Effective: September 1, 2026 · Version 1.5 · Last updated: June 2026
Plain English summary
We collect only what is needed to run Reclaim. We never sell your data. Bank connections are read-only — we cannot move your money. You can delete everything instantly in Settings. This policy tells you exactly what we collect, why, and your full legal rights in every country we operate.
Data Controller — Legal Entity
Company: Reach and Rally Inc. (operating as "Reclaim") Business type: Limited Liability Company Incorporation: State of New York, United States, 2026 Address: 521 Jerusalem Ave, Bellmore, NY 11710, United States EIN: 41-4941622 Privacy contact:privacy@getreclaimapp.store
This Privacy Policy governs the collection, use, storage, and disclosure of personal information by Reach and Rally Inc. ("we", "us", "our") through the Reclaim mobile application and website (collectively, the "Service"). It applies to all users globally and addresses applicable law including GDPR (EU & UK), CCPA/CPRA (California), PIPEDA (Canada), POPIA (South Africa), Australian Privacy Act, Brazil LGPD, Singapore PDPA, Hong Kong PDPO, South Korea PIPA, Japan APPI, and applicable regulations in the UAE, Saudi Arabia, and Qatar.
Account registration: Email address and password (stored as a bcrypt hash — Reach and Rally Inc. never has access to your plain-text password). Display name is optional.
Onboarding preferences: Country of residence, income range, and financial goals. These are used solely to personalise your in-app experience. They are never sold, shared with advertisers, or used for profiling outside the Service.
Tax documents: W-2s, 1099s, and prior-year tax returns, uploaded voluntarily and used exclusively for US tax professional services you explicitly request. Not processed for any other purpose.
Recovery case details: Information you enter about a billing issue (merchant name, charge amount, description) to generate a recovery email.
Consent records: Timestamp, device locale, app version, and version of Terms you agreed to at signup, retained as required by law.
Support communications: Emails or messages you send to our support address, retained for up to 24 months.
1.2 Information collected through integrations
Bank transaction data: Accessed read-only via Plaid (US/Canada) or TrueLayer (UK/EU). We receive transaction descriptions, amounts, dates, and merchant identifiers. We use this solely to identify potential billing errors. We never receive, store, or have access to your bank login credentials, account numbers, sort codes, or routing numbers.
Gmail data: With your explicit permission, read-only access is used to (a) send recovery emails you individually approve before dispatch, and (b) detect replies to those specific recovery threads to update your case status. We do not read, index, store, or process any other email content in your inbox.
Device information: Device locale (country and language) detected once at account creation to set your currency and regional feature availability. We do not collect device identifiers for advertising purposes.
Anonymised usage analytics: Non-identifiable event logs (e.g., "scan completed", "email generated") used to understand feature usage and improve the product. These events contain no personal information and cannot be reverse-linked to your account.
1.3 What we never collect
Bank account numbers, sort codes, routing numbers, PINs, or online banking credentials
Payment card numbers, CVVs, or billing addresses (all payments are processed by Apple)
Advertising identifiers (IDFA, GAID) or third-party tracking data
Location data beyond country-level locale detection at signup
The content of any Gmail messages other than the specific recovery threads Reclaim creates
Biometric data of any kind
2. How we use your data
We use the personal information we collect for the following purposes, and no others:
Providing the core Service: detecting duplicate charges, price increases, and unauthorized subscriptions in your transaction history
Generating recovery emails based on your transaction data, for your review and approval before any email is dispatched
Sending follow-up emails to merchants on your behalf, only for recovery threads you have explicitly activated
Tracking recovery case status and sending you in-app and push notifications about case updates
Operating budget tracking tools, savings goals, and income monitoring features
Securely storing tax documents you upload and connecting you with independent licensed tax professionals (US only)
Authenticating your identity and maintaining account security
Responding to your support requests
Improving the Service through anonymised, aggregated analytics that cannot identify you
Complying with legal obligations
AI processing disclosure: Transaction descriptions and merchant names are processed by Anthropic's Claude AI API to identify potential billing errors. Per Anthropic's API data usage policy, Anthropic does not use API inputs or outputs to train its models and does not retain your data beyond the duration of the API call. We do not send your name, email, or financial account details to Anthropic.
3. Legal basis for processing (GDPR / UK GDPR)
Applies to users in the European Economic Area and United Kingdom.
As an LLC with fewer than 250 employees, Reach and Rally Inc. is not mandated to appoint a Data Protection Officer under Article 37 GDPR. Privacy requests are handled directly by our team at privacy@getreclaimapp.store.
Our legal bases for processing are:
Performance of contract (Art. 6(1)(b)): Processing necessary to deliver the Reclaim service, including transaction analysis, email generation, and case tracking
Legitimate interests (Art. 6(1)(f)): Anonymised product analytics and security monitoring, where these do not override your fundamental rights
Consent (Art. 6(1)(a)): Gmail access, tax document storage, and optional analytics. Consent can be withdrawn at any time in Settings without affecting the lawfulness of prior processing.
Legal obligation (Art. 6(1)(c)): Retaining consent records and certain financial records as required by applicable law
For special category data (which we do not intentionally collect), the basis would be explicit consent under Art. 9(2)(a).
4. Data processors and third parties
We share data only with the following processors, each bound by data processing agreements, and only to the extent necessary to provide the Service. We do not sell, rent, or trade your personal data to any party for any purpose.
Plaid Technologies Inc. — Bank account linking for US and Canadian users. Plaid manages all credential handling and provides us only with tokenised transaction data. Plaid Privacy Policy ↗
TrueLayer Limited — Bank account linking for UK and EU users under Open Banking regulations. TrueLayer Privacy Policy ↗
Supabase Inc. — Database, authentication, and backend infrastructure. Data is hosted on AWS US East (N. Virginia). Supabase Privacy Policy ↗
Anthropic PBC — AI-powered transaction analysis. No data retention beyond the API call; no model training on your data. Anthropic Privacy Policy ↗
Apple Inc. — In-app purchase processing and App Store distribution. Apple processes payment information directly and shares only purchase confirmation with us. Apple Privacy Policy ↗
Clear Decisions Inc. — Independent licensed tax professionals. Data is shared only when you explicitly book a tax service, and only the information you choose to provide for that engagement. Clear Decisions Inc. operates independently and has its own professional obligations and privacy practices.
We may disclose personal data to law enforcement, regulatory authorities, or courts if required by a valid legal order, subpoena, or applicable law. Where permitted, we will notify you before complying with such a request.
5. International data transfers
Reach and Rally Inc. is based in the United States. Your data is stored on servers located in the United States (AWS US East, Virginia). If you are located in the EU, UK, or another jurisdiction with data transfer restrictions, your data is transferred to the US under the following safeguards:
EU/UK users: Transfers are governed by Standard Contractual Clauses (SCCs) between Reach and Rally Inc. and our data processors, as authorised under GDPR Article 46(2)(c) and UK GDPR
All users: Data is encrypted in transit (TLS 1.3) and at rest (AES-256) regardless of transfer origin
6. Security
We implement industry-standard technical and organisational security measures including:
All data encrypted in transit using TLS 1.3 and at rest using AES-256 encryption
Database row-level security policies ensuring each user can only access their own data — cross-user data access is architecturally impossible
Bank credentials never stored by Reach and Rally Inc. — all credential handling is delegated to Plaid and TrueLayer using tokenised access
Passwords hashed using bcrypt with per-record salts — stored hashes cannot be reversed
App sessions encrypted using iOS Keychain, leveraging hardware Secure Enclave on supported devices
Production database access restricted to authorised personnel on a need-to-know basis
Regular security reviews of our database policies and infrastructure
No method of transmission over the internet or method of electronic storage is 100% secure. In the event of a data breach that affects your rights and freedoms, we will notify you and applicable regulators within the timeframes required by law (72 hours under GDPR; as required under other applicable regulations).
7. Data retention
We retain personal data only as long as necessary for the purposes described in this policy or as required by law:
Account data (name, email): Retained while your account is active and deleted within 30 days of account closure
Transaction data: 24 months from the date of collection, then permanently deleted
Tax documents: Retained until you delete them or close your account
Recovery email content and case records: 12 months from case closure or last activity
Anonymised analytics: 36 months in aggregated, non-identifiable form
Legal consent records: 7 years, as required to demonstrate compliance
Support communications: 24 months from the date of the communication
You can request deletion of your account and all associated data at any time: Settings → Account → Delete Account. Deletion is permanent and irreversible and will be completed within 30 days (immediately for most data). Legal consent records are retained for compliance purposes only.
8. Your rights by jurisdiction
All users — universal rights
Access your data: Email privacy@getreclaimapp.store
Delete your account and data: Settings → Account → Delete Account
Export your data: Settings → Export My Data
Disconnect bank integration: Settings → Bank Connections → Disconnect
Disconnect Gmail: Settings → Gmail → Disconnect
Opt out of push notifications: iOS Settings → Notifications → Reclaim
EU & UK — GDPR / UK GDPR EU · UK
Right of access to your personal data (Art. 15)
Right to rectification of inaccurate data (Art. 16)
Right to erasure ("right to be forgotten") (Art. 17)
Right to restriction of processing (Art. 18)
Right to data portability in a machine-readable format (Art. 20)
Right to object to processing based on legitimate interests (Art. 21)
Right to withdraw consent without affecting the lawfulness of prior processing (Art. 7(3))
Right not to be subject to solely automated decisions with legal or similarly significant effects (Art. 22) — we do not make such decisions
We respond to rights requests within 30 days (extendable to 60 days for complex requests with notice). To lodge a complaint: UK → Information Commissioner's Office (ico.org.uk). EU → your national supervisory authority.
California — CCPA / CPRA US-CA
Right to know what personal information is collected about you
Right to know whether personal information is sold or disclosed, and to whom
Right to opt out of the sale or sharing of personal information
Right to deletion of personal information
Right to correct inaccurate personal information
Right to limit use of sensitive personal information
Right to non-discrimination for exercising your rights
We do not sell personal information. We do not share personal information for cross-context behavioural advertising. To submit a CCPA request: privacy@getreclaimapp.store. We will respond within 45 days.
Canada — PIPEDA / Quebec Law 25 CA
Right to access personal information we hold about you. Right to withdraw consent (which may limit your ability to use certain features). Right to correct inaccurate information. Right to know how your information is used and disclosed. Contact privacy@getreclaimapp.store. Complaints: Office of the Privacy Commissioner of Canada (priv.gc.ca).
South Africa — POPIA ZA
Compliant with the Protection of Personal Information Act 4 of 2013 (POPIA). You have the right to access, correct, object to, and request deletion of your personal information. You may lodge a complaint with the Information Regulator of South Africa (inforegulator.org.za). Contact privacy@getreclaimapp.store. We will respond within 30 days.
Australia & New Zealand AU · NZ
Compliant with the Australian Privacy Act 1988 (Privacy Principles) and New Zealand Privacy Act 2020. Right to access and correct personal information we hold about you. To lodge a complaint: Australia → Office of the Australian Information Commissioner (oaic.gov.au). New Zealand → Office of the Privacy Commissioner (privacy.org.nz). Contact privacy@getreclaimapp.store.
Brazil — LGPD BR
Compliant with the Lei Geral de Proteção de Dados (LGPD — Law 13,709/2018). Rights include: confirmation of processing, access, correction, anonymisation or deletion, portability, information about sharing, and revocation of consent. Legal bases: contract performance and consent. We respond within 15 days. Contact privacy@getreclaimapp.store.
Singapore — PDPA SG
Compliant with the Personal Data Protection Act 2012 (PDPA). Right to access and correct personal data we hold about you. Right to withdraw consent (which may affect your use of certain features). Complaints: Personal Data Protection Commission (pdpc.gov.sg). Contact privacy@getreclaimapp.store.
Hong Kong — PDPO HK
Compliant with the Personal Data (Privacy) Ordinance (Cap. 486). Right to access and correct personal data. Data Access Requests or Correction Requests: privacy@getreclaimapp.store. Complaints: Privacy Commissioner for Personal Data Hong Kong (pcpd.org.hk).
Japan — APPI JP
Compliant with the Act on the Protection of Personal Information (APPI) and 2022 amendments. Right to request disclosure, correction, addition, deletion, cessation of use, and cessation of third-party provision of your retained personal data. Contact privacy@getreclaimapp.store. Response within 30 days.
South Korea — PIPA KR
Compliant with the Personal Information Protection Act (PIPA). Right to access, correct, delete, and suspend processing of your personal information. Contact privacy@getreclaimapp.store. Complaints: Personal Information Protection Commission of Korea (pipc.go.kr).
UAE, Saudi Arabia & Qatar GCC
Compliant with applicable data protection frameworks including the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, DIFC Data Protection Law 2020, ADGM Data Protection Regulations 2021, and applicable Saudi and Qatari regulations. Contact privacy@getreclaimapp.store for any data requests.
9. Children
The Reclaim Service is rated 17+ on the Apple App Store and is not directed to individuals under the age of 17. We do not knowingly collect personal information from children under 17. Age eligibility is enforced at the platform level through Apple's App Store age-gating system.
If you are a parent or guardian and believe your child under 17 has created a Reclaim account without your consent, please contact us immediately at privacy@getreclaimapp.store. We will verify the report and delete the account and all associated data promptly, typically within 48 hours of a verified report.
10. Changes to this policy
We reserve the right to update this Privacy Policy at any time. For material changes — those that significantly affect your rights or how we use your data — we will provide at least 14 days' advance notice by:
Email to the address associated with your account
In-app notification upon your next login
Non-material changes (such as typographical corrections or clarifications that do not affect your rights) may be made without prior notice. The "Last updated" date at the top of this page always reflects the most recent revision. Continued use of the Service after the effective date of any changes constitutes your acceptance of the revised policy. If you do not agree with a material change, you may delete your account before it takes effect.
11. Contact
Data / privacy requests:privacy@getreclaimapp.store — response within 5 business days; rights requests within 30 days