Privacy Policy
Last updated: August 12, 2026
This policy explains what data Reach collects, how we use it, and the choices you have. We aim to collect only what the service needs to work.
What we collect
- Account: your email address and authentication identity (managed by Supabase Auth; Google/LinkedIn if you sign in with them).
- Your workspace data: job applications, company folders, contacts, interactions, tags, notes, and any résumé you upload.
- Email you send: recipients, subject, body, and engagement with outreach you send through Reach — whether a message was opened, whether links in it were clicked, and whether any document you shared was viewed. To show you that engagement we record the approximate time, device and location of those opens and clicks. This is standard email-tracking behavior; if you email contacts in the EU, local rules on tracking may apply to you as the sender.
- Billing: subscription status. Card details are handled by Stripe — we never see or store your full card number.
- Usage: which pages of Reach you open, roughly how long you spend on each, and which features you use. This is tied to your account and used only to work out which parts of Reach are worth building on. It records page names and feature names only — never the contents of a page, and never what you type into a search box.
Google / Gmail data
If you connect Google, we request the gmail.send scope so Reach can send email as you. We use this access onlyto send the messages you compose or schedule. We do not read your inbox, and Reach's use of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements. Your Google access tokens are stored encrypted at rest, and you can disconnect Google at any time from Settings.
AI features
Reach offers optional AI-assisted features — for example, drafting outreach email and scoring how well your résumé matches a job description. These only run when you use them.
- PII is stripped before anything is sent.Email addresses and phone numbers in your content are replaced with placeholders before it goes to the AI model, and restored only in what's shown back to you. If your content contains a Social Security number or a credit card number, we refuse to send it — the request is blocked, not redacted.
- Processing is US-hosted only.AI features run on DeepSeek open-weight models through a US-based inference provider (currently DeepInfra) — never DeepSeek's own China-hosted API. Your content is never sent to infrastructure we can't make retention commitments about.
- Your résumé file never leaves your browser. For résumé-matching features, the file is parsed locally in your browser — only the extracted text, not the file itself, is sent for scoring.
- Training is opt-in and off by default.Your AI usage is never used to train any model unless you turn on "Help improve Reach's models" in Settings → Privacy & data — and you can turn it back off at any time. Even when on, it's never shared with third parties.
- Every AI request is logged (which feature, when, and its cost) for abuse prevention and billing — never to build an advertising profile.
How we use your data
- To provide and operate the features you use.
- To send the email you ask us to send.
- To process payments (via Stripe) and manage your subscription.
- To secure the service and prevent abuse.
We do not sell your personal data. We do not use your contacts or email content for advertising.
Who we share with (processors)
- Supabase — database, authentication, and file storage.
- Google — sending email you authorize.
- DeepInfra— runs the AI models behind optional AI-assisted features, US-hosted, only when you use those features (see "AI features" above).
- Stripe — payment processing.
- Our hosting providers (Vercel, Railway) to run the app.
Your rights & choices
- Access / export: request a copy of your data.
- Deletion: delete your account and all associated data from Settings → Privacy & data → Delete account. This is permanent.
- Disconnect Google at any time in Settings.
- Depending on where you live (e.g. GDPR/CCPA), you may have additional rights; contact us to exercise them.
Data retention
We keep your data while your account is active. When you delete your account we delete it immediately — there is no grace period and no recovery. That includes your workspace data (applications, contacts, emails, notes) and the files you uploaded, such as résumés and your profile photo, which are removed from storage rather than merely unlinked. Any active subscription is cancelled at Stripe, and we revoke your Google authorization with Google rather than only discarding our copy of it.
Two narrow exceptions: billing records may be retained where tax and accounting law requires it, and security/audit entries are kept without your identity attached (your account's reference is removed, leaving only the fact that an action occurred).
Security
Data is encrypted in transit (HTTPS) and row-scoped per user, so one account cannot read another's. Provider tokens are encrypted at rest. No system is perfectly secure, but we work to protect your information.
Staff access to your account
A small number of authorised Reach staff can access account data when there is a specific need to: responding to a support request, diagnosing a bug, investigating fraud or abuse, or recovering an account. We do not browse accounts casually, and we do not use your data for any other purpose.
Every such access is recorded in an internal log with the reason for it and who performed it. This access is read-only — staff cannot act as you, and in particular cannot send email from your connected Gmail account. Your Google data is used only as described above and in line with the Limited Use requirements.
Contact
Privacy questions or requests: y.ethanenbus@outlook.com.

