Reach arrow_back Back

Privacy Policy

Last updated: August 2026

This Privacy Policy applies to the Reach iOS application and related services (tryreach.health), operated by James Martin. We respect your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable laws. If you have any questions, please contact us at hello@tryreach.health.

The short version: Reach is local-first

  • We do not sell your data to anyone. ever.
  • We do not run ads or track you across other apps.
  • Your personal recovery data stays on your device by default.
  • We never track your usage of crisis resources.
  • You only create an account if you want cloud backups.

1. Data we collect and why

We believe in collecting only what is strictly necessary to make Reach work for you.

Device-Only Data (Local Storage)

By default, Reach operates "local-first". This means the vast majority of your data is stored securely on your iOS device within the app's sandboxed environment and is not transmitted to our servers. This includes:

  • Your sobriety date and ongoing streak.
  • Onboarding preferences and reasons for staying sober.
  • Your designated "reach-out" contact details.
  • Your "Tape Forward" audio/video recordings and notes.
  • Your personalized Escape Plan.

Account Data (Cloud Backup - Optional)

If you choose to enable cloud backups, you must create an account. We collect:

  • Email address (used solely for login via One-Time Passcode / Magic Link).
  • A secure, encrypted sync of your local data to allow you to restore it on a new device.

Subscription Data

If you upgrade to a premium plan, we collect basic subscription status data via RevenueCat to unlock features. This data is linked to an anonymous app user ID unless you create a backup account.

What we NEVER collect

  • Crisis Usage: We do not log, track, or analyze when or how often you access emergency numbers (like 988) or crisis resources.
  • Location Data: We never track your GPS or physical location.
  • Payment Information: All payments are handled securely by Apple via the App Store. We never see your credit card details.
  • Advertising Identifiers (IDFA): We do not use trackers for targeted advertising.

2. Legal basis for processing (GDPR)

For users in the European Economic Area (EEA) or UK, our legal basis for collecting and using your personal data is:

  • Consent: When you voluntarily provide data for specific features (e.g., creating a backup account).
  • Performance of a Contract: Providing you with the core functionality of the Reach app and managing subscriptions.
  • Legitimate Interests: Ensuring the app functions correctly, securely, and providing customer support.

3. Third-party services

We use a carefully selected minimum of third-party services to operate Reach. We do not currently use any third-party analytics SDKs (like Google Analytics or Mixpanel).

  • Supabase: For database and authentication (if you enable cloud backups). Supabase data is stored securely and they act as our data processor.
  • RevenueCat: For managing in-app purchases and subscription status across devices.
  • Apple: For App Store distribution, iCloud (if you use device backups), and payment processing.

4. Data retention

We keep your personal information only for as long as necessary:

  • On-Device Data: Kept until you delete the Reach app or clear its data.
  • Account/Backup Data: Kept until you delete your account through the app settings, or request deletion via email. Upon deletion, cloud data is wiped within 30 days.
  • Subscription Records: Anonymized purchase records are retained as required by financial regulations.

5. Your rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate data.
  • Erasure (Right to be Forgotten): Request deletion of your account and cloud backup data directly within the app settings or via email.
  • Restriction/Objection: Limit or object to how we process your data.
  • Data Portability: Receive your data in a structured, machine-readable format.

To exercise any of these rights, contact hello@tryreach.health. You also have the right to lodge a complaint with your local Data Protection Commission (DPC).

6. Children's privacy

Reach is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a minor, we will take steps to delete it immediately.

7. Security

We prioritize the security of your sensitive recovery data:

  • All data in transit is encrypted using HTTPS/TLS.
  • Cloud backups use Supabase's Row Level Security (RLS) ensuring you can only access your own data.
  • Local data is stored in the secure iOS sandboxed environment.

8. Changes to this policy

We may update this privacy policy from time to time. If we make material changes, we will notify you within the app or by updating the "Last updated" date at the top of this page.

9. Contact us

If you have any questions, concerns, or requests regarding this Privacy Policy, please reach out:

James Martin
hello@tryreach.health

Medical Disclaimer

Reach is a tool designed to support your personal recovery journey. It is not a replacement for professional medical advice, diagnosis, therapy, or specialized crisis intervention.

If you are in immediate danger or experiencing a medical emergency, please call 911 (US) or your local emergency number immediately. For immediate mental health support in the US, dial 988.