Privacy Policy
This policy explains what A2Z Reach, Inc. (“A2Z Reach”, “we”, “us”) collects when you use our website and platform, why we collect it, who else sees it, how long we keep it, and what you can require us to do with it.
Effective date: August 19, 2026 · Last updated: September 22, 2026
1. Who this policy covers
This policy applies to the A2Z Reach platform, our website at a2zreach.ai, and the email and scheduling we use to support them. It covers you whether you are a registered user, someone evaluating the product, or a visitor who never signs in.
Where a customer uses A2Z Reach to monitor their own brand, that customer is the controller of the data in their account and we act as a processor on their instructions. For our own website, account records and billing, we are the controller. If you reached us through your employer's account, their privacy notice governs how they use what they see.
2. What we collect
Account and identity. Your email address, which is also how you authenticate. If you sign in with a password we store no copy of it — credentials are held by AWS Cognito, not by our application. If you sign in with a one-time passcode, the code lives only for its short validity window.
What you configure. The brand names, domains, competitors, topics and prompts you set up for tracking. This is the substance of the product, and it is usually commercial information about a business rather than personal information about a person.
What the platform produces. Responses captured from AI engines for your prompts, the citations and mentions extracted from them, and the metrics computed on top. Captured responses are the engines' public output; where a response names a person, that text is stored as captured.
Technical and usage records. IP address, browser and device metadata, request timestamps, pages and features used, and error traces. We use these to operate the service, investigate faults, and enforce rate limits that protect accounts from abuse.
Billing. Your plan, subscription status and invoice history. Payments are processed by Stripe, and we never receive or store your full card number, CVC or bank credentials — those go directly to Stripe.
Things you send us. Support email, demo and enterprise call bookings, and anything you choose to include in them.
3. What we do not collect
- We do not run third-party advertising, analytics or tracking scripts on our website. There is no Google Analytics, no advertising pixel and no cross-site tracking cookie.
- We do not sell personal information, and we never have.
- We do not share personal information for cross-context behavioural advertising.
- We do not knowingly collect anything from children — see section 11.
4. Why we use it
We use what we collect for these purposes and no others:
- To run the service — executing captures, computing your metrics, serving your dashboards, authenticating you, and billing you.
- To keep it working — security, availability, abuse prevention, debugging, and improving the product in aggregate.
- To contact you — service notices you cannot opt out of while you hold an account, and marketing email you can, with an unsubscribe link in every one.
- To meet legal obligations — retaining financial records, and responding to lawful requests.
We do not use your account data to train our own models, and we do not use it to build a profile of you for advertising.
5. Who else sees your data
We share data with service providers who process it on our behalf, under contract, for the purposes below and no other. The list matching this one is maintained on our Security & Trust Center.
| Recipient | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, database and object storage, and Cognito authentication | United States (us-east-1) |
| OpenAI, LLC | Semantic categorisation and topic generation from your brand configuration | United States |
| Stripe, Inc. | Subscription billing and payment processing | United States |
| DataForSEO LLC | Search keyword, ranking and demand data used by the SEO features | European Union / United States |
| Cal.com, Inc. | Scheduling, when you book a demo or enterprise call from our website | United States |
We also disclose data where the law requires it — a valid legal order, or to establish or defend a legal claim — and to an acquirer if the business is sold, in which case this policy travels with the data until it is replaced with notice to you.
6. AI engines we query on your behalf
The core of the product submits your configured prompts to public AI assistants — ChatGPT, Claude, Gemini, Perplexity and Google — and records what they answer. Two consequences are worth stating plainly:
- Those prompts leave our infrastructure and are handled by the engine operator under their terms and privacy policy, not ours.
- Prompts are composed from your brand and topic configuration, so do not put personal or confidential information in them. A prompt is a public search query, not a private note.
7. Where your data goes and how long we keep it
Data is hosted and processed in the United States, in Amazon Web Services' us-east-1 (Northern Virginia) region. A2Z Reach operates from the United States and does not offer the service to the EU or UK, so we do not rely on Standard Contractual Clauses or any other cross-border transfer mechanism. If you use the platform from outside the United States, your data is processed in the United States. Enterprise customers can execute a Data Processing Agreement.
Retention is enforced automatically, not by hand:
| Data | Kept for |
|---|---|
| AI engine capture artifacts (raw responses, screenshots, extracted citations) | 90 days from capture, then deleted automatically by storage lifecycle rule |
| Agent execution logs (raw traces from analysis runs) | 30 days from write, then deleted automatically |
| Account, brand and prompt configuration | Life of the account, then deleted within 30 days of closure |
| Computed metrics and dashboards derived from captures | Life of the account — these outlive the raw artifacts they came from |
| Billing and invoice records | Retained as long as required by tax and accounting law, typically 7 years |
Backups roll off on their own schedule, so a deleted record can persist in an encrypted backup for a short period after deletion before being overwritten.
8. Your rights
Depending on where you live, you can ask us to do any of the following, and we will not treat you differently for asking:
- Know and access — what we hold about you, and a copy of it.
- Correct — fix anything inaccurate.
- Delete — erase your account and the data attached to it.
- Port — receive your data in a machine-readable format.
- Object or restrict — to processing we base on legitimate interests.
- Withdraw consent — at any time, without affecting what we did before you withdrew it.
- Opt out of sale or sharing — which requires nothing of you here, because we do neither.
Write to support@a2zreach.ai and we will respond within 30 days, or tell you within 30 days why we need longer. We may need to verify your identity first, and where you are asking about data held in a customer's account we will refer you to that customer as the controller and assist them in answering you.
These rights are offered to everyone who asks, not only to residents of states whose law compels them. If you are unhappy with how we handled a request you can raise it with your state attorney general, though we would rather you came back to us first.
9. Cookies
We set a single HTTP-only session cookie so that you stay signed in. It is marked HttpOnly and SameSite so it cannot be read by scripts or sent from another site, and it is served over HTTPS in production. It is strictly necessary for authentication, so there is no consent banner asking you to accept it and no way to use an account without it.
We set no advertising, profiling or third-party analytics cookies. Pages that embed a scheduling widget load it from Cal.com, which may set its own cookies under its own policy when you interact with it.
10. How we protect it
Data is encrypted in transit and at rest, authentication is handled by AWS Cognito, access to production is restricted to staff who need it, and sensitive credentials are held in a managed secrets store rather than in code. Our Security & Trust Center sets out the detail, including how to report a vulnerability. No system is perfectly secure, and we will notify you and the relevant regulator without undue delay if a breach affects your personal data.
11. Children
A2Z Reach is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, write to support@a2zreach.ai and we will delete it.
12. Changes to this policy
We will update this page when our practices change, and revise the “last updated” date above. If a change materially affects your rights we will tell registered users by email before it takes effect, rather than relying on you to notice.
13. Contact
A2Z Reach, Inc. Privacy questions and rights requests: support@a2zreach.ai. Security reports: security@a2zreach.ai. Anything else: support@a2zreach.ai.