Legal
Privacy policy
Effective September 11, 2026
Who we are and what this policy covers
OmniReach is a multi-channel outreach workspace operated by Boolean and Bean from Victoria, Australia (“we”, “us”). This policy explains how we handle personal information through the OmniReach website, application, Chrome extension, support, marketing demos, and related services (the “Service”). Questions and requests may be sent to contact@useomnireach.com.
Our terms of use govern use of the Service. This policy is a notice about privacy practices; agreeing to the terms does not waive any privacy right.
Our role and your organisation’s role
We decide how account, billing, security, support, and product-usage information is used to operate OmniReach. For that information, we generally act as the business or controller.
A customer decides which prospects to upload or discover, which accounts to connect, and which outreach to send. For prospect records and communications processed on those instructions, the customer is generally the business or controller and OmniReach acts as its service provider or processor. The customer is responsible for required notices, consent or other lawful bases, and responding to prospects, subject to obligations the law places directly on us. Our data processing addendum sets out the terms on which we process that data for customers, including our sub-processors, transfer mechanisms, security measures, breach notice, and deletion commitments.
Information we collect
Depending on the features used, we collect or process:
- Account and profile information. Email address, display name, avatar, account identifiers, sign-in and membership timestamps, workspace roles, and authentication metadata. If you sign in with Google, we receive identity details Google and Supabase Auth make available for that sign-in (typically name, email, and profile image).
- Team information. Workspace names, member roles, invitations, invitee email addresses, invitation status, and inviter details.
- Prospect and campaign information. Names, professional roles, employers, LinkedIn URLs and identifiers, email addresses, imported fields (including from CSV or customer integrations), lists and list exports, campaign membership, notes, templates, approvals, scheduled actions, do-not-contact entries, and campaign history.
- Chrome extension (LinkedIn list building). If you install the OmniReach Chrome extension, it can read limited public fields from LinkedIn pages you have open, store drafts and session data locally in the browser, and — when you are signed in — send profile URLs or LinkedIn slugs and saved contact details to your OmniReach workspace. Details are in the Chrome extension section below.
- Connected LinkedIn information. Unipile account identifiers, account display details and status, profile and search results requested through the connected account, invitations, messages, InMail, replies, delivery or error events, and — where enabled — stale-invitation withdrawal events. LinkedIn credentials entered in a hosted connection flow are handled by Unipile, which holds the session token needed to act on the account; OmniReach does not receive or store your LinkedIn password and stores only the Unipile account identifier.
- Connected mailbox information. Email address, mailbox provider, Unipile account identifier, connection status, send limits and windows, message recipients, subjects, message content, replies, threading identifiers, attachment metadata or content retrieved for inbox features, and delivery, open, bounce, or error events. Mailbox credentials are handled by the hosted connection provider and are not stored in the OmniReach database.
- Seller and AI information. Website URL, offer, ideal-customer description, proof points, tone, prompts, excluded phrases, seller profile information, extracted website context, AI inputs and outputs, and draft status or errors.
- Signal information. Targeting preferences, discovery runs and usage, public professional and company information, provider identifiers, signal evidence, scores, recommendations, source links, and feedback. We do not intentionally persist email addresses or phone numbers returned solely by Signals discovery.
- API and agent information. Workspace API key identifiers and metadata (not the raw secret after creation), tool or method names invoked through MCP or the API, timestamps, and related audit or rate-limit events.
- Customer integration information. When you connect a tool such as Apollo, we store encrypted credentials or API keys you supply, connection status, and records imported or synchronised through that integration (for example contacts or tasks that become Actions).
- Billing information. Stripe customer, subscription and price identifiers, plan quantity, trial and grace status, billing status, invoice or payment status, and limited payment history. Stripe handles card and bank details; we do not store full payment-card numbers.
- Usage, device, and security information. IP address, browser and device information, timestamps, pages or actions, active workspace, rate-limit events, diagnostic logs, webhook and job status, errors, and security events.
- Product analytics. When PostHog is configured, we collect product-usage events in the signed-in application only (for example sign-in, campaign launches, feature use, and Chrome extension open or save events) with counts, identifiers, enums, and similar properties. Element text and attributes are masked, session recording is disabled, and analytics are designed not to include message bodies, prospect emails, API keys, or provider credentials. Public marketing pages do not load analytics.
- Marketing demo information. Website URLs you submit on public demo surfaces, extracted public-site context, and generated demo prospects. Demo results may be cached briefly by hostname.
- Communications. Support requests, privacy requests, feedback, billing communications, and transactional email delivery status.
Where information comes from
- You and other members of your workspace.
- Your browser, device, and use of the Service, including the Chrome extension when installed.
- Google, when you choose Google sign-in (via Supabase Auth).
- LinkedIn pages you open, when the Chrome extension reads public profile or people-search fields from the page DOM (separate from Unipile-connected LinkedIn accounts).
- LinkedIn and connected mailboxes through Unipile when you request or enable a feature in the web application.
- Stripe, Supabase, PostHog (when enabled), and other providers used to operate the Service.
- Public websites processed through Firecrawl when you request seller-context extraction or use a marketing demo.
- Autobound and public professional sources when you run Signals discovery.
- Customer integrations you connect (for example Apollo) when you import or sync data.
- Agent or API clients you authorise with a workspace API key.
- People who communicate with us or respond to outreach sent through the Service.
We do not buy or rent bulk prospect lists. Customers may upload or import lists obtained elsewhere and are responsible for their source and lawful use.
How and why we use information
We use information to:
- Create accounts, authenticate users (including Google sign-in and Chrome extension sign-in), and administer workspaces and permissions.
- Connect accounts and mailboxes and perform actions users configure and approve.
- Store prospects, campaigns, messages, replies, attachments needed for inbox features, DNC entries, and activity history — including contacts saved from the Chrome extension.
- Provide Chrome extension features such as duplicate detection, list and campaign selection, and saving contacts from LinkedIn pages you open.
- Import and sync data from customer integrations you connect, and run agent/API operations you authorise.
- Generate AI-assisted templates, prospect-specific drafts, and Signals targeting suggestions.
- Extract seller context and provide signal-based recommendations.
- Power public marketing demos and, when configured, cache demo results to reduce repeat processing.
- Apply caps, approval gates, billing and trial controls, suppression rules, reply-based stops, and optional invite withdrawal.
- Process subscriptions, trials, payments, invoices, and account changes.
- Provide support and send authentication, team, security, billing, and service notices.
- Measure product usage with analytics events when PostHog is configured, including extension usage events.
- Monitor reliability, investigate errors or abuse, secure the Service, and enforce terms.
- Comply with law and establish, exercise, or defend legal claims.
- Analyse aggregated or de-identified information to understand and improve the Service.
Where laws such as the GDPR require a legal basis, we rely as appropriate on performance of our contract, legitimate interests in providing and securing a business service, compliance with legal obligations, and consent where consent is required. A customer is responsible for identifying its legal basis for prospecting and outreach it directs.
Chrome extension
The OmniReach Chrome extension helps you capture LinkedIn profiles and people-search results into your OmniReach workspace. It is a list-building tool, not LinkedIn automation. It does not use Unipile, does not connect your LinkedIn account, does not run Signals discovery, and does not send invitations, messages, or other actions on LinkedIn.
What it reads on LinkedIn. On a profile page you have open, it reads public fields such as name, headline, current role and employer, profile URL, and public profile image URL, plus LinkedIn’s suggested-profiles sidebar (name, headline, profile URL, and public image) so you can save those people without opening each profile. On a people-search results page, it reads the visible result cards’ names, headlines, profile URLs, and public images. Search locations may be shown in the panel for disambiguation and are not saved as contact fields. The extension does not read your feed, messages, InMail, or notifications, does not inject UI into LinkedIn, and does not paginate, scroll, or click LinkedIn automatically.
What stays local until you save. Parsed profile and search rows are held in the extension’s browser session storage for the open tab so the side panel can display them. Unsaved drafts (including optional email and notes you type) are stored in local extension storage with a designed maximum and about a 30-day expiry. Theme preference may be stored in local browser storage. Signing out clears session tokens and related drafts from the extension.
What is sent to OmniReach before you save. When you are signed in and open a supported LinkedIn page, the extension may automatically call our servers to load workspace context (lists, campaigns, billing status, existing contact match) and to check whether visible LinkedIn profile URLs or slugs are already in your workspace. Those pre-save calls send identifiers such as the open profile URL or LinkedIn slugs — not full search-result contact records — so the panel can show duplicates and available lists.
What is sent when you save. When you save one or more people, the extension sends the selected contact fields (and any optional email or note you entered) to your workspace over HTTPS, along with your list or campaign choices. Public LinkedIn avatar images may be displayed in the panel from LinkedIn’s CDN; avatar URLs are not the primary stored contact payload for extension saves. Saved contacts become ordinary workspace Customer Content and may later be used in campaigns you run in the web application (including through Unipile, if you separately connect LinkedIn there).
Sign-in and permissions. Extension sign-in uses the same OmniReach account as the website. The extension may import your website session by reading OmniReach first-party authentication cookies on our app domain, or receive tokens after you complete the extension sign-in flow. Access and refresh tokens are stored locally in the extension and refreshed with Supabase Auth. The extension requests Chrome permissions for the side panel, storage, cookies (OmniReach site only), LinkedIn pages, and our app origin. It does not request permission to read LinkedIn cookies.
Analytics and retention. When PostHog is configured, we may record server-side product events about extension use (for example opening the extension or saving contacts), using identifiers and counts rather than message bodies or LinkedIn session data. Contacts saved through the extension are retained with other workspace data. Local drafts expire or are cleared as described above; uninstalling the extension removes its local storage from that browser. Delete workspace contacts or request account deletion through the Service as described elsewhere in this policy.
AI and automated assistance
When AI drafting or suggestions are enabled, relevant seller context, campaign prompts, targeting preferences, and prospect details such as name, role, employer, and professional profile context are sent to the AI provider configured for OmniReach. Generated drafts or suggestions are returned to and stored in the workspace. A user must review and approve outreach; OmniReach does not use AI to make a legally binding decision about a prospect.
We do not use Customer Content or prospect data to train a general-purpose model offered by OmniReach to other customers. A configured AI provider handles submitted information under its own business or API terms, including any stated retention and model-improvement practices. We will not knowingly enable provider training on Customer Content without the notice or permission required by law. Contact us to identify the provider currently in use before submitting information that requires particular AI data terms.
API, MCP, and agent access
If you create a workspace API key or connect an MCP client, OmniReach processes the requests that client makes — including creating or updating contacts, campaigns, sequences, and Signals actions — as Customer Content under your workspace’s instructions. We store key identifiers and usage metadata to authenticate requests, enforce limits, and audit activity. Keep keys confidential and revoke them if compromised.
Agent products you use (for example Claude Code, Cursor, or Codex) are separate services. Information those products send to OmniReach is processed under this policy; how those products handle data outside OmniReach is governed by their own terms.
Customer integrations
When you connect Apollo or another supported integration, you instruct us to use credentials you provide to retrieve or update information on your behalf. We store those credentials encrypted at rest where the product is designed to do so, and use them only for the sync and import features you enable. Imported contacts and synchronised tasks become workspace records subject to the same controls as other Customer Content.
Disconnecting an integration stops future API calls with your credentials. Previously imported records remain until you delete them. You are responsible for compliance with the third party’s terms and for having a lawful basis to process imported personal information.
Marketing demos
Public demo features may accept a website URL without an account, scrape public pages through Firecrawl, and generate sample prospects with the configured AI provider. Demo outputs are for illustration. When Upstash Redis is configured, we may cache demo results by hostname for a limited period (designed for about 24 hours) so repeat visits do not re-run the full pipeline. Do not submit confidential information into a public demo.
How we disclose information
We disclose personal information only as reasonably necessary:
- Within a workspace. Workspace members can see information made available according to their role. Owners and administrators control membership and may access or remove workspace content, including API keys and integrations.
- Service providers. Providers process information for hosting, authentication, connected accounts, sending, AI drafting, discovery, website extraction, billing, email delivery, analytics, caching, support, and background jobs.
- Connected platforms and recipients. We transmit messages and related details to connected accounts, LinkedIn, mailbox providers, customer integrations you enable, and the recipients selected by a user.
- Legal and safety. We may disclose information where reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate fraud or abuse, or enforce agreements.
- Business transfers. Information may be disclosed under confidentiality safeguards in a financing, merger, acquisition, restructuring, or sale, and transferred if the recipient assumes applicable privacy obligations.
- At your direction. We disclose information when you request an integration, export data, use an API or agent client, or otherwise direct us to do so.
We do not sell or rent personal information or prospect lists. We do not share personal information for cross-context behavioural advertising and do not use third-party advertising trackers in the product. Product analytics (PostHog), when enabled, is used to understand and improve the Service, not to sell ads.
Service providers
Our current product is designed to use the following provider categories:
- Supabase — authentication (including Google OAuth when enabled), account email delivery configuration, and database.
- Google — identity provider when you choose Google sign-in (via Supabase Auth).
- Vercel — application hosting, delivery, and platform logs.
- Unipile — LinkedIn and mailbox connection, search, profile data, invitations, messaging, email, replies, opens, bounces, and related webhooks.
- Stripe — checkout, subscriptions, trials, invoices, payment processing, and billing portal.
- Inngest — background jobs for sends, drafting, discovery, integration sync, and related automation.
- Autobound — Signals discovery and recommendations.
- Firecrawl — extraction of public website content for seller context and marketing demos.
- Resend — transactional and team-invitation email; it may also deliver Supabase authentication email.
- PostHog — product analytics when configured for the environment.
- Upstash — short-lived caching of public marketing demo results when configured.
- Apollo — customer-directed CRM/enrichment API when you connect your own Apollo API key.
- OpenAI — AI-assisted templates, prospect drafts, targeting suggestions, and demos, via its API under its business terms. If we change the AI provider we will update this policy and the data processing addendum and give notice as described there.
A provider is used only when the relevant feature is configured or enabled. Providers may use their own subprocessors. Before we add or replace a provider that processes prospect data on customers’ behalf, we give at least 14 days’ notice as set out in the data processing addendum. Contact us for the provider currently configured for a particular feature before submitting information that requires a specific processing location or contractual arrangement.
International processing
We operate from Australia and use providers that may process information in Australia, the United States, the United Kingdom, the European Union, and other countries in which they or their subprocessors operate. The likely location depends on our configured region, the connected platform, and the provider used for a feature.
Where required, we take reasonable steps to use contractual and organisational safeguards for overseas processing. Information processed elsewhere may be subject to foreign law and may not receive protections identical to those in your location. Contact us if you need more detail about a particular transfer.
Cookies and local storage
We use necessary cookies and similar browser storage for authentication sessions, active workspace selection, connected-account verification and return state, security, theme preference, and onboarding details such as a website URL you ask us to carry into signup. These are used to provide or secure requested functionality.
The Chrome extension uses Chrome extension storage (and limited local storage for theme) for OmniReach session tokens, selected workspace, unsaved contact drafts, and per-tab parsed LinkedIn profile caches. It may also read OmniReach website authentication cookies on our app domain to import a signed-in session. It does not read LinkedIn cookies.
When PostHog is configured, it sets a cookie and uses local storage in the signed-in application to distinguish users for product analytics. It is not loaded on public marketing pages, so visiting our website sets no analytics cookies. Extension analytics events are recorded on our servers when configured, not via a PostHog script inside the LinkedIn page. We do not use advertising cookies, pixels, or third-party ad trackers anywhere. You can limit analytics through browser controls; contact us if you need help with an analytics-related request.
Outreach, opt-outs, and suppression
Customers direct outreach sent through OmniReach and are responsible for consent or other lawful authority, sender identification, and unsubscribe content. If you receive an unwanted message sent through OmniReach, use the unsubscribe method in the message, reply to the sender asking them to stop, or contact us. We may assist the relevant customer in suppressing further outreach and investigate misuse.
We may retain a minimal do-not-contact record after other prospect details are removed when necessary to honour an opt-out, prevent repeated contact, demonstrate compliance, or resolve a complaint. Suppression information is not used to send marketing.
Retention and deletion
We retain account and workspace information while the account or workspace is active. After a workspace is closed or a verified deletion request is received, we delete or de-identify personal information within 30 days, with these exceptions: billing and tax records are kept for up to 7 years as required by Australian law; security, rate-limit, and API audit events are kept for up to 12 months; minimal do-not-contact records are kept to honour opt-outs; and information needed to resolve an open dispute or meet a legal obligation is kept until that need ends and then deleted.
While a workspace is active: Signals recommendations marked available or dismissed expire after 90 days; diagnostic logs are kept for up to 90 days; and saved prospect records, campaign history, integration imports, and usage ledgers remain until you delete them or the workspace closes. Cached marketing demo results expire after about 24 hours. A workspace with no sign-in for 24 months may be closed and deleted after 30 days’ notice to its owner.
Provider logs, backups, and disaster-recovery copies are removed on their normal rotation schedules and are not restored for ordinary product use after a verified deletion. Stripe and other providers may retain records they control where required by financial, fraud, security, or legal obligations.
To request account or workspace deletion, email contact@useomnireach.com. We will verify authority, explain any information that must be retained, and complete the request within 30 days, or sooner where applicable law requires. Workspace deletion may require approval from its owner and affects every member of that workspace.
Security and data breaches
We use reasonable administrative, technical, and organisational safeguards designed for the nature of the information, including access controls, workspace permissions, provider secrets, transport encryption, database row-level security, rate limits, and logging. No system is completely secure. You are responsible for protecting your email, sign-in links, devices, workspace roles, and connected accounts.
We assess suspected data breaches and will notify affected people and regulators where required by applicable law. Report a suspected security or privacy incident promptly to contact@useomnireach.com.
Your privacy choices and rights
You may edit or remove prospects, export lists you control, pause campaigns, disconnect accounts and integrations, revoke API keys, change workspace membership if authorised, and request account deletion. Depending on applicable law and our role, you may also request access, correction, deletion, restriction, objection, or a portable copy of personal information. You may withdraw consent where processing is based on consent, without affecting earlier lawful processing.
Send a request to contact@useomnireach.com. We may verify your identity and authority, ask you to contact the customer that controls a workspace, or forward a prospect request to that customer. We will not discriminate against you for exercising a right. Some requests may be limited by another person’s rights, security needs, legal privilege, or record-retention obligations.
Australian privacy complaints
We seek to handle personal information consistently with the Australian Privacy Principles where they apply. To complain, email us with your contact details, the conduct you are concerned about, and the outcome you seek. We will acknowledge the complaint, investigate it, and aim to respond within 30 days, or tell you if we reasonably need more time.
If you are not satisfied after giving us a reasonable opportunity to respond, you may be able to complain to the Office of the Australian Information Commissioner at oaic.gov.au.
United States privacy notices
If a U.S. state privacy law applies to OmniReach and to your information, you may have the rights described above and the right to appeal a denied request. We do not sell personal information, share it for cross-context behavioural advertising, or use it for targeted advertising. We do not knowingly use sensitive personal information to infer characteristics for advertising.
California categories we may process include identifiers, customer and commercial information, internet or electronic activity (including product-analytics events when PostHog is enabled), professional or employment information, communications, and inferences represented by signal scores or AI-assisted drafts. The sources, purposes, recipients, and retention approach are described above. An authorised agent may submit a request where permitted; we may verify the agent’s authority and the identity of the person concerned. If we deny an appealable request, reply to our decision explaining why you disagree.
European and United Kingdom users
Where the GDPR or UK GDPR applies, you may have rights to access, rectification, erasure, restriction, portability, and objection, and to complain to your local data-protection authority. Where we rely on legitimate interests, those interests are operating, securing, supporting, and improving a business outreach service without overriding your rights. You may object to direct marketing at any time.
When a customer controls prospect information, that customer is the primary contact for a prospect request. We will support the customer as required by our role. Information may be transferred outside Europe using an adequacy decision, contractual safeguards, or another lawful transfer mechanism where required.
Children
The Service is for business users aged 18 or older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child’s information has been submitted, contact us so we can investigate and take appropriate action.
Changes to this policy
We may update this policy to reflect product, provider, or legal changes. We will change the date above and, for a material change, provide reasonable notice by email or a prominent notice in the Service where required. If a change requires consent under applicable law, we will seek it rather than relying only on continued use.
Contact
Privacy questions, requests, complaints, and security reports: contact@useomnireach.com.