Legal

Privacy Policy

Last updated: February 2026

Reachly ("we", "us", or "the Service") helps you run personalised email outreach campaigns using your own email account. This policy explains what personal data we collect, how we use it, and the choices you have. Contact us at hello@ireachly.com with any questions.

1. Information we collect

  • Account information you provide directly: name, email, hashed password, timezone, and — if you upgrade — billing metadata.
  • Google or Microsoft account data if you connect Gmail or Outlook: your email address, a durable account identifier, and OAuth tokens that let us send email from your account and check for replies. We never ask for or store your Google/Microsoft password.
  • Campaign data you create: contacts you upload, campaign templates, follow-up schedules, and delivery / reply metadata.
  • Product usage: pages visited, actions taken, and error logs, used to keep the service reliable.

2. How we use Google user data

When you connect Gmail, we request the gmail.send and gmail.readonly scopes. We use this access only to:

  • Send emails you author on your behalf.
  • Read message metadata (headers, thread IDs) and the message list within threads Reachly created to detect replies and auto-pause a sequence.

Reachly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically we do not:

  • Use Google user data to train generalized AI or ML models.
  • Serve advertising, or transfer Google user data to third parties for advertising.
  • Allow humans to read Google user data unless (a) we have your explicit consent for specific messages, (b) it is necessary for security purposes like investigating abuse, (c) it is required to comply with applicable law, or (d) the data has been aggregated and anonymised.

3. How we use Microsoft user data

When you connect Outlook we request the Mail.Send and Mail.ReadWrite scopes. We use this access with the same constraints as Google data above: only to send campaign emails you authored and to detect replies in threads Reachly created.

4. Storage and retention

  • OAuth refresh tokens are encrypted at rest.
  • Contact and campaign data live in our database for as long as your account is active. You can delete a campaign or contact at any time.
  • If you delete your account, we remove your data within 30 days, except where retention is required to resolve disputes, prevent fraud, or comply with law.

5. Sharing

We do not sell your data. We share it only with subprocessors necessary to operate the service (hosting, email delivery, payment processing). All subprocessors are bound by data-processing agreements.

6. Your choices

  • Disconnect Google/Microsoft: revoke Reachly's access anytime from your Google or Microsoft security settings, or from Reachly's Settings page. This immediately deletes the stored refresh token.
  • Export or delete: email hello@ireachly.com to request an export or deletion of your account data.
  • Marketing: we don't send you marketing email without your consent. Transactional email (password resets, billing) is required for the service to function.

7. Security

We use HTTPS across the service, hash passwords with bcrypt, encrypt refresh tokens at rest, and follow the principle of least privilege for internal access. No system is perfectly secure — please report suspected vulnerabilities to hello@ireachly.com.

8. Children

Reachly is not intended for users under 16. We do not knowingly collect data from children.

9. Changes to this policy

When we change this policy we will update the "Last updated" date above and, for material changes, notify you by email or in-app before the change takes effect.

10. Contact

Reachly · hello@ireachly.com