Privacy Policy

Last Updated: July 23, 2026

1. Introduction

This Privacy Policy describes how ReachHound ("we", "us", or "our") collects, uses, stores, and protects your personal information when you use our Service.

ReachHound is an audience-research tool: you enter your app and a few competitors, and we build a ranked map of the channels — subreddits, communities, newsletters, YouTube channels, podcasts, directories, and more — where your audience already gathers, with public evidence behind each pick.

We are a sole proprietorship registered in Hungary, committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR), Hungarian data protection laws, and other applicable privacy regulations.

2. Data Controller Information

  • Business Type: Sole Proprietorship
  • Country: Hungary
  • Contact Email: hello@usegrand.app
  • Website: https://reachhound.com

3. Information We Collect

3.1 Account Information

When you create an account, we collect:

  • Email address — for account identification, authentication, and communication
  • Full name — for personalisation and invoicing
  • Password — securely hashed using bcrypt and never stored as plain text (accounts that sign in with Google, GitHub, or a magic link have no password)
  • Sign-in method and, for social sign-in, the provider account identifier and avatar returned by Google or GitHub
  • Account role, status, and registration and update timestamps

3.2 Billing and Payment Information

We collect:

  • Billing address (street, city, state, postal code, country) collected during Stripe checkout
  • Payment and subscription data including amount, currency, billing interval, status, any trial period, and transaction IDs processed by Stripe
  • Stripe identifiers, including checkout session, customer, subscription, payment intent, price, and invoice IDs
  • Billingo partner ID and invoice records for invoice generation

We do NOT store your credit card details. All payment card information is processed and stored securely by Stripe, our PCI-DSS compliant payment processor.

3.3 Map and Project Data

To generate your results, we store the inputs you provide and the data we produce for you, including:

  • The maps you create — your app name, app URL, category, and the competitor names and URLs (up to five) you enter
  • Generated results — ranked channels, the public evidence (mentions) behind them, keyword ideas, content-gap topics, on-page SEO snapshots, competitor pricing snapshots, and domain rank data
  • Your own outreach status, notes, and drafts saved against a channel
  • Per-run snapshots we keep so you can see what changed between generations, plus creation and update timestamps and related operational metadata

Our public "Discover" pages show only aggregated public channels grouped by category. They never reveal your account, a specific project, or which competitors you researched.

3.4 Usage and Technical Data

We automatically collect:

  • Authentication tokens stored in secure, HTTP-only cookies
  • Your IP address, read from standard proxy headers and processed transiently to apply rate limits and prevent abuse
  • Website analytics and performance data, including visited URL and path, referrer, engagement data, viewport size, browser, device, operating system, and Core Web Vitals

We do not use this information for targeted advertising, sell it to data brokers, or track your browsing activity after you leave our Service.

3.5 Email Communication Data

Your email address is processed to send:

  • Transactional emails, including password resets, magic sign-in links, welcome and account-created messages, and refund confirmations
  • Invoices via Billingo
  • Customer support responses

3.6 On-Device Processing

Some features run entirely inside your own browser and send nothing to us. Semantic keyword clustering and search use an on-device embedding model, and outreach draft rewriting uses your browser's built-in AI (where available). The people you plan to contact and the messages you draft never leave your device or reach our servers through these features.

4. How We Use Your Information

4.1 Service Provision

  • Account creation and maintenance
  • Identity authentication and account security
  • Generating and storing your maps — ranking channels, gathering public evidence, mining keywords, comparing on-page SEO, capturing pricing snapshots, and suggesting content gaps
  • Powering aggregated public Discover pages from ready maps
  • Providing technical support

4.2 Payment Processing

  • Processing subscriptions, renewals, and one-time payments through Stripe
  • Generating electronic invoices through Billingo for Hungarian tax compliance
  • Handling refunds
  • Applying discount codes
  • Metering your monthly map allowance and maintaining payment records for accounting and taxes

4.3 Communication

  • Password reset emails with time-limited tokens
  • Magic sign-in links
  • Welcome and account-created emails
  • Refund confirmations
  • Invoices and receipts
  • Responses to support inquiries

4.4 Security and Fraud Prevention

  • Protecting authentication, billing, and administrative functions
  • Rate limiting requests by IP and identifier to prevent abuse
  • Fraudulent transaction detection and prevention
  • Validating payment webhook signatures
  • Enforcing password requirements (8+ chars, mixed case, numbers, special characters)

4.5 Legal Compliance

  • Complying with GDPR, Hungarian, and EU data protection laws
  • Meeting Hungarian tax and invoicing regulations
  • Responding to legal requests and court orders
  • Enforcing our Terms of Service

5. Legal Basis for Processing (GDPR)

We process your data under the following legal bases:

  • Contract Performance: Creating your account, providing your plan, generating and storing the maps you request, and processing billing
  • Legal Obligation: Tax compliance, invoice generation, and fraud prevention mandated by law
  • Legitimate Interest: Security, fraud detection, service operation and improvement, and website usage and performance analytics
  • Consent: Explicit user approval for specific processing activities

6. Data Sharing and Third-Party Services

Stripe (Payments)

  • Data shared: Name, email, billing address, and payment and subscription details
  • Purpose: Checkout, subscriptions, one-time payments, refunds, and fraud screening
  • Role: Independent controller for payment data and service provider for related billing functions, subject to Stripe's terms and privacy documentation
  • Privacy Policy: https://stripe.com/privacy

Billingo (Invoice Generation)

  • Data shared: Name, email, billing address, payment amount
  • Purpose: Electronic invoice generation for Hungarian tax compliance
  • Location: Hungary
  • Privacy Policy: https://www.billingo.hu/adatkezelesi-tajekoztato

Resend (Email Delivery)

  • Data shared: Email address, name, and the content required for each transactional message
  • Purpose: Transactional email delivery
  • Location: Processing may occur outside the EEA under applicable transfer safeguards
  • Privacy Policy: https://resend.com/legal/privacy-policy

MongoDB Atlas and Vercel (Infrastructure)

  • Data shared: Account data, your maps and project content, billing records, and technical request data needed to host and operate the Service
  • Purpose: Database storage, application hosting, content delivery, logging, security, and performance monitoring
  • Location: Processing location depends on our infrastructure configuration and each provider's subprocessors
  • Privacy Policies: https://www.mongodb.com/legal/privacy-policy and https://vercel.com/legal/privacy-notice

Upstash Redis (Rate Limiting)

  • Data shared: Short-lived request identifiers derived from your IP address and the endpoint being called
  • Purpose: Rate limiting and abuse prevention
  • Privacy Policy: https://upstash.com/privacy

Google and GitHub (Optional Sign-In)

  • Data shared: If you choose to sign in with Google or GitHub, we receive your verified email, name, a stable account identifier, and avatar. We request only basic profile and email scopes and do not access any other data in those accounts
  • Purpose: Account creation and authentication
  • Privacy Policies: https://policies.google.com/privacy and https://docs.github.com/privacy

Public Data Sources (Map Generation)

  • Data shared: When you generate a map, we query public web sources using the app name, app URL, and competitor names and URLs you entered. We do not send these sources your account details or other personal data beyond those search terms
  • Purpose: Discovering and ranking channels, keywords, evidence, competitor pricing, and content gaps from publicly available information
  • Example sources: Search suggestion services (Google, YouTube, DuckDuckGo), community and content platforms (Reddit community data, Hacker News, Lemmy, Substack, YouTube), podcast and app catalogs (Apple Podcasts, Apple App Store, Google Play), package registries (npm), product directories, news search (Bing), domain ranking (Tranco), and the public web pages, RSS feeds, and sitemaps of the sites you enter
  • Provider terms: These sources are operated by third parties under their own terms and privacy policies

SaaS Analytics and Vercel Speed Insights (Usage and Performance)

  • Data shared: Visited URLs and paths, referrers, engagement data, viewport, device, browser, and anonymous Core Web Vitals
  • Purpose: Website usage analytics and performance measurement
  • Privacy Policies: https://saasanalytics.app and https://vercel.com/legal/privacy-notice

We do NOT sell, rent, or trade your personal information to third parties for marketing purposes.

7. Data Retention

7.1 Active Accounts

We retain your account and map data while your account remains active or as needed to provide the Service. Cancelling a subscription does not automatically delete your account or your maps; you may separately request account deletion.

7.2 Deleted Content

Maps you delete are removed from your account and may remain temporarily in backups, logs, or operational records before being overwritten or deleted under our normal retention processes. Note that your monthly map allowance is metered per calendar month, so deleting a map does not restore that month's usage count.

7.3 Closed Accounts

Following a valid account-deletion request, we delete or anonymise personal data that is no longer required to provide the Service. Some information may remain in backups or be retained for legal, accounting, fraud-prevention, dispute, and security purposes. Aggregated or anonymised analytics may be retained.

7.4 Legal Retention Requirements

  • Payment and invoice records: retained for 8 years (Hungarian tax law requirement)
  • Fraud prevention records: retained as necessary to prevent future fraudulent activity

8. Cookies and Tracking Technologies

8.1 Authentication Cookie

  • Name: auth_token (configurable)
  • Purpose: Storing JWT authentication token
  • Type: Strictly necessary
  • Security: HttpOnly: Yes, Secure: Yes in production, SameSite: Lax, lifetime up to 7 days

8.2 Sign-In Cookies

When you sign in with Google or GitHub, we set short-lived, HTTP-only cookies to protect against cross-site request forgery and to remember where to return you after sign-in. These cookies (for example google_oauth_state and github_oauth_state) expire within about ten minutes and are strictly necessary.

8.3 Browser Storage

Browser localStorage stores your selected display theme. Browser sessionStorage stores temporary checkout hand-off state so you can resume a purchase after signing in; this is transient and is normally cleared when the tab closes. The app reads these values to apply your theme or resume the relevant flow.

8.4 Analytics and Performance

SaaS Analytics measures visits, URLs and paths, referrers, engagement, viewport, device, and browser to help us understand site usage. Vercel Speed Insights records anonymous device and Core Web Vitals data for performance monitoring. We do not set a visitor-tracking cookie of our own for these purposes.

8.5 What We DON'T Use

  • Advertising or marketing cookies for targeted ads
  • Social media tracking pixels for advertising
  • Cross-site tracking for ad networks
  • Behavioural advertising networks
  • Data brokers

9. Data Security

9.1 Encryption

  • Data in transit: HTTPS/TLS encryption
  • Data at rest: database encryption provided by MongoDB Atlas
  • Passwords: hashed with bcrypt (10+ salt rounds, irreversible)

9.2 Access Controls

  • Role-based access control (user/admin)
  • JWT-based authentication with secure, HTTP-only cookies
  • Authorization checks on account, billing, and administrative operations
  • Password reset tokens expiring after 1 hour
  • Rate limiting on authentication and sensitive endpoints

9.3 Infrastructure Security

  • Secure MongoDB Atlas database hosting
  • Application hosting and delivery via Vercel
  • PCI-DSS compliant Stripe payment processing
  • Regular security updates and patches

9.4 Fraud Prevention

  • Stripe fraud detection and prevention
  • Authentication controls against unauthorized access
  • Webhook signature verification
  • Account monitoring for suspicious activity

While we implement strong security measures, no system is 100% secure. You are responsible for maintaining the confidentiality of your password and reporting any unauthorized access immediately.

10. Your Rights Under GDPR

Right to Access: Request a copy of all personal data we hold about you.

Right to Rectification: Update your account information at any time through your account settings or by contacting us.

Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention requirements.

Right to Data Portability: Request an export of your personal data by contacting us.

Right to Restrict Processing: Request that we limit how we use your data under certain circumstances.

Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent: Withdraw consent at any time where processing is based on your consent.

Right to Lodge a Complaint: File a complaint with your local data protection authority.

To exercise your rights, please contact us at hello@usegrand.app. We will respond to your request within 30 days as required by GDPR.

11. International Data Transfers

We are based in Hungary (EU), but some of our service providers are located outside the EU. All international transfers comply with GDPR through Standard Contractual Clauses approved by the European Commission, adequacy decisions, and data processing agreements with GDPR compliance guarantees.

  • Stripe, Resend, MongoDB, Vercel, Upstash, and the public data sources we query may process relevant data outside the EEA
  • Where required, transfers rely on an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism

12. Children's Privacy

Our Service is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@usegrand.app immediately and we will delete that information.

13. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours
  • Notify affected users without undue delay if the breach poses a high risk
  • Provide information about the nature of the breach and steps taken
  • Take immediate steps to contain and remediate the breach

14. Automated Decision-Making

We do NOT use automated decision-making or profiling that produces legal effects or similarly significantly affects you. The automated processes we use are limited to: scoring and ranking public channels and evidence when generating your maps, Stripe's automated fraud screening, security and rate-limiting controls, and automatic website usage and performance measurement.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. When we make changes we will:

  • Update the "Last Updated" date at the top of this page
  • Notify you of material changes via email or through the Service
  • Provide a prominent notice on our website
  • Seek renewed consent where required for significant changes

Your continued use of the Service after changes indicates your acceptance of the updated Privacy Policy.

16. Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

  • Email: hello@usegrand.app
  • Website: https://reachhound.com
  • Data Controller: ReachHound (sole proprietorship, Hungary)

We will respond to your inquiry within 30 days as required by GDPR.