Connect in a click
Add to Slack with standard OAuth, or pair a WhatsApp number by scanning a QR code. Both connections survive restarts — no daily re-authentication.
BulkReach connects your Slack workspace and WhatsApp number, then sends bulk or scheduled messages to exactly the right people — with per-recipient consent, rate limits handled for you, and a delivery log for every single send.
Sends through the channels your people already use
Built on Next.js, Supabase and Postgres Row Level Security
Slack has no bulk DM. WhatsApp has no real broadcast for a list you actually own. So it becomes a person, a spreadsheet and two hours of pasting — and nobody can tell you afterwards who actually got it.
Not a bigger textbox. The queue, the pacing, the consent checks and the audit trail that turn one message into two hundred delivered ones.
Add to Slack with standard OAuth, or pair a WhatsApp number by scanning a QR code. Both connections survive restarts — no daily re-authentication.
Templates resolve {{first_name}}, {{name}}, {{email}} and {{phone}} at send time, previewed against a real recipient before anything leaves.
Pick a time, and the send waits in the queue until it is due. Edit or cancel right up to the moment it starts.
Slack is paced to its one-per-second budget; WhatsApp gets a randomised three-to-eight-second gap. You never think about it.
Sent, failed, skipped, and why — down to the individual person and the exact text they received.
Tag recipients once and reuse them as saved audiences. Filter by source, tag or search across every channel at once.
Common header names are recognised automatically, numbers are normalised, duplicates merged — and nothing is opted in without you saying so.
Monthly usage per channel, so the volume question is answered before someone asks it.
From an empty workspace to a scheduled, personalised, fully logged send.
Install the Slack app, or scan a QR code to pair a WhatsApp number. Tokens and session credentials are encrypted before they are stored.
Sync your Slack directory in one click, pull WhatsApp contacts, or import a CSV. Tag them into audiences as you go.
Pick your channels and audience, write with variables, and check the preview as a real recipient would see it.
Queue it now or pick a time. The dispatcher handles pacing, retries and the delivery log while you get on with something else.
Slack and WhatsApp behave nothing alike. BulkReach handles the difference so you do not have to.
Install once with the standard “Add to Slack” flow. BulkReach syncs your member directory — skipping bots and deactivated accounts — and sends direct messages paced to Slack’s one-per-second budget, retrying automatically if Slack pushes back.
Pair a number by scanning a QR code, the same way you link WhatsApp Web. The session runs on a dedicated always-on service and survives restarts, so you scan once rather than every morning.
WhatsApp automation is unofficial and against WhatsApp’s terms of service. We say so plainly, build the safeguards in, and leave the decision with you.
Bulk messaging goes wrong in predictable ways. Each of these exists because of one of them.
Once when the audience is chosen, and again at the moment of delivery — so someone who opts out after a send is queued still never receives it.
A randomised three-to-eight-second gap between WhatsApp messages, on top of a hard floor in the sending service. Nothing bursts.
A CSV lands with consent unset unless you explicitly confirm the list agreed to be contacted. Having a number is not permission to use it.
Each recipient is a separate queued row. An interrupted send picks up where it stopped instead of starting over and messaging people twice.
Multi-tenancy is enforced by the database, not by remembering to add a WHERE clause.
Every table is scoped by workspace and guarded by Postgres Row Level Security. One customer’s query cannot return another’s rows, even if the app has a bug.
Slack bot tokens and WhatsApp session credentials are AES-256-GCM encrypted before storage, with a key the database never sees.
The Slack token column is revoked from client roles entirely. Server-side jobs that must bypass row security scope every query by workspace explicitly.
An isolation audit script ships with the schema and flags any table left unprotected. Passing it is part of deploying, not an afterthought.
Against the two things most teams do instead: send by hand, or use a generic blast tool.
| Capability | BulkReach | Sending by hand | Generic blast tool |
|---|---|---|---|
| Send to a whole Slack directory | Yes | No | Yes |
| Slack and WhatsApp from one screen | Yes | No | No |
| Per-recipient personalisation | Yes | Manual | Yes |
| Consent recorded per person | Yes | No | No |
| Automatic rate limiting | Yes | You wait | No |
| Scheduled sends | Yes | No | Yes |
| Per-recipient delivery log | Yes | No | Aggregate only |
| Resumes after interruption | Yes | No | No |
| Data isolated per workspace | Yes | n/a | Varies |
Every plan includes the delivery log, scheduling and message variables. You are paying for volume, not for the features that make a send safe.
For trying it properly
Everything you need to connect Slack, import recipients and send your first campaigns.
Start freeFor teams sending weekly
Adds WhatsApp, CSV imports and the consent tooling you need to message outside Slack.
Start free trialFor higher volume
More headroom, more numbers and more seats, on the same isolated per-workspace database.
Start free trialBulkReach is a multi-tenant web app for sending bulk and scheduled messages to Slack workspaces and WhatsApp numbers from one place. You connect a channel, import or sync recipients, compose a message with per-recipient variables, and send now or schedule for later. Every send produces a per-recipient delivery log.
Through Slack OAuth v2 — the standard "Add to Slack" flow. BulkReach requests four bot scopes: team:read, users:read, users:read.email and chat:write. The bot token is encrypted with AES-256-GCM before it is stored, and the column holding it is revoked from client roles at the database level, so it is only ever readable by the server.
You pair a WhatsApp number by scanning a QR code, exactly as you would to link WhatsApp Web. The session runs on a dedicated always-on service, and the session credentials are encrypted before being stored so the connection survives restarts without a re-scan. WhatsApp automation is unofficial and against WhatsApp's terms of service, so BulkReach requires per-recipient opt-in and paces sends deliberately.
Any unofficial WhatsApp automation carries ban risk, and a banned number cannot be recovered. BulkReach reduces that risk rather than eliminating it: imported contacts start opted-out until you confirm consent, the sender re-checks consent at delivery time, and messages are spaced three to eight seconds apart at random on top of a hard floor in the sending service. Messaging people who never asked to hear from you is what gets numbers banned, and BulkReach is built to make that inconvenient.
Slack allows roughly one chat.postMessage per second per workspace, so BulkReach paces Slack sends at that rate — about 1,000 messages in 17 minutes. WhatsApp sends are spaced three to eight seconds apart at random to reduce ban risk, so they are intentionally slower. Sends run through a queue, so closing the browser does not interrupt them.
Yes. Every table is scoped by tenant and protected by Postgres Row Level Security, so one workspace's queries cannot return another workspace's rows even if the application had a bug. The three server-side paths that bypass RLS — the send dispatcher, the Slack OAuth callback and the WhatsApp service — scope every query by tenant explicitly, and the repository ships an audit script that fails if any table is left unprotected.
Yes. Pick a date and time when composing, and the send is queued but held until it is due. A scheduler checks every minute and dispatches anything that has come due. Scheduled sends can be edited or cancelled up until they start, and times are shown in your workspace timezone.
Nothing is lost. Each recipient is a separate queued row, so a send that is interrupted resumes from where it stopped rather than restarting and double-messaging people. Failures are recorded per recipient with the provider error, visible in the delivery log for that send.
Yes. Templates support {{name}}, {{first_name}}, {{email}} and {{phone}}, resolved per recipient at send time. The compose screen previews the message as a selected recipient would receive it, and warns about placeholders that do not match a known variable rather than silently sending a blank.
Yes. CSV import accepts a phone column and an optional name column, and recognises common header variations. Numbers are normalised to international format and duplicates are merged. Imported numbers arrive opted-out unless you explicitly confirm that the people on the list agreed to be contacted.
Create a workspace, connect Slack, and send something real today. The free plan does not expire and does not ask for a card.