Privacy Policy

Last updated 2026-08-11

Who we are

ReachKit ("ReachKit", "we", "us") is a discoverability tool for founders. This policy explains how we handle personal data when you use the website and product at reachkit.app.

For any question about this policy, or to exercise any of the rights below, contact us at support@reachkit.app.

What data we collect

We try to collect as little as possible. Specifically:

• Scan inputs — the website domain or URL you submit, and the report we generate from it: your Discoverability Score, the signals behind it, and the fixes it's based on.

• Email address — collected when you ask us to email your report, when you start checkout through Stripe (even if you don't complete it), and when you subscribe. Submitting your address for the report is your opt-in to the emails described under "How we use it" below — the report itself, then up to three short follow-ups about your score, which stop as soon as you subscribe — and we record the moment you submitted it as the record of that opt-in. There is no password: you sign in with a one-time emailed link, so this address is also how we authenticate you.

• A hashed form of your IP address — free scans are rate-limited per visitor using a salted one-way hash of your IP address (never the raw address itself, which we do not store).

• Billing data — if you subscribe, Stripe collects and stores your payment details; we store only your subscription status and a Stripe customer reference, never your card number.

• Approved product data — if you subscribe, the product category and up to five competitor domains you approve during onboarding, so we can track your standing against them.

• Usage analytics — page views and a small number of named product events (for example, that a scan started or a checkout began), captured via PostHog from both your browser and our servers.

Your scan results are public

A free scan is public from the moment it completes: its domain, score and report page appear in our public gallery and in the "companies we've analyzed" strip on our homepage, and the report has its own shareable URL. This is deliberate — it is how visitors see real examples before running their own scan — and there is currently no automatic removal path once a scan has run, including for a domain you don't personally own. If you have a concern about a specific scan, contact support@reachkit.app and we will review it by hand.

How we use it

We use your data to run scans and generate your report and score; to email you the report you asked for; to send a fixed nurture sequence of up to three follow-ups, which stops automatically once you subscribe; to send one follow-up email if you start a Stripe checkout but don't complete it, to the address you entered there; to sign you in; to operate and bill your subscription; to rate-limit free scans; and to protect the service from abuse. We do not sell your personal data.

During onboarding, the visible text of your site is sent to Anthropic's language model for one narrow purpose: proposing a short product-category label and a handful of suggested search terms. That step never writes anything that reaches another person on your behalf — see "What ReachKit does not do" in our Terms.

Service providers (sub-processors)

We rely on a small set of providers to deliver the service. Each receives only the data its function needs:

• Supabase — our database (accounts, scans, reports, and billing status) and sign-in.

• Vercel — hosting for every request to reachkit.app.

• Stripe — checkout, subscription billing, and the billing portal.

• Anthropic — the language model used only for the category / search-term step described above.

• DataForSEO — keyword, ranking, and search-visibility data used while scanning.

• Resend — delivery of the emails described above.

• PostHog — the product analytics described above.

• Inngest — background job scheduling for scans and the weekly refresh.

Data Processing Agreement

If you need a Data Processing Agreement for your own compliance, contact support@reachkit.app and we'll provide what's available from the providers above.

Legal basis & retention

Where the GDPR applies, we process your data to perform our contract with you (running scans, providing the product), and for our legitimate interest in rate-limiting abuse, understanding product usage, and following up on an action you specifically started — emailing the report you asked for, one reminder if you start checkout and don't finish it, and the automatic nurture sequence described above, which you opt into by submitting your email address for the report. That opt-in is specific to those follow-ups and is not a general marketing opt-in: we do not use your email for anything beyond them, and you can ask us to stop any of them at any time by emailing support@reachkit.app.

We don't currently run an automatic deletion schedule. Account and billing data persists for as long as your account exists; free scan results are, as explained above, kept indefinitely as part of the public gallery unless you ask us to review one. If you close your account or ask us to delete your data, we act on that request by hand within a reasonable time, except for records we must keep longer under law (for example, billing records).

Your rights

You can ask us to access, correct, delete, or export your personal data, and you can object to or restrict certain processing. We don't yet have a self-service tool for this — email support@reachkit.app and we'll handle the request by hand, including reviewing a specific scan in the public gallery. If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority.

Cookies & analytics

We use one strictly necessary cookie, set by our authentication provider, to keep you signed in.

We also run PostHog product analytics. It's configured to store its visitor identifier in your browser's local storage rather than in a cookie, so it doesn't add a second cookie on top of the one above. It loads automatically on every page when configured and records page views plus the events listed above; it does not currently sit behind a separate consent prompt. We do not run third-party advertising cookies or cross-site trackers.

Changes & contact

We may update this policy as the product evolves; the "Last updated" date above always reflects the current version. For any privacy question or request, contact us at support@reachkit.app.