Legal · Last updated August 31, 2026
Privacy Policy
How StudioAnchor collects, uses, shares, retains, and responds to requests involving personal data across the public site, Reach workspace, and Reach MCP connection.
Questions about this page can be sent to [email protected]. Requests involving an account should come from the account email when possible.
1. Scope and roles
This policy covers the StudioAnchor public website and StudioAnchor products that link to it, including Reach. When a customer organization submits or manages member, contact, campaign, or operational data, the customer generally decides why that data is processed and StudioAnchor processes it to provide the service. StudioAnchor may separately act as the party deciding how account, billing, security, and website data is used.
2. Data we handle
- Account and organization data: name, email, organization name, role, authentication identifiers, settings, and membership.
- Product data: contacts, lists, tags, campaigns, templates, assets, engagement events, sender settings, and other content a workspace user supplies.
- Billing data: subscription status, plan, invoices, and provider identifiers. Payment-card details are handled by the payment provider rather than this public site.
- Technical and security data: IP address, device and browser information, request metadata, timestamps, authentication and audit events, and diagnostics.
- Support data: correspondence and the information needed to investigate a request.
3. Reach MCP and connected-app data
When a user connects Reach through MCP or OAuth, Reach receives authorization details and tool requests needed to act for the selected workspace. Depending on the approved tool and user instruction, this may include workspace, contact, campaign, template, analytics, or sender information. Reach uses that data to authenticate the connection, return requested results, perform explicitly requested actions, apply plan and approval controls, prevent abuse, and troubleshoot failures. Reach does not treat an OpenAI connection as an endorsement and does not bypass the workspace’s existing permissions.
4. Why we use data
- Provide, secure, maintain, and improve the requested service.
- Authenticate users, enforce organization boundaries, and administer connected applications.
- Process campaigns and other user-directed product actions.
- Manage billing, plan limits, and account support.
- Detect abuse, investigate incidents, comply with law, and protect rights and safety.
- Communicate operational, security, and account information.
5. Recipients and processors
Data may be shared with infrastructure, hosting, database, authentication, email-delivery, storage, payment, analytics, support, and security providers only as needed for their services; with customer-authorized connected applications; with professional advisers under confidentiality obligations; or with authorities and other parties when legally required or necessary to protect rights and safety. StudioAnchor does not sell customer member lists.
6. Retention
We retain account and product data while the account is active and for a limited period afterward to support recovery, security, billing, dispute, and legal needs. Backups and provider logs may expire on different schedules. OAuth tokens are retained until revoked, expired, replaced, or deleted under the applicable workflow. Support and security records may be kept longer when needed to document the issue. Final production retention periods require owner and legal approval and will be added when confirmed.
7. Access, correction, export, and deletion
Workspace administrators can manage much of their data in the product. Requests for access, correction, export, restriction, objection, or deletion can be sent to [email protected]. We verify the requester’s authority, coordinate with the customer organization when it controls the data, and explain any legal or technical limitation. Disconnecting a connected application revokes its access but does not automatically erase records the user already asked Reach to create.
8. Security and international processing
We use access controls, HTTPS, managed infrastructure protections, and organization-scoped application checks. No system is perfectly secure. Providers may process data in jurisdictions different from the user’s location; applicable contractual and legal safeguards depend on the provider and customer arrangement.
9. Children, changes, and contact
The service is for organizations and authorized adult account holders, not children creating their own accounts. Customer organizations are responsible for permissions and notices when they process children’s data. We may update this policy and will change the date above; material changes may also be communicated in-product or by email.