reach

Privacy Policy

Last updated: July 9, 2026  ·  Effective date: May 2, 2026
This Privacy Policy explains how Füger, Hahn & Pestka GbR, a partnership operating the reach platform ("reach", "we", "us", "our"), collects, uses, shares, and protects personal data when you use our website, application, and services (the "Service"). reach is intended for users aged 18 and over. This Policy applies in addition to our Terms and Conditions.
Contents
  1. Who we are
  2. What data we collect
  3. How we collect data
  4. Why we use data & legal bases
  5. AI processing
  6. Hosting in the United States
  7. Sub-processors & third parties
  8. International transfers
  9. Cookies & analytics
  10. Retention
  11. Your rights (EU/UK/US)
  12. Children
  13. Sensitive data
  14. Security
  15. Domain registration data
  16. Changes to this Policy
  17. Contact

1. Who we are

The data controller responsible for processing your personal data under the GDPR is:

Füger, Hahn & Pestka GbR
Adickesallee 38, Room 3437
60322 Frankfurt am Main, Germany
Email: dev@reach-the-world.com

For questions about this Policy or to exercise your rights, contact us at the email above.

2. What data we collect

The categories of personal data we process depend on how you use the Service:

CategoryExamples
Account dataemail address, password (hashed), name, sign-in provider (Google, LinkedIn, email/password)
Profile datafull name, city, country, industry, LinkedIn / GitHub / Instagram / Calendly URLs
Uploaded filesportrait photos, CV files (PDF/DOCX) and the text extracted from them, additional images you upload
Survey & questionnaire answersfree-text answers used to enrich your generated website
Generated contentthe HTML/CSS of your website, edits you make, your selected colors, template, blocks, and other design choices
Payment databilling email, plan, transaction ID, invoice records — full card details are processed only by Stripe and not stored by us
Domain dataif you purchase a custom domain: registrant name, postal address, phone number, email — required by ICANN and shared with Name.com and the relevant registry
Usage & technical dataIP address, browser type, device, operating system, language, pages visited, clicks, errors, timestamps, generation jobs, Credit usage, log records
Communicationsemails or messages you send to us, including support requests

3. How we collect data

We collect data (a) directly from you when you create an account, fill in a profile, upload files, answer survey questions, edit your website, purchase a plan or domain, or contact us; (b) automatically when you use the Service, through server logs, cookies, and similar technologies; and (c) from third parties such as Google or LinkedIn when you sign in via one of these providers (in which case we receive basic identifiers such as your email address and name).

4. Why we use data & legal bases

We process your personal data for the following purposes and on the following legal bases under Article 6(1) GDPR:

We do not carry out automated decision-making with legal or similarly significant effects within the meaning of Art. 22 GDPR.

5. AI processing

The Service uses artificial-intelligence models to generate and improve your website. When you upload a CV, fill in survey answers, or use AI features, the relevant inputs are transmitted to AI providers (currently Anthropic, Inc. and potentially other providers) located in the United States. These providers process your inputs on our behalf to generate AI Output and return it to us.

By using AI features of the Service, you understand and accept that your inputs will be transmitted to and processed by these AI providers in the United States. We do not knowingly use your raw or identifiable personal data to train general-purpose AI models that benefit other customers. Anonymised or aggregated data may be used to evaluate, debug, and improve the Service.

6. Hosting in the United States

The Service runs on third-party infrastructure that may be located in the United States, including in particular Supabase (database, authentication, file storage, edge functions; primary region currently in the United States). This means that personal data you upload — including CVs, photos, profile information, survey answers, and generated websites — is stored and processed in the United States.

By creating an account and uploading data to the Service, you acknowledge and accept that your personal data will be transferred to and stored in the United States and processed there in line with this Policy.

7. Sub-processors & third parties

We share personal data only where necessary to operate the Service. The current main recipients are:

RecipientRoleLocation
Supabase, Inc.Database, authentication, file storage, realtime, edge functionsUnited States
Cloudflare, Inc.CDN, DNS, custom-domain hostnames, securityUnited States / global
Anthropic, PBCAI model provider for website generation and text improvementsUnited States
Stripe, Inc.Payment processing for subscriptions and Credit purchasesUnited States / Ireland
Name.com, Inc.Domain registrar (when you purchase a custom domain)United States
Pexels GmbHStock photo search if you choose to use it in the editorGermany
Google LLC / LinkedIn CorporationAuthentication (only if you sign in via Google or LinkedIn)United States

We may add or replace sub-processors as the Service evolves. Where required by law, we will give reasonable notice of material changes.

We may also disclose personal data to: (a) competent authorities, courts, or regulators where we are legally required to do so; (b) professional advisers (lawyers, accountants); and (c) any successor or acquirer in connection with a merger, acquisition, restructuring, or asset sale.

We do not sell your personal data. We do not "share" your personal data for cross-context behavioural advertising as defined under U.S. state privacy laws.

8. International transfers

Because most of our infrastructure is U.S.-based, transfers of personal data from the EU/UK/Switzerland to the United States and other third countries take place. Where required, such transfers are protected by the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, the Swiss Addendum, the EU-U.S. Data Privacy Framework (where the recipient is certified), and supplementary measures such as encryption in transit and access controls. By using the Service, you acknowledge that no level of protection equivalent to the GDPR can be guaranteed in third countries, particularly with regard to potential access by U.S. authorities.

9. Cookies & analytics

We currently use only strictly necessary cookies and local storage. Specifically:

We do not currently use any analytics, advertising, marketing, or other non-essential cookies or trackers — there is no Google Analytics, no advertising pixel, and no cross-site tracking on the Service today. That is why you will not see a cookie-consent banner: none is legally required for strictly necessary cookies.

If we ever add a non-essential analytics or marketing tool (for example, Google Analytics or PostHog), we will update this Policy and, where the law requires it, present a consent banner and obtain your consent before that tool is activated. You would then be able to accept or decline, and to withdraw consent at any time.

10. Retention

We keep your personal data only as long as necessary for the purposes described above:

11. Your rights

11.1 Rights under the GDPR (EU/UK)

If the GDPR or UK GDPR applies to you, you have the right to: access your personal data; rectify inaccurate data; erase data ("right to be forgotten"); restrict processing; object to processing based on legitimate interests; data portability; and withdraw consent at any time without affecting the lawfulness of prior processing. You also have the right to lodge a complaint with a supervisory authority — with your local data protection authority or the appropriate regulator in your jurisdiction.

11.2 Rights under U.S. state laws

Depending on your state of residence (e.g., California, Colorado, Connecticut, Virginia, Utah, Texas, Florida), you may have rights to know what personal information we collect, to access or delete it, to correct inaccuracies, to opt out of "sale" or "sharing" of personal information, and to opt out of targeted advertising or profiling. We do not sell or share personal data for cross-context behavioural advertising. To exercise your rights, contact us at dev@reach-the-world.com. We will not discriminate against you for exercising your rights.

11.3 How to exercise your rights

Send an email to dev@reach-the-world.com from the address linked to your account. We may ask for additional information to verify your identity. We will respond within the time limits required by applicable law (typically one month under the GDPR; up to 45 days under most U.S. state laws).

12. Children

reach is not directed at children. We require all users to be at least 18 years old. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us at dev@reach-the-world.com and we will delete it promptly.

13. Sensitive data

You agree not to upload sensitive personal data that is not strictly necessary for the Service, including health data, biometric identifiers, government identification numbers, financial-account credentials, precise geolocation, or data revealing racial or ethnic origin, religion, political opinion, trade-union membership, or sex life. The Service is not designed to handle such categories, and you assume responsibility if you choose to upload them.

14. Security

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), encryption at rest provided by our infrastructure providers, role-based access controls, hashed passwords, and regular review of access permissions. However, no system is 100% secure. You are responsible for keeping your credentials confidential and for protecting your own copies of important Customer Content.

15. Domain registration data

If you purchase a custom domain through our reseller integration with Name.com, we collect the contact details required by ICANN (registrant name, address, phone, email). We share this information with Name.com and, as required, with the relevant top-level-domain registry, ICANN, and ICANN-accredited escrow providers. Some of this data may appear in public WHOIS / RDDS records, subject to ICANN privacy rules and any privacy-protection service offered by Name.com. By purchasing a domain you confirm that the registrant data is accurate and that you have authority to provide it.

16. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date at the top of this page reflects the latest version. For material changes, we will provide reasonable advance notice by email or in-app banner. Your continued use of the Service after the new Policy takes effect means you accept the changes.

17. Contact

Füger, Hahn & Pestka GbR
Adickesallee 38, Room 3437
60322 Frankfurt am Main, Germany
Email: dev@reach-the-world.com
Website: reach-the-world.com