Skip to content

Ch 01 · Features

Everything a real send needs

BulkReach is not a bigger textbox. It is the queue, the pacing, the consent checks and the audit trail that turn one message into hundreds of delivered ones — without you watching it happen.

Ch 01
Channel

Slack, connected properly

A standard OAuth install, a synced member directory, and sending that respects the rate limit Slack actually enforces.

One-click OAuth install

The regular “Add to Slack” flow, requesting four bot scopes and nothing more: team:read, users:read, users:read.email and chat:write. Install state is signed and tied to your browser session, so an install link cannot be replayed into someone else’s workspace.

Member directory sync

Pull the full workspace directory on demand, paginated automatically. Bots, deactivated accounts and Slackbot are filtered out. People who leave are marked inactive rather than deleted, so historical delivery logs keep pointing at a real person.

Rate limiting that matches Slack

Slack allows roughly one chat.postMessage per second per workspace. BulkReach paces to that automatically and backs off when Slack returns a 429, so a large send completes instead of half-failing.

Direct messages, no channel noise

Messages go to people, not to a channel everyone has to mute. DMs are opened implicitly at send time, so there is no setup per recipient.

Ch 02
Channel

WhatsApp, with the safeguards stated up front

QR pairing, a session that survives restarts, and consent enforcement that is not optional. WhatsApp automation is unofficial — we build accordingly.

Pair by scanning a QR code

The same flow as linking WhatsApp Web: open Linked devices on your phone and scan. The pairing screen updates live as the session connects.

Sessions that survive restarts

Session credentials are encrypted with AES-256-GCM and stored, so a deployment or restart resumes the connection instead of demanding a fresh scan every morning.

Randomised send pacing

Messages are spaced three to eight seconds apart at random, on top of a hard floor enforced inside the sending service itself. A predictable cadence looks automated, and looking automated is what gets numbers banned.

Consent checked twice

Once when you pick the audience, and again at the moment of delivery. Someone who opts out between queueing and sending never receives the message.

Ch 03
Audience

One recipient list, every channel

Slack members, WhatsApp contacts and imported numbers live in one place, searchable and segmentable together.

Unified across sources

Everyone you can reach in a single table, tagged by where they came from — Slack, WhatsApp or CSV — so you never have to remember which list someone is on.

CSV import with consent confirmation

Common header names are recognised automatically (phone, number, mobile, whatsapp). Numbers are normalised to international format, duplicates merged, unreadable rows reported. Nothing is marked opted-in unless you explicitly confirm the list agreed to be contacted.

Tags as saved audiences

Tag people once and reuse the tag as a segment when composing. Bulk-tag a selection in one action rather than editing rows one at a time.

Search and filter

Search across names, emails and phone numbers; filter by source or tag. Selection survives filtering, so you can build an audience across several searches.

Bulk actions

Record or withdraw consent, add tags, or delete — for hundreds of recipients at once, from one selection bar.

Consent visible at a glance

Every WhatsApp and CSV recipient shows their opt-in state in the list, so you know what a send will actually reach before you write a word.

Ch 04
Composing

Write once, land right for each person

Templating, live preview and channel selection, with the mistakes caught before they ship rather than after.

Per-recipient variables

Use {{name}}, {{first_name}}, {{email}} and {{phone}}. Each is resolved for the individual recipient at send time and stored with the delivery, so the log shows exactly what each person received.

Live preview

See the message rendered as a real selected recipient would receive it, not as a template with braces in it.

Typos caught, not sent

A placeholder that does not match a known variable is flagged before you send, and left visible in the message rather than silently replaced with a blank.

Multi-channel in one pass

Select Slack, WhatsApp or both. Each recipient is routed on the channel that can actually reach them, and the summary tells you how many will be skipped and why.

Ch 05
Timing

Send now, or exactly when it lands best

Scheduling is not a separate mode. It is the same queue, held until it is due.

Schedule to the minute

Pick a date and time when composing. A scheduler checks every minute and dispatches anything that has come due.

Editable until it starts

Change the message or the time right up to the moment the send begins. Editing the text re-renders every queued recipient, so nobody receives the previous draft.

Timezone per workspace

Each workspace sets its own timezone, and scheduled times are displayed in it — so a team spread across three countries reads the same schedule the same way.

Ch 06
Accountability

Know what happened, per person

A send is not a fire-and-forget. Every recipient is a row you can look at afterwards.

Per-recipient delivery log

Sent, failed, pending or skipped — for every recipient on every channel, with the exact text delivered and the provider error where one occurred.

Resumable sends

Each recipient is queued separately, so an interrupted send resumes where it stopped. Nobody gets messaged twice because a browser tab closed.

Monthly usage

How many messages went out this month, split by channel, on the overview — the foundation for plan limits and for answering “how much are we sending?”.

Ch 07
Trust

Security that is structural, not procedural

Isolation enforced by the database, secrets encrypted at rest, and an audit you can run yourself.

Row Level Security throughout

Every table is scoped by workspace and guarded by Postgres RLS. A query cannot cross workspaces even if the application layer has a bug, because the database refuses to return the rows.

Encrypted secrets

Slack bot tokens and WhatsApp session credentials are AES-256-GCM encrypted before storage. The Slack token column is additionally revoked from client roles, since row-level security does not protect individual columns.

Explicit privilege boundaries

Only three server-side paths bypass row security — the send dispatcher, the OAuth callback and the WhatsApp service — and each scopes every query by workspace explicitly.

Light and dark, done well

A single accent on a neutral base, tuned separately for both themes, with reduced-motion respected throughout. It defaults to light and remembers what you pick.

Stand by · cue in 3 · 2 · 1

See it on your own workspace

Connect Slack in under a minute and send something real. The free plan does not expire.