← Back to AReach

AReach

Privacy Policy

How AReach collects, uses, shares, and protects information when you use the app and related services.

Last updated: August 31, 2026

1. About this policy

This Privacy Policy explains how AReach handles information when you use the AReach mobile application, our website, or services that link to this policy. AReach is designed for event-scoped social discovery: people join a shared event, choose what to include in their profile, and discover eligible attendees during that event.

By using AReach, you acknowledge the practices described here. If you do not agree with this policy, do not use AReach.

2. Information we collect

Account and authentication information

  • Your name and email address.
  • Account verification information and records used for password authentication, password resets, and email-address changes.
  • Authentication session information, including session identifiers, expiry information, and security metadata such as an IP address and user-agent string when available.

Password credentials are used to authenticate your account. Your password, authentication tokens, and account-security information are not shown to other attendees. Do not send passwords or authentication codes to support.

Profile and user-generated content

You may provide a profile name, headline, and “Ask me about…” topics. An image associated with your account may also be present in your profile where available. You may also submit event content, including an event title, description, venue, capacity, dates, and times.

Event and attendance information

We store events that you create, invite codes, registrations, event membership, host or attendee role, check-in and join information, and recent live attendance information such as when an attendee was last seen. Invite codes are used to join and share an event; they are not described or treated by the app as a substitute for a password.

Nearby and augmented-reality information

During a live event, AReach may use Apple Nearby Interaction, Bluetooth, Local Network services, and ARKit on a compatible iPhone to identify participating event devices and estimate relative proximity or direction. The service uses temporary, event-scoped credentials, peer identifiers, and public-key data for this process. Nearby Interaction is not GPS, and AReach does not use this feature to create a general location history.

In the production camera flow, camera frames are read on your iPhone by ARKit and on-device Vision/body-detection code to position attendee overlays. The inspected production path does not upload or persist raw camera video, raw camera frames, or microphone audio as part of this live detection feature. The app configuration does not request a microphone or location permission for this feature.

Support and optional research study information

If you contact us, we receive the information you include in your message. If you voluntarily opt in to the AReach Hunt research study through its in-app consent notice, AReach may store a study session, consent details, the controlled event identifier, and a small set of interaction events such as entering the event, opening the camera or attendee list, selecting a participant, and viewing conversation cues. The study records are created only after consent. AReach does not use study telemetry to record raw camera or audio data, GPS, distance, invite codes, participant names or profile text, private messages, or native device identifiers. The applicable in-app notice explains the study before it is enabled.

3. How we use information

  • To create and protect your account and send verification, password-reset, and email-change messages.
  • To create, join, manage, and display events, registrations, and attendance.
  • To display event-scoped attendee profiles and live presence to eligible participants under the visibility rules below.
  • To issue temporary nearby-device credentials and provide the live spatial experience.
  • To respond to support requests, receive safety reports, prevent misuse, and maintain service security.
  • To collect optional research study telemetry only after the applicable notice and consent.

AReach does not sell personal information and the current mobile and website code does not use advertising SDKs to track you across other apps or websites.

4. Discoverability and what other people can see

Within an event, eligible participants may see limited attendee information such as a visible name, image where available, headline, “Ask me about…” topics, host or attendee role, and live presence. Approximate distance or proximity may be shown when the live experience makes it available. Email addresses, passwords, authentication tokens, and private account-security information are not shown to attendees.

The app setting is named Visible to nearby attendees. When it is turned off in Profile → Privacy, you remain a member of your events and can still see and edit your own profile, but AReach hides your attendee identity and profile from other attendees in attendee lists, profile details, nearby results, proximity or distance presentations, and camera overlays. Event hosts cannot override this choice. Aggregate event registration or attendee counts may still include you because a count is not an identity discovery result.

This setting controls AReach profile and identity discoverability; it does not promise that a physical device is invisible to every underlying Bluetooth or Nearby Interaction protocol, and it does not make you physically absent from an event.

AReach applies these rules on the server for event attendee lists, profile details, registrations, and nearby identity resolution. A participant must be associated with the event, and the server checks the target’s discoverability setting and blocking relationships before returning identity information.

5. Blocking

You can block another attendee from that attendee’s profile during a live event. While the block is in place, AReach mutually hides the two users from attendee discovery, profile access, nearby identity results, proximity or distance displays, and camera cards. Blocking changes what AReach reveals; it does not prevent two people from being physically near one another.

You can review your blocked users and choose Unblock from Profile → Blocked Users. An independent block made by the other person is not changed by your unblock action.

6. Reports and safety

You can report another attendee from within a live event. The selected reason can be inappropriate profile content, harassment or abusive behavior, impersonation, spam, or other. A report records the reporting account, reported account, event, selected reason, status, and creation and update timestamps. The service prevents a duplicate report for the same reporter, attendee, and event.

Reports are used for safety and moderation. A new report may notify an internal moderation recipient when that notification is configured. Report status can be pending, reviewed, resolved, or dismissed; AReach does not promise a particular review time or outcome.

7. Website technologies and service providers

The public website does not require an AReach login and its current source contains no analytics scripts, tracking pixels, or advertising SDKs. It uses browser localStorage only to remember the visitor’s light or dark theme preference. The current website does not set an AReach analytics or advertising cookie.

Requests for public website pages are handled by Cloudflare and may include ordinary connection metadata such as an IP address, user-agent, requested path, and request time for delivery and security. The repository does not define a separate retention period for that metadata.

The homepage loads a QR-code image from api.qrserver.com so visitors can open AReach in the App Store. That image request can expose standard connection metadata such as an IP address and user-agent to that provider, and includes the public App Store URL in the request. It does not include your AReach account or attendee data. Selecting an App Store link takes you to Apple, which processes that visit under Apple’s policies.

We use Cloudflare Workers, website assets, network services, and Cloudflare Hyperdrive to operate the website and API. Hyperdrive connects the API to a PostgreSQL database. Cloudflare Email Sending delivers account verification, password-reset, email-change, and, when configured, internal report-notification messages. Cloudflare and the database infrastructure process the information needed to provide these services. The repository does not identify the underlying PostgreSQL hosting company.

The app uses Apple system frameworks such as ARKit and Nearby Interaction for device-side live features. Better Auth, Drizzle, Expo, and React Native are software components used by AReach; the repository does not show them as separate AReach data recipients.

We may disclose information when required by law, to protect the rights or safety of users and the service, or to investigate fraud, abuse, or security incidents. We do not share attendee profile information with people who are not authorized participants in the relevant event.

8. Retention and deletion

The repository does not define one fixed retention period for all data. We retain active account, profile, event, registration, and attendance records for as long as needed to provide AReach, support security, resolve disputes, comply with legal obligations, and maintain event history. Authentication sessions expire according to their configured lifetime. Leaving an event removes the active check-in and nearby attendance record, while the registration and event record may remain.

Blocks and attendee reports are stored for the privacy and safety functions described above. Under the current database relationships they are deleted when the relevant user is deleted, and reports also follow deletion of their event. Evaluation records have a separate study relationship: where the study protocol requires it, previously collected server-side evaluation records may remain with their account foreign key removed. The app clears local evaluation records during account deletion.

To permanently delete your account, open Profile → Account → Delete Account in AReach and confirm with your password. This is the normal deletion path and cannot be undone. The server deletes the account and the account-linked profile, hosted events, event registrations and attendance records, nearby credentials, blocks, and attendee reports according to the current deletion relationships. Hosted-event deletion also removes related event records. The app stops nearby activity, clears account-scoped local event, profile, privacy, and evaluation data, and clears the stored authenticated session. If local cleanup cannot complete, the app displays a notice with further guidance.

The app’s deletion flow does not require an email request. Contact areach.prescribe586@passmail.com for privacy questions, access or correction requests, support, or other data questions. We may need to verify your identity and may retain information where required for security or law.

9. Permissions and security

AReach requests camera, Bluetooth, Local Network, and Nearby Interaction permissions only when the related live features need them. You can deny or later revoke these permissions in iOS Settings, although the related features may not work without them.

We use HTTPS, authenticated requests, access controls, and event-scoped credentials to protect information. No internet service can guarantee absolute security, so use a strong unique password and notify us if you suspect unauthorized access.

10. Children

AReach is intended for professional events and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us so that we can investigate and delete it where appropriate.

11. Changes to this policy

We may update this policy when AReach’s features, data practices, or legal obligations change. We will update the date at the top of this page and, where appropriate, provide additional notice in the app.

12. Contact

For privacy questions or requests, contact areach.prescribe586@passmail.com.