Privacy Policy

Effective Date: 2026-06-12

@reach respects your privacy. This policy explains how we collect, use, share, and protect your information when you use the Service.

1. Information We Collect

Information you provide

  • Email address and password (account registration)
  • Profile settings such as language, timezone, and country
  • Auto-reply rules, reply templates, and scheduled post content you create
  • Payment information — processed and stored by Stripe; we never see your full card number

Information from your Threads account

When you connect a Threads account via Meta's OAuth flow, we receive and store, with your authorization:

  • Your Threads user ID, username, and profile information
  • An access token used to act on your behalf (post replies, publish scheduled posts, read insights)
  • Posts, comments/replies, and mentions delivered to us by Meta's webhooks, so that your auto-reply rules can be evaluated
  • Account and post analytics (views, likes, replies, reposts, followers) used to render your insights dashboard

Automatically collected

  • Log data (IP address, browser, timestamps) for security
  • Usage analytics via Google Analytics (when enabled)

2. How We Use Your Information

  • To operate the core features: evaluating auto-reply rules, posting replies and scheduled posts to your Threads account, and showing analytics
  • To process subscription payments and manage your plan
  • To send transactional notifications (e.g. payment failure, a rule being paused) according to your notification settings
  • To secure the Service, prevent abuse, and debug failures

We do not sell your personal information.

3. Information Sharing and Subprocessors

We share data only with the service providers needed to run the Service:

  • Meta Platforms (Threads API) — your replies and posts are published through the official API
  • Supabase — database and authentication hosting
  • Vercel — application hosting
  • Stripe — payment processing
  • Resend — transactional email delivery
  • Sentry — error monitoring
  • Google Analytics — aggregate usage analytics

We may also disclose information if required by law or to protect our rights, users, or the public.

4. Data Security

  • All traffic is encrypted in transit (TLS)
  • Database access is protected by row-level security so each user can only access their own data
  • Threads access tokens are stored server-side and are never exposed to the browser

5. Data Retention and Deletion

We retain your data while your account is active. When you delete your account from the settings page, we cancel your subscription, revoke stored Threads tokens, and permanently delete your profile, connected accounts, rules, reply logs, stored posts, and analytics. Backups expire on a rolling basis.

6. Your Rights and Choices

  • Access / correction — view and edit your data from the dashboard and settings
  • Deletion — delete your account at any time (Settings → Delete account), or contact us at floatengineering2023@gmail.com
  • Disconnect — disconnect a Threads account at any time, which deactivates its stored token
  • Notifications — control email notifications from your settings

7. Cookies and Tracking

We use cookies for:

  • Authentication (keeping you signed in)
  • Your language preference
  • Google Analytics measurement (when enabled)

8. Meta Platform Compliance

Our use of Threads data complies with the Meta Platform Terms and the Threads API terms. We only request the OAuth scopes needed for the features you use, and we delete Threads data when you disconnect an account or delete your account. You can also revoke @reach's access from your Threads/Meta account settings at any time.

9. Children's Privacy

The Service is not intended for children under 13 (or the minimum age required to use Threads in your region). We do not knowingly collect data from children.

10. International Data Transfers

Our infrastructure providers may process data in countries other than your own, including the United States and Japan. We rely on our providers' standard contractual safeguards for such transfers.

11. European and California Privacy Rights

If you are in the EEA/UK, you may have rights under the GDPR (access, rectification, erasure, portability, restriction, objection) and may lodge a complaint with your supervisory authority. If you are a California resident, you may have rights under the CCPA, including the right to know and the right to delete. We honor these requests via floatengineering2023@gmail.com; we do not sell personal information.

12. Changes to This Policy

We may update this policy from time to time. Material changes will be announced on this page with a revised effective date.

13. Contact Us

Operator: floatengineering
Email: floatengineering2023@gmail.com