Legal

Privacy Policy

Effective Date: June 13, 2026  ·  Last Updated: June 13, 2026

At a Glance

This summary is provided for readability. The full policy below governs in the event of any inconsistency.

1. Who We Are and How to Contact Us

Reach ("Reach," "we," "us," or "our") is an iOS application and website operated by:

UniCen LLC, a California limited liability company

For all privacy-related requests, including questions about this policy or to exercise your rights under U.S. state privacy laws, please contact us at the email address below. We respond to verified requests within the timeframes required by applicable law (generally 45 days, with one permitted extension where lawful).

2. Scope of This Policy

This Privacy Policy describes how we collect, use, and share personal information about you — meaning information about you in your capacity as a user of the Reach app or a visitor to our website — when you:

This policy does not govern information that you record in Reach about other people (for example, names, addresses, notes, or other information you enter when documenting an outreach visit). When you use Reach on behalf of an organization (such as a non-profit, faith community, campaign, or community group), that organization is generally the controller of the information you record about third parties, and Reach acts as that organization's service provider. The handling of that information is governed by our Data Processing Addendum and your organization's own privacy practices. See Section 11 for more.

Reach is distributed only in the United States and is not intended for users located outside the United States.

3. Information We Collect

We collect the following categories of personal information. For California residents, Section 10.6 maps these to the statutory categories in Cal. Civ. Code § 1798.140(v).

3.1 Information you provide when you create an account

3.2 Information we receive from third-party sign-in providers

If you sign in using Apple or Google, we receive:

We do not receive your password or any other credentials from these providers.

3.3 Information we create about your account

3.4 Team and membership information

3.5 Subscription information

If you purchase a subscription to Reach Pro, we receive the following from Apple's StoreKit service:

We do not receive your payment card number, billing address, or any other payment credential. All payment processing is handled directly by Apple.

3.6 Device location (only with your permission)

If you grant location permission, we access your device's precise location while the Reach app is in use, in order to:

We request "When In Use" location authorization only. We do not access your location when the app is closed or running in the background.

Your device's precise location is used locally by the app to power the map experience and is not transmitted to or stored on our servers as a separate data record. If you drop a pin at a specific location, those pin coordinates are handled as described in Section 11.

Under California law, precise geolocation is treated as sensitive personal information. We use it only for the purposes described above — i.e., to provide the service you have reasonably requested — and not to infer any other characteristics about you.

3.7 Log and infrastructure data

Our hosting and authentication provider, Google Firebase, automatically logs limited technical information when your app communicates with our backend, including:

We use this information for security, to diagnose service problems, and to comply with law.

3.8 Website visits and contact form

When you visit reachfield.app:

Our website does not use advertising cookies, analytics trackers, or social media pixels.

3.9 What we do not collect

For clarity, Reach does not collect or use:

4. How We Use Information

We use the information described in Section 3 only for the following purposes:

  1. To operate and provide the service — to authenticate you, create and manage your account, sync your data across your devices, create and manage teams, and display the map and pin features.
  2. To process transactions — to validate your subscription with Apple and unlock paid features.
  3. To communicate with you — to respond to your questions and contact form submissions, send account-related notices (for example, password resets), and notify you of material changes to this policy.
  4. To maintain security and integrity — to detect and prevent fraud, abuse, unauthorized access, and violations of our Terms of Service.
  5. To comply with law — to meet our obligations under applicable law and to respond to lawful requests from public authorities.
  6. To improve the service — to understand in aggregate how Reach is used and to fix bugs, always using the minimum information necessary.

We do not use your personal information to train any artificial intelligence or machine learning model.

5. How We Share Information

We share personal information only with the limited service providers listed below, and only as necessary for them to perform services for us. We do not sell your personal information. We do not share it for cross-context behavioral advertising.

5.1 Service providers and sub-processors

Provider Purpose Location of Processing
Google LLC (Firebase Authentication, Cloud Firestore, App Check) Account authentication, database hosting, data sync, anti-abuse attestation United States
Google LLC (Google Sign-In) Optional third-party sign-in United States
Apple Inc. (Sign in with Apple, StoreKit, App Store, App Attest) Optional third-party sign-in, subscription processing, app distribution, anti-abuse attestation United States
Porkbun LLC Website hosting for reachfield.app United States
Web3Forms Contact form delivery United States
Intuition Machines, Inc. (hCaptcha) Bot prevention on our contact form United States

Each of these providers is contractually bound to use information we share only as necessary to provide services to us and to maintain commercially reasonable security practices. Their handling of information they receive directly from you (for example, when you complete the Google or Apple sign-in flow, or when hCaptcha runs in your browser) is subject to their own privacy policies.

5.2 Legal and protective disclosures

We may disclose information when we believe in good faith that disclosure is necessary to:

Where lawful and reasonable, we will provide notice to affected users before making such a disclosure.

5.3 Business transfers

If UniCen LLC or the Reach service is involved in a merger, acquisition, asset sale, or similar transaction, personal information may be transferred as part of that transaction. We will provide notice and, where required, obtain consent before personal information becomes subject to a materially different privacy policy.

5.4 With your direction

We share information with others when you direct us to — for example, when you join a team, certain account information (your display name and role) becomes visible to that team's other members.

6. Location Data — Specific Disclosures

Because we handle precise device location, we make the following additional disclosures:

7. We Do Not Sell or Share Your Information for Advertising

Reach does not engage in any of the following activities:

Because we do not engage in these activities, there is no opt-out mechanism for them. Our app and website do not respond to Do Not Track signals or Global Privacy Control signals differently, because we do not engage in the tracking or data sales these signals are designed to prevent.

8. How Long We Keep Information

We retain personal information only as long as necessary for the purposes described in this policy. Our specific retention practices are:

Category Retention Period
Account records (email, name, Firebase UID, timestamps) For the life of your account, plus 30 days after deletion
Team membership records For the life of the membership, plus 30 days after you leave or the team is deleted
Location data processed for map display Not retained on our servers; processed only on your device
Subscription and transaction records 7 years after the transaction, to comply with tax and accounting obligations
Log and infrastructure data (IP addresses, etc.) Up to 90 days
Contact form submissions and support correspondence Up to 24 months after the matter is resolved
Backup copies of our database Purged on a 90-day rolling window

Inactive accounts: If you do not sign in for 24 months, we will send a deletion notice to the email on file and delete your account 30 days later unless you sign in or contact us.

Account deletion: When you delete your account, we immediately remove it from active service. We then purge the underlying records from our database within 30 days and from backup copies within 90 days, except where retention is required by law (for example, subscription and transaction records, which are retained for the period noted above).

9. How We Protect Information

We maintain commercially reasonable administrative, technical, and physical safeguards designed to protect the personal information we handle, including:

No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If we become aware of a security breach affecting your personal information, we will notify you and relevant authorities as required by applicable state law.

10. Your Privacy Rights

Depending on where you live in the United States, you may have rights under state privacy law — including in California, Colorado, Connecticut, Texas, Virginia, Oregon, Montana, and other states with comprehensive privacy statutes. We honor the rights below for all U.S. users, regardless of state of residence, unless otherwise noted.

10.1 Rights available to you

10.2 How to make a request

Email us at legal@reachfield.app with the subject line "Privacy Request." Please describe the request and include the email address associated with your Reach account. You may also delete your account directly in the app.

10.3 Verification

To protect your information, we will verify your identity before acting on a request. For most requests, signing in to your account and confirming the request from your account email is sufficient. For deletion or sensitive requests, we may ask for additional information.

10.4 Authorized agents

You may designate an authorized agent to submit a request on your behalf. We will ask for written authorization signed by you and may also ask you to verify your identity directly with us.

10.5 Response timeline

We respond to verified requests within 45 days. If we need more time, we will let you know and may extend by up to an additional 45 days where permitted by law.

10.6 California — categories of personal information

For California residents, the table below maps our practices to the categories defined in Cal. Civ. Code § 1798.140(v). It reflects our practices over the 12 months preceding the "Last Updated" date.

Category Examples Collected
A. Identifiers Name, email address, Firebase user ID, IP address YES
B. Customer records (Cal. Civ. Code § 1798.80(e)) Name, email address YES
C. Protected classification characteristics Race, gender, age, religion NO
D. Commercial information Subscription tier and purchase history (via Apple) YES
E. Biometric information Fingerprints, faceprints NO
F. Internet or network activity App interaction logs, website server logs YES
G. Geolocation data Precise device location (with permission, processed on device) YES
H. Audio, electronic, visual, or similar information Profile photo URL (only if provided via Google Sign-In) YES
I. Professional or employment information Job title, employer NO
J. Education information Student records NO
K. Inferences Profiles or predictions about preferences or characteristics NO
L. Sensitive personal information Precise geolocation (see Section 3.6); account login credentials (hashed) YES

We collect each "YES" category directly from you or from your device, use it for the purposes in Section 4, disclose it only to the service providers in Section 5.1, and retain it per the schedule in Section 8. We do not sell or share any category, and we have not done so in the preceding 12 months. Category L is used solely to provide the services you request, which means the right to limit its use is not triggered.

10.7 California — "Shine the Light"

California Civil Code § 1798.83 permits California residents to request information about disclosure of personal information to third parties for those parties' direct marketing purposes. We do not disclose personal information to any third party for direct marketing purposes.

11. Information You Record About Other People

A core function of Reach is to let you record information about the homes you visit and the people you speak with during outreach — for example, pin locations, residence type, response information, and free-text notes.

When you use Reach on behalf of an organization (such as a non-profit, faith community, campaign, or community group), that organization is generally the controller of the information you record about third parties, and Reach acts as a service provider / processor on the organization's behalf. Our handling of that information is governed by the Reach Data Processing Addendum that applies to your team.

You should not enter the following kinds of information into Reach without an appropriate legal basis and a direct relationship with the person concerned:

It is your responsibility — and your organization's responsibility — to ensure that the information you record in Reach is lawful to collect and retain in your jurisdiction. We provide tools to help you meet that responsibility, but we are not the controller of the information you enter about third parties.

If you are a third party (for example, a resident who was visited by a Reach user and whose information may have been recorded), please contact the organization that visited you first. If you do not know the organization, you may contact us at legal@reachfield.app and we will use reasonable efforts to help identify the relevant organization and route your request.

12. Children's Privacy

Reach is intended for users aged 18 and older and is not directed to children. Our Terms of Service require account holders to be at least 18 years old, and we do not design, market, or promote the Service to anyone under 18.

We do not knowingly collect personal information from children under 13. This is a firm commitment: consistent with the Children's Online Privacy Protection Act, if we become aware that we have collected personal information from a child under 13, we will delete it promptly.

Because the Service is not directed to minors and we do not verify the age of every user, it is possible that a person under 18 could create an account contrary to our Terms. If we become aware that an account belongs to a person under 18, we will take appropriate steps, which may include deactivating the account and deleting the associated personal information. If you are a parent or guardian and believe a person under 18 has provided personal information to us, please contact us at legal@reachfield.app and we will address it promptly.

A note on future features. As described in Section 14, we may in the future develop features intended for younger users, such as youth-ministry tools. We will not direct the Service to, or knowingly collect personal information from, children under 13 unless and until we have implemented the verifiable parental consent mechanisms and other protections required by the Children's Online Privacy Protection Act, and have updated this Privacy Policy accordingly.

13. Third-Party Sign-In Providers

If you choose to sign in using Apple or Google, your use of that sign-in flow is also subject to the privacy policy of the provider:

We encourage you to review those policies.

14. Future Features

We are actively developing Reach and may add features that involve new categories of information or new processing activities, including (but not limited to):

We will not begin any of these new processing activities before updating this Privacy Policy and providing notice to users. Where the law requires it, we will also obtain consent before processing sensitive personal information.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will post the revised policy at the link where you first accessed it and update the "Last Updated" date at the top. If the changes are material, we will also provide notice in the app or by email to the address on file.

Your continued use of Reach after the effective date of an updated policy constitutes acceptance of the updated policy, except where additional consent is required by law.

16. Contact

For any questions, concerns, or privacy requests, please contact:

legal@reachfield.app

This policy is provided for compliance with applicable U.S. state privacy laws, the Federal Trade Commission Act, the Children's Online Privacy Protection Act, and the Apple App Store Review Guidelines, in effect as of the "Last Updated" date above.