Privacy policy
Your information. Clear choices.
This policy covers Reachuals's website, early-access waitlist, signed-in campaign workspaces, creator records and optional Instagram connections. It explains the information involved, its sources and purposes, and how to ask for access, correction or removal.
Last updated 5 October 2026
Who we are
Reachuals is a creator operations platform made by Hyve Labs for influencer-marketing teams. The business responsible for your data under this policy is HYVE LABS LLC, at Sharjah Media City (Shams), Al Messaned, Al Bataeh, Sharjah, United Arab Emirates.
For anything about your data, write to rabz-angel@hotmail.com.
Website, waitlist and workspace information
- Waitlist: your name, email, selected role and submission details. We use these to respond about Reachuals early access. Joining is free, creates no subscription and is not permission for unrelated marketing.
- Accounts: team members' names, email addresses, roles and authentication/session records, used to provide authorised workspace access.
- Workspace records: campaign briefs, creator contact or shipping details, conversations or exports supplied by an authorised customer, content evidence, approvals, fees and financial records. The customer determines what it submits and must have authority to use it.
- Public creator research: public handles, profile imagery, biography, follower counts, posts, engagement and source information obtained from public sources, licensed research providers or an official platform API. Public availability does not remove privacy rights.
- Technical information: requests, IP addresses, browser/device information, error and security logs used to deliver the site, prevent abuse and investigate faults. This does not mean an advertising or analytics cookie is active.
The operator is responsible for its website, account and waitlist processing. For a customer's campaign records, the customer determines the campaign purposes; applicable customer instructions and contractual processing arrangements also apply. Contact us if you need the relevant processing agreement or want to identify the responsible agency.
Why information is used
Information is used to respond to requested early-access contact, operate authorised accounts and campaign workflows, provide creator research with its sources, support customers, prevent abuse and meet applicable legal obligations.
The applicable processing basis depends on the activity and jurisdiction: a requested service or contract, an applicable legal obligation, a lawful legitimate interest where available, or consent where required. Optional Instagram audience access uses the specific consent described below. If broader marketing is introduced, permission will be requested separately where required; withdrawing it will not prevent access to necessary service communications.
Service providers and international processing
Google Cloud hosts the current service; the inspected deployment is in the United States. Authorised research, AI/extraction, messaging and payment providers may process information when the relevant integration is enabled. Research inputs can include a public creator handle, profile or source excerpt; a workspace feature may process authorised customer content. Provider locations and terms differ.
Access is limited to the people and providers needed for the relevant workflow, authorised customer/brand recipients, and disclosures required by law or necessary to address abuse or legal claims. This policy does not authorise publication or sale of private workspace records. We do not sell personal information.
Cross-border processing must meet the safeguards required by applicable law. Contact us for information about the providers, location and transfer arrangements relevant to your workspace. The safeguards depend on the destination, provider and applicable agreement.
Cookies and browser choices
Signing in sets an eight-hour, first-party session cookie. Requested interface choices, such as appearance and navigation layout, can be saved in your browser. The audited Reachuals application does not load advertising or analytics tracking integrations.
The footer's Cookie settings control explains necessary storage. See the cookie and browser-storage notice for the actual cookie and preference categories. Optional tracking must not be enabled before any consent required by applicable law.
Retention of website and workspace records
Waitlist information is kept while it is relevant to the early-access programme or until you ask to leave, subject to necessary legal or security records. Workspace records follow the customer's instructions, the applicable agreement and any legal/accounting retention need. Technical logs follow the hosting provider's configured retention.
No fixed automatic expiry for all workspace or waitlist records is promised here. You can ask what is retained, request correction or removal, or object to a use. Some records may need to be retained for a legal obligation, a dispute or another person's rights; we will explain an applicable limitation. The separate Instagram connection lifecycle below has its own withdrawal and deletion behavior.
When you connect Instagram through our invite link
A Reachuals team member may send you a personal link (it looks like reachuals.hyvelabs.tech/c/…). Opening it shows you a consent screen; nothing is read until you tap Connect Instagram and then approve Scout Beeinside Instagram's own permission screen. You sign in on Instagram, never on our page. Connecting is voluntary, and you can tap No thanks instead — we record the no so you are not asked again through that link.
If you approve, Instagram lets Scout Bee read the following about your account, and nothing else:
- The age groups of your followers
- The women / men split
- Which countries and cities they're in
- How many accounts you reached in the last 30 days
- Your username, account ID and follower count, so the numbers are attached to the right account
In Instagram's own words these are two permissions: basic account details and audience insights (the age, gender, country, city and reach figures). Precisely, we read:
- Your Instagram username and account ID, so we can tell whose numbers these are.
- Your follower count. We do not read or download your posts.
- Follower demographics as totals only: how many followers fall in each age band, the women / men / unknown split, and the top countries and cities. Instagram never gives us — and we never ask for — the identity of any individual follower.
- How many accounts you reached in the last 30 days.
- An access token from Instagram that lets us read the items above while you stay connected.
What I will never see:
- Your DMs
- Who your followers are — only totals, never a single name
- Your password. You sign in on Instagram, never on this page
- Anything new, once you disconnect
The permissions we ask Instagram for are read-only. We never post, comment, reply, message, follow or change anything on your account, and we have no way to.
We also keep a record of the consent itself: the exact version of the wording you agreed to (shown at the bottom of the consent screen), the handle we invited, the handle that actually connected (flagged if they differ — unless Instagram reports that the same account, by its account ID, now uses a new username, which we record as a rename, never as a different account), and the dates you were invited, opened the link, connected and disconnected.
Where it is kept, and how
- Your connection record and your audience figures are kept as small files in a Google Cloud Storage bucket inside our own Google Cloud project, under a folder of their own. Reachuals reads and writes them with its own service account; they are not published anywhere and are not served to the web. When a developer runs Reachuals on their own computer, the same files live in a folder on that computer that is never added to the source code.
- Your Instagram access token is encrypted by us with AES-256-GCM before it is written, using a key that lives only in the deployment's configuration, never alongside the data. The token is never stored, logged or shown in plain text. If that key is not configured on a deployment, the connection is refused rather than stored unprotected.
- Your invite link contains a random token; we store only a hash of it, so our records cannot be used to reconstruct a live link.
- The audience figures are stored as the raw totals Instagram returned, with the date they were read. Percentages are worked out on screen so the real denominator (how many followers Instagram could classify) is always shown next to them.
Who sees it
Who sees it: me and my team at Reachuals, and any brand I put your profile in front of, with your name on it.
- Reachuals team members signed in to Reachuals, when they look at your profile while planning a campaign.
- A brand Reachuals proposes you to, alongside your name and handle, with a line saying the figures came from your own Instagram account through Instagram's official API on a given date.
- Our hosting provider, Google Cloud, which stores the data for us and does not use it for its own purposes.
These Instagram audience figures are shared for the authorised campaign workflow described above, not sold as personal records. We never claim that Reachuals verified your audience — your own Instagram account supplied the figures, and that is what the label says. Hosting and other legally required disclosures are described in this policy.
How long we keep it
- An invite link works for 21 days. After that it expires and a new one has to be sent.
- Your figures are read once, at the moment you connect. Reachuals does not go back to Instagram on its own: a newer reading exists only when you connect again through a new link. At the moment that newer connection goes live, your earlier connection is withdrawn and its reading deleted — there is never more than one live connection, or more than one stored reading, for one Instagram account. If a connection attempt does not complete, nothing from it is kept: no access token, no reading, and not which account Instagram named.
- A link sent to you speaks for your account only if your account is the one that connects through it. If a different Instagram account connects through your link, that connection is that account's — it appears on that account's profile, it is disconnected from there, and on your profile it is at most a note that the link was used by that account; it is never shown as your connection or your disconnection, it is never counted as an answer from you, and it never stops a new link being sent to you. If Instagram does not tell us the username of the account that connected, the figures are held back from your profile rather than attributed to you.
- A link you have already connected through cannot connect again and cannot record a no: opened again, it shows that you are connected and offers to disconnect for as long as any connection of yours is live, and says that it was disconnected once none is. If Instagram sends us back to that link a second time, nothing changes.
- Instagram's access token lasts 60 days. When it lapses, your profile with Reachuals shows “Connection needs renewing” with the date of the last reading, and nothing new can be read until you connect again.
- The moment you disconnect — from any link you connected through (an older link still works for this, whoever withdrew it, as long as any connection of yours is live), from the screen shown right after connecting, or inside Instagram — every connection for your Instagram account is withdrawn: the access tokens are destroyed and your audience figures are deleted from your profile in the same request. The Reachuals team can withdraw it from your profile too, and the same happens. A link you never connected through has nothing to withdraw, and says so — with one exception: a link you said no through shows that you are connected, and can disconnect you, while your own account is connected through another link; it can never disconnect anyone else's account. Your profile then shows “Disconnected on” with the date in place of your figures, and says whether you, the Reachuals team or Instagram withdrew it. That note is never rewritten — saying no through an old link cannot turn a disconnection into a no. We keep the dated note so a withdrawn consent is never shown as a live one, and so Reachuals refuses to create a new invite link for you unless the team records that you asked for one; while such a link is out, the profile shows that link instead of the note, with the disconnection as history. The note, and that refusal, follow your account under the username Instagram last reported for it: if you renamed your account before disconnecting, they sit on the profile for the new name, and the profile for the old name points there.
- If you ask us to delete everything (see below), that note is removed as well. A data-deletion request from Instagram names your Instagram account ID, and we delete every Instagram connection record in our connection store carrying that ID — your connections in whatever state they are in, any access token still held on them, the readings they produced and the dated note — and nothing else. An invite link that never connected carries no account ID: one still waiting for you, one you opened, one you said no through, one whose connection attempt failed. Nothing on it says whose it is, so a request naming an account ID cannot be shown to be about it and does not touch it; it is left to expire on its own, 21 days after it was sent, and you can ask us to remove it sooner, or open it and disconnect if you connected through it. A no you recorded on a link stays for the same reason, and while it stands Reachuals still will not send you a new link unless you ask for one.
The scope of Instagram deletion
Meta's signed deletion request removes the Instagram connection records, tokens, audience readings and invite-index entries that carry the account ID in our connection store. It does not automatically remove separate public research, customer campaign records, waitlist information, hosting logs or backups. Use the general data-request contact above for those records; we will explain the applicable verification, retention and processing roles.
How to disconnect, and how to delete your data
You can withdraw at any time, and you do not need our permission to do it:
- Open your invite link again and tap “Disconnect and delete my numbers”. The same button is on the screen you see right after connecting.
- Or remove the connected app inside Instagram: Settings → Website permissions (also called Apps and websites). Instagram tells us through its deauthorize callback, and we disconnect you in the same way.
- The Reachuals team can also withdraw your connection from your profile in Reachuals. When they do, the same withdrawal runs, and the note on your profile and on your link says it was them.
- To have the Instagram connection records carrying your account ID removed from our connection store, including the connection history, ask Meta to send us a data-deletion request from your Instagram settings, or email us. Meta-initiated requests get a confirmation code you can check on our data-deletion page. An invite link that never connected carries no account ID and so is not reached by a request from Instagram — email us and we will remove that too.
Full step-by-step instructions are on the delete my data page.
Account and billing context
- Team accounts use the necessary signed-in session cookie. Cookie settings may also remember that you have read the storage notice. We use no advertising or analytics tracking integrations in the audited application.
- Creator profiles: public information about creators (handle, follower count, public posts and engagement, category) gathered from public sources and through Instagram's official API, plus the agency's own notes and campaign history. If you are a creator and would rather not appear, email us and we will remove your profile.
- The current early-access waitlist is free. If a paid plan is later enabled and you choose it, Stripe processes payment and we receive transaction/customer/subscription references; we do not receive your full card number or card security code. Read the separate refunds and cancellation policy before purchasing.
Things we work out about creators, and how to correct them
Besides what is public on a profile, Reachuals records a few things about a creator that it has worked out rather than been told. Each one is shown to the agency with a label saying where it came from, and each one can be corrected or removed on request.
- Your gender. Where a Reachuals campaign sheet records it, that is used. Otherwise it is read from your own public profile — your display name checked against lists of first names, self-descriptions in your bio (for example she/her, mom, صانعة محتوى), and a model's read of your profile photo — and recorded only when two of those agree and none disagrees, labelled “from profile”. Failing that, an estimate from your first name or from a public web page may be shown, always labelled “est.”. It is never taken from who follows you.
- Your age band (for example teen, young adult, adult). Only from an age or a birth date you stated yourself — in your bio, a caption, or a public web page — or “adult” when you describe yourself as a parent. It is never guessed from a photo, a name or your followers, and it is labelled with where it was read.
- Where you are based (city and country). From Reachuals' own records where they exist; otherwise from public web pages, labelled “est.”. This is your home, never where your audience is.
- Your content category. From what you post and how you describe yourself publicly.
If any of these is wrong, or you would rather we did not hold it, email rabz-angel@hotmail.com from any address, naming your Instagram handle. We will correct or remove it and reply from the same address when it is done.
Your rights
You can ask us what we hold about you, ask us to correct it, ask us to delete it, or withdraw a consent you gave. Email rabz-angel@hotmail.com and we will reply from the same address. Where local law gives you further rights, you keep them.
Depending on the law that applies to you, rights may also include restriction, objection, portability and a complaint to a competent data-protection authority. We may need proportionate identity verification before disclosing or changing personal information. Do not send passwords, access tokens or unnecessary identity documents in your first request.
The website and workspace accounts are intended for adults doing professional creator-marketing work. They are not directed to children. We do not knowingly collect information from anyone under 13. If you believe a child's information has been included inappropriately, contact us so we can review and restrict or remove it as required.
Changes to this policy
If we change what we collect or how we use it, we will update this page and the date at the top. The consent wording you agreed to is versioned and kept, so a later change never rewrites what you actually approved.
