Skip to content
Reach-book.com

Reach-book.com · Legal

Privacy policy

Last updated: 16 September 2026

Reach-book.com is currently an independently operated test project based in Germany. It is not yet operated by an incorporated company. The operator plans to establish a company later. Testing does not remove our responsibilities for personal data or your statutory rights.

1. Who this policy covers

This policy describes how the operator of Reach-book.com ("we", "us") handles personal data on our website and in our prospecting, email outreach, and shared inbox application. It covers visitors, account holders, newsletter subscribers, and people whose details appear in a workspace.

The project operator is responsible for account administration, website operation, support, and security. A workspace customer normally determines why and how its prospect and correspondence data is used; we process that data on its instructions to provide the service. Contact [email protected] for privacy questions, requests, or information about the operator.

2. Data we collect and where it comes from

Account and workspace data: name, email address, authentication records, profile settings, workspace membership, permissions, invitations, and preferences. If you choose Google or Microsoft sign-in, we receive the account identifier and profile information supplied for sign-in. Signing in and connecting a mailbox are separate actions.

Prospect and outreach data: names, business email addresses, phone numbers where supplied, job titles, companies, domains, public profile links, research notes, imported records, verification results, drafts, campaigns, replies, tasks, meetings, deals, and opt-out records. These come from you, workspace members, connected systems, public business websites, and requested lookups through Anymail Finder or Hunter.

Mailbox data: connected email address, provider identifiers, authorization scopes, access and refresh tokens, and message data described below. We receive the credentials you supply for other mailbox or customer database connections. OAuth connections do not give us your Google or Microsoft password.

AI and integration data: prompts, writing instructions, business reference material, assistant conversation history, relevant tool results, generated text, and data exchanged with integrations you enable.

Service records: IP address, browser or device information, request times, security and error logs, activity history, feature usage and credit consumption, support correspondence, and newsletter confirmation and unsubscribe records. When a paid feature is used, we keep billing contact details, subscription, invoice, and payment-status records. Stripe handles payment details through its payment interfaces.

3. Purposes and legal bases

We use account and workspace information to provide requested features, authenticate users, manage access, answer support requests, and administer any subscription. Where GDPR applies, the basis is performance of a contract or steps requested before entering one (Article 6(1)(b)). Necessary account information is required to provide access; optional integrations and newsletter subscriptions are not required to browse the website.

We use security logs, activity records, and service usage to prevent abuse, investigate failures, enforce access controls, and operate the service. Our basis is our legitimate interest in a functioning and secure service (Article 6(1)(f)), subject to your rights and interests. We use records required for accounting or other legal duties under Article 6(1)(c).

For optional newsletters and processing that requires consent, we rely on consent (Article 6(1)(a)). You can withdraw it whenever you choose, without affecting processing that was lawful before withdrawal. OAuth authorization controls access to your provider account; it does not give permission for unrelated uses of your data.

Workspace customers must establish their own lawful basis and give required notices for the contacts they import, research, or email. Availability on a public website or a successful email lookup does not establish consent to receive marketing.

4. Google and Gmail access

Connecting Gmail requests userinfo.email to identify the mailbox, gmail.compose to create and manage drafts and send messages, and gmail.readonly to read messages and threads for the shared inbox and reply tracking. The consent screen describes the scope of the permissions Google grants. Read access can technically cover your mailbox; our integration uses message and thread identifiers associated with your outreach to retrieve conversations.

We process sender and recipient addresses and names, subjects, message text, snippets, dates, labels, message and thread identifiers, and reply headers. We store the connected address, authorization details, encrypted access and refresh tokens, and the correspondence records needed to show conversation history, recognize replies, stop or schedule follow-ups, and report campaign activity. Offline authorization lets approved sending and reply checks run while you are away.

We create drafts or send messages when you or an authorized workspace member request those actions, including schedules and sequences you approve. Mailbox permissions govern which workspace members may read or send. We do not use Gmail access to build a contact database for sale, serve advertisements, or create advertising profiles.

Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. This applies to raw Google data and data derived from it. We use and transfer it only to provide or improve the user-facing features you request, for necessary security purposes, as required by law, or in another case expressly permitted by that policy. A transfer in a merger or asset sale requires the prior user consent required by Google.

We do not sell Google user data, use it for creditworthiness or lending decisions, or use it to develop, improve, or train generalized AI or machine-learning models. Service providers may process it only for the permitted service purpose. Human access to Google data is limited to your affirmative agreement to view specific data, necessary security investigation, legal requirements, or aggregated and anonymized internal operations permitted by Google. These restrictions also apply to our service providers.

You can disconnect Gmail in Workspace settings → Mailboxes & connections and remove Reach-book.com access in your Google Account connections. Disconnecting removes the stored Google authorization record and stops use of that connection; we also attempt to revoke its token with Google. Revoking access does not erase correspondence already stored in Reach-book.com or messages held by Google or recipients. See the deletion section for those requests.

5. AI writing and assistant features

When you use AI features, Reach-book.com sends the relevant prompt, draft text, company and prospect context, workspace business reference material, and, for the assistant, conversation history and tool results to the OpenAI API to generate the requested response. This can include personal data that you place in prompts or drafts. Do not include information that you are not authorized to share.

We store assistant conversations and generated drafts for your later review. We do not use connected Google data to train generalized models. AI processing supports the requested writing or assistant feature; it is not permission to use mailbox data for unrelated purposes. Provider processing and retention depend on the API service and the account settings in use; we do not promise zero provider retention.

You can choose not to use the AI features and use available manual drafting tools instead. Review generated content and suggested actions before approval. We do not use AI to make decisions about you with legal or similarly significant effects.

6. Who receives data

Authorized workspace members receive access according to their role and mailbox grants. Email providers and intended recipients receive the messages you send. People who receive an email may keep or forward their own copies.

We use infrastructure and service providers for hosting, storage, delivery, security, and support. Feature-specific recipients include Google and Microsoft for connected accounts and mailboxes; your configured SMTP provider for sending; OpenAI for requested AI features; Anymail Finder and Hunter for requested email lookup, verification, and enrichment; and Stripe for payments where enabled. If you open live chat, Crisp receives your message, the name shown on your account and, for signed-in members, your email address and workspace name.

If you enable HubSpot, Calendly, a customer database API, workspace APIs, or webhooks, relevant contact, meeting, outreach, or event data passes to or from the selected service or destination. Your workspace administrator controls these connections. Only enable destinations you trust and are authorized to use.

We may disclose information when law requires it or when necessary to investigate abuse or protect people and the service. Google data remains subject to the restrictions above. We do not sell private mailbox contents or provide them to advertising networks. Contact us for information about providers involved in your use of the service.

7. Processing locations and international transfers

The project operates from Germany. This does not mean all data stays in Germany: connected providers and infrastructure may process data elsewhere, including the United States. The destination depends on the feature and provider you use.

Where GDPR restricts an international transfer, an applicable adequacy decision or appropriate safeguards, such as the European Commission standard contractual clauses with any necessary supplementary measures, are required. Contact [email protected] for the destinations and safeguards applicable to your data and to request a copy of applicable safeguards. We do not claim an EU-only hosting or processing arrangement.

8. Retention, disconnection, and deletion

We keep account and workspace data while needed to provide the service. Correspondence, drafts, campaign history, and assistant conversations remain until deleted or included in a completed deletion request; disconnecting an integration alone does not delete them. We retain billing records for applicable statutory periods, and security or dispute records for as long as necessary for their specific purpose.

Ask [email protected] to delete your account, connected-provider data, or workspace records. Tell us the account address and the scope of your request; do not send passwords or access tokens. We may verify your identity and authority over workspace data. Account settings also offer deletion, but workspace ownership or linked outreach history can require support before deletion can proceed.

We assess deletion requests under applicable law, delete data no longer needed, and explain any necessary retention and its basis. Limited suppression records may remain to honor opt-outs. Residual copies in backups, where present, follow the applicable backup lifecycle and must remain protected until removed; this policy does not promise instant deletion from backups. Ask us for the timing applicable to your request.

Deleting data from Reach-book.com does not delete copies in recipients’ mailboxes or independent third-party systems. You may need to contact those providers or the workspace customer as well. When the test project ends, we will tell affected users how to request export or deletion and retain data only for a continuing lawful purpose.

9. Protection of data

Reach-book.com uses HTTPS, encrypted stored integration credentials, workspace access controls, separate mailbox read and send permissions, and activity records. Account protection includes available two-factor authentication and passkeys. Access for administration and support must be limited to the task being performed.

No service can guarantee absolute security. Report suspected unauthorized access to [email protected]. We will assess incidents and notify affected people and authorities when applicable law requires it.

10. Cookies, browser storage, and newsletters

We use cookies and browser storage for sessions, protection against forged requests, appearance and navigation preferences, and recent workspace activity. You can remove or block storage in your browser; doing so may sign you out or prevent account features from working. Necessary storage supports the service you request. Optional analytics and advertising tools remain blocked until you consent in Cookie settings. You can reject them or withdraw consent there. The cookie policy lists the tools currently configured and their storage lifetimes.

Newsletter signup is separate from workspace outreach and requires email confirmation. You can unsubscribe using the link in a newsletter or by contacting us. Opting out of a newsletter does not stop essential account, security, or requested service messages. To stop outreach from a workspace customer, use its unsubscribe link or contact that sender.

11. Your privacy rights

Subject to the conditions in applicable law, you can request access, correction, deletion, restriction, and a portable copy of your personal data. You can object to processing based on legitimate interests and object to direct marketing whenever you choose. You can withdraw consent without affecting earlier lawful processing.

Send requests to [email protected]. Under GDPR, we normally respond within one month. If the law permits an extension for a complex request, we will explain the reason and timing within that month. We request only the information reasonably needed to verify the request.

If a workspace customer controls the data, you may contact that customer directly. We will help route your request and assist the customer as required. You can complain to a supervisory authority, including the German state data protection authority responsible for your place of residence or the operator. You do not have to contact us before complaining.

12. Children and policy changes

Reach-book.com is intended for adults using business outreach tools, not children. If you believe a child has supplied personal data, contact us so we can investigate and arrange deletion where appropriate.

We will update this page and its date when our practices change, and notify affected users of material changes through the service or email. If a company is formed later, we will identify the company and explain any change in responsibility before it takes over personal data. We will obtain fresh consent where required; the plan to form a company is not blanket permission to transfer or repurpose data.