At a Glance
This summary is provided for readability. The full policy below governs in the event of any inconsistency.
- Who we are: Reach is operated by UniCen LLC, a California limited liability company.
- What this covers: the Reach iOS application and our website at reachfield.app.
- What we collect about you: your account information, the email address and name you provide, limited device and log information, your subscription status, and — with your permission — your device's precise location while you use the app.
- Why we collect it: to operate the app, authenticate you, sync your data across your devices, process your subscription, keep the service secure, and comply with law.
- Who we share it with: only the service providers needed to run the service (Google Firebase, Google Sign-In, Apple, and our website vendors), and only as necessary to operate or comply with law.
- What we don't do: we do not sell your personal information. We do not share it for cross-context behavioral advertising. We do not use it to track you across other apps or websites.
- You control your data: you can access, correct, delete, or export your information at any time by contacting us or using in-app controls.
- Important: Reach lets you record information about other people (for example, when you drop a pin after an outreach visit). How that information is handled is explained in Section 11 and is governed primarily by our Data Processing Addendum with your organization, not by this Privacy Policy.
1. Who We Are and How to Contact Us
Reach ("Reach," "we," "us," or "our") is an iOS application and website operated by:
UniCen LLC, a California limited liability company
For all privacy-related requests, including questions about this policy or to exercise your rights under U.S. state privacy laws, please contact us at the email address below. We respond to verified requests within the timeframes required by applicable law (generally 45 days, with one permitted extension where lawful).
2. Scope of This Policy
This Privacy Policy describes how we collect, use, and share personal information about you — meaning information about you in your capacity as a user of the Reach app or a visitor to our website — when you:
- Download and use the Reach iOS application
- Visit our website at reachfield.app, or any site of ours that links to this policy
- Contact us by email or through our website's contact form
This policy does not govern information that you record in Reach about other people (for example, names, addresses, notes, or other information you enter when documenting an outreach visit). When you use Reach on behalf of an organization (such as a non-profit, faith community, campaign, or community group), that organization is generally the controller of the information you record about third parties, and Reach acts as that organization's service provider. The handling of that information is governed by our Data Processing Addendum and your organization's own privacy practices. See Section 11 for more.
Reach is distributed only in the United States and is not intended for users located outside the United States.
3. Information We Collect
We collect the following categories of personal information. For California residents, Section 10.6 maps these to the statutory categories in Cal. Civ. Code § 1798.140(v).
3.1 Information you provide when you create an account
- Email address (required)
- Display name (required)
- Password (if you sign up with email/password; stored only in hashed form by Firebase Authentication — we never see or store your plaintext password)
3.2 Information we receive from third-party sign-in providers
If you sign in using Apple or Google, we receive:
- A unique user identifier from the provider
- Your name (if you choose to share it)
- Your email address (or, if you use Apple's "Hide My Email" feature, a private relay address that forwards to your real email)
- Your profile photo URL (Google only, if available)
We do not receive your password or any other credentials from these providers.
3.3 Information we create about your account
- A unique Reach user ID (your Firebase UID)
- Your account creation timestamp
- Your most recent activity timestamp
- The authentication method you used (email, Apple, Google)
3.4 Team and membership information
- The teams you create or join
- Your role within each team (Owner, Team Lead, or Member)
- The timestamp of when you joined each team
- Team-generated join codes you use
3.5 Subscription information
If you purchase a subscription to Reach Pro, we receive the following from Apple's StoreKit service:
- The product identifier of the subscription you purchased
- Your subscription tier (Free or Pro)
- Your subscription expiration date
- The timestamp of our last verification with the App Store
We do not receive your payment card number, billing address, or any other payment credential. All payment processing is handled directly by Apple.
3.6 Device location (only with your permission)
If you grant location permission, we access your device's precise location while the Reach app is in use, in order to:
- Show your current position on the map
- Help you drop pins at or near your current location
- Provide accurate address lookups
We request "When In Use" location authorization only. We do not access your location when the app is closed or running in the background.
Your device's precise location is used locally by the app to power the map experience and is not transmitted to or stored on our servers as a separate data record. If you drop a pin at a specific location, those pin coordinates are handled as described in Section 11.
Under California law, precise geolocation is treated as sensitive personal information. We use it only for the purposes described above — i.e., to provide the service you have reasonably requested — and not to infer any other characteristics about you.
3.7 Log and infrastructure data
Our hosting and authentication provider, Google Firebase, automatically logs limited technical information when your app communicates with our backend, including:
- Your IP address (used for rate-limiting and abuse prevention)
- Device type, operating system version, and app version
- Timestamps of requests to our backend
- Authentication tokens (session tokens; not credentials)
We use this information for security, to diagnose service problems, and to comply with law.
3.8 Website visits and contact form
When you visit reachfield.app:
- Our static hosting provider automatically logs standard technical information (IP address, browser type, pages requested, timestamps) for security and operational purposes.
- If you submit our contact form, we collect the name, email address, and message contents you provide, which are delivered to us by our form-processing vendor.
- Our contact form is protected by hCaptcha, a bot-prevention service, which may set a cookie or use similar technology solely to distinguish humans from automated traffic. hCaptcha's processing is described in its own privacy policy at https://www.hcaptcha.com/privacy.
Our website does not use advertising cookies, analytics trackers, or social media pixels.
3.9 What we do not collect
For clarity, Reach does not collect or use:
- Advertising identifiers (IDFA)
- Contacts, photos, microphone, camera, or health data
- Push notification tokens (the app does not currently send push notifications)
- Cross-app or cross-website tracking data
- Firebase Crashlytics crash reports (this product is not enabled)
- Firebase Analytics events (this product is not enabled)
4. How We Use Information
We use the information described in Section 3 only for the following purposes:
- To operate and provide the service — to authenticate you, create and manage your account, sync your data across your devices, create and manage teams, and display the map and pin features.
- To process transactions — to validate your subscription with Apple and unlock paid features.
- To communicate with you — to respond to your questions and contact form submissions, send account-related notices (for example, password resets), and notify you of material changes to this policy.
- To maintain security and integrity — to detect and prevent fraud, abuse, unauthorized access, and violations of our Terms of Service.
- To comply with law — to meet our obligations under applicable law and to respond to lawful requests from public authorities.
- To improve the service — to understand in aggregate how Reach is used and to fix bugs, always using the minimum information necessary.
We do not use your personal information to train any artificial intelligence or machine learning model.
5. How We Share Information
We share personal information only with the limited service providers listed below, and only as necessary for them to perform services for us. We do not sell your personal information. We do not share it for cross-context behavioral advertising.
5.1 Service providers and sub-processors
| Provider | Purpose | Location of Processing |
|---|---|---|
| Google LLC (Firebase Authentication, Cloud Firestore, App Check) | Account authentication, database hosting, data sync, anti-abuse attestation | United States |
| Google LLC (Google Sign-In) | Optional third-party sign-in | United States |
| Apple Inc. (Sign in with Apple, StoreKit, App Store, App Attest) | Optional third-party sign-in, subscription processing, app distribution, anti-abuse attestation | United States |
| Porkbun LLC | Website hosting for reachfield.app | United States |
| Web3Forms | Contact form delivery | United States |
| Intuition Machines, Inc. (hCaptcha) | Bot prevention on our contact form | United States |
Each of these providers is contractually bound to use information we share only as necessary to provide services to us and to maintain commercially reasonable security practices. Their handling of information they receive directly from you (for example, when you complete the Google or Apple sign-in flow, or when hCaptcha runs in your browser) is subject to their own privacy policies.
5.2 Legal and protective disclosures
We may disclose information when we believe in good faith that disclosure is necessary to:
- Comply with a subpoena, court order, warrant, or other lawful process
- Enforce our Terms of Service or other agreements
- Protect the rights, property, or safety of Reach, our users, or the public
- Investigate or prevent fraud, abuse, or illegal activity
Where lawful and reasonable, we will provide notice to affected users before making such a disclosure.
5.3 Business transfers
If UniCen LLC or the Reach service is involved in a merger, acquisition, asset sale, or similar transaction, personal information may be transferred as part of that transaction. We will provide notice and, where required, obtain consent before personal information becomes subject to a materially different privacy policy.
5.4 With your direction
We share information with others when you direct us to — for example, when you join a team, certain account information (your display name and role) becomes visible to that team's other members.
6. Location Data — Specific Disclosures
Because we handle precise device location, we make the following additional disclosures:
- We request location access only while the app is in use. We do not access location when the app is backgrounded or closed.
- You may revoke location permission at any time in Settings → Privacy & Security → Location Services → Reach.
- If you revoke location permission, the map and pin features will continue to function, but features that require your current location (such as centering the map or auto-filling your current address) will not.
- We do not use your location for advertising, profiling, or analytics.
7. We Do Not Sell or Share Your Information for Advertising
Reach does not engage in any of the following activities:
- Selling personal information for monetary or other valuable consideration
- Sharing personal information for cross-context behavioral advertising (as that term is defined under the California Consumer Privacy Act)
- Targeted advertising based on your activity across non-affiliated apps or websites (as defined under the Texas Data Privacy and Security Act and similar state laws)
- Processing personal information for profiling that produces legal or similarly significant effects about you
Because we do not engage in these activities, there is no opt-out mechanism for them. Our app and website do not respond to Do Not Track signals or Global Privacy Control signals differently, because we do not engage in the tracking or data sales these signals are designed to prevent.
8. How Long We Keep Information
We retain personal information only as long as necessary for the purposes described in this policy. Our specific retention practices are:
| Category | Retention Period |
|---|---|
| Account records (email, name, Firebase UID, timestamps) | For the life of your account, plus 30 days after deletion |
| Team membership records | For the life of the membership, plus 30 days after you leave or the team is deleted |
| Location data processed for map display | Not retained on our servers; processed only on your device |
| Subscription and transaction records | 7 years after the transaction, to comply with tax and accounting obligations |
| Log and infrastructure data (IP addresses, etc.) | Up to 90 days |
| Contact form submissions and support correspondence | Up to 24 months after the matter is resolved |
| Backup copies of our database | Purged on a 90-day rolling window |
Inactive accounts: If you do not sign in for 24 months, we will send a deletion notice to the email on file and delete your account 30 days later unless you sign in or contact us.
Account deletion: When you delete your account, we immediately remove it from active service. We then purge the underlying records from our database within 30 days and from backup copies within 90 days, except where retention is required by law (for example, subscription and transaction records, which are retained for the period noted above).
9. How We Protect Information
We maintain commercially reasonable administrative, technical, and physical safeguards designed to protect the personal information we handle, including:
- Encryption of data in transit using TLS
- Encryption of data at rest in Google Cloud infrastructure
- Role-based access controls to our backend and strict permissions in our database security rules
- App-integrity attestation (Apple App Attest via Firebase App Check) to ensure only legitimate copies of the app can reach our backend
- Use of hashed passwords (never plaintext)
- Multi-factor authentication on administrative accounts
- Regular review of third-party dependencies for security issues
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If we become aware of a security breach affecting your personal information, we will notify you and relevant authorities as required by applicable state law.
10. Your Privacy Rights
Depending on where you live in the United States, you may have rights under state privacy law — including in California, Colorado, Connecticut, Texas, Virginia, Oregon, Montana, and other states with comprehensive privacy statutes. We honor the rights below for all U.S. users, regardless of state of residence, unless otherwise noted.
10.1 Rights available to you
- Right to know / access. You may request confirmation of whether we process your personal information and obtain a copy of the specific pieces we hold.
- Right to correct. You may request that we correct inaccurate personal information we hold about you.
- Right to delete. You may request that we delete your personal information, subject to the legal exceptions described in Section 8.
- Right to data portability. You may request a copy of your personal information in a portable, commonly used format.
- Right to opt out of sale, sharing, and targeted advertising. As noted in Section 7, we do not engage in these activities, so no action by you is needed.
- Right to limit use of sensitive personal information (California). Because we use precise geolocation only to provide the service you requested, this right is not triggered in the ordinary course of using Reach.
- Right of no retaliation / non-discrimination. We will not deny you service, charge you a different price, or provide a different level of quality because you exercised a privacy right.
- Right to appeal (available in some states, including Texas, Virginia, Colorado, Connecticut, and others). If we decline a request in whole or in part, you may appeal by replying to our response, and a human will review the appeal.
10.2 How to make a request
Email us at legal@reachfield.app with the subject line "Privacy Request." Please describe the request and include the email address associated with your Reach account. You may also delete your account directly in the app.
10.3 Verification
To protect your information, we will verify your identity before acting on a request. For most requests, signing in to your account and confirming the request from your account email is sufficient. For deletion or sensitive requests, we may ask for additional information.
10.4 Authorized agents
You may designate an authorized agent to submit a request on your behalf. We will ask for written authorization signed by you and may also ask you to verify your identity directly with us.
10.5 Response timeline
We respond to verified requests within 45 days. If we need more time, we will let you know and may extend by up to an additional 45 days where permitted by law.
10.6 California — categories of personal information
For California residents, the table below maps our practices to the categories defined in Cal. Civ. Code § 1798.140(v). It reflects our practices over the 12 months preceding the "Last Updated" date.
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Name, email address, Firebase user ID, IP address | YES |
| B. Customer records (Cal. Civ. Code § 1798.80(e)) | Name, email address | YES |
| C. Protected classification characteristics | Race, gender, age, religion | NO |
| D. Commercial information | Subscription tier and purchase history (via Apple) | YES |
| E. Biometric information | Fingerprints, faceprints | NO |
| F. Internet or network activity | App interaction logs, website server logs | YES |
| G. Geolocation data | Precise device location (with permission, processed on device) | YES |
| H. Audio, electronic, visual, or similar information | Profile photo URL (only if provided via Google Sign-In) | YES |
| I. Professional or employment information | Job title, employer | NO |
| J. Education information | Student records | NO |
| K. Inferences | Profiles or predictions about preferences or characteristics | NO |
| L. Sensitive personal information | Precise geolocation (see Section 3.6); account login credentials (hashed) | YES |
We collect each "YES" category directly from you or from your device, use it for the purposes in Section 4, disclose it only to the service providers in Section 5.1, and retain it per the schedule in Section 8. We do not sell or share any category, and we have not done so in the preceding 12 months. Category L is used solely to provide the services you request, which means the right to limit its use is not triggered.
10.7 California — "Shine the Light"
California Civil Code § 1798.83 permits California residents to request information about disclosure of personal information to third parties for those parties' direct marketing purposes. We do not disclose personal information to any third party for direct marketing purposes.
11. Information You Record About Other People
A core function of Reach is to let you record information about the homes you visit and the people you speak with during outreach — for example, pin locations, residence type, response information, and free-text notes.
When you use Reach on behalf of an organization (such as a non-profit, faith community, campaign, or community group), that organization is generally the controller of the information you record about third parties, and Reach acts as a service provider / processor on the organization's behalf. Our handling of that information is governed by the Reach Data Processing Addendum that applies to your team.
You should not enter the following kinds of information into Reach without an appropriate legal basis and a direct relationship with the person concerned:
- Sensitive personal information (including information about religion, political views, health, immigration status, sexual orientation, or racial or ethnic origin)
- Information about children under 13
- Government identifiers (such as Social Security numbers)
- Financial account numbers
- Biometric data
It is your responsibility — and your organization's responsibility — to ensure that the information you record in Reach is lawful to collect and retain in your jurisdiction. We provide tools to help you meet that responsibility, but we are not the controller of the information you enter about third parties.
If you are a third party (for example, a resident who was visited by a Reach user and whose information may have been recorded), please contact the organization that visited you first. If you do not know the organization, you may contact us at legal@reachfield.app and we will use reasonable efforts to help identify the relevant organization and route your request.
12. Children's Privacy
Reach is intended for users aged 18 and older and is not directed to children. Our Terms of Service require account holders to be at least 18 years old, and we do not design, market, or promote the Service to anyone under 18.
We do not knowingly collect personal information from children under 13. This is a firm commitment: consistent with the Children's Online Privacy Protection Act, if we become aware that we have collected personal information from a child under 13, we will delete it promptly.
Because the Service is not directed to minors and we do not verify the age of every user, it is possible that a person under 18 could create an account contrary to our Terms. If we become aware that an account belongs to a person under 18, we will take appropriate steps, which may include deactivating the account and deleting the associated personal information. If you are a parent or guardian and believe a person under 18 has provided personal information to us, please contact us at legal@reachfield.app and we will address it promptly.
A note on future features. As described in Section 14, we may in the future develop features intended for younger users, such as youth-ministry tools. We will not direct the Service to, or knowingly collect personal information from, children under 13 unless and until we have implemented the verifiable parental consent mechanisms and other protections required by the Children's Online Privacy Protection Act, and have updated this Privacy Policy accordingly.
13. Third-Party Sign-In Providers
If you choose to sign in using Apple or Google, your use of that sign-in flow is also subject to the privacy policy of the provider:
- Apple: https://www.apple.com/legal/privacy/
- Google: https://policies.google.com/privacy
We encourage you to review those policies.
14. Future Features
We are actively developing Reach and may add features that involve new categories of information or new processing activities, including (but not limited to):
- Integration with voter file or party registration data
- Features designed for users under the age of 13, such as youth-ministry tools
- Features that involve sensitive outreach contexts, such as health-related or immigration-related support
- Advertising integrations
- An Android version of the application
We will not begin any of these new processing activities before updating this Privacy Policy and providing notice to users. Where the law requires it, we will also obtain consent before processing sensitive personal information.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the revised policy at the link where you first accessed it and update the "Last Updated" date at the top. If the changes are material, we will also provide notice in the app or by email to the address on file.
Your continued use of Reach after the effective date of an updated policy constitutes acceptance of the updated policy, except where additional consent is required by law.
16. Contact
For any questions, concerns, or privacy requests, please contact:
legal@reachfield.app
This policy is provided for compliance with applicable U.S. state privacy laws, the Federal Trade Commission Act, the Children's Online Privacy Protection Act, and the Apple App Store Review Guidelines, in effect as of the "Last Updated" date above.