Legal
Privacy Policy
Last updated: 28 September 2026
This policy explains what Reach12 ("we", "us") collects, why, who it is shared with, and what you can ask of us. Reach12 is in early access, and this page describes the service as it runs today. We will update it as the service grows.
Two kinds of data
Data about you, as a visitor or a customer. Your name and email when you ask for early access, your account details when we open an account for your business, and the technical data any website receives. We decide how this data is used, so we are its controller.
Data your business sends through Reach12. The phone numbers and email addresses of your customers, the messages you send them, their delivery status and the opt-outs you record. This data is yours. We process it on your behalf and only to provide the service to you, so you are its controller and we are your processor.
If you received a message sent through Reach12, please contact the business that sent it: it decides what happens to your data, and we will help it answer you.
What we collect
When you visit reach12.com
- The site sets no cookies, stores nothing in your browser, and runs no analytics or advertising scripts.
- Our servers log each request (IP address, time, the page requested and the browser type) to operate and secure the service.
When you ask for early access
- The name, work email, company, interest and note you type into the form.
- Your IP address, used only to limit repeated submissions, and your browser type.
- The request goes to the founders' email and phones so we can reply. We don't add you to a mailing list or use it for marketing.
When your business has an account
- Account details: your business name, the sender name and email address we set up for you, your daily limits, and who on our team created or changed them.
- API keys: we keep only a one-way hash of each key and a short prefix to tell keys apart. We cannot see or recover a key.
- Usage: the requests made with your keys, including the time, the result and the address they came from, to run the service, enforce limits and investigate problems.
What your business sends
- For each message: the recipient's phone number or email address, the content, the category and label you set, the time and the delivery status. We don't store the text of a message you mark as a one-time code.
- Your opt-out list: the address, the channel, the reason you gave, and when an opt-out was added or lifted. A lifted opt-out is kept as a record.
- Messages sent with a test key never leave Reach12, and what they record is kept apart from live data.
How we use it
- To provide the service: sending your messages through carriers, keeping your message log and opt-out list, and applying your limits and the contact hours.
- To keep it secure: detecting and blocking abuse, and investigating errors and incidents.
- To talk to you about your account and early access.
We don't sell personal data, use it for advertising, or use your customers' data for any purpose of our own. We don't use it to train AI models.
Who we share it with
Only the providers we need to run the service, under agreements that require them to protect it:
| Provider | What for |
|---|---|
| Railway | Hosting and the database |
| Backblaze | Off-site backups |
| Cloudflare | Domain name service for reach12.com |
| InforU | Delivering SMS messages |
| Resend | Delivering email |
When the voice agent is part of your account, calls also go through Twilio (the phone call), Deepgram (speech to text), Anthropic (the conversation and the summary), and Google and OpenAI (the agent's voice).
We may also disclose data when the law requires us to.
The voice agent
The voice agent is in early access. When it is part of your account, the calls it places or answers are recorded and transcribed, and a summary is written, so that you can review them. The agent says it is an AI in the first sentence of every call. Recordings, transcripts and summaries belong to your business, like your messages.
International transfers
Some of our providers operate outside Israel, including in the United States. We use providers that commit to protecting the data they handle for us, and we send them only what they need to do their part.
How long we keep it
- Early-access requests: until you ask us to delete them, or until it is clear we won't work together.
- Account data, message logs and opt-out lists: while your account is active. When it closes, we delete them on request, except what the law requires us to keep, such as billing records.
- Records that stop a request from being sent twice: 24 hours.
Security
Data travels encrypted. API keys are stored only as hashes. Access to production is limited to the founders, with two-step sign-in, and backups are kept off-site. No system is perfectly secure, and if a breach affects your data we will tell you without undue delay.
Your rights
You can ask to see, correct or delete the personal data we hold about you, or object to how we use it. Depending on where you live, for example under Israel's Privacy Protection Law or the EU and UK GDPR, you may have further rights, including the right to complain to your data protection authority. Write to us and we will answer within 30 days.
Children
Reach12 is a service for businesses and is not meant for children.
Changes
If we change this policy in a way that matters, we will post the new version here with a new date, and tell customers by email.
Contact
Questions and requests: hello@reach12.com.