Draft, pending review by a lawyer. Details in square brackets are still being filled in. Nothing on this page is binding yet.

Privacy Policy

Last updated 5 October 2026

What personal data Owl Reach handles, why, and what you can do about it.

1. Who is responsible

Owl Reach is run by Emiel Declercq, a sole trader registered in Belgium, at Hooikaai 17, 1000 Brussel, Belgium, enterprise number BE 0803.550.176. For anything about your personal data, write to privacy@owlreach.be. We answer within one month.

Owl Reach handles data about two groups of people: the people who use Owl Reach, and the professionals Owl Reach finds for them. This policy covers both.

2. If you use Owl Reach

What we keep about you:

  • Your account: email address and login details.
  • Your brief: your name, goal, pitch and the kind of people you want to reach.
  • Connections you make: access tokens for Gmail, Google Calendar and Notion, so Owl Reach can place drafts, book follow-ups or export contacts when you ask it to.
  • Your contacts, notes, drafts and their status.
  • Billing: your plan and the Stripe customer reference. Stripe handles your card; we never see it.
  • Technical data: server logs (such as IP address, time and the request made) to keep the service running and secure.

Why, and on what legal basis:

  • To provide Owl Reach and your plan (performance of our contract with you).
  • To send service emails such as receipts and important changes (contract).
  • To keep invoices and accounting records (legal obligation).
  • To prevent abuse, fix errors and keep the service secure (our legitimate interest).

3. Google account data

When you connect Gmail, Owl Reach asks for permission to create drafts and send emails (the gmail.compose scope) and to read mail (the gmail.readonly scope). It only sends a letter when you press Send and confirm. It only reads the conversations it started for you, to show the replies on the contact's history, and never opens the rest of your inbox. Those replies are stored with the contact and deleted with it. When you connect Google Calendar (the calendar.events scope), it only creates, and when you cancel, deletes the meeting events for follow-ups you schedule. It does not read your other events.

What Owl Reach stores from Google: your Gmail address, the access tokens (encrypted at rest), the ids of the drafts, messages and events it created, and the replies to letters it sent. Your Gmail and Calendar content is never sent to our AI provider or any other third party.

Owl Reach's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google data for advertising, do not sell it, and do not use it to train AI models.

You can remove Owl Reach's access at any time in your settings or at myaccount.google.com/permissions.

4. If Owl Reach found you

If you received an email from someone using Owl Reach, this section is for you.

What we hold: your name, work email address, job title, employer, and where available a work phone number, professional profile link (such as LinkedIn) and similar public professional information. We also hold what the Owl Reach user wrote about you or to you, and your replies to those emails.

Where it comes from: your employer's own public website (such as its team or contact page), other public web pages found through a web search, Hunter.io, a B2B contact database that collects professional contact details from public sources, and information the Owl Reach user added.

Why: to help a user reach you about something relevant to your professional role, such as a job, a sponsorship, a partnership or a service.

Legal basis: legitimate interest. We limit ourselves to work-related data about people whose role matches the user's goal, never collect sensitive data, keep the data only for a limited time, and make it easy to object.

Who decides what: Owl Reach is responsible for finding your details. The user who contacts you decides whether and what to send you, and is responsible for that email.

Don't want to be contacted? Reply to the email, or write to privacy@owlreach.be. We delete your details and add a scrambled (hashed) version of your email address to a do-not-contact list, so Owl Reach never suggests you to any user again.

5. Who we share data with

We do not sell personal data. We only use service providers that need the data to run Owl Reach, bound by data processing agreements:

  • Anthropic (Claude API): writes drafts, searches the web and helps pick relevant people. Data sent to the API is not used to train its models.
  • Hunter.io (France): looks up professional contact details for some Pro searches.
  • Render (servers and database) and Vercel (website): hosting. Region: [TO CONFIRM].
  • Stripe: payments and invoices. Stripe is independently responsible for payment data.
  • Resend: sends our account emails (password reset, confirming your address) to your email address.
  • Google and Notion: only when you connect your own account, and only to do what you ask.

We may also share data when the law requires it, for example with tax authorities for invoices.

6. Transfers outside the EU

Some providers (such as Anthropic, Render, Vercel, Stripe and Resend) are based in the United States. Where data leaves the European Economic Area, we rely on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission's Standard Contractual Clauses.

7. How long we keep data

  • Your account and workspace: as long as your account exists. When you delete your account in Settings, everything is deleted straight away and copies in our backups are gone within 30 days.
  • Contacts Owl Reach found: deleted after 12 months without any activity on them, or sooner when you delete them or they object.
  • The do-not-contact list: kept for as long as Owl Reach runs, so the objection keeps working.
  • Server and search logs: 90 days.
  • Invoices and accounting records: as long as Belgian tax and accounting law requires (up to 10 years).

8. Cookies

Owl Reach uses one strictly necessary cookie to keep you logged in, and stores your chosen theme (colours, day or night) in your browser. We do not use advertising or tracking cookies, so we do not ask for cookie consent. If that ever changes, we will ask first.

9. Security

We protect data with encrypted connections (HTTPS), access controls on our servers and API, encryption at rest of the access tokens for Gmail, Google Calendar and Notion, signed and expiring connection requests for Gmail and Notion, and limited access for staff (currently only the owner). No system is perfectly secure; if a breach puts your data at risk, we inform the authority and, where required, you.

10. Automated choices

Owl Reach uses AI to suggest which professionals fit a user's goal and to draft a first email. This does not lead to any decision with legal or similarly significant effects on you: a person always decides whether to send anything.

11. Your rights

You can ask for access to your data, correction, deletion, restriction, a copy in a portable format, and you can object to processing based on legitimate interest. Write to privacy@owlreach.be; we may ask you to confirm your identity.

If you are not happy with how we handle your data, you can complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels, dataprotectionauthority.be, or to the authority in your own country.

12. Children

Owl Reach is not meant for anyone under 18, and we do not knowingly hold data about children.

13. Changes

If we change this policy in a way that matters, we tell users by email before the change applies and update the date at the top.