Skip to content

ReachQuill legal

Privacy Policy

Effective September 22, 2026
Last updated September 22, 2026

Production-quality draft based on the current ReachQuill implementation. Bracketed legal identity, contact, address, jurisdiction, and operational details require confirmation before launch.

1. Introduction

This Privacy Policy explains how [Legal entity name to be confirmed], operating ReachQuill ("ReachQuill," "we," "us," or "our"), handles information when you use the ReachQuill website and service. ReachQuill is a business-discovery and email-outreach workspace.

This is a draft based on the current product implementation. Legal identity and contact details shown in brackets must be confirmed before production publication.

2. Information we collect

We collect information you provide, information created through your use of the service, limited technical information needed to operate accounts and sessions, and information received from connected services.

Account information

When you create or update an account, we may collect your username, email address, phone number, and password. Passwords are stored as one-way hashes rather than in readable form.

Authentication and session information

We maintain authentication sessions and may process session identifiers, browser or device user-agent information, IP address, creation and last-use times, expiration time, and revocation status to authenticate accounts and help users manage active sessions.

Business and lead information

When you use business discovery, ReachQuill stores searches and results, including business names, addresses, phone numbers, websites, business categories, ratings, map links, and related source information. When enrichment is requested, the service may inspect publicly accessible business websites and store contact methods, people, roles, source URLs, and evidence associated with discovered information.

Outreach content and activity

We store the templates, subjects, message content, merge-tag configuration, selected recipients, campaign configuration, suppression records, sending status, and related activity needed to provide email-outreach features.

Connected Google account information

If you connect Google, we receive your Google account identifier, email address, optional display name, granted scopes, connection status, and an OAuth refresh credential. The refresh credential is encrypted before storage and is not returned through normal account API responses.

3. How we use information

We use information to operate and secure ReachQuill, authenticate users, provide business discovery, save searches and business records, perform user-requested website enrichment, maintain templates and campaigns, connect email accounts, send outreach requested by the user, show notifications and activity, troubleshoot failures, and maintain service reliability.

  • Provide and maintain the features a user chooses to use.
  • Protect accounts, manage sessions, prevent abuse, and investigate errors.
  • Preserve user workspace state, campaign history, and delivery records.
  • Communicate service information inside the product.

4. Google account and Gmail data

ReachQuill uses Google OAuth. The current integration requests OpenID, email, profile, and Gmail send permission. Gmail send permission allows ReachQuill to send messages on your behalf when you initiate individual outreach, tests, scheduled sends, or campaigns. ReachQuill does not request permission to read your Gmail inbox through the current implementation and does not ask for or collect your Gmail password.

ReachQuill stores the connected account identity and an encrypted OAuth refresh credential so that user-requested and scheduled sending can continue. Disconnecting a Google account triggers an attempt to revoke the credential with Google and removes the local connection.

Information received from Google Workspace APIs is used only to provide the user-facing connected-email and sending functionality described here. ReachQuill’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

5. Cookies and authentication

ReachQuill uses an HTTP cookie containing a refresh-session credential to restore and maintain an authenticated session. Access credentials are held in application memory rather than intentionally stored in browser local storage. The interface may also store non-authentication preferences, such as color mode, accent color, and sidebar behavior, in local storage.

The current frontend does not include advertising, behavioral analytics, or third-party tracking packages. Deployment infrastructure may generate operational request logs; the final production host and its logging configuration must be reviewed separately.

6. Data storage and security

Current application records are stored using MongoDB. ReachQuill uses measures including hashed account passwords, hashed session refresh credentials, encrypted Google refresh credentials, account-scoped data access, and session revocation controls. No system can guarantee absolute security, and users should protect their credentials and report suspected unauthorized access.

7. Service providers and external sources

The current implementation relies on Google services for business-place discovery, Google account authorization, and Gmail sending. It uses MongoDB-compatible database infrastructure for application storage and may retrieve publicly available pages from business websites when enrichment is requested.

A final production subprocessor list cannot be completed from the repository because the hosting provider, managed database vendor, monitoring services, and production network configuration are not established in code. These must be confirmed before launch.

8. Data retention

ReachQuill retains account and workspace information while needed to provide the service and maintain its operational records. Authentication sessions expire or may be revoked; some expired session records are configured for automatic database removal. A formal retention schedule for accounts, searches, business records, outreach content, campaign history, and operational logs is not established in the repository and must be confirmed before production launch.

9. Your choices and controls

The current product allows users to update supported profile details, change a password, review and revoke active sessions, sign out all sessions, manage outreach content, and disconnect a Google email account. Google permissions may also be reviewed or revoked through the user’s Google account.

The current product does not expose self-service account deletion or data export. A verified process and contact channel for those requests must be established before launch if required by applicable law.

10. Children’s privacy

ReachQuill is designed as a business service and is not directed to children. Do not create an account or submit personal information if you are not legally able to agree to these terms in your location.

11. Changes to this policy

We may update this policy as the service, providers, or legal requirements change. We will update the date shown above and provide additional notice when appropriate for a material change.

12. Contact

Legal entity: [Legal entity name to be confirmed]

Privacy contact: [Contact email to be confirmed]

Mailing address: [Mailing address to be confirmed, if required]