Legal

Privacy Policy

Last updated: September 4, 2026

This Privacy Policy explains how Reacherly ("we", "us", "our") collects, uses, and safeguards information when you use our platform at reacherly.com and related services (the "Service"). By using Reacherly, you agree to the practices described here.

1. Information we collect

Account information — Name, email address, company name, phone number, password, and login credentials from OAuth providers (Google, LinkedIn) you connect.

Prospect data — Contact information you upload or provide about people you want to reach: names, email addresses, LinkedIn URLs, phone numbers, company details.

Communications data — Emails, LinkedIn messages, and WhatsApp messages sent and received through Reacherly, along with metadata such as opens, clicks, replies, and delivery status.

Connected accounts — With your explicit permission, we access your Gmail, Outlook, LinkedIn, or WhatsApp Business account solely to send outreach on your behalf and detect replies.

Usage data — IP address, browser type, device information, pages visited, and actions taken within the Service.

Payment information — When applicable, billing details processed by our payment provider. We do not store full credit card numbers.

2. How we use your information

  • To operate the Service — send outreach on your behalf, personalize messages, track replies
  • To authenticate you and secure your account
  • To communicate with you about your account, updates, and important notices
  • To improve the Service — analyze usage patterns, fix bugs, develop new features
  • To comply with legal obligations and enforce our Terms

We do not use the content of your emails or messages to train AI models. Personalization is generated per-message and not retained for training purposes.

3. Google API Services User Data

Reacherly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data accessed via OAuth is used only to send outreach on your behalf and detect replies — never sold, transferred, or used for advertising.

4. Third-party services

To operate the Service, we work with the following processors. Each is bound by data protection agreements:

  • Supabase — Database and authentication
  • Railway — Backend hosting
  • Vercel — Frontend hosting
  • Google Workspace / Gmail — Email sending on your behalf (with your OAuth permission)
  • Resend — Transactional email delivery from Reacherly to you
  • Unipile — LinkedIn integration
  • WhatsApp Business API (Meta) — WhatsApp messaging
  • Slack — Team notifications (if you connect it)
  • Anthropic / OpenAI — AI models used for message generation
  • Google Analytics and cookies for anonymous usage tracking

5. Data sharing

We do not sell your personal information. We share it only with the processors listed above (as needed to operate the Service), when required by law, in response to valid legal process, or in the event of a business transfer (merger, acquisition, asset sale) with appropriate protections.

6. Data retention

We retain your data as long as your account is active or as needed to provide the Service. If you delete your account, we delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (fraud prevention, accounting).

7. Your rights

Depending on your jurisdiction (including GDPR for EU residents and CCPA for California residents), you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data ("right to be forgotten")
  • Export your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent at any time (for consent-based processing)

To exercise any of these rights, email bk@reacherly.com.

8. Security

We use industry-standard security measures including encryption in transit (TLS), encryption at rest, secure OAuth-based authentication, and access controls to protect your data. No system is 100% secure, but we work to minimize risk and respond promptly to any incidents.

9. International transfers

Reacherly is operated from Jordan, and our processors operate globally (primarily in the US and EU). By using the Service, you consent to your data being transferred to and processed in these locations, subject to appropriate safeguards under applicable law.

10. Children's privacy

Reacherly is not directed at children under 16. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notice. The "Last updated" date at the top reflects the latest revision.

12. Contact

Questions about this Privacy Policy or your data? Email bk@reacherly.com.