Legal

Privacy Policy

This policy explains what A2Z Reach, Inc. (“A2Z Reach”, “we”, “us”) collects when you use our website and platform, why we collect it, who else sees it, how long we keep it, and what you can require us to do with it.

Effective date: August 19, 2026 · Last updated: September 22, 2026

1. Who this policy covers

This policy applies to the A2Z Reach platform, our website at a2zreach.ai, and the email and scheduling we use to support them. It covers you whether you are a registered user, someone evaluating the product, or a visitor who never signs in.

Where a customer uses A2Z Reach to monitor their own brand, that customer is the controller of the data in their account and we act as a processor on their instructions. For our own website, account records and billing, we are the controller. If you reached us through your employer's account, their privacy notice governs how they use what they see.

2. What we collect

Account and identity. Your email address, which is also how you authenticate. If you sign in with a password we store no copy of it — credentials are held by AWS Cognito, not by our application. If you sign in with a one-time passcode, the code lives only for its short validity window.

What you configure. The brand names, domains, competitors, topics and prompts you set up for tracking. This is the substance of the product, and it is usually commercial information about a business rather than personal information about a person.

What the platform produces. Responses captured from AI engines for your prompts, the citations and mentions extracted from them, and the metrics computed on top. Captured responses are the engines' public output; where a response names a person, that text is stored as captured.

Technical and usage records. IP address, browser and device metadata, request timestamps, pages and features used, and error traces. We use these to operate the service, investigate faults, and enforce rate limits that protect accounts from abuse.

Billing. Your plan, subscription status and invoice history. Payments are processed by Stripe, and we never receive or store your full card number, CVC or bank credentials — those go directly to Stripe.

Things you send us. Support email, demo and enterprise call bookings, and anything you choose to include in them.

3. What we do not collect

  • We do not run third-party advertising, analytics or tracking scripts on our website. There is no Google Analytics, no advertising pixel and no cross-site tracking cookie.
  • We do not sell personal information, and we never have.
  • We do not share personal information for cross-context behavioural advertising.
  • We do not knowingly collect anything from children — see section 11.

4. Why we use it

We use what we collect for these purposes and no others:

  • To run the service — executing captures, computing your metrics, serving your dashboards, authenticating you, and billing you.
  • To keep it working — security, availability, abuse prevention, debugging, and improving the product in aggregate.
  • To contact you — service notices you cannot opt out of while you hold an account, and marketing email you can, with an unsubscribe link in every one.
  • To meet legal obligations — retaining financial records, and responding to lawful requests.

We do not use your account data to train our own models, and we do not use it to build a profile of you for advertising.

5. Who else sees your data

We share data with service providers who process it on our behalf, under contract, for the purposes below and no other. The list matching this one is maintained on our Security & Trust Center.

RecipientPurposeLocation
Amazon Web Services, Inc.Cloud hosting, database and object storage, and Cognito authenticationUnited States (us-east-1)
OpenAI, LLCSemantic categorisation and topic generation from your brand configurationUnited States
Stripe, Inc.Subscription billing and payment processingUnited States
DataForSEO LLCSearch keyword, ranking and demand data used by the SEO featuresEuropean Union / United States
Cal.com, Inc.Scheduling, when you book a demo or enterprise call from our websiteUnited States

We also disclose data where the law requires it — a valid legal order, or to establish or defend a legal claim — and to an acquirer if the business is sold, in which case this policy travels with the data until it is replaced with notice to you.

6. AI engines we query on your behalf

The core of the product submits your configured prompts to public AI assistants — ChatGPT, Claude, Gemini, Perplexity and Google — and records what they answer. Two consequences are worth stating plainly:

  • Those prompts leave our infrastructure and are handled by the engine operator under their terms and privacy policy, not ours.
  • Prompts are composed from your brand and topic configuration, so do not put personal or confidential information in them. A prompt is a public search query, not a private note.

7. Where your data goes and how long we keep it

Data is hosted and processed in the United States, in Amazon Web Services' us-east-1 (Northern Virginia) region. A2Z Reach operates from the United States and does not offer the service to the EU or UK, so we do not rely on Standard Contractual Clauses or any other cross-border transfer mechanism. If you use the platform from outside the United States, your data is processed in the United States. Enterprise customers can execute a Data Processing Agreement.

Retention is enforced automatically, not by hand:

DataKept for
AI engine capture artifacts (raw responses, screenshots, extracted citations)90 days from capture, then deleted automatically by storage lifecycle rule
Agent execution logs (raw traces from analysis runs)30 days from write, then deleted automatically
Account, brand and prompt configurationLife of the account, then deleted within 30 days of closure
Computed metrics and dashboards derived from capturesLife of the account — these outlive the raw artifacts they came from
Billing and invoice recordsRetained as long as required by tax and accounting law, typically 7 years

Backups roll off on their own schedule, so a deleted record can persist in an encrypted backup for a short period after deletion before being overwritten.

8. Your rights

Depending on where you live, you can ask us to do any of the following, and we will not treat you differently for asking:

  • Know and access — what we hold about you, and a copy of it.
  • Correct — fix anything inaccurate.
  • Delete — erase your account and the data attached to it.
  • Port — receive your data in a machine-readable format.
  • Object or restrict — to processing we base on legitimate interests.
  • Withdraw consent — at any time, without affecting what we did before you withdrew it.
  • Opt out of sale or sharing — which requires nothing of you here, because we do neither.

Write to support@a2zreach.ai and we will respond within 30 days, or tell you within 30 days why we need longer. We may need to verify your identity first, and where you are asking about data held in a customer's account we will refer you to that customer as the controller and assist them in answering you.

These rights are offered to everyone who asks, not only to residents of states whose law compels them. If you are unhappy with how we handled a request you can raise it with your state attorney general, though we would rather you came back to us first.

9. Cookies

We set a single HTTP-only session cookie so that you stay signed in. It is marked HttpOnly and SameSite so it cannot be read by scripts or sent from another site, and it is served over HTTPS in production. It is strictly necessary for authentication, so there is no consent banner asking you to accept it and no way to use an account without it.

We set no advertising, profiling or third-party analytics cookies. Pages that embed a scheduling widget load it from Cal.com, which may set its own cookies under its own policy when you interact with it.

10. How we protect it

Data is encrypted in transit and at rest, authentication is handled by AWS Cognito, access to production is restricted to staff who need it, and sensitive credentials are held in a managed secrets store rather than in code. Our Security & Trust Center sets out the detail, including how to report a vulnerability. No system is perfectly secure, and we will notify you and the relevant regulator without undue delay if a breach affects your personal data.

11. Children

A2Z Reach is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, write to support@a2zreach.ai and we will delete it.

12. Changes to this policy

We will update this page when our practices change, and revise the “last updated” date above. If a change materially affects your rights we will tell registered users by email before it takes effect, rather than relying on you to notice.

13. Contact

A2Z Reach, Inc. Privacy questions and rights requests: support@a2zreach.ai. Security reports: security@a2zreach.ai. Anything else: support@a2zreach.ai.