Cresvern Reach Privacy Policy
Cresvern Reach is a social publishing app that lets you write a post once and publish it to your connected social accounts. This policy explains what we collect, how we protect it, what we deliberately do not keep, and your responsibilities for securing your own device.
Cresvern Reach, a product by Cresvern. Last updated: 27 July 2026.
1. Who we are
Cresvern Reach is operated by Cresvern. Contact: support@cresvern.com.
2. What we collect
- Account details: your name, email address, and a password — the password is stored only as a one-way BCrypt hash, never in readable form.
- Connected social accounts: when you connect LinkedIn, Facebook, Instagram, YouTube, Threads, Pinterest, Reddit, etc., we store the access tokens those platforms issue so we can publish on your behalf when you tap Publish. These tokens are encrypted at rest (see section 4).
- Content you create: post text, and any image/video you attach, only for as long as needed to publish or to hold a scheduled post. Attached media is deleted from our servers after the post is published.
- Usage analytics: coarse, non-content events (e.g. "connected a platform", "published") to improve the app. We do not put your post content in analytics.
- Purchase records: your Pro plan status and the store purchase reference, so your subscription follows your account.
We do not collect your contacts, location, browsing history, or biometric data (see section 6).
3. What we deliberately do NOT store
- No card or payment details — all payments go through Google Play / the App Store; we never see your card number.
- No plaintext passwords — only BCrypt hashes.
- No long-lived copies of your media — attachments are removed after publishing.
- No post content in analytics or logs.
4. How we protect your data
- Encryption in transit: all communication with our servers uses HTTPS/TLS.
- Encryption at rest: your connected-platform tokens, scheduled-post content, and related secrets are encrypted before being written to our database (ASP.NET Data Protection). A copy of the database alone therefore cannot be used to post as you — the encryption keys are held separately.
- Hashed passwords: BCrypt, so even we cannot read your password.
- Server-side authority: your plan and permissions are decided on our servers, not the device.
- Hosting: our servers and database run on Microsoft Azure, which provides physical security and disk-level encryption.
- Revocation: you can disconnect any platform at any time, which deletes its stored token; you can also revoke our access from the platform's own settings.
No system is perfectly secure, but we design so that a single point of failure (for example, a database leak) does not expose usable credentials.
5. Connected social accounts
- We use official OAuth — you sign in on the platform's own site and we never see your social passwords.
- We publish only content you create and only when you choose to (tap Publish or schedule).
- We request the minimum permissions needed to publish. Each connected platform (LinkedIn, Meta/Facebook/Instagram/Threads, Google/YouTube, Pinterest, Reddit, etc.) has its own privacy policy governing what happens on their side; we encourage you to review theirs.
6. Biometric unlock (Face / Fingerprint)
Cresvern Reach offers an optional biometric lock (fingerprint or face) as an extra layer of security on your device. If you enable it:
- Your fingerprint/face data is handled entirely by your device's operating system (Apple Face ID / Touch ID, Android BiometricPrompt). We never receive, see, or store your biometric data — the OS simply tells us "unlock succeeded" or "failed".
- Biometric unlock only controls access to the app on your device; it is a convenience/security feature and does not send anything to us.
- You can turn it off at any time in the app's Profile settings.
7. Your responsibility for your device
The app runs on your device, and some data (your saved login, local drafts, and — if you use it — the biometric unlock setting) lives on that device. You are responsible for keeping your device secure — using a device passcode, keeping the OS updated, and not leaving it unlocked or sharing it.
We are not responsible for unauthorized access, loss, or misuse that results from your device being lost, stolen, jailbroken/rooted, shared, left unlocked, or otherwise compromised, or from malware or another app on your device. If your device is compromised, sign out of Cresvern Reach, change your password, and disconnect your social accounts; contact us and we can help revoke access.
8. Data retention and deletion
- We keep your account data while your account exists.
- You can delete your account in the app (Profile → Delete account). This permanently removes your account, connected-platform tokens, drafts held on our servers, and scheduled posts. Where a Google Play subscription exists, we also cancel it so you are not billed again; Apple subscriptions must be cancelled by you in App Store settings.
- Diagnostic logs may be retained briefly for reliability and are unlinked from your identity.
For full details on deleting your account and data — including how to request deletion if you no longer have the app — see our Data Deletion page.
9. Children
Cresvern Reach is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data.
10. Your rights
Depending on where you live (e.g. GDPR in the EU/UK), you may have rights to access, correct, export, or delete your personal data. You can exercise most of these directly in the app, or contact us at support@cresvern.com.
11. Changes to this policy
We may update this policy; the "Last updated" date reflects the latest version. Significant changes will be surfaced in the app.
12. Contact
Questions about privacy or your data: support@cresvern.com.