Privacy / notice

Your data should be easy to understand.

This policy explains what DeepReachAI collects, why we collect it, how we use service providers, and how you can exercise your rights. It is written as a first draft for legal review.

Draft for legal reviewLast updated: August 23, 2026

1. Who we are

DeepReachAI is operated personally by Aryan Agrawal ("DeepReachAI", "we", "us", or "our").

Operator location
Pune, India
Privacy contact
tyronmrx@gmail.com
Grievance Officer
Aryan Agrawal — tyronmrx@gmail.com

You can also send a request through our Contact page.

2. What personal data we collect

We collect the data below for the specific purposes listed. We do not treat all data as one broad category.

Account identity data
Name and email address. We use this to create and secure your account, identify you when you sign in, provide support, and send service messages.
Account and onboarding data
Role or company, use case, offer, target audience, preferred tone, website, phone number, and business vertical selection when you choose to provide them. We use this to personalize research and generate outreach that fits your work.
Billing and subscription data
Plan, subscription status, amount, Razorpay order ID, Razorpay payment ID, and expiry information. Razorpay processes payment details such as card or bank details. We use the data we receive to confirm payment, provide the plan you selected, prevent fraud, and keep billing records. DeepReachAI does not need to store your full card number to provide the service.
Usage and product data
Generation history, saved outreach, search history, sequence activity, provider usage, timestamps, and account-level product events. We use this to provide the product, enforce plan limits, troubleshoot issues, improve reliability, and understand which features are useful.
Prospect and lead data processed for you
Names, job titles, company names, work emails, phone numbers, locations, websites, public company or person information, and other research content you search for, upload, or ask us to process. We process this data on your behalf to discover businesses, enrich leads, research relevant signals, and generate personalized email, LinkedIn, and WhatsApp outreach. You are responsible for having the rights and permissions needed to provide and use this data.
Support and communications data
Information you include when you contact us, such as your name, email address, and message. We use it to respond and keep a record of support work.
Analytics and device data
Page views, browser and device information, approximate usage information, and product events may be collected by Google Analytics, Vercel Analytics, and PostHog when those tools are enabled. We use this to understand traffic, sign-up, generation, and product behavior. PostHog product events are enabled only when its public project key is configured.
Google user data — only if Gmail connection is enabled
The current repository does not implement Gmail OAuth. If we later enable the optional Gmail connection, we will request the narrow gmail.send scope. We would access the connected Gmail account identity and the message content, recipient details, and send metadata needed to send outreach at your direction. We would not read your inbox under this scope. See the dedicated Google user data section below.

3. How we use and share data

We use personal data to:

  • provide account access, research, enrichment, personalization, exports, and outreach workflows;
  • process subscriptions and payments through Razorpay;
  • apply usage limits, protect the service, and investigate misuse;
  • answer support requests and send important service notices; and
  • measure and improve product performance through the analytics tools listed above.

We share data with service providers only when they need it to provide part of the service. These providers include Supabase for authentication and database services, Firecrawl and other configured enrichment providers for research, Razorpay for payments, Resend for transactional email, PostHog, Google Analytics, Vercel Analytics, and our hosting or infrastructure providers. Each provider may process data under its own terms and privacy documentation.

We do not sell personal data. We do not use prospect data to create a general-purpose public directory or to train a general-purpose AI model. We may disclose data when required to comply with law, enforce our terms, protect users, or prevent fraud and security abuse.

4. Your rights and how to use them

Under the Digital Personal Data Protection Act, 2023, a Data Principal may ask us for the following. Send a request to tyronmrx@gmail.com or use the Contact page. We may ask for information needed to verify the request belongs to you.

Access — Section 11
Ask for a summary of the personal data we process about you, the purposes for processing, and the categories of data shared with processors.
Correction and erasure — Section 12
Ask us to correct inaccurate or incomplete data, or erase data that we no longer need or are not required to keep.
Grievance redressal — Section 13
Contact our Grievance Officer: Aryan Agrawal at tyronmrx@gmail.com. You may also use our Contact page.
Nomination — Section 14
You may nominate another person to exercise your rights under applicable law if you die or become incapable of exercising them. Contact us to record or update a nomination.
Withdraw consent
You may withdraw consent at any time where consent is the basis for processing. Withdrawal does not affect processing that was lawful before withdrawal. It may mean that we cannot continue a feature that needs that data.

5. Complaints and escalation

First, send your complaint to our Grievance Officer using the details above. Include the account email, what happened, and the outcome you want. We will review it and respond through the contact method you provide.

If your complaint is not resolved by DeepReachAI, you may escalate it to the Data Protection Board of India through the Board's official complaint channel.

6. International processing and transfers

DeepReachAI uses cloud and infrastructure providers that may process or store data outside India. The repository confirms use of Supabase, Firecrawl, Razorpay, Resend, PostHog, Google Analytics, Vercel Analytics, and hosting infrastructure, but the exact region for each provider depends on account configuration.

Supabase project region
ap-northeast-w
Hosting provider and region
Vercel — ap-northeast-w

Where data leaves India, we will use safeguards required by applicable law and the contracts and security controls of the relevant provider. A lawyer should confirm the final transfer wording and vendor agreements.

7. Children's data

DeepReachAI is a business service. It is not directed at anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us so we can review and delete it where appropriate.

8. Retention and security

We keep account, billing, outreach, and support data while it is needed to provide the service, meet legal and accounting duties, resolve disputes, and enforce our terms. We delete or anonymize data when the applicable period ends, unless a longer period is required by law.

Our current safeguards include:

  • Supabase row-level security policies that restrict user-owned records to the relevant authenticated user;
  • server-side use of privileged database credentials for admin-only work;
  • secrets kept in server environment variables rather than exposed in the client interface; and
  • HTTPS/TLS connections for the web application and provider APIs.

No online service is completely secure. If you find a security issue, please contact us through the Contact page and do not publicly disclose it before we have had a chance to respond.

9. Data breach notifications

If we become aware of a personal data breach, we will assess it, contain it, keep a record of what happened, and notify the Data Protection Board of India and affected Data Principals as required by applicable law. Our current response target is to notify affected Data Principals within 72 hours of becoming aware, subject to any different legal direction or required format.

A breach notice will aim to explain:

  • what happened and when we detected it;
  • the categories and approximate number of people and records affected;
  • the likely consequences for affected people;
  • what we have done and what we recommend you do; and
  • how to contact us for updates.

10. Google API Services User Data disclosure

Gmail connection is not currently implemented in this repository. This section describes the planned feature and will be updated if the requested scope or data flow changes.

What we access

If you choose to connect Gmail, DeepReachAI will request the gmail.send scope. We will use the connected account identity, access authorization, message content, recipient addresses, and send metadata only as needed to send an outreach message that you choose to send. We will not use this scope to read your inbox.

How we use Google data

We use Google user data only to provide the disclosed Gmail sending feature at your initiation. We do not use it for advertising, sell it, or transfer it to data brokers. Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Revoking access

You can revoke Gmail access from DeepReachAI settings when that feature is available, and from your Google Account's third-party app permissions page at any time. Revoking access stops new Gmail sends, but does not undo messages already sent.

11. Changes to this policy

We may update this policy when the service, law, or data practices change. We will publish the updated version here and change the date at the top. If a change materially affects how we use data, we will provide any notice or consent required by law.