — only the extracted text, not the file itself, is sent for scoring.
- Training is opt-in and off by default.Your AI usage is never used to train any model unless you turn on "Help improve Reach's models" in Settings → Privacy & data — and you can turn it back off at any time. Even when on, it's never shared with third parties.
- Every AI request is logged (which feature, when, and its cost) for abuse prevention and billing — never to build an advertising profile.
How we use your data
- To provide and operate the features you use.
- To send the email you ask us to send.
- To process payments (via Stripe) and manage your subscription.
- To secure the service and prevent abuse.
We do not sell your personal data. We do not use your contacts or email content for advertising.
Who we share with (processors)
- Supabase — database, authentication, and file storage.
- Google — sending email you authorize.
- DeepInfra— runs the AI models behind optional AI-assisted features, US-hosted, only when you use those features (see "AI features" above).
- Stripe — payment processing.
- Our hosting providers (Vercel, Railway) to run the app.
Your rights & choices
- Access / export: request a copy of your data.
- Deletion: delete your account and all associated data from Settings → Privacy & data → Delete account. This is permanent.
- Disconnect Google at any time in Settings.
- Depending on where you live (e.g. GDPR/CCPA), you may have additional rights; contact us to exercise them.
Data retention
We keep your data while your account is active. When you delete your account we delete it immediately — there is no grace period and no recovery. That includes your workspace data (applications, contacts, emails, notes) and the files you uploaded, such as résumés and your profile photo, which are removed from storage rather than merely unlinked. Any active subscription is cancelled at Stripe, and we revoke your Google authorization with Google rather than only discarding our copy of it.
Two narrow exceptions: billing records may be retained where tax and accounting law requires it, and security/audit entries are kept without your identity attached (your account's reference is removed, leaving only the fact that an action occurred).
Security
Data is encrypted in transit (HTTPS) and row-scoped per user, so one account cannot read another's. Provider tokens are encrypted at rest. No system is perfectly secure, but we work to protect your information.
Staff access to your account
A small number of authorised Reach staff can access account data when there is a specific need to: responding to a support request, diagnosing a bug, investigating fraud or abuse, or recovering an account. We do not browse accounts casually, and we do not use your data for any other purpose.
Every such access is recorded in an internal log with the reason for it and who performed it. This access is read-only — staff cannot act as you, and in particular cannot send email from your connected Gmail account. Your Google data is used only as described above and in line with the Limited Use requirements.
Contact
Privacy questions or requests: y.ethanenbus@outlook.com.

