Privacy Policy
Last updated: July 14, 2026
What we collect
PennReach stores your name, email address, and the contacts you save through the MyPenn browser extension or add manually.
When you connect your Google account, we access the following Google user data: your Google account email address and basic profile (to identify the connected account); an OAuth refresh token, stored encrypted, so we can act on your behalf; the content of email messages in outreach threads you started through PennReach (to display replies and detect who has responded — we do not read mail outside of those threads); and your calendar free/busy availability (busy time blocks only — we never read event titles, details, or attendees).
How we use it
Google user data is used solely to provide PennReach's user-facing features for you: sending the emails you compose and approve from your own Gmail account, detecting and displaying replies in your dashboard, stopping follow-ups to contacts who have responded, and suggesting reply drafts with meeting times based on your availability. We do not use your data for advertising, and we do not expose it to human review except where required to debug an issue at your request.
Data sharing and transfer
We do not sell, trade, rent, or otherwise transfer your data — raw, aggregated, or anonymized — to third parties such as data brokers or advertisers. Google user data is shared only with the infrastructure service providers that operate PennReach, and only as needed to run the app: our database and authentication provider (Supabase), our hosting provider (Vercel), and — solely when generating a suggested reply draft for you — Anthropic, whose Claude API processes the relevant outreach thread and your free/busy windows to produce the draft. These providers process data on our behalf and are not permitted to use it for their own purposes.
AI features and Limited Use
PennReach uses an AI model (Anthropic's Claude, via API) to generate suggested reply drafts. Google user data sent for this purpose is used for inference only — that is, to generate your draft — and is never used by us to develop, improve, or train generalized AI or machine learning models. Under Anthropic's commercial API terms, Anthropic does not train its models on API inputs or outputs. Every AI-generated draft requires your explicit review and approval before anything is sent.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
How we protect it
All data is transmitted over TLS and stored in an access-controlled Postgres database. Gmail OAuth tokens are encrypted at rest with a dedicated key held outside the database. Your data is scoped to your account — no other PennReach user can access it — and production database access is limited to the operator of the service.
Google API data
PennReach's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
We retain your data while your account is active so your dashboard, campaign history, and reply tracking keep working. You can disconnect Gmail at any time from Settings, which immediately revokes our access and deletes the stored token. Deleting your account removes your Gmail token, contacts, message history, and campaign history from our database within 30 days.
Contact
Questions: neelj@wharton.upenn.edu