Skip to content

Privacy Policy

This Privacy Policy is issued by Reachype ("we", "us") as data controller, to meet our disclosure obligations under Turkish Personal Data Protection Law no. 6698 ("KVKK") and — for users established in the European Union — the General Data Protection Regulation ("GDPR").

1. Data controller

Reachype
Turkish tax number (Vergi No): 9790649140
Email: support@reachype.com

2. Data we collect

Account and organisation data

Name, email address, an irreversible hash of your password, time zone, language preference, organisation name and your role within the organisation.

Usage and session data

Sign-in time, IP address and browser information (user agent) — for account security and session management; you can view and end your active sessions from your account settings.

Product usage analytics

We keep anonymous usage data to measure which of your registration and setup steps were completed (e.g. viewing the sign-up form, creating an account, verifying email). Before you create an account this data is tied to a random identifier generated in your browser's local storage; it contains no identity, email address or other personal data. It is held only by us — it is not shared with any third-party analytics or advertising network.

Content you generate and upload

Your chat history, brand profile, prompts, the images, video and text you generate, and the reference files you upload. This content is passed to the relevant AI provider for generation (see section 4).

Payment data

Your payments are processed through Paddle acting as merchant of record; your card number never reaches or is stored in our systems. What we hold is limited to your plan, your credit balance and the transaction identifier Paddle passes back to us.

Third-party accounts you connect

If you connect a YouTube, Meta, X or TikTok account, we store the access token within the scope that platform grants you, and the profile/statistics data covered by the scopes you select. You can remove that connection at any time — see Deleting your data for how, and for exactly what is removed when you do.

YouTube API Services

Our YouTube features are built on YouTube API Services. Whether a channel is added by its handle or by authorising Reachype through your Google account, what we read is that channel's videos, their public statistics and their comment threads — and, where you grant the analytics permissions, the channel's own YouTube Analytics figures. We use this solely to produce the dashboards and replies you see inside Reachype. We do not sell it, we do not disclose it to advertisers, and we do not send it to the AI providers listed in section 4.

Reachype also asks for permission to upload videos to a channel you connect. This permission is optional: declining it leaves everything above working, and only publishing from Reachype becomes unavailable. Where you grant it, we upload a video only when you explicitly publish one, with the title, description and visibility you chose in Reachype. The permission does not let us edit or delete videos already on your channel, and we never upload anything you did not compose yourself.

Connecting a channel also means accepting the YouTube Terms of Service. Google's own handling of your data is described in the Google Privacy Policy.

You can withdraw Reachype's access to your Google account at any time from Google's security settings, or from the Channels screen inside Reachype. Either route stops all further reading; what is deleted afterwards is set out in Deleting your data.

Meta advertising data

If you connect a Meta (Facebook/Instagram) advertising account, we read that account's reporting data through the Meta Marketing API: the ad accounts you grant us access to, together with their name, currency and time zone; your campaign, ad set, ad and creative structure; and the performance figures reported against them — impressions, reach, clicks, amount spent, conversions and conversion value, along with the breakdowns you select (such as date, age, gender, country, placement or device). Where your ad accounts sit under a Meta Business Manager, we also read the list of Business Managers you administer and the ad accounts they own, solely so that we can show you which accounts are available to connect.

This access is read-only. We cannot create, edit, pause or spend against your campaigns, and we do not request the permissions that would allow it. We use this data solely to produce the dashboards and reports you see inside Reachype. We do not sell it, we do not disclose it to advertisers, and we do not send it to the AI providers listed in section 4.

You can withdraw Reachype's access at any time from your Facebook business integrations settings, or from the Channels screen inside Reachype. Either route stops all further reading; what is deleted afterwards is set out in Deleting your data.

Google Ads data

If you connect a Google Ads account, we read that account's reporting data through the Google Ads API: the advertising accounts your sign-in can reach, together with their name, currency, time zone and status; your campaign, ad group, ad and keyword structure; and the figures reported against them — impressions, clicks, amount spent, budget, conversions, conversion value, video views and the auction impression-share figures — along with the breakdowns you select (such as date, age, gender or country). Where your accounts sit beneath a manager (MCC) account, we also read the list of accounts that manager holds, solely so that we can show you which ones are available to connect.

Google offers a single Google Ads permission that covers both reading an account and managing it; there is no reporting-only variant to request. Reachype only reads. We issue reporting queries and nothing else: we do not create, edit, pause or delete campaigns, budgets, keywords or ads, and we never spend against your account. We use this data solely to produce the dashboards and reports you see inside Reachype. We do not sell it, we do not disclose it to advertisers, and we do not send it to the AI providers listed in section 4.

You can withdraw Reachype's access to your Google account at any time from Google's security settings, or from the Channels screen inside Reachype. Either route stops all further reading; what is deleted afterwards is set out in Deleting your data.

3. Purposes and legal bases

We process your personal data for the following purposes, on the bases stated:

4. Parties we share data with

We share your data, only to the extent needed to provide the Service, with:

We never sell your data to third parties for marketing purposes.

5. Retention and deletion

We keep your account data for as long as your account is active, and after it is closed for as long as our legal obligations require (for example, the period prescribed by applicable law for billing records). At the end of those periods the data is deleted or anonymised.

Closing an account is not self-service. To have your account and its data deleted, write to support@reachype.com from your registered address; we complete verified requests within 30 days, which is the response period set by KVKK art. 13/2 and GDPR art. 12(3).

Data imported from a connected social account is deleted separately from your account, and can be deleted without closing it. Deleting your data sets out both routes step by step, including what a deletion request from Meta covers.

6. Security

Your password is stored as an irreversible hash (bcrypt); traffic is encrypted with TLS; your session access tokens are short-lived and refresh tokens are protected by rotation (single-use, with reuse detection).

7. Your rights

Under KVKK art. 11 you may apply to us to:

If you are established in the EU, you may additionally exercise your GDPR rights to data portability and to object to processing. Send applications to support@reachype.com. For the deletion right specifically, Deleting your data gives the procedure, what each route deletes and how long it takes.

8. Cookies

reachype.com uses your browser's local storage only for essential functionality (such as your theme preference); we use no third-party advertising or tracking cookies. The Cloudflare Web Analytics we use for visit statistics is also cookieless (see section 4). The application (app.reachype.com) manages your session through browser memory and local storage rather than cookies.

9. Changes

We may update this policy; for material changes we will send a notification to your registered email address.

10. Contact

For privacy questions, reach us at support@reachype.com.