Last updated: July 2, 2026 • Version: privacy-2026-07-02
This Privacy Policy explains how Pilum Reach Lite collects, uses, stores, shares, and protects information when you use our website, dashboard, APIs, billing features, and omnichannel messaging platform.
For account, billing, security, product, and support data, we generally act as a data controller. For contact lists, recipient data, and message content you upload or send through the platform, we generally act as your service provider or data processor and process that data to provide the service you request.
We use Polar as our payment processor and billing platform. Polar handles checkout, payment details, invoices, receipts, tax collection where applicable, subscriptions, renewals, cancellations, and customer-portal access. We store plan, subscription, invoice, credit-wallet, refund, coupon, referral, and transaction records needed to operate billing, but we do not store full payment card numbers.
To facilitate omnichannel broadcasts and one-to-one messages, we temporarily process and store message payloads. Payloads may include message text, subject lines, template variables, recipient identifiers, media URLs or attachments, provider message IDs, delivery status, timestamps, and provider error responses.
Message payloads are stored so the platform can queue, send, retry, display history, reconcile credits, process inbound replies, enforce opt-outs, provide support, and maintain auditability. Message payloads are retained according to the retention rules below unless you delete them earlier or a longer retention period is required for legal, fraud, security, or dispute purposes.
Meta Platform Data
We do not sell, rent, or trade data obtained from Meta platforms. We do not use Facebook, Instagram, or WhatsApp data to build advertising profiles, train AI models, or for purposes unrelated to providing the messaging services you request.
We use essential cookies for authentication, session management, security, and referral-code attribution during signup. OAuth providers such as Google and Facebook may set their own cookies during authentication.
The application uses browser localStorage for preferences such as theme, sidebar state, and dismissed onboarding prompts. It uses sessionStorage for short-lived interface state such as temporary dashboard nudges. These browser storage mechanisms help the interface remember your choices and may remain on your device until cleared by you, your browser, or the application.
In production, the client application may send error and performance telemetry to our internal monitoring endpoint. Telemetry may include event name, error message, severity, timestamp, limited context, request or feature area, and stack trace information when captured. We use this data to diagnose bugs, API failures, and performance problems.
We retain information for as long as needed to provide the platform, meet legal obligations, resolve disputes, enforce agreements, prevent fraud, and maintain security. Current retention targets include:
| Data Type | Typical Retention |
|---|---|
| Message payloads and delivery logs | 6 months unless deleted earlier or retained for disputes, fraud, or legal needs |
| Contact and broadcast records | Account lifetime, then deletion or obfuscation after the deletion grace period |
| Credit transactions, invoices, billing ledgers, refunds, and chargebacks | 7 years or longer if required for tax, accounting, fraud, audit, or disputes |
| Legal consent records | Account lifetime and any additional period needed to prove compliance |
| Closed support tickets | 3 years |
| Deleted account grace period | 30 days before irreversible deletion workflows continue |
| Webhook logs | 14 days for successful events and 90 days for failed events |
| Client monitoring telemetry | Operational log retention needed for debugging, security, and reliability |
Account deletion removes or obfuscates user-facing content according to our deletion workflows, but financial ledgers, invoices, legal consent records, fraud-prevention records, and audit evidence may be retained. Some retained financial records may no longer identify a deleted user directly because the user reference can be set to null in the database.
You can view and update much of your information in the dashboard. You may request access, correction, export, or deletion by contacting us at privacy@pilumreach.com or through the in-app Support Center. We may need to verify your identity before fulfilling requests.
You can request account deletion from Settings. Your profile is obfuscated, active access is restricted according to the product flow, and a 30-day grace period begins. If you sign in during that period, deletion may be canceled. After the grace period, deletion workflows continue, subject to retained billing, legal, security, fraud, and compliance records described above.
Contacts can opt out per channel. SMS replies such as STOP, UNSUBSCRIBE, CANCEL, QUIT, or END may automatically mark a contact as opted out. WhatsApp and Meta opt-out requests must be honored according to their policies and applicable law.
Deleting data from Pilum Reach Lite does not delete messages already delivered to recipients or stored by third-party messaging providers, recipients, carriers, or recipient devices.
We use administrative, technical, and organizational safeguards designed to protect the platform. These include:
No online service can guarantee absolute security. You are responsible for strong passwords, safe API-key handling, limiting team access, and maintaining security for connected provider accounts.
When you use third-party channels or billing services, your data is also handled under those providers' terms and privacy policies. Review the policies for the services you connect:
| Service | Privacy Policy |
|---|---|
| Facebook Messenger | facebook.com/privacy/policy |
| privacycenter.instagram.com/policy | |
| whatsapp.com/privacy | |
| Telegram | telegram.org/privacy |
| Email (Resend) | resend.com/legal/privacy-policy |
| Twilio (SMS) | twilio.com/legal/privacy |
| Vonage (SMS) | vonage.com/privacy-policy |
| Plivo (SMS) | plivo.com/legal/privacy |
| MessageBird/Bird (SMS) | bird.com/en-us/legal/privacy |
| Telnyx (SMS) | telnyx.com/privacy-policy |
| Supabase (Infrastructure) | supabase.com/privacy |
| Polar (Billing) | polar.sh/privacy |
Our infrastructure, messaging, and billing providers may process data in multiple countries. When data is transferred across borders, we rely on safeguards offered by those providers and the contractual, legal, and technical measures available for the relevant transfer.
The platform is not intended for children under 13, and we do not knowingly collect information from children. If we learn that a child has provided personal information, we will delete it as required by law.
We may update this Privacy Policy from time to time. Material changes will be posted here or communicated through the platform.
For privacy questions or requests, contact us at privacy@pilumreach.com or through the in-app Support Center.