← Back

Privacy Policy

Version 2.0 · Effective 2026-09-01 (UTC)

This Privacy Policy describes how Dropping Alphas Media LLC, a Wyoming limited liability company, which operates the JournoReach platform, together with its affiliates, parent companies, subsidiaries, and successors (together “JournoReach,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects personal information when you use our website, applications, and services (collectively, the “Service”). It applies to all users of the Service worldwide.

It also applies to people who never signed up for the Service: journalists whose published queries we ingest, the recipients our system pitches to, and anyone named in a Persona or in a generated pitch. If that is you, Sections 1.1, 2.3, 3.1, 4.3, and 9.1 are the parts written for you.

If you are a California resident, Section 10 sets out your rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”), and serves as our Notice at Collection.

By using the Service you agree to the practices described in this Privacy Policy and our Terms of Service. If you do not agree, do not use the Service.

Plain-language summary: we collect what we need to run automated journalist outreach on your behalf. That includes your account info, the SMTP credentials and biographical content you upload for each Persona, and the pitches our system generates and sends.

Our system, not you, selects which journalist query a Persona is put in front of and determines the technical means by which a draft is produced, so for those steps we are a controller in our own right rather than a processor acting on your instructions — Section 1.1 sets out exactly which role applies to which activity. Pitch text is written by third-party AI models and is not read by anyone here before it is sent, so it can contain inaccurate statements about real people (Section 3.1).

We share necessary data with hosting, payment, automation, and AI providers. Nobody pays us for your data and we do not sell it for money. We do run Google Analytics on every page, and California law defines “sharing” widely enough that an ordinary analytics setup can fall inside it — Section 10.3 says so plainly instead of promising otherwise, and lists the ways to opt out. The record of a pitch — including who it was sent to — is kept after an account is closed, because it is the only evidence of what was sent in someone's name; Section 8 gives the reasons category by category and Section 8.1 explains how to ask us to erase it. SMTP passwords are encrypted at rest using AES-256-GCM with a key stored separately from the database — see Section 6 for the full details.

1. Who We Are

In plain English
The company is Dropping Alphas Media LLC; JournoReach is a product name, not a company. Our role changes depending on the activity, so we set it out activity by activity rather than claiming one label. We are the controller — we decide why and how — for your account and billing data, the journalist query database, the matching, the generation of pitch text, our own analytics, and the pitch records we keep after an account closes. We are your processor — acting on your instructions — for the Persona content you upload, the mail credentials you supply, and sending through your mailbox. For the matching-and-generation stage we are likely joint controllers with you under Article 26: whichever of us receives a request acts on its own part and passes on the rest. Being a controller is not the same as being the sender — the customer sends every pitch.
Key points only. The full section below gives the complete details, conditions, and exceptions.

The Service is provided by JournoReach, a product of Dropping Alphas Media LLC, a Wyoming limited liability company. We and our affiliates operate under the laws of the State of Wyoming, USA. JournoReach is a product name, not a company: the entity that holds your data, that you contract with, and that is answerable for the processing described in this Privacy Policy is Dropping Alphas Media LLC, a Wyoming limited liability company. Our postal address is in Section 15.

1.1 Our role: where we are a controller and where we are a processor

Data protection law distinguishes between a controller, who determines the purposes and the essential means of processing personal data, and a processor, who processes it on a controller's instructions. Our role is not the same across the whole Service, so we set it out activity by activity rather than claiming a single label for everything.

We are the controller — we decide why and how the processing happens — for:

  • Your account, billing, support, and security data. Here you are the data subject rather than another controller, and we decide the purposes: operating your account, taking payment, preventing abuse, and keeping our audit log.
  • Journalist query feeds. We choose which feeds to ingest, what to keep from them, how long to keep it, and how to make it searchable inside the Service. No customer instructs us to do any of this, so for the query database we are an independent controller.
  • Matching. Our automated pipeline decides which journalist query each Persona is put in front of, and how candidate matches are scored and filtered. You do not make that decision, cannot see the logic, and cannot direct its outcome.
  • Generation of pitch content. Our pipeline determines the means of generation: which Persona fields and which parts of the query are transmitted to a model provider, which model and prompt are used, and how the output is filtered. That determination is ours.
  • Our own analytics, service metrics, abuse prevention, and the retention of pitch records after an account is closed (Section 8). Those serve our purposes, not yours.

We act as your processor — on your instructions, with you as the controller — for:

  • Hosting and storing the Persona content you upload, including any personal data about another person that you choose to put into it;
  • Holding the SMTP credentials you supply and transmitting the finished pitch through the mailbox you supply, from your account and under your authority (Section 6);
  • Carrying out an export, correction, or deletion that you ask us to make in respect of that content.

For those activities you decide the lawful basis, and our instructions come from you and from our Terms of Service.

Joint controllership of the matching-and-generation stage. You decide whether to run a Persona at all, what expertise it represents, and when it is switched on; we determine who it is put in front of and the means by which a draft is produced. Because both of us determine part of the purposes and means of that single stage, we and you are likely to be joint controllers of it under Article 26 of the GDPR. The essence of that arrangement is this: we answer questions and requests about how matching and generation work, what data we hold about a journalist or recipient, and how to have it corrected or erased; you answer requests about your Persona, your relationship with the recipient, and anything you do with a reply. Whichever of us receives a request will act on the part that belongs to it and pass on the rest. A data subject may exercise their rights against either of us.

Being a controller is not the same as being the sender. Controllership describes who decides how personal data is processed. It says nothing about who sends, authors, or is answerable for the content of a pitch. We determine the means by which text is generated. We do not select, compose, review, or adopt the statements a pitch makes about any person. As set out in our Terms of Service, the customer is the sender of every pitch transmitted from their account, the mailbox and sending credentials used are theirs, and no employee, contractor, or agent of ours reads a pitch before it goes out.

For privacy-related inquiries, contact us at privacy@journoreach.com.

1.2 Our joint-controller arrangement (Article 26 GDPR)

Article 26 requires joint controllers to agree, in a transparent way, which of them does what — and to make the essence of that agreement available to the people whose data is involved. This section is that arrangement. It covers only the matching-and-generation stage identified in Section 1.1. Everything outside that stage is governed by the controller / processor split in Section 1.1, not by this section.

  • Telling people their data is being processed. We provide the information required by Articles 13 and 14 through this Privacy Policy, which is public and needs no account to read. You provide any notice owed to a person you already have a relationship with — someone you name in a Persona, or a recipient you already know.
  • Access, correction, erasure, restriction, objection, and portability. We answer requests about the journalist query database, how matching works and what it decided, and the personal data held in generated drafts and pitch records in our systems. You answer requests about your Persona, the copy of the message in your own mailbox, your relationship with the recipient, and anything you do with a reply.
  • Handing over what belongs to the other. Whichever of us receives a request acts on the part that belongs to it and passes the rest to the other without undue delay — and in any event in time for the other to meet the one-month deadline in Article 12(3). We tell the person we have done so.
  • Contact point. We are the designated contact point for data subjects for this stage: privacy@journoreach.com. Naming us as the contact point does not move responsibility for the items allocated to you above; it just means a person always has one address that works.
  • Security and personal data breaches. Each of us secures the systems under its own control. We detect, assess, and where required notify the supervisory authority and affected individuals about breaches in our infrastructure (Section 11), and we will tell you without undue delay about a breach affecting data of this stage. You must tell us without undue delay about any breach you become aware of involving your mailbox, your sending credentials, or your own systems, and you are responsible for the notifications arising from it.
  • Records and regulators. Each of us keeps its own record of processing for this stage and cooperates with a supervisory authority on request. We will give you the information you reasonably need about our part of the stage to answer a regulator or complete a data protection impact assessment.
  • You can always come to either of us. Under Article 26(3) a data subject may exercise their rights in respect of and against each joint controller, whatever we have agreed between ourselves. Nothing in this arrangement limits that, and we will not turn anyone away on the ground that their request “belongs” to the other side.

This arrangement allocates data protection work. It does not change who authors or sends a pitch — the last paragraph of Section 1.1 governs that — and it does not affect the allocation of liability between us in our Terms of Service.

1.3 Processing terms where we act as your processor (Article 28 GDPR)

Where we act as your processor (Section 1.1), Article 28(3) requires the relationship to be governed by terms covering a specific list of matters. These are those terms. They form part of your contract with us alongside our Terms of Service. If your own compliance programme needs a separate signed data processing agreement, write to privacy@journoreach.com and we will provide one.

  • Subject matter and duration. Subject matter: storing the Persona content you upload, holding your SMTP credentials, transmitting finished pitches through the mailbox you supply, and carrying out exports, corrections, or deletions you ask for. Duration: for as long as you have an account with us, plus the retention periods in Section 8.
  • Nature and purpose. Storage, hosting, access control, transmission, and deletion — carried out solely to operate the Service for you, and for no purpose of our own.
  • Type of personal data. Persona biographical content (name, job title, employer, professional background, areas of expertise, website and LinkedIn addresses, the headshot location you point us at, and signature content); SMTP host, port, username, and password; and the drafts and sent pitches held in your account.
  • Categories of data subject. The person each Persona represents; anyone named or described in Persona content or in a pitch; and, for the transmission step, the journalist or other recipient the pitch is sent to.
  • Documented instructions. We process this data only on your documented instructions. Your instructions are your use of the Service's features, the Terms of Service, this Privacy Policy, and any further written instruction we accept — including for transfers to a third country. If we are required by law to process otherwise, we will tell you before doing so unless the law forbids it. We will tell you if, in our opinion, an instruction infringes the GDPR or UK GDPR. Where we act as a controller in our own right (Section 1.1 — matching, generation, the query database, our analytics, and retained pitch records) we are not acting on your instructions and this paragraph does not apply to that processing.
  • Confidentiality of personnel. Access is limited to the people who need it to operate or support the Service. We require everyone with access to keep it confidential, and that obligation continues after their engagement with us ends.
  • Security (Article 32). We apply the technical and organisational measures described in Sections 6 and 11: encryption in transit, AES-256-GCM encryption at rest for SMTP passwords with the key held outside the database, Postgres row-level security, least-privilege administrative access, audit logging, and abuse controls at signup. We may change specific measures over time provided the overall level of protection is not reduced.
  • Sub-processors. You give us general written authorisation to engage the sub-processors listed in Section 5.1. We impose data protection obligations on each of them that are no less protective than these terms, and we remain fully liable to you for their performance. Before we add or replace one, we will update Section 5.1 and notify you of the change under Section 14. You may object on reasonable data protection grounds; if we cannot resolve your objection you may stop using the affected part of the Service and cancel under the Terms of Service.
  • Assistance with data subject requests. Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures in responding to requests from data subjects about the data we process for you. Your Persona content and pitch history are visible in your account at any time; for anything else, write to us and we will help. If we receive a request that plainly concerns your processing as controller, we will pass it to you rather than answer it ourselves — unless it also concerns processing where we are the controller, in which case Sections 1.2 and 9.1 apply.
  • Assistance with Articles 32 to 36. Taking into account the nature of the processing and the information available to us, we will assist you with security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority. We will notify you without undue delay after becoming aware of a personal data breach affecting the data we process for you, with the information we have at the time and the rest as it becomes available.
  • Deletion or return at the end. On termination of the Service, or on your written request, we delete the Persona content and SMTP credentials we hold for you; this happens as part of account deletion (Section 8), and backups are overwritten on the cycle described there. We delete rather than return, so if you want a copy, export it or ask us before you close the account. Two things survive, and we would rather be blunt about them than bury them: pitch records are retained by us as a controller, remain identifiable, and are not deleted by closing your account (Section 8 and our Terms of Service), and we keep whatever the law requires us to keep.
  • Information and audit rights. We will make available the information necessary to demonstrate compliance with this section, and allow for and contribute to audits or inspections conducted by you or an auditor you mandate. Reasonable terms apply: at least 30 days' notice, no more than once in any 12-month period unless a regulator requires it or there has been a breach affecting your data, during business hours, without unreasonable disruption to the Service, subject to confidentiality, and at your cost. Where a written response or a third-party report answers your question, we may offer that first.

2. Information We Collect

2.1 Information you provide to us

  • Account information: email address, password (hashed), full name, company name (optional).
  • Persona content: biographical information about each Persona you create, including name, job title, company, professional background, areas of expertise, website and LinkedIn URLs, and any photographs or signatures you upload.
  • SMTP credentials: the host, port, username, and password for the outbound email account associated with each Persona.
  • Communication content: support requests, feedback, and any correspondence you send us.
  • Payment information: when you subscribe, our payment processor (Stripe, Inc.) collects and processes your payment card details directly. We do not store your full card number; we only store a customer identifier, the last four digits, and metadata (subscription status, plan, billing amount) returned by Stripe.

2.2 Information we generate or collect automatically

  • Pitches: the AI-generated pitch content sent from your Personas, the recipient email address, the subject line, the message body, the timestamp, the result status, and any signature attached.
  • Usage data: log files, IP addresses, browser type, device information, referring URL, pages accessed, and timestamps. We use this for security, debugging, and analytics.
  • Cookies and similar technologies: session and authentication cookies required to keep you signed in, and Google Analytics 4 cookies (_ga and related) which Google sets to measure how the Service is used. Google Analytics records pages viewed, approximate location, device and browser, a randomly generated identifier, and a small number of events we tag ourselves — that a signup completed, for instance, with no name or email address attached to the event; we use it in aggregate to understand which parts of the product people actually use. We do not run advertising on the Service, we do not build a marketing profile of you from this data, and no money passes in either direction for it. What Google may do with it is a separate question: an Analytics property carries settings, in Google's console rather than in our code, that can permit Google to use the data for its own advertising purposes. Section 10.3 explains what that means under California law, and this Policy does not tell you those settings are switched off. Two opt-outs work regardless of how any of them are set — Google's browser add-on at tools.google.com/dlpage/gaoptout, and blocking cookies in your browser. Section 10.3 adds a third route: writing to us.
  • Audit log: we record administrative actions (account changes, persona changes, bans, trial grants, etc.) in an internal audit log including the actor, the timestamp, the IP address, and a description of the action.

2.3 Information from third parties

  • Stripe: subscription status, payment card metadata (brand, last four digits, fingerprint), customer identifier, and webhook events relating to your subscription.
  • Journalist query feeds: we ingest journalist requests published through media-query services (such as HARO, Source of Sources, Qwoted, MentionMatch, and DotStarMedia) and store them in our database. A stored query can include the journalist's name, email address, publication or outlet domain, the text of the request, the deadline, and the date we collected it. We collected this from the feed rather than from you, and we do not verify it. This Privacy Policy is the notice we provide about that collection: Section 4.3 explains the legal basis we rely on, Section 5.2 explains who can see it, Section 8 explains how long we keep it, and Section 9.1 explains your rights, including how to have your queries excluded from our database. To ask for exclusion or erasure, write to privacy@journoreach.com.
  • People named in Persona content or in a generated pitch: the Persona content our customers upload, and the pitch text our system generates from it, can name or describe other people — a colleague, a client, a co-author, or someone mentioned as an example. We do not collect that information from those people and we do not verify it. Section 3.1 explains what that means for accuracy, and Section 9.1 explains how to raise it with us.

3. How We Use Your Information

In plain English
The list below covers running the Service, sending your pitches, billing, support, security and analytics. The part worth reading twice is what follows it. Pitches are written by third-party language models, not by a person, and no employee, contractor or agent of ours reads, edits or approves a pitch before it goes out. Language models produce text that is plausible rather than verified, so a pitch can contain personal data that is simply wrong — a misattributed quotation, an invented credential or job title, a description of someone with no basis in the source material. We do not fact-check it, and once a message has left a customer’s mail server we cannot recall it. If a pitch about you is wrong, write to us with a copy: we will correct or erase what we hold, we may suspend the Persona or the account, and we may pass your request to the customer who sent it.
Key points only. The full section below gives the complete details, conditions, and exceptions.

We use the information described above to:

  • Provide, operate, and maintain the Service;
  • Authenticate the email account associated with each Persona via SMTP and send pitches from that account on your behalf;
  • Generate AI-written pitch content by sending Persona biographical information and journalist query text to third-party large language model providers;
  • Ingest, de-duplicate, store, and display journalist queries inside the Service so that customers can see what a journalist has asked for;
  • Decide which journalist query each Persona is matched to, and score, rank, and filter candidate matches;
  • Process payments, manage subscriptions, and send billing-related communications;
  • Communicate with you about your account, the Service, and product updates;
  • Respond to support requests and provide customer service;
  • Detect, prevent, and address technical issues, abuse, fraud, security incidents, and violations of our Terms of Service;
  • Comply with legal obligations, respond to lawful requests from public authorities, and enforce our agreements;
  • Generate aggregate, de-identified analytics about Service usage for product improvement and benchmarking.

3.1 AI-generated content and accuracy

Pitch content is written by third-party large language models, not by a person. We send the Persona's biographical details and the text of the journalist's query to the model provider, and the text that comes back is sent from the customer's own mailbox.

No employee, contractor, or agent of ours reads, edits, verifies, or approves a pitch before it is transmitted. That is a deliberate design of the Service, and it is disclosed here so that no one is surprised by it.

Language models produce text that is plausible rather than verified. A generated pitch can therefore contain personal data that is simply wrong: a misattributed quotation, an invented credential, qualification, or job title, an inaccurate description of what someone said or does, or a statement about a person with no basis in the source material. We do not fact-check generated content, and once a message has been sent through a customer's mail server we cannot recall it.

We are required to take reasonable steps to keep personal data accurate. In this context that means acting quickly on what we are told, because we cannot detect an inaccuracy ourselves. If you believe a pitch sent through the Service contains inaccurate personal data about you, write to privacy@journoreach.com with a copy of the message, or its subject line and date, and tell us what is wrong.

We will correct or erase the inaccurate data held in our systems, and we may suspend the Persona or the account involved. We may pass your request to the customer whose account sent the message — they are the sender and hold their own copy — where doing so is necessary to resolve your request and appropriate in the circumstances.

In plain English
For EU, UK and Swiss users, four bases: contract, legitimate interests, legal obligation, and consent where it is required. For the activities where we act as your processor, you are the controller and it is your job to identify the lawful basis — including for any personal data about someone else that you put into a Persona. Separately, we process data about people who never signed up: journalists whose published queries we ingest, the recipients we match to, and people named in Persona or pitch text. Where we control that, we rely on legitimate interests, and the balancing we carried out is set out below. You may object at any time, and for anything amounting to direct marketing we will stop without qualification.
Key points only. The full section below gives the complete details, conditions, and exceptions.

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR and UK GDPR. Which of them applies depends on the role we hold for the activity in question, as set out in Section 1.1.

4.1 Where we are the controller

  • Contract: processing necessary to perform our contract with you (these are most uses of your account and Persona data).
  • Legitimate interests: processing for our legitimate business interests such as fraud prevention, security, analytics, and product improvement, where those interests are not overridden by your rights and freedoms.
  • Legal obligation: processing necessary to comply with applicable law.
  • Consent: where required, we will ask for your consent (for example, for non-essential cookies or marketing communications).

4.2 Where we act as your processor

For the activities listed as processor activities in Section 1.1 — storing the Persona content you upload and transmitting pitches through the mailbox you supply — you are the controller and you are responsible for identifying a lawful basis. That includes a lawful basis for any personal data about a third party that you put into a Persona, and for your outreach to the recipient. We process that data only on your instructions and as described in this Privacy Policy and our Terms of Service.

4.3 Journalists, recipients, and other people who did not sign up

We process personal data about people who never created an account with us: journalists whose published queries we ingest, the recipients our system matches and pitches to, and people named in Persona content or in generated pitch text. Where we are the controller of that processing, we rely on legitimate interests (Article 6(1)(f) GDPR): our interest, and our customers' interest, in connecting a journalist who has publicly asked for expert sources with a source relevant to that request.

In carrying out the balancing exercise we have weighed, among other things, that:

  • the journalist published the query for the express purpose of receiving responses of this kind, so a response is within their reasonable expectations;
  • we ingest only what the journalist chose to publish through the feed, and we do not enrich it with data from other sources, sell it, or use it for advertising;
  • the data is used for the purpose it was published for, and the matching decision is taken on the subject matter of the query rather than on any profile of the individual;
  • a request to be excluded from our database is honoured, and is easy to make (Section 9.1).

We will provide a summary of our assessment on request. You may object at any time to processing based on legitimate interests, and to the extent any processing of your data amounts to direct marketing you have an absolute right to object and we will stop. Sections 9 and 9.1 explain how.

5. How We Share Your Information

In plain English
We do not sell your personal information for money. Who receives it: our hosting and database provider, our application host, our payment processor, our automation engine, the large language model providers that write the pitches, our transactional email provider, and a private staff channel that receives operational alerts.Pitches go through your own mail server, not ours. One entry deserves attention: Google Analytics. Settings in Google’s console — not in our code — govern whether Google may also use that data for its own purposes. Where such a setting is on, Google is not acting solely on our behalf, and the disclosure may count as “sharing” as California law defines it. We do not claim those settings are off. Section 10.3 explains what follows from that.
Key points only. The full section below gives the complete details, conditions, and exceptions.

We do not sell your personal information for money. Nobody pays us for it and we do not offer it for sale. We disclose it only as described below. One of those disclosures — web analytics — may count as “sharing” in the technical sense California law gives that word, even though no money changes hands and we run no advertising; Section 10.3 sets that out in full rather than leaving you to infer it.

5.1 Service providers (sub-processors)

We disclose personal information to third-party vendors who process it on our behalf under contractual obligations to protect it. These currently include — with Google Analytics as the one entry where “on our behalf” may not be the whole story, as that entry explains:

  • Supabase, Inc. — database, authentication, and file storage hosting. All account data, Persona data, SMTP credentials, and pitch history are stored on Supabase infrastructure.
  • Vercel Inc. — application hosting, serverless function execution, and edge content delivery.
  • Stripe, Inc. — payment processing, subscription management, and card-fingerprint-based fraud prevention. Stripe's privacy policy applies to the payment data they collect directly from you.
  • n8n GmbH (or our self-hosted n8n instance): automation workflow engine that fetches active Personas, generates pitches, and sends them via SMTP. n8n has read access to Persona data including SMTP credentials and writes pitch results back to our database.
  • Google LLC, Anthropic, PBC, and OpenAI, OpCo, LLC: large language model providers that generate pitch content. We send Persona biographical information and journalist query text to these providers via their APIs. Which provider handles a given pitch depends on the model selected for that stage of our pipeline, and we may change providers as models change. These providers may temporarily process the request data on their infrastructure. We access these models through their commercial APIs and rely on each provider's API terms, which govern whether submitted data may be used to improve or train their models; those terms are set by the provider and may change.
  • Google LLC (Google Analytics 4): measures how the Service is used. Google receives pages viewed, approximate location derived from IP, device and browser details, a randomly generated identifier stored in a cookie on your device, and the events described in Section 2.2. We do not send it your name, your email address, or your account identifier. We use the results only in aggregate, and we neither pay for nor receive money for the data. Google Analytics properties carry settings, configured in Google's console rather than in our code, that govern whether Google may also use the data for its own purposes, including advertising. Where such a setting is enabled, Google is not acting solely on our behalf for that use, and the disclosure may amount to “sharing” for cross-context behavioural advertising as California law defines it. This Policy does not represent that those settings are disabled — Section 10.3 explains the consequence and Section 2.2 gives the opt-outs that work either way.
  • Outbound pitches — your own mail server: pitches are relayed through the SMTP server you specify in the Persona's credentials, using your own mail provider. We do not route pitches through any centralized email service of our own, and your mail provider's privacy policy governs messages sent through it.
  • Resend, Inc.: delivery of the transactional email we send to you — account verification, welcome, billing, trial, support-ticket, and report emails. Resend is not involved in sending pitches.
  • Internal operational alerts: we send ourselves automated alerts about events such as a new signup, a subscription change, a Persona awaiting review, or a support ticket. These alerts can contain an account email address and the content of a support message, and are delivered to our own staff mailbox and to a private Discord channel operated by Discord Inc. that only our staff can access.
  • Google reCAPTCHA: we use Google reCAPTCHA on the signup form to prevent automated abuse. Google's use of data collected via reCAPTCHA is governed by the Google Privacy Policy.

5.2 Journalist queries and recipients of pitches

Queries inside the Service. The journalist queries we ingest, including the journalist's name, email address, and outlet, are visible to signed-in customers in the query browser. They are also supplied to the automation workflow that matches them to Personas. They are not published on the open web, sold, or made available to anyone who is not a customer or one of the service providers listed above.

Pitches. When a Persona is enabled and the system sends a pitch, the contents of that pitch (including the Persona's name, photograph, signature, and biographical information) are transmitted to the journalist or recipient our pipeline matched it to. The message is sent from the customer's own mailbox, and the recipient may store, share, forward, or publish its contents. We have no control over what they do with it.

5.3 Legal requests and protection of rights

We may disclose your information if we believe in good faith that disclosure is necessary to (a) comply with a subpoena, court order, search warrant, or other legal process; (b) protect our rights, property, or safety, or the rights, property, or safety of our users or others; (c) detect, prevent, or address fraud, security, or technical issues; or (d) enforce our Terms of Service.

5.4 Business transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, your information may be transferred as part of that transaction. You will be notified by email or via a prominent notice on the Service of any change in ownership.

5.5 Aggregated or de-identified information

We may share aggregated or de-identified information — information stripped of identifiers so that it can no longer reasonably be linked to you, to your Personas, or to any other individual — with third parties for research, benchmarking, product analytics, and marketing of our own Service. Typical examples: the total number of pitches sent across the platform in a month, average response rates by industry, or the proportion of queries that arrive from a given feed.

De-identified data is only genuinely de-identified if someone commits to keeping it that way, so we make the commitments that California law (Cal. Civ. Code § 1798.140(m)) requires of anyone relying on that status:

  • we take reasonable measures to ensure the information cannot be associated with a consumer or household;
  • we publicly commit — here, in this Privacy Policy — to maintain and use the information only in de-identified form, and not to attempt to re-identify it, except that we may attempt re-identification solely to test whether our own de-identification works, and we do not use the result of any such test for any other purpose;
  • we contractually require anyone we give it to, to do both of the above and not to re-identify it or combine it with other data in order to do so.

Information that satisfies those conditions is not personal information, and this Privacy Policy does not otherwise restrict our use of it. Information that does not satisfy them is personal information and is governed by the rest of this Policy.

The analytics data described in Section 5.1 is not covered by this section. It carries a randomly generated identifier tied to your device, so we do not treat it as de-identified and we do not rely on this section to justify it. It is personal information, and Sections 5.1, 10.1 and 10.3 describe it as such.

6. SMTP Credentials — Storage and Access

When you create a Persona, you provide the SMTP host, port, username, and password for the email account that will be used to send pitches on the Persona's behalf. The following describes how those credentials are stored, who can access them, and the inherent limits of what we can protect. We hold these credentials as your processor (Section 1.1): they are yours, they authenticate your mailbox, and we use them only to send from it at your direction.

  • Encryption at rest: SMTP passwords are encrypted using AES-256-GCM (a standard authenticated symmetric cipher) before they are written to our database. The encryption key is a 256-bit secret stored only in our application's server environment variables — it is not stored in the database, in our source code repository, or in any database backup. A leaked database backup, by itself, contains only ciphertext that cannot be decrypted without the key.
  • Encryption in transit: all communication with the Service occurs over HTTPS / TLS. Your password is transmitted from your browser to our server in plaintext over this encrypted channel. It is then encrypted server-side, and the resulting ciphertext is what gets persisted.
  • Access controls: credentials are additionally protected by Postgres row-level security (RLS) policies that restrict access to (a) the account that owns the Persona, (b) authorized JournoReach administrative personnel, and (c) the service-role key used by our backend and our automation workflows. The public anon key that ships with our frontend application has no access to the credentials at all.
  • Who can decrypt them in practice: our automated pitch-sending system (which must decrypt the password to authenticate with your SMTP server), our authorized staff for support and debugging purposes, and any legal authority that compels disclosure. Anyone who simultaneously compromises our application's environment variables and our database can decrypt the credentials; anyone with only one of those cannot.
  • You cannot view your own SMTP password after saving it. The application UI lets you set a new password, but never displays the existing one. This is intentional — the plaintext password is never sent back to your browser after the initial save.
  • Recommended practice: we still recommend creating a dedicated email account or app-specific password (such as a Gmail App Password) for use with the Service, rather than using credentials that protect other sensitive systems. This limits the blast radius if anything ever goes wrong.

By providing SMTP credentials to the Service, you acknowledge and accept the storage, encryption, and access conditions described above.

7. International Data Transfers

The Service is operated from the State of Wyoming, USA. Our service providers are located in various countries including the United States, the European Union, and the Asia-Pacific region. By using the Service, you consent to the transfer of your personal information to these countries, which may have data protection laws different from those of your country of residence. Where required by law, we put in place appropriate safeguards (such as the European Commission's Standard Contractual Clauses) to protect personal information transferred internationally.

8. Data Retention

In plain English
Data protection law sets no maximum period; the rule is that identifiable data is kept no longer than necessary, and that we can say why. Rather than quote a number we do not apply, this section goes category by category. Deleted when the account goes: your profile, Persona content and mail credentials, support tickets, and affiliate records. Kept after the account goes: pitch records — identifiable, not anonymised, and keyed to a mailbox rather than a user ID, so deleting an account does not remove them — along with journalist queries, the audit log, and the record of your acceptance of these documents. Each is kept for a stated purpose, including being able to answer for what was actually sent when someone complains about it. Section 8.1 explains what “indefinitely” means in practice and how to challenge it.
Key points only. The full section below gives the complete details, conditions, and exceptions.

Data protection law does not impose a maximum retention period. It requires that personal data be kept in a form that identifies people no longer than is necessary for the purposes it is processed for, and that we be able to say what those purposes are. So instead of quoting a number we do not actually apply, this section sets out category by category what we keep, why we keep it, and what closing an account does and does not reach. Section 8.1 explains what “indefinitely” means in practice and how to challenge it.

Deleted when the account or the item goes. Closing an account is a real deletion for everything in this group:

  • Account and profile data — the row in app_profiles, including your name, billing state, preferences, and any unfinished onboarding draft. Deleted when the account is deleted. We do not purge accounts that are simply inactive: while you hold an account, we keep what is needed to run it.
  • Persona content and SMTP credentials — the rows in app_personas, including the encrypted SMTP password. Deleted when you delete the Persona, and in any event when the account is deleted. This is the material we hold as your processor (Sections 1.1 and 1.3), and it is the material you can have removed at any time without asking us.
  • Support tickets and correspondence — deleted with the account.
  • Affiliate, referral, commission, and payout records — deleted with the account of the affiliate or the referred customer they belong to.

Retained after the account closes. Five categories survive, and each is retained for a purpose that itself survives. Where we rely on legitimate interests (Article 6(1)(f) GDPR) we have weighed the interest against the effect on the people concerned, and we will provide a summary of that assessment on request:

  • Pitch records — retained, identifiable, and not anonymised. A row in app_completed_answers holds the pitch text, subject line, and signature, the Persona's name and sending address, the recipient journalist's name and address, the query it answered, and the send result. It is keyed to a Persona by email address rather than to a user ID, so it is not removed when the account that created it is deleted. We hold it as a controller in our own right, for these purposes:
    • To be able to answer for what the Service transmitted. Pitches are written by a language model and sent from a customer's own mailbox with nobody here reading them first (Section 3.1). The pitch record is the only copy we hold of what actually went out. When a journalist, or someone named in a pitch, tells us a message about them was wrong, that record is what lets us check the claim, correct our copy, identify which Persona and account sent it, and give that person a straight answer under Sections 3.1 and 9.1. Our Terms of Service require customers to tell us promptly when a pitch turns out to have been inaccurate, misleading, or unlawful — an obligation that presupposes the record still exists and still says who sent what to whom.
    • Establishment, exercise, and defence of legal claims. A complaint about a message can arrive long after it was sent, and the limitation periods for claims about published statements run for years. Destroying the only record of the message would leave us, the customer who sent it, and the person complaining about it with nothing to reason from.
    • Security, abuse prevention, and enforcement. Because the record is keyed to a mailbox rather than to an account, it is what lets us recognise a sending address that was already suspended for abuse when it reappears behind a new account.
    • Operating and monitoring the pipeline. Send outcomes, failure rates, and volumes feed our automated health checks and the pitch history shown in your own account.
    We have considered whether a less identifying record would serve those purposes and concluded that it would not. A pitch record with the sender and the recipient stripped out cannot answer the only questions it exists to answer. That is why these records are not anonymised, and our Terms of Service say so in the same words rather than leaving you to infer it. Erasure can still be requested under Section 9 or 9.1, and Section 8.1 explains how we handle such a request.
  • Journalist queries. The rows in app_queries — the journalist's name and address, the outlet, the request text, the deadline, and when we collected it — are kept as a historical corpus. They are the other half of every pitch record: a pitch cannot be assessed without the query it was answering. They are also what we de-duplicate incoming feeds against, what the in-product query browser shows for past dates, and what we measure matching quality on. Basis: legitimate interests, assessed in Section 4.3. A journalist can have their queries erased, and future ones excluded from matching, under Section 9.1 — that request is honoured, not balanced away.
  • Matching and scoring records. Before a pitch is drafted, our pipeline writes a working record of each stage: the Persona considered, the query it was scored against, the journalist's name and address carried over from that query, the score or relevance decision, and the model's stated reasoning. We keep these to measure and diagnose the matching pipeline, and to explain a matching decision to anyone who asks about one. Basis: legitimate interests. We should be straightforward that these are working records rather than something anyone needs kept forever, and they are the first category we would expect to shorten under the review described in Section 8.1.
  • Records of your acceptance of these documents. When you accept our Terms of Service or this Privacy Policy we record who accepted, when, which version, the IP address and browser, and — where we have it — a hash of the exact text shown. That record is deliberately kept when an account is deleted, with the email address of the person who accepted, so that it remains attributable. The reason is narrow and, we think, obvious: a dispute about whether somebody agreed to something usually arises after they have gone, and a consent record that dies with the account is not a consent record. Basis: legitimate interests in the establishment and defence of legal claims. It contains nothing beyond what proving the acceptance requires.
  • Audit log. We record privileged and destructive administrative actions — bans, deletions, trial grants, credential tests, persona approvals — with the actor, the timestamp, the IP address, and what was affected. Entries are kept after the account they concern is deleted, because the deletion is itself one of the logged actions and an audit trail that can be shortened by deleting the subject is worthless. We use it to investigate security incidents, to resolve disputes about what was done to an account and by whom, and to demonstrate our own accountability. Basis: legitimate interests in the security and integrity of the Service. It is a record of what administrators did, not a profile of how anyone uses the Service.

Held outside our own database. Two categories are on someone else's schedule rather than ours:

  • Server, platform, and analytics logs — retained by our hosting providers under their standard settings, and by Google under the retention setting on our Analytics property. We do not copy them into any longer-term store of our own.
  • Backups — deleted data persists in our database host's backups until the backup containing it ages out of their rotation, which is not more than 90 days. We do not restore a backup in order to recover data somebody asked us to delete.

8.1 What “indefinitely” means, and how to challenge it

“Indefinitely” means the purposes set out above have no fixed end date, so we have not invented one. It does not mean the data is beyond your reach, and it does not mean we have stopped thinking about it. The mechanics, stated plainly:

  • We do not run a scheduled deletion job. Nothing in our systems erases a pitch record, a stored query, an acceptance record, or an audit entry on a timer. We would rather tell you that than publish a retention period we do not keep to. Erasure happens because somebody asks for it and we act, or because we decide a purpose has ended.
  • We review whether each purpose still holds — at least whenever we revise this Policy or materially change how the Service works — and we delete what we can no longer justify keeping.
  • You can ask us to erase it, and we will assess the request rather than refuse it. Section 9 explains how, and Section 9.1 covers you if you are not a customer. We weigh what you ask against the specific purpose stated above for that category, not against a blanket policy. Where the purpose does not apply to your data, or has stopped applying, we delete it. Where we do rely on a purpose to keep something, we will tell you which one and why — and where restricting the data protects you as well as deleting it would, we will restrict it instead (Article 18 GDPR), which means we keep it but stop using it.
  • If we adopt a fixed retention period, or start truncating older records, we will state the period here. The absence of a number in this section is not an oversight.

9. Your Rights

In plain English
Access, correction, deletion, portability, restriction, objection, and withdrawal of consent, depending on where you live. Write to the privacy address and we will respond within 30 days. These rights are not limited to our customers. You do not need an account and we will not ask you to create one — which matters if you are a journalist whose query we hold, or someone named in a pitch. You can ask to be excluded from our query database, for a copy of what we hold, for correction or erasure of an inaccurate AI-generated statement about you, or object to the processing altogether. Some of what you may want sits with the customer who sent the message rather than with us; we will act on our part and pass on the rest, and tell you we have done so. If you want the pitches to stop, telling us is the fastest route — we can disable the Persona.
Key points only. The full section below gives the complete details, conditions, and exceptions.

Depending on where you live, you may have some or all of the following rights with respect to your personal information:

  • Access: request a copy of the personal information we hold about you;
  • Correction: request that we correct inaccurate or incomplete information;
  • Deletion: request that we delete your personal information, subject to certain exceptions (e.g., we may retain information necessary to comply with legal obligations or to defend legal claims);
  • Portability: request a copy of your personal information in a structured, commonly used, machine-readable format;
  • Restriction: request that we restrict the processing of your personal information in certain circumstances;
  • Objection: object to our processing of your personal information based on legitimate interests;
  • Withdrawal of consent: withdraw any consent you have previously given.

To exercise any of these rights, contact us at privacy@journoreach.com. We will respond within 30 days, and where a request is complex or we receive a number of requests from you, we may extend that period as permitted by applicable law, and will tell you if we do.

We may need to verify your identity before processing your request. If you are dissatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

California residents have a further set of rights, with their own deadlines and their own rules about authorised agents. Those are set out separately in Section 10.

9.1 If you are a journalist, a pitch recipient, or someone named in a pitch

These rights are not limited to our customers. You do not need an account with us to exercise them, and we will not ask you to create one. Write to privacy@journoreach.com and tell us which of the following you want:

  • Exclusion from our query database: we will erase the queries of yours that we hold and take reasonable steps to prevent future ones from being matched to any Persona.
  • Access: a copy of what we hold about you, including the queries stored against your name or address and, where we can identify them, the pitches sent to you through the Service.
  • Correction or erasure of inaccurate AI-generated statements about you — see Section 3.1, which explains what we do and what we cannot do once a message has been sent.
  • Objection: you may object to the processing described in Section 4.3. We will stop unless we can demonstrate compelling legitimate grounds that override your interests; for anything amounting to direct marketing, we will stop on request without qualification.

Some of what you may want sits with the customer rather than with us — they are the sender of the message, they hold their own copy of it, and they decide what to do with any reply. Where that is the case we will act on the part that belongs to us and pass the rest on, and we will tell you that we have done so. If you want a pitch to stop, the fastest route is to tell us: we can disable the Persona.

10. California Privacy Rights (CCPA/CPRA)

In plain English
This is our Notice at Collection for California, and it covers everyone whose information we handle there — customers, journalists whose queries we ingest, and people who receive or are named in a pitch. Four words in it are wider than everyday usage: personal information, sensitive personal information, sale(any valuable consideration, not just money), and sharing (disclosure for cross-context behavioural advertising, whether or not anyone is paid). We do not sell for money, but the analytics disclosure in Section 5 may fall inside that last definition. The rest of the section lists the statutory categories, where each came from, what we use it for, and how long we keep it.
Key points only. The full section below gives the complete details, conditions, and exceptions.

This section applies if you are a California resident. It is our Notice at Collection under Cal. Civ. Code § 1798.100(a) as well as the fuller notice required by § 1798.130(a)(5), and it applies to everyone whose personal information we handle in California — customers, journalists whose queries we ingest, and people who receive or are named in a pitch.

Four words in this section carry legal meanings that are wider than everyday usage. Personal information means anything that identifies or could reasonably be linked to you or your household. Sensitive personal information is a defined sub-set (Cal. Civ. Code § 1798.140(ae)) — see Section 10.2. Sale means disclosing personal information to a third party for money or any other valuable consideration, which is much broader than selling a list. Sharing has nothing to do with sharing in the ordinary sense: it means disclosing personal information for cross-context behavioural advertising, whether or not anyone is paid. Because the word reaches that far, a routine web-analytics installation can land inside it while an ordinary reader would never call it sharing. Section 10.3 deals with ours directly.

Where we handle personal information as a service provider or contractor to one of our customers — the activities listed as processor activities in Section 1.1 — we use it only to perform the Service for that customer. If your request concerns data a customer put into a Persona, send it to us anyway: we will act on our part and pass the rest to them, as described in Sections 1.2 and 9.1.

10.1 What we collect, where it comes from, why, and for how long

The categories below are the statutory CCPA categories, not our own labels, so you can compare this notice with anyone else's. Section 2 describes the same information in plainer terms and Section 8 sets out our retention rules in full.

  • Identifiers — name, email address, account identifier, IP address, and cookie identifiers (our session and authentication cookies, our referral-tracking cookie, and Google Analytics cookies); for journalists, the name and email address published with a query. Sources: you, your device, Stripe, and media-query feeds. Purposes: operating your account, authentication, matching, billing, support, security and abuse prevention, and analytics. Retention: for the life of the account; journalist queries, audit-log entries, records of your acceptance of these documents, and pitch records are retained indefinitely, on the criteria set out in Sections 8 and 8.1.
  • Customer records (Cal. Civ. Code § 1798.80(e)) — name, email address, and payment card metadata (brand, last four digits, fingerprint). We never hold your full card number. Sources: you and Stripe. Purposes: taking payment, managing your subscription, and detecting card reuse across accounts. Retention: for the life of the account, plus what we need to keep for tax and accounting purposes or to defend a legal claim.
  • Commercial information — plan, subscription status, billing amount, number of Personas, and trial and payment history. Sources: you and Stripe. Purposes: providing and billing for the Service. Retention: as for customer records above.
  • Internet or other electronic network activity — log files, pages viewed, browser and device information, referring URL, timestamps, and the administrative actions recorded in our audit log. Source: collected automatically. Purposes: security, debugging, and analytics. Retention: the audit log is retained indefinitely, on the criteria set out in Sections 8 and 8.1; server and platform logs are retained for as long as our hosting providers keep them under their standard settings, and we do not copy them into any longer-term store of our own.
  • Geolocation data (approximate only) — a coarse location inferred from your IP address by Google Analytics. We do not collect precise geolocation. Source: collected automatically. Purpose: aggregate analytics and security. Retention: held by Google under the retention setting on our Analytics property; we do not store it separately.
  • Visual information — the headshot you point us at for a Persona (we store the link, not a copy of the image file) and the signature content attached to your pitches. Source: you. Purpose: including them in the pitches sent from your Personas. Retention: for the life of the Persona; a copy embedded in a message that has already been sent persists in our pitch record and in the recipient's mailbox, and we cannot recall the latter.
  • Professional or employment-related information — a Persona's job title, employer, professional background, areas of expertise, and professional profiles; and, for journalists, the outlet or publication attached to a query. Sources: you, and media-query feeds. Purposes: matching a Persona to a query and generating pitch content. Retention: for the life of the Persona; queries and pitch records indefinitely, on the criteria set out in Sections 8 and 8.1.
  • Sensitive personal information — see Section 10.2, which sets out exactly what we hold, why, and what the right to limit does and does not reach.
  • Inferences — we do not build a profile of anyone's personality, preferences, intelligence, aptitudes, or behaviour. Our matching pipeline produces a relevance score that compares the subject matter of a Persona with the subject matter of a query. We treat that score as information about the match rather than about a person, and it is retained with the tracking record for that match.
  • Categories we do not collect at all — protected classification characteristics, biometric information, education information, and precise geolocation.

10.2 Sensitive personal information, and the right to limit its use

We collect two categories of sensitive personal information. We would rather name them plainly than let you discover them:

  • Account log-in credentials. The SMTP username and password for the mailbox each Persona sends from are credentials that allow access to an account, which makes them sensitive personal information under Cal. Civ. Code § 1798.140(ae). We use them to authenticate to your mail server so that a pitch can be sent from it, and our authorised staff can decrypt them for support and debugging. We never use them to infer anything about anyone. Section 6 sets out how they are encrypted, exactly who can decrypt them, and what we recommend you do to limit your exposure.
  • The contents of email where we are not the intended recipient. The pitches our system drafts and sends — the subject line, the body, and the signature — are email contents addressed to a journalist, not to us. We hold them to operate the Service, to show you your own pitch history, and for the analytics, audit, and abuse prevention described in Section 3.

The right to limit. Under the CCPA, the right to limit the use of sensitive personal information applies where a business uses it to infer characteristics about a consumer. We do not do that. We use both categories only to perform the Service that was requested and to maintain its security and integrity — purposes the CCPA expressly excludes from the limitation right — so we do not display a “Limit the Use of My Sensitive Personal Information” link, because there is no additional use for it to switch off.

If you want us to stop holding these anyway, the practical remedies are real ones: delete the SMTP credentials from a Persona, or delete the Persona, and we will erase them. Email us and we will do it for you. Removing sending credentials stops that Persona pitching, which is the trade-off. If we ever start using sensitive personal information to infer characteristics, we will add the limitation link before we do.

10.3 Sale, sharing, and how to opt out

  • We do not sell personal information for money. No one pays us for personal information, we do not offer it for sale, and we have not done so in the 12 months before the effective date of this Policy.
  • We will not tell you that no “sharing” occurs, because we would be guessing. Google Analytics runs on every page of the Service (Sections 2.2 and 5.1). Whether the data it collects reaches Google for Google's own advertising purposes is controlled by settings inside Google's Analytics console — not by anything in our code — and where those settings are enabled the disclosure can meet the statutory definition of “sharing” for cross-context behavioural advertising in Cal. Civ. Code § 1798.140(ah). That is a technical meaning: it does not imply we sold anything, ran an ad, or handed anyone a mailing list. This Policy makes no representation that those settings are switched off, and we would rather write this paragraph than an assurance we cannot stand behind. Treat our use of analytics as sharing that may be happening, and use the routes below if you do not want it.
  • How to opt out. Two routes work from your own browser whatever is set on our side, and they are the reliable ones, because the analytics identifier is a cookie on your device rather than anything attached to your account: install Google's opt-out add-on, or block cookies (both in Section 2.2). The third route is to tell us — email privacy@journoreach.com with “Do Not Sell or Share My Personal Information” in the subject line and we will treat it as a request under Cal. Civ. Code § 1798.120, act on what is within our control, and write back telling you what we did and anything we could not do. That email address is the request method we offer: there is no toggle or link on the site, and no automated mechanism behind it. We say so rather than imply one exists.
  • We do not knowingly sell or share the personal information of consumers under 16. The Service is for adults only (Section 12).
  • Disclosed for a business purpose in the last 12 months. Every category in Section 10.1, including both categories of sensitive personal information, has been disclosed to service providers and contractors in these categories: database and authentication hosting; application and edge hosting; payment processing; automation and workflow execution; large language model providers; web analytics; transactional email delivery; and anti-abuse and bot-detection. Section 5.1 names each of them individually. Each is engaged under terms that limit what they may do with the information to performing the service we engaged them for — with the web-analytics exception described above, where the provider's own settings may permit wider use.
  • Disclosed to parties who are not our service providers. The recipient of a pitch — a journalist receives the Persona's name, headshot, role, biography, and the pitch text, because that is the entire point of the Service (Section 5.2); legal and governmental authorities, in the circumstances described in Section 5.3; a buyer or successor in the circumstances described in Section 5.4; and, to the extent set out above, our analytics provider.
  • Global Privacy Control. There is no code anywhere in the Service that reads the GPC browser signal, so sending it changes nothing on our side by itself. We would rather state that than let you assume a signal you send is being acted on. If you send GPC and want it honoured, email us as described above and we will handle it by hand; and the two browser-side routes in Section 2.2 stop the analytics collection whether or not we ever read the signal.
  • Shine the Light (Cal. Civ. Code § 1798.83). We do not disclose the categories of personal information that statute covers — your name, postal address, email address and the like — to third parties for those third parties' own direct marketing purposes. None of that is sent to our analytics provider.

10.4 Your California rights

  • Know and access. Ask us for the categories of personal information we have collected about you, the sources, the business or commercial purposes, the categories of third party we disclosed it to, and the specific pieces of information themselves. You may make this request twice in any 12-month period, free of charge. For information collected on or after 1 January 2022 you may ask us to look back further than 12 months, and we will go back as far as our records reasonably allow.
  • Delete. Ask us to delete the personal information we collected from you. The CCPA allows us to keep some of it — to complete a transaction you asked for, for security and integrity, to fix errors, to comply with a legal obligation, or to exercise or defend legal claims. Where we do keep something we will tell you which category and why. Three exceptions are important enough to state up front: pitch records remain identifiable and survive account deletion, as do the record of your acceptance of these documents and the audit-log entries about your account. Section 8 gives the specific purpose we rely on for each, and Section 8.1 explains how we assess a request to erase them anyway.
  • Correct. Ask us to correct inaccurate personal information. If the inaccuracy is in AI-generated pitch content, Section 3.1 explains what we can and cannot do once a message has already been sent.
  • Opt out of sale or sharing. Available to you as a matter of right. We do not sell personal information for money, but we do not claim that no sharing occurs: our analytics setup may fall inside the statutory definition, for the reasons in Section 10.3. That section gives you three routes to opt out — two that work from your own browser, and an email request we action by hand.
  • Limit the use of sensitive personal information. See Section 10.2 for why this right does not attach to our use of it, and what we will do instead if you ask.
  • Non-discrimination. We will not deny you the Service, charge you a different price, give you a lower quality of service, or suggest we might, because you exercised any of these rights. We do not offer financial incentives in exchange for personal information.

10.5 How to exercise these rights

  • Where to send it. Email privacy@journoreach.com with “California privacy request” in the subject line. Tell us which right you are exercising and give us enough to find you — the email address on your account, or, if you are not a customer, the address a pitch was sent to or the address your query was published under. You do not need an account, and we will not ask you to create one.
  • Verification. We verify a request by matching what you give us against what we already hold. For a request for specific pieces of information we will ask you to confirm from the email address the information is associated with. If we cannot verify you to a reasonable degree of certainty we will say so rather than release someone else's data.
  • Timing. We acknowledge a request within 10 business days and respond within 45 calendar days. If we need more time we may extend once by a further 45 days and will tell you why within the first 45.
  • Authorised agents. An agent may submit a request for you if they give us written permission signed by you, or a power of attorney under Cal. Prob. Code §§ 4000–4465. Unless they hold a power of attorney, we may also ask you to verify your own identity with us directly and to confirm that you gave the agent permission. We will decline bulk agent submissions that come with neither.
  • If we say no. We will tell you which exception we are relying on. You may complain to the California Privacy Protection Agency or the California Attorney General.

11. Security

We implement reasonable technical and organizational measures designed to protect your personal information against unauthorized access, accidental loss, alteration, and disclosure. These measures include:

  • HTTPS encryption in transit;
  • Database-level access controls and Row-Level Security policies enforced by Postgres;
  • Restricted administrative access on a need-to-know basis;
  • Secret rotation and credential management practices for our service providers;
  • Audit logging of administrative actions;
  • Disposable email blocking and reCAPTCHA at signup to limit automated abuse.

However, no method of transmission over the internet or storage system is 100% secure. We cannot guarantee absolute security. As described in Section 6, SMTP passwords are encrypted at rest with AES-256-GCM, but our automated systems and authorized staff can still decrypt them when necessary to operate the Service. You provide your information to us at your own risk and should consider the sensitivity of the credentials you provide.

If we become aware of a personal data breach affecting your information, we will notify you and any applicable regulator as required by law.

12. Children's Privacy

The Service is not directed to children under the age of 18. We do not knowingly collect personal information from children under 18. If you are aware that a child has provided us with personal information, please contact us and we will take steps to delete it.

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read the privacy policy of every website you visit.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on the Service before the changes take effect. The revised Privacy Policy will be effective on the date posted (or such later date as specified). Your continued use of the Service after the effective date constitutes your acceptance of the revised Privacy Policy.

15. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or our handling of your personal information, please contact us at privacy@journoreach.com, or write to us at the address below.

Dropping Alphas Media LLC
30 N. Gould Street, Suite R
Sheridan, WY 82801
United States
privacy@journoreach.com

Version 2.0 · Effective 2026-09-01 (UTC)