your data,
your controls.
dreach is a local-first Mac app and autonomous messaging agent. It reads sources you connect, such as iMessage, Gmail, Slack, Calendar, Stripe, and meeting tools, so it can send first messages, follow up, handle one-to-one and group replies, and book meetings under the rules you choose.
The short version
local Mac data such as iMessage is read on your machine after you grant macOS permissions. Cloud systems store account metadata, billing and entitlement state, encrypted OAuth tokens for hosted integrations, hosted integration records when enabled, product telemetry, and selected context only when a hosted AI or cloud automation feature needs it.
we do not sell your data, share it with advertisers, or train a shared AI model on your messages. Local LLM generation sends prompt content to local Ollama; BYOK cloud generation sends selected context to the provider you configure.
What we collect
Account data
- your email, name, workspace identifiers, member roles, and sign-in state
- OAuth tokens you grant for connected services, encrypted at rest
- billing details, plan state, invoices, and payments handled with Stripe
Product and automation data
- sources connected, features used, app version, and settings
- automation choices such as selected people, channels, limits, templates, and status
- hosted integration records from Slack, Gmail, Calendar, Stripe, or lead sources when enabled
- selected context needed for hosted AI, cloud automation, follow-up, reply handling, or booking
- AI provider, model, operation, token counts, aggregate counts, and product telemetry
- error logs, designed to avoid message bodies where possible
Customer website visitor data
a dreach customer can choose to install our consent-required website tracker. For that customer's visitors, we process pseudonymous page-view telemetry on the customer's behalf. The customer is responsible for providing an appropriate notice, collecting any consent required by law, and deciding how long to retain the data.
- site-specific first-party visitor and session cookies, which expire after 180 days and 30 minutes respectively unless consent is withdrawn sooner
- redacted page paths, referrer origin, and UTM source, medium, and campaign values
- event time, site identifier, and keyed pseudonymous visitor, session, and IP fingerprints
- transient user-agent processing used to reject common automated traffic; the raw user-agent is not stored in the website-event record
- an optional network-level company match, including company name, domain, provider, and confidence, when the customer enables a supported resolver
raw visitor IP addresses are not stored in dreach's application database. They pass through hosting and security infrastructure and, when company resolution is enabled, are sent to the selected resolution provider. Those services may maintain their own security or access logs. A company match indicates a likely organization associated with a network; it does not identify or verify a person.
Support data
- messages you send to [email protected] or through support channels
- screenshots, exports, logs, or recordings you voluntarily attach to a request
Local Mac data
- iMessage / chat.db. the Mac app reads iMessage locally when you grant the required macOS permission, including supported direct and group chats. the raw chat.db file is not uploaded as a source file.
- local index. dreach can keep a local index on your Mac so searches and context work without making our cloud the primary copy of your local conversations.
- AI provider paths. hosted dreach AI sends selected context through our backend, BYOK sends selected context to the cloud provider you configure, and local LLM generation sends selected context to local Ollama. BYOK and local LLM usage may still report provider, model, operation, and token counts for entitlement and billing.
How we use data
- operate the Mac app, backend, billing, and connected account flows
- send first messages, follow up, handle one-to-one and group replies, and book meetings when automation is enabled
- generate messages, summaries, signals, and call context from the sources you choose
- show plan, credit, and usage state inside the app
- debug, secure, and improve the product
- respond to support, privacy, legal, and security requests
How we store data
cloud metadata that reaches our backend is stored on managed cloud infrastructure. Transport is protected with TLS 1.2 or higher. Managed databases and cloud storage use encryption at rest. Sensitive tokens and secrets are additionally protected with application-level encryption where configured.
account data is retained for the life of your workspace plus a limited deletion window unless a longer period is required by law, tax, security, or legitimate business needs. Product telemetry may be retained in aggregate form after raw records expire.
customer website events use the retention period selected by the workspace, from 1 to 730 days, with a 180-day default. Workspace administrators can pause collection, erase a site's events, or delete the tracking site. Company-resolution cache records expire separately and do not contain the raw IP address or provider response.
Third-party processors
- Stripe for payment processing, checkout, invoicing, and billing records.
- DigitalOcean for compute and database hosting.
- Cloudflare for CDN, DNS, security, and performance.
- Sentry for error monitoring and reliability.
- AI providers for hosted dreach AI or customer-managed Anthropic/OpenAI keys depending on your plan and settings. Local Ollama runs on your machine and is not a cloud AI processor for prompt content.
- Connected tools such as Google, Slack, Stripe, calendar providers, and meeting tools when you authorize them.
- Website company-resolution providers such as KickFire or Ipregistry when a workspace administrator enables that optional feature. The enabled external provider receives a public visitor IP address to return network or company information.
Your choices
- choose which sources to connect
- choose the people, channels, limits, templates, and rules before automation runs
- choose hosted dreach AI, BYOK cloud providers, or local LLM where your plan allows it
- pause automation at any time
- revoke connected account access through dreach settings or the provider
- remove local app data and the local database from your Mac
- for customer website tracking, honor browser Global Privacy Control and Do Not Track signals, require consent before setting tracking cookies or sending events, and stop collection and expire those cookies when consent is withdrawn
Your rights (GDPR + CCPA)
if you are in the EU, UK, or California, you may have the right to access, correct, export, or delete personal data. You can also object to processing or restrict it. Submit a request to [email protected] and we will respond within 30 days where required by law.
if you visited a dreach customer's website, contact that website operator first because it controls the tracking configuration and can identify the relevant site. We will support the operator with a valid request as required by applicable law.
Children
dreach is built for businesses. it is not intended for anyone under 16 and we do not knowingly collect data from minors.
Changes to this policy
we may update this policy from time to time. for material changes we will notify workspace admins or users through the app, email, or another reasonable channel. the "last updated" date at the top of this page reflects the current version.
SMS and text messaging
if you provide a mobile number and separately opt in to the dreach marketing SMS program, we use it to send the marketing messages you requested. these may include product updates, feature launches, offers, events, and opportunities to book a demo. consent is not a condition of purchase.
text messaging originator opt-in data and consent will not be shared with any third parties or affiliates. we do not sell, rent, or share mobile phone numbers or SMS consent with third parties for marketing or promotional purposes.
message and data rates may apply and message frequency varies. you can opt out at any time by replying STOP, or reply HELP for help. see our SMS terms and conditions for details.
Contact
questions, requests, or concerns: [email protected]. for general support, write to [email protected].