Privacy Policy

Last updated: July 2026

We never sell your data. We never use your data to train AI models. You own everything you create. When you use Digital Employee agents, they act on your explicit instructions and within your configured settings โ€” you remain in control at all times. You can delete your account and all your data at any time.

1. Who This Policy Applies To

This policy applies to visitors to reachvo.ai, registered users and trial users of app.reachvo.ai, users of the Reachvo Assistant Chrome extension, agency clients and sub-account users on Agency plans, and anyone whose personal data we process in connection with the Service.

2. Information We Collect

When you create an account, we collect your name, email address, company name, job title, and a hashed password. Payment details are processed directly by Stripe โ€” we store only non-sensitive billing metadata. We also collect profile and preference settings, communications with our support team, outreach content you create, and contact or prospect data you import into the CRM.

We automatically collect usage data (pages visited, features used), device and technical data (IP address, browser type, operating system), session data (authentication tokens), and performance data (page load times, error rates).

When you connect a LinkedIn account through the Reachvo Assistant Chrome extension, we receive your LinkedIn member identifier, profile information (name, headline, profile photo, connection count), and data needed to execute your configured campaigns. We do not access your private LinkedIn inbox messages, your connections' private information beyond what is necessary, or any LinkedIn data not directly required to execute your configured actions.

When you connect Gmail or other email accounts, we access only what is necessary to send your configured sequences and detect replies. For calendar connections (Google Calendar or Calendly), we access busy/available slots to propose meeting times โ€” we never read the content of your existing events.

The Reachvo Assistant Chrome extension collects your LinkedIn authentication session token at the moment you click Connect and the URL of the LinkedIn page you are on for connection context. It does not collect your LinkedIn username, password, browsing history, private messages, or any data after the initial connection. Session data is transmitted via encrypted HTTPS and stored encrypted.

If you use Digital Employee features, we collect agent configuration settings (personas, tone preferences, goal targets, auto-send thresholds, ICP definitions, signal monitoring keywords, working hours, calendar preferences). Prospect memory data โ€” records of agent interactions with your prospects โ€” is stored as vector embeddings strictly within your workspace and is never shared across workspaces.

We may receive information from third parties including Stripe (payment confirmation), analytics providers (aggregated usage data), LinkedIn via Unipile (profile and engagement data), and external signal sources for the Scout agent (publicly available funding events, job postings, and news articles from Crunchbase and news APIs).

3. Legal Bases for Processing (GDPR)

For users in the EEA, United Kingdom, or Switzerland, we process your personal data under the following legal bases: performance of contract (account management, payment processing, outreach features, transactional emails, operating Digital Employee agents); legitimate interests (analytics and service improvement, fraud detection, marketing to existing customers with opt-out, enabling the Scout agent feature you configured); legal obligation (tax and accounting compliance); and consent (cookie analytics where required).

Where we rely on legitimate interests, we have assessed that our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests โ€” see Section 8.

4. How We Use Your Information

We use the information we collect to provide the Service (outreach sequences, content intelligence, CRM, email warmup, video messaging, AI generation), process transactions (subscription billing, invoicing, refunds), communicate with you (account notifications, security alerts, feature updates, support), execute your campaigns, operate Digital Employee agents within your configured parameters, improve the Service, ensure security, comply with legal obligations, and personalise your experience.

We never sell your personal data to any third party. We never use your data, content, contact lists, prospect data, or campaign data to train AI or machine learning models. We never use your data for advertising purposes. We never share your data with other Reachvo customers. We never share your data with LinkedIn or social platforms beyond what is required to execute your explicitly configured actions.

5. Prospect Data โ€” You Are the Data Controller

When you import or collect data about third-party prospects in the Reachvo CRM, you are the data controller for that prospect data and Reachvo is the data processor acting on your instructions. You are responsible for ensuring you have a lawful basis to collect and process prospect data, for complying with applicable anti-spam laws, and for honouring opt-out and unsubscribe requests.

We enter into Data Processing Agreements (DPAs) with customers who require them for GDPR compliance. To request a DPA, contact support@reachvo.ai.

6. Data Sharing and Disclosure

We share your information only with service providers (sub-processors) bound by data processing agreements and prohibited from using your data for their own purposes. Our sub-processors include Stripe (payment processing), Mailgun (transactional email), Unipile (LinkedIn API integration, France EU), Supabase (database hosting), Cloudflare (CDN and recording storage), OpenRouter, Anthropic, OpenAI, and Google (AI model routing โ€” your content is never used for training), Google Analytics (anonymised usage data), Google News API and Crunchbase (signal retrieval for the Scout agent).

For BYOK (Bring Your Own Key) users, AI API calls route directly through your own key โ€” Reachvo does not process that content.

We may disclose information when required by law, regulation, or enforceable governmental request. We will notify you unless legally prohibited and disclose only the minimum required. In the event of a merger, acquisition, or asset sale, your data may be transferred as part of the transaction with notice before a different privacy policy applies. We may share information with your explicit consent in ways not described above.

7. Data Security

We implement encryption (TLS 1.3 in transit, AES-256 at rest), role-based access control with multi-factor authentication for all internal systems, the principle of least privilege, regular automated vulnerability scanning and dependency auditing, separate development/staging/production environments, and a documented incident response plan.

LinkedIn session tokens are stored encrypted, workspace-scoped, and invalidated on account disconnection or deletion. In the event of a data breach affecting your rights and freedoms, we will notify affected users within 72 hours and notify relevant supervisory authorities as required by GDPR.

While we implement commercially reasonable security measures, no system is completely secure. If you believe your account has been compromised, contact support@reachvo.ai immediately.

8. Your Rights

Regardless of your location, you have the right to access, correct, delete, and export your personal data, and to opt out of marketing communications.

EEA, UK, and Switzerland users additionally have the right to object to processing based on legitimate interests, restrict processing in certain circumstances, withdraw consent where processing is consent-based, and lodge a complaint with your local data protection supervisory authority (for the UK: the ICO at ico.org.uk).

California residents (CCPA/CPRA) have the right to know what personal information we collect, use, disclose, and share; the right to delete and correct; the right to opt out of sale or sharing (we do not sell or share personal information); and the right to non-discrimination for exercising these rights. California residents may designate an authorised agent to submit requests on their behalf.

To exercise your rights, submit a request to support@reachvo.ai. We will acknowledge your request within 48 hours and complete it within 30 days (extendable to 60 days for complex requests with notice). We will verify your identity before processing deletion or portability requests. Reasonable requests are free; manifestly unfounded or excessive requests may incur a reasonable fee.

9. Data Retention

Account and profile data is retained for the duration of your active subscription plus 90 days after deletion. Campaign and outreach data, video and voice recordings, and prospect memory embeddings are retained per your plan: 60 days (Launch), 120 days (Scale), 365 days (Agency/Team). CRM contact data is retained per your plan or until you delete it. Billing and transaction records are retained for 7 years as required by US tax law. Server and access logs are retained for 90 days. Security and audit logs are retained for 1 year. Agent configuration data is retained for the duration of your active subscription plus 90 days after deletion.

After account deletion, your data is permanently deleted within 90 days, except billing records retained for 7 years. You may request deletion of your data at any time by contacting support@reachvo.ai.

10. Cookies and Tracking

Essential cookies (reachvo_session, reachvo_csrf, reachvo_locale) are required for the Service to function and cannot be disabled. Analytics cookies (Google Analytics _ga, _gid) help us understand how the Service is used and can be opted out of via our cookie preferences panel.

We do not use advertising cookies, cross-site tracking cookies, third-party retargeting pixels, or social media tracking pixels. Disabling essential cookies will prevent you from using the Service.

11. International Data Transfers

Your data is primarily stored and processed in the United States. Team members in India may access data where necessary to provide support and maintain the Service. For transfers of EEA/UK personal data to countries not recognised as providing adequate protection, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and UK International Data Transfer Agreements (IDTAs) where required.

12. Compliance Standards

We process EEA and UK personal data in compliance with GDPR, with documented lawful bases, DPAs with all sub-processors, SCCs for international transfers, a data subject rights response process, 72-hour breach notification, data minimisation, and privacy by design principles.

We do not sell personal information under CCPA/CPRA. All marketing emails include a functional unsubscribe link processed within 10 business days. Our registered physical address is included in all commercial email footers.

Reachvo uses Unipile (SOC 2 Type II certified) for LinkedIn infrastructure. Our own infrastructure security controls are designed to meet SOC 2 Trust Service Criteria, with a formal SOC 2 audit planned as the platform scales.

Reachvo is not a HIPAA-covered entity and the Service is not designed for Protected Health Information. Users must not submit PHI to the Service. We target compliance with WCAG 2.1 Level AA for accessibility, including colour contrast, keyboard navigability, screen reader compatibility, and resizable text.

13. Children's Privacy

The Service is intended for users aged 18 and over and is directed at business professionals. We do not knowingly collect personal data from individuals under 18. If you believe a person under 18 has provided us with personal data, contact support@reachvo.ai and we will promptly delete that data.

14. Automated Processing and AI Agent Actions

We use automated processing for outlier scoring of LinkedIn posts, reply classification (interested, not interested, question, objection), blacklist enforcement, and opt-out detection (automatic blacklisting when a reply indicates an unsubscribe request). None of this produces legal or similarly significant effects on individuals.

When you enable Digital Employee features on the Reachvo Team plan or Reachvo Agent add-on, AI agents perform automated actions on your behalf. Nova researches LinkedIn profiles and company websites, generating prospect briefs without taking outreach action. Finn generates personalised connection notes and messages within your campaign configurations and LinkedIn's rate limits. Sage monitors inboxes for replies, classifies intent, and drafts responses. Orion runs a daily background job re-scoring prospects and coordinating agent scheduling.

By default, all agent actions are queued for your approval before sending. You may configure agents to send automatically within defined parameters โ€” if you do, you accept responsibility for the content of automatically sent messages. Every agent can be paused individually at any time. All agent actions are logged in real time and you can review, edit, or cancel any queued action.

Prospect memory records are stored as vector embeddings within your workspace, used only to improve agent personalisation within your own workspace, subject to your plan's data retention limits, and permanently deleted when a contact or your account is deleted. None of the agent actions produce legal or similarly significant effects โ€” outreach messages do not determine credit, employment, or access to services.

15. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. For material changes that significantly affect your rights, we will post the updated policy on this page with a new "last updated" date, send you an email notification at least 30 days before the changes take effect, and display a prominent notice within the Service. Your continued use after the effective date constitutes acceptance. If you do not agree, you may delete your account before changes take effect.

16. Contact Us

For questions, concerns, rights requests, or complaints about this Privacy Policy or our data practices:

Email: support@reachvo.ai ยท General inquiries: hello@reachvo.ai ยท Address: Appfoster LLC, Austin, TX, United States

For EEA users: you have the right to lodge a complaint with your local supervisory authority. For UK users: Information Commissioner's Office (ico.org.uk). We aim to respond to all privacy inquiries within 48 hours.