We believe in radical transparency about how we collect, use, and protect your data. This policy explains everything clearly — no legal jargon.
✅ The short version: We collect only what we need to run the service. We never sell your data. You can delete your account and all data at any time.
ReachFlux, Inc. ("ReachFlux", "we", "our", or "us") operates the ReachFlux platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this privacy policy, please do not access the Service.
When you create an account, use our Service, or contact us, we may collect:
| Data Type | Purpose | Retention |
|---|---|---|
| Account data | Service delivery & authentication | Until account deletion |
| Campaign data | Outreach & reporting | Until account deletion |
| Usage analytics | Product improvement | 24 months |
| Support messages | Customer service | 36 months |
| Billing records | Legal compliance | 7 years |
We use the data we collect to:
📧 Marketing emails: We will only send you promotional content if you have opted in. You can unsubscribe at any time using the link at the bottom of any marketing email.
🚫 We never sell your data to third parties, advertisers, or data brokers. Full stop.
We may share your data only in these limited circumstances:
Reach Flux allows users to voluntarily connect their Google account to enable Google Calendar functionality. Google Calendar access is requested only after the user explicitly initiates the connection and grants permission through Google's OAuth consent process.
When authorized, Reach Flux may use the Google Calendar API to create and manage meeting events on behalf of the user. This access is used only to provide calendar and meeting-scheduling functionality requested or enabled by the user.
Reach Flux includes an AI-powered Auto-Pilot feature. When enabled by the user, Auto-Pilot may analyze outreach conversations and determine that an action, such as scheduling a meeting, should be performed.
Auto-Pilot does not directly access or call the Google Calendar API. When Auto-Pilot determines that a meeting should be scheduled, it dispatches a scheduling action to the Reach Flux application. The Reach Flux backend then performs the authorized Google Calendar API request and creates or manages the calendar event on the user's behalf.
Reach Flux uses third-party AI inference services, including Groq, to provide certain AI-powered functionality. AI models are used for tasks such as analyzing outreach conversations, determining appropriate actions, and generating responses.
Google Workspace API data obtained through the Google Calendar API is not transmitted to our third-party AI service provider. AI determines the appropriate scheduling action from the outreach conversation, while Google Calendar API operations are performed independently by the Reach Flux backend.
Reach Flux does not sell Google user data or use Google Workspace API data for advertising purposes.
Reach Flux's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Users can revoke Reach Flux's access to their Google account at any time through their Google Account settings.
We use cookies and similar tracking technologies to:
You can manage cookie preferences in your browser settings or via the Cookie Settings link in the footer. Disabling essential cookies will prevent the platform from functioning correctly.
ReachFlux is SOC 2 Type II certified. Our security practices include:
While we implement industry-standard safeguards, no system is 100% secure. If you discover a security vulnerability, please contact us at security@reachflux.io.
You have the following rights regarding your personal data:
To exercise any of these rights, email us at privacy@reachflux.io or use the Data & Privacy section in your account settings.
If you are located in the European Economic Area (EEA), UK, or Switzerland, we process your data under the following legal bases:
When transferring data outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. Data Processing Agreements (DPAs) are available on request.
Our EU representative can be reached at gdpr@reachflux.io.
Our Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal information, please contact us and we will take steps to delete such information.
We may update this Privacy Policy from time to time. We will notify you of material changes by:
Your continued use of the Service after the effective date of any changes constitutes acceptance of the updated policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
ReachFlux, Inc.
🔒 security@reachflux.io (security issues only)
📍 548 Market St, Suite 92901, San Francisco, CA 94104