Privacy
Privacy Policy
Last updated 22 July 2026
This page explains what Quillreach collects, why, who else touches it, and what you can ask us to do about it. It is written to be read, not to be survived. If anything here is unclear, email us and a human will explain it.
Who this covers
This policy covers quillreach.com and the Quillreach application. Quillreach is operated as an independent software business. If you have a question about anything below, you can reach a human at the address at the end of this page.
Two different kinds of data
Quillreach handles personal data in two distinct roles, and your rights differ depending on which one applies.
- Your data, where we decide
- Your account, your workspace, your billing record, and how you use the product. We determine why and how this is processed, so we are the controller and this policy governs it.
- Your contacts' data, where you decide
- When you connect a LinkedIn account, we sync the connections, conversations, and profile information that account can already see, so the product can show you an inbox and a lead list. You decide who to contact and what to send. For that data we act on your instructions as a processor, and you are responsible for having a lawful basis to contact those people and for answering their requests. We will help you respond to any such request.
What we collect
- Account and profile
- Your name, email address, company name and size, your role, what you plan to use Quillreach for, and your answer to how you heard about us. Most of this comes from you during signup.
- Billing
- Subscription status, seat count, and renewal dates. Card details are entered directly with our payment provider and are never sent to or stored on our servers.
- Connected LinkedIn accounts
- Access to the account you connect, plus the connections, messages, and profile data that account can see. This is the data the product exists to work with, and it stays scoped to your workspace.
- Usage and diagnostics
- Pages viewed, features used, errors encountered, browser and device type, and an approximate location derived from your IP address. We use this to find bugs and understand what to build next. It is collected by default, as described in the cookie section below.
- Session recordings
- We record how the interface was used during your visit, so we can see what actually happened when something breaks. Everything you type into a form field is masked before it leaves your browser, and so are message bodies and lead names. This runs by default and stops the moment you turn analytics off.
- How you found us
- The website that referred you, the first page you landed on, and any campaign tag on the link. See the cookie table below.
How we use it
- To run the product
- Sign you in, sync your inbox, and send what you ask us to send.
- To bill you
- Manage your subscription, seats, and trial.
- To keep accounts safe
- Enforce the sending limits and pacing that protect your connected accounts, detect abuse, and alert you to a new sign-in on your account.
- To support you
- Answer your emails and investigate problems you report.
- To improve Quillreach
- Understand which features are used, which pages convert, and where people get stuck. We never sell your data, and we never use the contents of your messages to train AI models.
AI personalisation
If you use AI personalisation, the lead details needed to draft a message are sent to a third party model provider to generate that draft. We do not permit that provider to use your data to train its models. You can avoid this entirely by not using AI steps in your campaigns.
Why we are allowed to process it
If you are in the UK, EU, or another region with similar law, we rely on the following legal bases.
- Contract
- Almost everything above, because we cannot deliver the product without it.
- Legitimate interests
- Keeping the service secure, preventing abuse, understanding which channels bring us customers, and improving the product. This is also the basis for the analytics and session recordings that run by default, because we cannot fix or improve a product we cannot see being used. We balance that against your rights, you can object at any time, and one switch turns all of it off.
- Consent
- Where the law where you live requires your permission before any of the analytics described above may run, we rely on your consent instead, and the same switch is how you give or withhold it.
- Legal obligation
- Keeping the tax and accounting records we are required to keep.
Where it goes
Our providers operate internationally, so your data may be processed outside your home country, including in the United States. Where that happens for data protected by UK or EU law, we rely on Standard Contractual Clauses or an equivalent approved safeguard.
How long we keep it
We keep your account and workspace data for as long as your account is open. If you delete your account, we delete your workspace data, including synced contacts and conversations, and we remove your sign-in record. Some records are kept longer where the law requires it, such as invoices for tax purposes. Backups age out on their own cycle.
You can ask us to delete your account at any time using the address below, and we will action it.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data. To use any of them, email us. We will respond within 30 days and we will not charge you or make the product worse because you asked.
- Access
- Get a copy of the personal data we hold about you.
- Correction
- Fix anything inaccurate.
- Deletion
- Ask us to erase your data.
- Portability
- Receive your data in a portable format.
- Objection and restriction
- Object to processing based on legitimate interests.
- Withdraw consent or opt out
- Turn analytics off at any time in Settings, both on this website and inside the app, without affecting anything we did beforehand.
- Complain
- Raise a complaint with your local data protection authority. We would appreciate the chance to put it right first.
How we protect it
Data is encrypted in transit and at rest. Access to production data is limited and access to your workspace is enforced at the database level, so one customer's data cannot be read by another. We scan our code for vulnerabilities and leaked credentials on every change. No system is perfectly secure, but if a breach ever affects your data we will tell you promptly.
Children
Quillreach is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
If we make a material change, we will update the date at the top of this page and tell account holders by email before it takes effect. Continuing to use Quillreach after that means the updated policy applies.
Contact us
For access, correction, deletion, or any privacy question:
Real humans reply, usually within a business day, and always within 30 days.