Privacy Policy

Last updated: January 20, 2026

Introduction

FireReach ("we," "our," or "us") operates the service available at app.firereach.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use immediately.

Information We Collect

Account Information

When you create an account, we collect:

  • Full name and email address.
  • Account credentials (passwords are securely hashed using bcrypt).
  • Profile avatar and Google ID (if applicable).
  • Onboarding details such as company name, size, website, location, role, and business challenges.

Google OAuth and Gmail Data

When you connect your Google account, we request access to specific Google services. Specifically, we access:

  • Gmail Permissions: We request scopes (gmail.send, gmail.compose, gmail.modify, userinfo.email) to allow you to compose, modify, and send emails directly through our platform.
  • OAuth Tokens: We securely store access tokens and refresh tokens to maintain your connection.
  • Usage: We use these permissions solely to facilitate the email automation features you initiate. We do not use your email content for advertising purposes.

Contact and Research Data

  • Contact Information: We store contact details (names, emails, LinkedIn profiles) that you import or discover through our platform.
  • Research Data: We collect and process company research data (earnings reports, news, challenges) to help generate personalized outreach content.

Technical Data

We automatically collect:

  • Analytics: We use Google Analytics (GA4) to track usage metrics, page visits, and session duration to improve our Service.
  • Device Information: IP address, browser type, and operating system.
  • Usage Data: Credits used for research and discovery, and transaction history.

How We Use Your Information

We use collected data to:

  • Authenticate your account and maintain your session.
  • Provide AI-powered features, such as generating email drafts using Google Gemini (Generative AI).
  • Facilitate email sending and drafting via your connected Gmail account.
  • Display analytics on credit usage and operational limits.
  • Improve Service reliability, performance, and security.

Information Sharing and Disclosure

Service Providers

We may share data with third-party service providers who process information on our behalf:

  • Google Gemini: For generating email content and research summaries.
  • Google Analytics: For analyzing user behavior and app performance.
  • MongoDB: For secure database storage.

Legal Requirements

We may disclose your information if required by law to protect the rights, property, or safety of FireReach, our users, or others.

No Sale of Personal Data

We do not sell, rent, or trade your personal information or Google user data to third parties for monetary consideration.

Data Retention

We retain your account information and stored data (contacts, drafts, research) for as long as your account is active. You may disconnect your Google account at any time, which revokes our access to your Gmail. OAuth tokens are deleted upon account deletion or disconnection.

Data Security

We implement industry-standard security measures:

  • Encryption: Data is encrypted in transit (HTTPS/TLS) and passwords are hashed.
  • Secure Storage: OAuth tokens and sensitive keys are stored securely in our database.
  • Access Control: Access to data is restricted to authorized personnel and systems.

Your Choices and Rights

  • Disconnect Google Account: You can revoke FireReach's access to your Gmail account via your Google Account permissions or within our application settings.
  • Delete Data: Request deletion of your account and associated data by contacting support.
  • Cookies: You can manage cookie preferences in your browser. Note that authentication relies on secure cookies/tokens (fr_token).

Children's Privacy

The Service is not intended for users under the age of 13. We do not knowingly collect personal information from children.

International Data Transfers

Your information may be transferred to and processed in servers handling our database and AI services, which may be located outside your country of residence.

Changes to This Privacy Policy

We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.