legal
Privacy Policy
Last updated: August 6, 2026
This Privacy Policy explains how Reachpad (“Reachpad,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information when you use our website at reachpad.dev, the Reachpad developer collaboration platform, our applications, APIs, integrations, and related services, and support, communications, and other interactions with Reachpad. Together, these are referred to as the “Services.”
Reachpad is based in the United States, and the Services are intended primarily for individuals and organizations located in the United States.
1. Information We Collect
The information we collect depends on how you interact with the Services.
A. Account and Profile Information
When you create or use an account, we may collect:
- Your name;
- Email address;
- Username;
- Profile image;
- Organization or team name;
- Job title or role;
- Authentication identifiers;
- Account preferences; and
- Information associated with your workspace or organization.
If you sign in through an identity provider, we may receive information that the provider makes available to us based on your settings and authorization.
B. Billing and Transaction Information
If you purchase a paid subscription, we may collect:
- Billing name and address;
- Subscription plan;
- Transaction history;
- Payment status; and
- Limited payment-method information, such as card type and the last four digits of a payment card.
Payments are processed by a third-party payment processor. Reachpad does not directly store complete payment-card numbers or card security codes.
C. Customer Content
The Services allow users and organizations to submit, connect, process, and collaborate on software-development materials. “Customer Content” may include:
- Source code and code snippets;
- Files and repository contents;
- Repository names and metadata;
- Commits, branches, pull requests, issues, and worktrees;
- Developer tasks, comments, messages, and collaboration activity;
- Agent prompts, instructions, responses, and outputs;
- Terminal output, command output, build results, and error messages;
- Uploaded files and other materials; and
- Information received through integrations that you connect to Reachpad.
Customer Content may contain personal information, confidential information, trade secrets, or other information selected by you or your organization. You are responsible for ensuring that you have the rights and permissions necessary to submit Customer Content to the Services.
D. Integration Information
When you connect Reachpad to a source-control platform, identity provider, developer tool, or other third-party service, we may receive:
- Your account identifier with that service;
- The names of accessible organizations, projects, or repositories;
- Repository and project metadata;
- Permissions and authorization information;
- Access tokens or similar credentials used to maintain the integration; and
- Content that you authorize Reachpad to access.
The information available to Reachpad depends on the integration, the permissions requested, and the permissions you approve. You may disconnect an integration through the applicable Reachpad account or workspace settings. Disconnecting an integration prevents future access through that integration but may not automatically delete information previously imported into Reachpad.
E. Usage, Device, and Log Information
When you access the Services, we may automatically collect:
- Internet Protocol address;
- Browser type and version;
- Device and operating-system information;
- Approximate location derived from an IP address;
- Pages, screens, and features viewed;
- Referring pages;
- Dates and times of access;
- Session and account identifiers;
- Clicks and other interactions;
- API requests and response information;
- Application performance information;
- Crash reports;
- Security events; and
- Diagnostic and error logs.
We use this information to operate, secure, troubleshoot, and understand the use of the Services.
F. Cookies and Similar Technologies
We and our service providers may use cookies, local storage, software development kits, and similar technologies to keep users signed in, remember settings, protect accounts and prevent abuse, measure website and product usage, diagnose performance problems, and understand how users interact with the Services.
Reachpad does not use cookies to sell personal information or for cross-context behavioral advertising. You can control cookies through your browser settings. Disabling necessary cookies may prevent parts of the Services from functioning correctly.
G. Communications and Support
When you contact us, participate in a product interview, respond to a survey, or request support, we may collect your contact information, the contents of your communication, screenshots, files, or logs you provide, support history, and other information you choose to provide.
2. How We Use Information
We may use information to:
- Create, authenticate, and administer accounts;
- Provide developer collaboration and workspace functionality;
- Connect and maintain integrations authorized by users;
- Process Customer Content at a user’s direction;
- Run requested agent operations and return outputs;
- Enable collaboration between users and teammates;
- Process subscriptions and payments;
- Communicate about accounts, transactions, security, and service updates;
- Respond to questions and provide customer support;
- Monitor the reliability and performance of the Services;
- Debug errors and resolve technical problems;
- Detect, investigate, and prevent fraud, abuse, and security incidents;
- Enforce our agreements and acceptable-use requirements;
- Analyze product usage and improve the Services;
- Develop new features;
- Comply with legal obligations; and
- Protect the rights, safety, and property of Reachpad, our users, and others.
We may create aggregated or de-identified information that cannot reasonably be used to identify an individual or organization. We may use and disclose aggregated or de-identified information for product analytics, research, security, service improvement, and other lawful purposes.
3. Paid Customer Data
For customers using a paid Reachpad plan, Reachpad does not sell, rent, license, or otherwise commercialize Customer Content. Paid Customer Content includes source code, repositories, files, prompts, instructions, agent responses and outputs, developer communications, terminal output, and other content submitted to or generated through the Services.
Reachpad does not use paid Customer Content:
- For advertising or marketing;
- To create advertising profiles;
- For data-brokerage purposes;
- To sell datasets or insights to third parties;
- To train or fine-tune generalized artificial-intelligence models; or
- To develop products or services unrelated to the Services purchased by the customer.
We process paid Customer Content only as reasonably necessary to provide features requested by the customer, execute customer-authorized agent operations, maintain, secure, and troubleshoot the Services, prevent fraud, abuse, and security incidents, provide customer support, comply with applicable law, enforce our agreements, or follow the customer’s documented instructions.
We may provide Customer Content to service providers that help us operate the Services, including hosting, storage, monitoring, authentication, and artificial-intelligence infrastructure providers. These providers may process Customer Content only to provide services to Reachpad and may not use it for their own advertising, data-sale, or generalized model-training purposes.
This section does not prevent Reachpad from processing account information, billing information, service usage information, or technical telemetry as necessary to operate, secure, maintain, and improve the Services. Reachpad may also use aggregated or de-identified usage information that does not identify a customer, reveal Customer Content, or reasonably permit the information to be associated with a particular individual or organization.
4. Customer Content and Artificial Intelligence
Some Reachpad features may use artificial-intelligence models or automated systems to process Customer Content and generate requested outputs. To provide these features, Reachpad may transmit relevant portions of Customer Content, including prompts, code, files, contextual information, and instructions, to infrastructure providers or artificial-intelligence service providers acting on our behalf.
Reachpad does not use Customer Content to train or fine-tune generalized artificial-intelligence models. This applies to Customer Content from both free and paid accounts. Where Customer Content is sent to an artificial-intelligence provider to perform a user-requested operation, Reachpad uses available contractual and technical controls intended to prevent the provider from using that content for generalized model training, advertising, data sale, or unrelated purposes.
Automated outputs may be inaccurate, incomplete, insecure, or unsuitable for a particular use. Users are responsible for reviewing outputs before relying on, executing, merging, deploying, or distributing them.
5. How We Disclose Information
We may disclose information in the following circumstances.
A. Service Providers
We may provide information to vendors that perform services on our behalf, including providers of cloud computing and hosting, database and file storage, authentication and identity management, payment processing, email delivery, customer support, product analytics, application monitoring and error reporting, security and fraud prevention, artificial-intelligence inference, and other technical infrastructure. These providers may access information only as reasonably necessary to perform services for Reachpad and subject to applicable contractual restrictions.
B. Your Organization and Workspace
If you use the Services through an organization, employer, team, or shared workspace, administrators of that workspace may be able to:
- Access account information;
- Manage workspace membership;
- Configure permissions and integrations;
- View activity associated with the workspace;
- Access or control Customer Content;
- Export information; and
- Suspend or delete accounts associated with the workspace.
Your organization’s privacy practices are governed by its own policies and agreements.
C. User-Directed Integrations and Actions
We disclose information when you direct us to interact with a third-party service, share content with another user, invite a collaborator, publish content, or otherwise perform an action that requires disclosure. Information sent to a third-party service is also subject to that service’s privacy policy and terms.
D. Legal and Safety Reasons
We may disclose information when we reasonably believe disclosure is necessary to comply with applicable law, regulation, legal process, or governmental request; enforce our agreements; detect, prevent, or investigate fraud, abuse, or security incidents; protect the rights, property, or safety of Reachpad, our users, or the public; or establish, exercise, or defend legal claims. Where legally permitted and appropriate, we may attempt to notify affected customers before disclosing their information in response to a legal demand.
E. Business Transactions
Information may be disclosed or transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction. We will take reasonable steps to require a recipient to handle personal information consistently with this Privacy Policy unless users are provided notice of different practices.
F. With Consent or at Your Direction
We may disclose information for another purpose with your consent or at your direction.
6. Sale and Sharing of Personal Information
Reachpad does not sell personal information for money. Reachpad does not share personal information for cross-context behavioral advertising and does not use Customer Content to target third-party advertisements. We have not knowingly sold or shared personal information belonging to individuals under 16 years old.
The disclosure of information to service providers for the operational purposes described in this Privacy Policy is not intended to constitute a sale of personal information.
7. Data Retention
We retain information only for as long as reasonably necessary to provide the Services, satisfy the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Our expected retention periods are:
- Account information: for as long as the account remains active and for up to 30 days after account deletion.
- Customer Content: until it is deleted by an authorized user, the applicable workspace is deleted, or the related account is terminated, subject to backup retention.
- Deleted Customer Content: removed from active production systems within approximately 30 days.
- System backups: retained on a rolling basis for up to 90 days before being overwritten or deleted.
- Application and diagnostic logs: generally retained for up to 90 days, unless a longer period is necessary to investigate an error, security event, or abuse.
- Security and audit records: retained for up to 12 months, or longer where reasonably necessary for security or legal purposes.
- Support communications: retained for up to 24 months after the request is resolved.
- Billing, tax, and transaction records: retained for the period required by applicable tax, accounting, and financial laws.
Some information may be retained longer when necessary to comply with law, preserve evidence, prevent fraud or abuse, enforce agreements, or resolve disputes. Deleting an account may not immediately remove information from encrypted backups. Backup information will be removed according to our normal backup-rotation process and will not be restored to active systems except when required for disaster recovery, security, or legal purposes.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure. These safeguards may include encryption of information in transit, authentication and access controls, restrictions on employee and contractor access, logging and monitoring, secure software-development practices, infrastructure and network protections, vendor review procedures, and incident-response processes.
No system or method of electronic transmission is completely secure. We cannot guarantee that information will never be accessed, used, or disclosed without authorization. You are responsible for protecting your account credentials, maintaining the security of connected integrations, and notifying us promptly of suspected unauthorized access.
9. Your Choices and Privacy Rights
Depending on where you live and whether an applicable privacy law covers Reachpad, you may have the right to:
- Request access to personal information we maintain about you;
- Request correction of inaccurate information;
- Request deletion of personal information;
- Receive a portable copy of certain information;
- Opt out of certain processing activities;
- Limit certain uses of sensitive personal information;
- Appeal the denial of a privacy request; and
- Receive equal service without unlawful discrimination for exercising a privacy right.
You may also update certain account information through the Services, disconnect integrations, delete Customer Content when the applicable feature permits, unsubscribe from promotional emails by following the instructions in the email, and control cookies through your browser settings.
To submit a privacy request, contact us at hello@reachpad.dev. Please describe your request and identify the account involved. We may need to verify your identity before processing a request. We will use information provided for verification only to verify and respond to the request.
An authorized agent may submit a request where permitted by law. We may request evidence of the agent’s authority and may also require the individual to verify their identity directly with us. We may deny or limit a request where permitted by law, including where we cannot verify identity, the information is subject to an exception, or fulfilling the request would adversely affect another person’s rights.
Organization-Controlled Information
When Reachpad processes information on behalf of an organization customer, that organization may control the relevant Customer Content. In those circumstances, you should first direct your request to the organization or workspace administrator. We will assist organization customers with privacy requests as required by our agreements and applicable law.
10. Do Not Track and Global Privacy Control
Some browsers offer a “Do Not Track” setting. Because there is not currently a universally accepted standard governing these signals, the Services do not respond to traditional Do Not Track signals. Where legally required and technically applicable, we recognize supported browser-based opt-out preference signals, such as Global Privacy Control. Because Reachpad does not sell personal information or share it for cross-context behavioral advertising, an opt-out signal should not materially change our current practices.
11. Third-Party Services
The Services may contain links to, integrate with, or allow access to third-party websites and services. Reachpad does not control the privacy, security, or data-handling practices of third parties acting independently from Reachpad. You should review their privacy policies before providing information or enabling an integration. This Privacy Policy does not apply to information processed independently by third parties.
12. Children’s Privacy
The Services are not directed to children under 13 years old, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without legally valid authorization, we will take reasonable steps to delete it. A parent or guardian who believes a child under 13 has provided information to Reachpad may contact us at hello@reachpad.dev.
13. United States Service
Reachpad is operated from the United States, and information may be processed and stored in the United States and in other locations where our service providers operate. The Services are not presently marketed or offered specifically to residents of the European Economic Area, United Kingdom, or Switzerland. Accessing the Services from outside the United States may result in information being transferred to and processed in the United States, where privacy laws may differ from those in your location.
14. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes to the Services, our practices, technologies, vendors, or applicable law. When we update the policy, we will revise the “Last updated” date. If a change materially affects how we use personal information, we may provide additional notice through the Services, by email, or on our website. Changes become effective when the updated Privacy Policy is posted unless a later date is stated.
15. Contact Us
For questions about this Privacy Policy, privacy requests, or concerns about how Reachpad handles information, contact us at:
- Reachpad
- Email: hello@reachpad.dev
- Website: reachpad.dev