Last updated:
This policy explains what personal data Reyport collects, why, who else receives it, where it is stored, how long it is kept, and what rights you have. It describes the system as it actually works on the date above, including the parts that are less convenient to describe.
The Turkish version of this page is also Reyport's information notice (aydınlatma metni) under Turkish Personal Data Protection Law No. 6698 (KVKK). Both versions describe the same practices; if they ever differ, the version that is more protective of you applies.
Data controller: Reyport — Emir Zanyar Kaya. Reyport is a brand name and is not yet operated through an incorporated company, so the natural person named here operates reyport.com and app.reyport.com and is personally responsible, as data controller, for the personal data described in this policy. "Reyport", "we" and "us" in this policy refer to that person. If a company is incorporated, this policy will be updated to name it as controller and account holders will be notified as described in section 14.
For any question about this policy or to exercise any of your rights, write to info@reyport.com.
Reyport is a business-to-business tool for exporters. A user describes, in their own words, the kind of buyer they are looking for in a country. Reyport then searches public map listings and the public web for matching companies, uses AI to judge whether each one could plausibly buy, collects the business contact details those companies publish, drafts an outreach email per company with AI, and sends it from the user's own mailbox only after a person on the user's team approves it. Replies are read back from the user's mailbox so they can be matched to the email that caused them.
Accounts are created by us for business customers; there is no public sign-up.
Why: to let you sign in and to keep each company's data separate from every other company's.
Why: the AI reads your profile to decide which discovered companies count as potential buyers and to write emails that describe your business accurately. Only include personal data in these fields if it is needed for that.
Why: to send the emails you approve, to show you your inbox inside Reyport, to link each reply to the email that caused it, and to detect bounced addresses so they are never emailed again.
Companies you move from discovery into your customer list, with their status, your notes, follow-up dates and AI-written summaries; a history of changes to them; and a log of actions in your account (discovery runs, drafts generated, emails sent) with their cost. Why: so you can manage your sales pipeline and see what was done.
Messages you type to the Reyport AI assistant. Your conversation history is stored only in your browser (localStorage), not on our servers, and is removed from the browser when you log out. Each message you send is processed by OpenAI together with your company context (see section 6). If you use the assistant on the Mail page while a message is open, that message's sender name and address, subject, and the first 500 characters of its body are included.
Server logs kept by our hosting provider. They contain company and mailbox identifiers, error messages, and in some cases email addresses (for example, the sender of a reply that could not be matched to a sent email) and the message and thread IDs Gmail returns after a send. Why: to operate, debug and secure the service.
Under KVKK Article 5(2) and GDPR Article 6(1), we rely on: performance of our contract with your company (KVKK 5(2)(c), GDPR 6(1)(b)) for providing the service; compliance with legal obligations (KVKK 5(2)(ç), GDPR 6(1)(c)); and our legitimate interests in operating, securing and improving the service (KVKK 5(2)(f), GDPR 6(1)(f)). We do not intentionally process special categories of personal data.
Reyport's core function collects information about companies that our users may want to contact, and about people who work at them. If you work at such a company, this section is for you. It is also how we meet the duty to inform people whose data we did not obtain from them directly (KVKK Article 10, GDPR Article 14).
To let businesses find and make first contact with other businesses that may buy their products. We rely on legitimate interests in business-to-business commercial contact (KVKK 5(2)(f), GDPR 6(1)(f)) and, for contact details a person or company has published for business contact, on the data having been made public by the person concerned (KVKK 5(2)(d)). Only information that is publicly available is collected. The Reyport user who decides to contact you is responsible for having a lawful basis to email you in your country (see our Terms of Service); Reyport is responsible for how the discovery system collects and stores the data.
Discovery results are kept with the search run's records and are not deleted automatically. Some derived search statistics expire after 90 days, and the memory of companies a search rejected expires after 30 days.
Connecting Google is optional. It exists only so that Reyport can send the emails you approve from your Gmail address through the Gmail API. This section describes exactly which Google permissions Reyport requests and what happens to the data they give access to.
| Scope | What Google calls it | What Reyport does with it |
|---|---|---|
| https://www.googleapis.com/auth/gmail.send | Send email on your behalf | Sends each email you approve in Reyport from your Gmail account, through the Gmail API's messages.send method. Nothing else. This permission cannot read, list, search, change or delete any message in your mailbox. |
| openid | Associate you with your personal info on Google | Requested together with email because Google's user-info endpoint does not accept a token that only has gmail.send. Reyport does not store your Google account ID. |
| email (https://www.googleapis.com/auth/userinfo.email) | See your primary Google Account email address | Read once, immediately after you connect, to record which Google account was authorised and to warn you if it is not the same address as the mailbox you connected it to. |
Reyport requests no other Google permissions. It does not request read access to Gmail through Google's APIs. Reading your inbox (section 3.4) happens over IMAP with the server credentials you entered when adding the mailbox, not through the Google authorisation.
The content of the emails sent through Gmail is written in Reyport before it is sent; Reyport does not receive email content from Google. That content is stored as described in section 3.4. All of the above is held in our database (Supabase, Switzerland) and passes through our application servers (Railway, United States).
Reyport's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is not used to train any artificial intelligence or machine learning model, and it is not sold or shared for advertising.
We do not sell personal data. The following providers process personal data on our behalf to run Reyport:
| Provider | What it does | What it receives | Location |
|---|---|---|---|
| Supabase | Database, sign-in, file storage | Everything stored by Reyport and described in sections 3 to 5: account and company data, mailbox credentials and Google tokens (encrypted), drafts, sent and received emails, customer records, discovery results. Login email and password hash. Uploaded files and outgoing attachments. | Switzerland (AWS eu-central-2, Zurich) |
| Railway | Hosting of the application, the background worker and the Redis working store | All data passes through its servers while being processed. Redis holds working data for discovery searches, including discovered companies and contacts, and usage counters. Server logs (section 3.7). | United States |
| OpenAI | AI models: understanding your search goal, scoring companies, classifying found addresses, writing and translating drafts, customer summaries, the AI assistant | Your search goals; your company profile, notes, file names and file notes, template instructions; the email addresses of mailboxes you connected (as assistant context); discovered company data, page excerpts and search snippets; found email addresses with the text around them; draft subjects and bodies; your messages to the assistant; on the Mail page, the open message's sender, subject and first 500 characters. It does not receive mailbox passwords, Google tokens, your Google account email address or Gmail thread IDs. | United States |
| Serper.dev | Web and map search | Search queries built from your goal: product and category terms, city and country names, and company names and websites when looking up a company's site. No account data or email content. | Outside Türkiye |
| Gmail API, only if you connect Google | The emails you send through the Gmail API, and the authorisation described in section 5. | Google's global infrastructure | |
| OpenStreetMap Nominatim | Converting city names to map coordinates | City and country names only. No personal data. | Outside Türkiye |
| Your email provider | Your own mail servers | Your mailbox credentials when Reyport connects, and the emails sent and read. | Chosen by you |
Reyport's crawler also requests pages from the websites of discovered companies and looks up their domains in DNS; those sites and DNS servers see a request from our hosting provider, but no user data is sent to them.
OpenAI requests are made with OpenAI's default setting, which lets OpenAI keep the request and response content. Under OpenAI's API data policies this content is retained for up to 30 days and is not used to train OpenAI's models. We do not use the data sent to OpenAI to train any model.
Reyport's code can also check email addresses with an email verification provider (MyEmailVerifier, or ZeroBounce). This is not enabled as of the date above. If it is enabled, this policy will be updated before it is, to say so.
Reyport's database is in Switzerland and its application servers are in the United States, and OpenAI processes data in the United States. Personal data is therefore transferred outside Türkiye and, for people in the European Economic Area, outside the EEA.
These transfers are made under Article 9 of KVKK and Chapter V of the GDPR, relying on the standard contractual clauses in these providers' data processing terms. You can ask us at info@reyport.com for information about the safeguards used for a particular provider.
| Data | Retention |
|---|---|
| Account and company data | As long as the company account exists. There is no self-service account deletion; write to us and we will delete the company account and all data attached to it. |
| Mailbox credentials | Until you delete the mailbox in Reyport. |
| Google tokens and Google account email | Until you disconnect Google or delete the mailbox (details in 5.4). |
| Sent and received emails | Not deleted automatically. Deleting a message in Reyport's mail view hides it but keeps it in the database. Deleting the mailbox in Reyport permanently deletes all of its stored messages. Drafts remain after the mailbox is deleted. |
| Uploaded files and outgoing attachments | Deleting a file in Reyport removes its record; the stored file remains until we delete it at your request. |
| Customer records and activity history | As long as the company account exists. |
| Discovery results, including discovered business contacts | Not deleted automatically (section 4). Derived search statistics expire after 90 days; the list of rejected companies after 30 days. |
| Do-not-send list | As long as the company account exists, so that an opt-out keeps working. |
| Email verification results | Kept; a result is re-checked when it is older than 30 days. |
| AI assistant history | In your browser only, until you log out or clear it. |
| Server logs | For our hosting provider's log retention period. |
| Data sent to OpenAI | Up to 30 days at OpenAI (section 6). |
When data is deleted from the database, copies in the database provider's backups can persist until those backups expire.
Connections to Reyport use HTTPS. Mailbox passwords and Google tokens are encrypted with AES-256-GCM using a key held only by the application server; the background worker holds neither that key nor any access to the database. Every company's data is kept separate from every other company's, and automated tests check that separation. Uploaded files and attachments are the exception described in 3.2: they are reachable by anyone who has their exact link. No system is completely secure; if a breach affects your personal data, we will notify you and the authorities as the law requires.
Under Article 11 of KVKK you have the right to learn whether your personal data is processed; to request information about it; to learn the purpose of processing and whether it is used for that purpose; to know the third parties it is transferred to in Türkiye or abroad; to request correction of incomplete or inaccurate data; to request its deletion or destruction; to request that third parties it was transferred to are notified of a correction or deletion; to object to a result against you arising exclusively from automated analysis; and to claim compensation for damage caused by unlawful processing.
Under the GDPR (Articles 15 to 22), people in the EEA have the rights of access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests, including at any time to direct marketing.
To exercise any of these rights, email info@reyport.com from the address concerned, or tell us how we can confirm that the data is yours. We may ask for information to verify your identity. We answer free of charge within 30 days (KVKK) and within one month (GDPR), unless the law allows a fee or an extension for a particular request.
If you are not satisfied with our answer, you can complain to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, https://www.kvkk.gov.tr) or, in the EEA, to the data protection authority of your country.
AI scores decide which companies are shown as potential buyers and which are set aside. These scores concern businesses, not individuals, and do not produce legal effects for anyone. Users can restore a company the AI set aside, and no email is sent without a person approving it.
Reyport is a service for businesses and is not intended for anyone under 18.
When this policy changes, the date at the top of this page changes. For a material change, such as a new category of data, a new purpose, or a new provider receiving personal data, we will email account holders at least 30 days before the change takes effect. A change required by law or needed to protect security can take effect sooner, and we will explain why.