Skip to content

Privacy Policy

Last updated: 24 August 2026. This policy explains what personal data Meowreach processes, why, on what legal basis, and the rights you have.

1. Who we are (Data Controller)

The controller of personal data processed through Meowreach is Meowreach (beta) — sole operator, Poland, Poland (EU). Full registered address and company / VAT details will be published here before paid plans launch ("Meowreach", "we", "us"). For any privacy question or to exercise your rights, contact hello@meowreach.com.

2. Two roles: your data vs. your contacts’ data

For your own account data (your email, login, campaigns, settings, billing) we act as the controller. For the contact lists you upload and the emails you send through them, you are the controller and we act as your processor — we process those personal data only on your documented instructions to run your campaigns. A Data Processing Agreement (Section 10) governs that role.

3. What we collect

  • Account: name, email, hashed password (or Google/Microsoft sign-in identifier), language and app preferences.
  • Mailbox connection: when you connect Gmail or Outlook we receive your address and OAuth tokens with the minimum scopes needed to send your campaigns and read delivery-status/bounce messages. Tokens are encrypted at rest.
  • Campaign content: the sequences you write or generate, sender settings and signatures.
  • Contacts you import: the fields in your CSV/paste (email, name, company, position, custom columns).
  • Delivery records: per-message send status, bounces and unsubscribes — needed to stop mailing bad or opted-out addresses.
  • Technical: minimal server logs (IP, timestamp, error traces) for security and debugging.

We do not store or surface per-recipient open or click analytics. Messages may carry a tracking pixel and redirect links, but opening a message or following a link records nothing about the recipient; the redirect exists only so links in already-delivered mail keep working.

4. Why we process it, and the legal basis

  • To provide the service (create/send campaigns, connect mailboxes) — performance of our contract with you (GDPR Art. 6(1)(b)).
  • Security, abuse-prevention, deliverability (bounce/opt-out suppression, rate-limiting) — our legitimate interests (Art. 6(1)(f)).
  • Legal compliance (tax, lawful requests) — legal obligation (Art. 6(1)(c)).
  • Your contacts are processed on your instructions; you are responsible for having a lawful basis (e.g. legitimate interest for B2B outreach) and for honouring opt-outs.

5. Subprocessors we rely on

We use these vetted providers strictly to run the service. Each is bound by a data-processing agreement:

  • Supabase — database, authentication and storage (hosting region: US).
  • Cloudflare — application hosting, edge network and security (global).
  • Anthropic — AI generation of your sequence copy (US). Prompts are sent to generate copy; they are not used to train models.
  • Google — Gmail API for sending and bounce/reply detection, when you connect a Google mailbox (US).
  • Microsoft — Outlook / Microsoft Graph API for sending, when you connect an Outlook mailbox (US).
  • Resend — our own transactional/notification emails to you (US).
  • Bouncify — optional address validation before sending (only if you enable it).

An up-to-date subprocessor list is available on request; we will give notice before adding a new one.

6. International transfers

Some subprocessors are located in the United States. Where personal data of individuals in the EEA/UK is transferred, we rely on the European Commission’s Standard Contractual Clauses (SCC) and the UK IDTA/Addendum, together with the providers’ supplementary safeguards, as the transfer mechanism.

7. How long we keep it

  • Account & campaign data: for as long as your account is active.
  • After you delete your account: erased from live systems promptly and from backups within 30 days.
  • Suppression records (unsubscribes/bounces): kept as long as needed to keep honouring opt-outs.
  • Minimal logs: 90 days, then deleted or anonymised.

8. Your rights

Under GDPR you can request access, rectification, erasure, restriction, portability and object to processing. You can delete your account and all its data yourself in Settings, or email hello@meowreach.com. You may also lodge a complaint with your local supervisory authority.

9. Security

Mailbox tokens are encrypted at rest, traffic is encrypted in transit (TLS), access is scoped by row-level security so you only ever see your own data, and signatures/inputs are sanitised. No system is perfectly secure, but we design for least-privilege and fail-closed behaviour.

10. Data Processing Agreement (DPA)

Because Meowreach processes the personal data of the contacts you upload on your behalf, we make a DPA available incorporating the SCC. If you require a signed DPA, email hello@meowreach.com.

11. Cookies

We use only the strictly-necessary cookies/local storage needed to keep you signed in and remember your app preferences. We do not use third-party advertising or cross-site tracking cookies.

12. Changes

We’ll post any material change here and update the date above; significant changes will be notified by email.