The data controller responsible for processing your personal data under the GDPR is:
Füger, Hahn & Pestka GbR
Adickesallee 38, Room 3437
60322 Frankfurt am Main, Germany
Email: dev@reach-the-world.com
For questions about this Policy or to exercise your rights, contact us at the email above.
The categories of personal data we process depend on how you use the Service:
| Category | Examples |
|---|---|
| Account data | email address, password (hashed), name, sign-in provider (Google, LinkedIn, email/password) |
| Profile data | full name, city, country, industry, LinkedIn / GitHub / Instagram / Calendly URLs |
| Uploaded files | portrait photos, CV files (PDF/DOCX) and the text extracted from them, additional images you upload |
| Survey & questionnaire answers | free-text answers used to enrich your generated website |
| Generated content | the HTML/CSS of your website, edits you make, your selected colors, template, blocks, and other design choices |
| Payment data | billing email, plan, transaction ID, invoice records — full card details are processed only by Stripe and not stored by us |
| Domain data | if you purchase a custom domain: registrant name, postal address, phone number, email — required by ICANN and shared with Name.com and the relevant registry |
| Usage & technical data | IP address, browser type, device, operating system, language, pages visited, clicks, errors, timestamps, generation jobs, Credit usage, log records |
| Communications | emails or messages you send to us, including support requests |
We collect data (a) directly from you when you create an account, fill in a profile, upload files, answer survey questions, edit your website, purchase a plan or domain, or contact us; (b) automatically when you use the Service, through server logs, cookies, and similar technologies; and (c) from third parties such as Google or LinkedIn when you sign in via one of these providers (in which case we receive basic identifiers such as your email address and name).
We process your personal data for the following purposes and on the following legal bases under Article 6(1) GDPR:
We do not carry out automated decision-making with legal or similarly significant effects within the meaning of Art. 22 GDPR.
The Service uses artificial-intelligence models to generate and improve your website. When you upload a CV, fill in survey answers, or use AI features, the relevant inputs are transmitted to AI providers (currently Anthropic, Inc. and potentially other providers) located in the United States. These providers process your inputs on our behalf to generate AI Output and return it to us.
By using AI features of the Service, you understand and accept that your inputs will be transmitted to and processed by these AI providers in the United States. We do not knowingly use your raw or identifiable personal data to train general-purpose AI models that benefit other customers. Anonymised or aggregated data may be used to evaluate, debug, and improve the Service.
The Service runs on third-party infrastructure that may be located in the United States, including in particular Supabase (database, authentication, file storage, edge functions; primary region currently in the United States). This means that personal data you upload — including CVs, photos, profile information, survey answers, and generated websites — is stored and processed in the United States.
By creating an account and uploading data to the Service, you acknowledge and accept that your personal data will be transferred to and stored in the United States and processed there in line with this Policy.
We share personal data only where necessary to operate the Service. The current main recipients are:
| Recipient | Role | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage, realtime, edge functions | United States |
| Cloudflare, Inc. | CDN, DNS, custom-domain hostnames, security | United States / global |
| Anthropic, PBC | AI model provider for website generation and text improvements | United States |
| Stripe, Inc. | Payment processing for subscriptions and Credit purchases | United States / Ireland |
| Name.com, Inc. | Domain registrar (when you purchase a custom domain) | United States |
| Pexels GmbH | Stock photo search if you choose to use it in the editor | Germany |
| Google LLC / LinkedIn Corporation | Authentication (only if you sign in via Google or LinkedIn) | United States |
We may add or replace sub-processors as the Service evolves. Where required by law, we will give reasonable notice of material changes.
We may also disclose personal data to: (a) competent authorities, courts, or regulators where we are legally required to do so; (b) professional advisers (lawyers, accountants); and (c) any successor or acquirer in connection with a merger, acquisition, restructuring, or asset sale.
We do not sell your personal data. We do not "share" your personal data for cross-context behavioural advertising as defined under U.S. state privacy laws.
Because most of our infrastructure is U.S.-based, transfers of personal data from the EU/UK/Switzerland to the United States and other third countries take place. Where required, such transfers are protected by the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, the Swiss Addendum, the EU-U.S. Data Privacy Framework (where the recipient is certified), and supplementary measures such as encryption in transit and access controls. By using the Service, you acknowledge that no level of protection equivalent to the GDPR can be guaranteed in third countries, particularly with regard to potential access by U.S. authorities.
We currently use only strictly necessary cookies and local storage. Specifically:
We do not currently use any analytics, advertising, marketing, or other non-essential cookies or trackers — there is no Google Analytics, no advertising pixel, and no cross-site tracking on the Service today. That is why you will not see a cookie-consent banner: none is legally required for strictly necessary cookies.
If we ever add a non-essential analytics or marketing tool (for example, Google Analytics or PostHog), we will update this Policy and, where the law requires it, present a consent banner and obtain your consent before that tool is activated. You would then be able to accept or decline, and to withdraw consent at any time.
We keep your personal data only as long as necessary for the purposes described above:
If the GDPR or UK GDPR applies to you, you have the right to: access your personal data; rectify inaccurate data; erase data ("right to be forgotten"); restrict processing; object to processing based on legitimate interests; data portability; and withdraw consent at any time without affecting the lawfulness of prior processing. You also have the right to lodge a complaint with a supervisory authority — with your local data protection authority or the appropriate regulator in your jurisdiction.
Depending on your state of residence (e.g., California, Colorado, Connecticut, Virginia, Utah, Texas, Florida), you may have rights to know what personal information we collect, to access or delete it, to correct inaccuracies, to opt out of "sale" or "sharing" of personal information, and to opt out of targeted advertising or profiling. We do not sell or share personal data for cross-context behavioural advertising. To exercise your rights, contact us at dev@reach-the-world.com. We will not discriminate against you for exercising your rights.
Send an email to dev@reach-the-world.com from the address linked to your account. We may ask for additional information to verify your identity. We will respond within the time limits required by applicable law (typically one month under the GDPR; up to 45 days under most U.S. state laws).
reach is not directed at children. We require all users to be at least 18 years old. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us at dev@reach-the-world.com and we will delete it promptly.
You agree not to upload sensitive personal data that is not strictly necessary for the Service, including health data, biometric identifiers, government identification numbers, financial-account credentials, precise geolocation, or data revealing racial or ethnic origin, religion, political opinion, trade-union membership, or sex life. The Service is not designed to handle such categories, and you assume responsibility if you choose to upload them.
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), encryption at rest provided by our infrastructure providers, role-based access controls, hashed passwords, and regular review of access permissions. However, no system is 100% secure. You are responsible for keeping your credentials confidential and for protecting your own copies of important Customer Content.
If you purchase a custom domain through our reseller integration with Name.com, we collect the contact details required by ICANN (registrant name, address, phone, email). We share this information with Name.com and, as required, with the relevant top-level-domain registry, ICANN, and ICANN-accredited escrow providers. Some of this data may appear in public WHOIS / RDDS records, subject to ICANN privacy rules and any privacy-protection service offered by Name.com. By purchasing a domain you confirm that the registrant data is accurate and that you have authority to provide it.
We may update this Policy from time to time. The "Last updated" date at the top of this page reflects the latest version. For material changes, we will provide reasonable advance notice by email or in-app banner. Your continued use of the Service after the new Policy takes effect means you accept the changes.
Füger, Hahn & Pestka GbR
Adickesallee 38, Room 3437
60322 Frankfurt am Main, Germany
Email: dev@reach-the-world.com
Website: reach-the-world.com