Last updated: July 19, 2026

Privacy Policy

The French version is the authoritative version. This English version is provided for information only.

This policy describes how TheFactory Labs (“we”) processes personal data as controller in connection with the HyperReach service, in line with the EU General Data Protection Regulation (GDPR).

1. Data controller

TheFactory Labs, SAS, RCS Paris 106 474 638, 61 rue de Lyon, 75012 Paris, France. Contact: contact@gethyperreach.com.

2. Data we collect

  • Account data: email address, OAuth sign-in identities (X, Google).
  • X access tokens: stored encrypted, used to read and publish on your behalf via X's official API.
  • Voice profile and knowledge base: style examples, offers, expertise and links you provide to calibrate suggestions.
  • Generated drafts and your edits: kept to improve suggestion quality and measure outcomes.
  • Usage and credit data: consumption counters, billing history via Stripe.
  • Support data: exchanges with our team when you request assistance.

3. Third-party public data collected by the radar

To surface reply opportunities, the service collects public X posts and public author profiles (via TwitterAPI.io), based on your niche and keywords.

Legal basis: legitimate interest, namely helping you identify public conversations relevant to your activity.

This data is retained for a bounded period, as needed for the radar to function.

Rights of concerned third parties: anyone whose public post appears in the service may request exclusion or deletion of their data by contacting us at contact@gethyperreach.com.

Influencer prospecting: under the same conditions (public data, via TwitterAPI.io), the service identifies public X creators for potential commercial partnerships and may initiate professional outreach directly related to their activity. Legal basis: legitimate interest. These profiles are retained for 3 years from their last review, then automatically purged. Anyone concerned may object at any time to being included in this prospecting, without justification, by contacting us at contact@gethyperreach.com or via the opt-out link included in every outreach message; objecting permanently excludes the account from both discovery and outreach.

4. The extension sensor (optional signal sharing)

The HyperReach browser extension reads the public posts on your x.com pages to show its companion widget. Nothing is collected or sent anywhere by default.

Optional signal sharing, off by default: if you opt in, HyperReach records which public posts you see on x.com: the post's id, its author, the time, and the surface (timeline, search, profile, thread, notifications).

This sensor never collects the post's text, your keystrokes, your private messages, or any other website.

These pointers join a shared pool that helps your radar, and the radar of other opted-in members, spot conversations getting attention right now.

Sighting records are deleted after 30 days.

Enabling it requires your explicit consent through a dedicated screen, versioned so any future change to what is collected requires renewed consent. You can turn it off at any time in Settings; switching off stops collection immediately.

Limited Use statement: HyperReach's use of information received from Chrome APIs and from the HyperReach browser extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension data is used only to provide the reply-first discovery features described here, is never sold, never transferred to advertising platforms or data brokers, and never used for creditworthiness.

5. Legal bases per purpose

Lifecycle emails: each category (activation nudges, weekly digest, credit alerts) can be turned off separately, via the one-click unsubscribe link included in every email or from Settings (Account > Email preferences). Transactional emails are always sent.

  • Contract performance: providing the service, generating suggestions, billing, transactional emails (welcome, trial ending, 100% credit alerts, never optional).
  • Legitimate interest: opportunity radar over public data and influencer prospecting (see section 3), security and fraud prevention, lifecycle and weekly digest emails (onboarding nudge, first reply, re-engagement).
  • Consent: optional marketing communications, extension sensor (see section 4), in-app product analytics (see section 10).

6. Retention periods

  • Account data: for the duration of the contract, then archived for applicable legal (notably accounting and tax) obligations.
  • Reply history and outcomes (Reply Outcome DB): retention configurable by the user.
  • Technical logs: bounded duration, as needed for diagnostics and security.

7. Recipients and subprocessors

Your data is shared with the subprocessors listed on our dedicated subprocessors page: gethyperreach.com/legal/subprocessors, strictly as needed to provide the service. For transfers outside the European Union, Standard Contractual Clauses (SCCs) govern the transfer.

No data is sold to third parties. No data is used to train global AI models without your explicit consent.

8. Hosting

Data is hosted primarily within the European Union (Supabase database, AWS eu-west-3 region, Paris). The application is served by Vercel.

9. Your rights

Under GDPR, you have the right to access, rectify, erase, port, restrict, and object to the processing of your personal data.

You can exercise most of these rights directly in the app (Settings, Account section): export your data as JSON, erase your data, and close your account.

You may also exercise these rights by writing to us at contact@gethyperreach.com.

You have the right to lodge a complaint with the French data protection authority (CNIL).

10. Cookies and trackers

The app sets strictly necessary cookies: Supabase authentication cookies, a technical OAuth flow cookie (PKCE), and a language preference cookie.

The public marketing site uses PostHog (EU hosting) in cookieless mode: analytics are anonymized and kept in memory, with no cookie set in your browser.

Inside the app, PostHog (EU hosting) measures anonymous usage by default, in the same cookieless mode as the public site: events are kept in memory, no identifier persists across visits and no cookie is set (consent-exempt audience measurement). Detailed analytics (events linked to your account, a technical analytics cookie, and session replay with inputs and text masked) only start once you explicitly agree via the in-app consent prompt or the dedicated setting (Advanced > Privacy). You can withdraw this consent at any time from that same setting: the app then falls back to anonymous cookieless measurement only.

No consent banner is required for the public site or for the app's strictly necessary cookies. This analysis is re-examined whenever the trackers in use change.

11. Security

API keys and access tokens are encrypted at rest. Isolation between accounts is enforced at the database level (Row Level Security).