Privacy Policy
Last updated 3 September 2026
This policy explains what Reachara collects, why we collect it, who we share it with, and what you can do about it. It covers both the website and the product.
1. Two different kinds of data
Reachara keeps two separate stores, and almost every question about privacy here has a different answer depending on which one you mean.
Your account data is specific to you: who you are, which competitors you asked us to watch, and the timeline we built for them. Nobody else can see it.
The crawled corpus is a record of a public market: profiles and videos published openly on a channel, and what each hashtag has produced. It is not scoped to a customer, and it is shared across all customers — if two customers monitor the same competitor, one crawl serves both. What stays private is the fact that you are the one watching.
2. What we collect about you
Your account. Your email address, and your name and profile picture if they come from Google when you sign in that way. You can sign in with Google, with a one-time link sent to your email, or with a password. If you use a password we store only a hash of it — we never see the password itself and cannot recover it.
What you asked us to watch. The competitors you add — their name, their website if you give us one, their account handle on a channel if you know it — and the hashtags you confirmed we should sweep for each one. Alongside them we keep the day-by-day results of those sweeps, plus any lists or saved filters you create.
Billing. Your subscription status and plan. Card details go directly to Stripe and never touch our servers.
API keys and API usage. If you use the API we store a hash of each key plus a short display prefix — never the key itself — and a log of the calls made with it: which endpoint, the status, how long it took. That log is for your own usage page and for answering support questions.
Basic technical logs. IP address, browser and timestamps, kept for security and debugging.
3. Information about other people, in the corpus
This is the part worth reading carefully, because it is the part most policies in this category leave out.
To monitor a channel we crawl what is publicly visible on it, the way any logged-out visitor sees it, and store it. That includes account handles, display names, profile pictures, follower and post counts, and the videos published under the hashtags being watched, with their captions and their public play, like, comment, share and save counts. We do not sign in to any account to do it, and we collect nothing that a channel keeps behind a login or that an account has restricted.
This means the corpus contains personal data about people who are not our customers. Where an account has published contact details in its own public bio — a business email address, a link to a website or a link-in-bio page — those are stored too, exactly as published. We do not construct, guess or enrich an address that was not there: if an account published nothing, we record that it published nothing.
Our lawful basis is legitimate interest — specifically, our customers’ interest in understanding a public market, acting on information that businesses and creators chose to publish publicly, and usually published precisely so that it would be found. We limit that to what is genuinely public and commercial in nature.
If you are in the corpus and want out. Write to [email protected] from, or naming, the account in question. You can ask us what we hold about that account, ask us to correct it, ask us to delete it, or object to us processing it at all. We will action a removal. Being straight about the limit of that: the corpus is rebuilt by repeated crawls of pages that are still public, so tell us if an account reappears and we will remove it again — we would rather say that than claim a permanent block we have not built.
4. Why we collect it
- To run the product you signed up for, which is the bulk of it.
- To bill you correctly, and to keep an account inside the plan it pays for.
- To decide where to crawl next — recording what a hashtag has actually yielded is how we avoid re-sweeping tags that produce nothing.
- To keep the service up and to investigate abuse.
- To send you service email. We do not sell your data to anyone, ever.
5. Who else sees it
We use a small number of processors, and only where the work genuinely requires it:
- Stripe — payments and subscriptions.
- Google — only if you choose to sign in with a Google account.
- UseSend — the service that delivers our sign-in links and service email.
- Our hosting and database providers — where the application runs and the data is stored.
We run no third-party analytics on this site: no analytics script, no advertising pixel, no session recording, no heatmap. Nothing about your visit is sent to an analytics vendor, because we do not use one.
We also disclose data where the law requires it, and we will tell you when we are permitted to.
6. How long we keep it
Your account and everything under it stay until you delete them. Deleting a competitor deletes the timeline we built for it. Ask us to close your account and we will delete your personal data and revoke your API keys; we keep the minimum billing records that tax law requires.
The corpus is not kept per customer and does not disappear when you close your account, because it is not about you — it is a record of a public market that other customers are also reading. Rows in it are overwritten by later crawls, and are deleted on request as described in section 3. We are not, at this stage, committing to a fixed retention period for it; we would rather say that plainly than publish a number the system does not enforce.
7. Your rights
Whether you are a customer or someone whose public account we crawled, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to how we are using it. Email us and we will action it — normally within a few days, and always within a month. If you are in the UK or EU you also have the right to complain to your data protection authority.
8. Cookies
We set a cookie to keep you signed in, and Stripe sets its own on the checkout flow to prevent fraud. Both are strictly necessary to operate the service. We run no advertising, analytics or cross-site tracking cookies.
9. Security
Traffic to the site and the API is served over HTTPS. Passwords and API keys are stored only as hashes, so neither can be read back out of the database — an API key is displayed once, at creation, and is unrecoverable afterwards. Each customer’s records are scoped to their own account, and access is limited to the people who need it. No system is perfect; if a breach affects you we will tell you promptly.
10. Changes
If we change this policy materially we will email you before it takes effect. The date at the top always reflects the current version.
11. Contact
Questions about any of this, and removal requests: [email protected].