Pulse
Home About Support Privacy Terms

Privacy Policy

Effective: June 2, 2026 · v2.1

Summary

Your privacy matters. We collect only what we need to operate the Service, we never sell or share personal information for cross-context behavioral advertising, and we give you full control to access, port, correct, or delete your data at any time.

1. Who We Are (Data Controller)

The controller of your personal information is Pulse. Contact: meir56885@gmail.com — the same address handles general privacy, EEA/UK, and Brazilian (LGPD) DPO matters.

2. Information We Collect

  • a) Account data — the Apple-provided identifier, and the name and email (or Apple private-relay email) you choose to share via Sign in with Apple, plus your account creation timestamp. We do not operate passwords or email/password accounts; authentication is handled entirely by Apple.
  • b) Goal data — goal titles, descriptions, categories, deadlines, motivation level, time-per-day, skill level, obstacles, AI-generated pulses and roadmaps, completion timestamps, progress notes, photos and free-text proof you attach.
  • c) Coach chat — messages you send to the AI coach, AI responses, selected personality, and goal context.
  • d) Photos — any image you attach as proof or submit to Photo Transformation. Photos are transmitted to our AI provider in transient memory for analysis only and are NOT retained on our servers after the response returns to your device. We do not perform biometric identification.
  • e) Device & diagnostic — device model, OS version, App version, time zone, locale, anonymized installation identifier, crash reports.
  • f) Notification state — your on/off preference and the AI-determined local schedule.
  • g) Subscription state — your free or paid status as reported by Apple StoreKit (we do not see your payment-card data).

3. How We Use Information

  • Operate, secure, and improve the Service.
  • Generate AI-powered roadmaps, mentor responses, and photo analysis (transient processing).
  • Send adaptive notifications based on your goals, streak, and deadline.
  • Sync your data privately across your devices via Apple iCloud / CloudKit.
  • Detect and prevent fraud, abuse, and violations of the Terms.
  • Comply with legal obligations and respond to lawful requests.

We do NOT sell your personal information. We do NOT "share" personal information for cross-context behavioral advertising as defined under the California Privacy Rights Act. We do NOT use the Service for targeted advertising.

4. Legal Bases (GDPR, UK GDPR, LGPD, Other)

  • Performance of a contract — delivering the Service you signed up for.
  • Your consent — for notifications and for photo-based features.
  • Our legitimate interests — security, fraud prevention, product improvement (subject to your right to object).
  • Legal obligation — compliance with applicable law.

For LGPD (Brazil): we additionally rely on the hipóteses set out in Art. 7 — execução de contrato, consentimento, legítimo interesse, cumprimento de obrigação legal e regulatória.

For India DPDP 2023: we rely on consent and legitimate uses where applicable.

5. Categories of Recipients & Sub-Processors

We share data only with these categories of recipients, each bound to confidentiality:

  • Google LLC (Gemini API) — AI inference for coach chat, roadmap generation, translation, and image analysis. This sub-processor receives the chat content, roadmaps, translation requests, and user photos described in Sections 2 and 3, processed transiently and not retained by us.
  • Cloudflare, Inc. — operates the secure proxy that relays your AI requests (prompts and photos) to the AI provider above. It transmits these in transient memory and does not store them for us.
  • Apple, Inc. — iCloud / CloudKit, App Store payments, Sign in with Apple, push notification routing.
  • Our hosting and infrastructure providers (subject to confidentiality).
  • Law-enforcement / government — only when legally required (with notice to you where lawful).

A current list of named sub-processors and their roles is available on request at meir56885@gmail.com.

6. Sensitive / Special-Category Data

We do not solicit sensitive personal information under CCPA/CPRA, special-category data under GDPR Art. 9, sensitive personal data under LGPD Art. 5(II), or sensitive data under India's DPDP Act 2023. If you voluntarily submit such information in free-text goals, notes, or coach chat, you do so at your own discretion; we will treat it confidentially but you should avoid disclosing more than necessary. We do not knowingly collect biometric identifiers.

7. International Data Transfers

Your information may be processed in the United States and other countries where our providers operate. For transfers from the EEA, UK, or Switzerland to the United States or other countries lacking an adequacy decision, we rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and equivalent UK and Swiss addenda. For transfers from Brazil we rely on the safeguards set out in LGPD Art. 33. We perform transfer-impact assessments where required.

8. Retention

  • Account data — until you delete your account (then deleted within 30 days, except where legal retention applies).
  • Goal & mentor data — until you delete the goal or your account.
  • Photos — discarded immediately after the AI response returns.
  • Diagnostic logs — up to 90 days, then deleted.
  • Backups — purged within 30 days of deletion request.
  • Legal holds — we may retain data longer where required to comply with law or to defend legal claims.

9. Security

We use industry-standard technical and organizational measures: TLS 1.2+ in transit; iOS Data Protection at rest on your device; Keychain (Secure Enclave where available) for credentials; least-privilege access controls on the backend. Despite these measures, no internet transmission or storage is 100% secure. You are responsible for choosing a strong, unique password and securing your device.

10. Your Rights — Universal Summary

Depending on your jurisdiction, you have one or more of the following rights:

  • Access — copy of your personal information.
  • Rectification — correct inaccurate or incomplete data.
  • Deletion / erasure — request we erase your data.
  • Portability — receive your data in a structured, commonly-used, machine-readable format.
  • Object — to processing based on our legitimate interests, or to direct marketing.
  • Restrict — request restriction of processing.
  • Withdraw consent — for any processing based on consent.
  • Non-discrimination — we will not retaliate for exercising any right.

Exercise any right via Profile → Your Data or by emailing meir56885@gmail.com. We respond within 30 days (extendable to 60 in complex cases under GDPR). You also have the right to complain to your data-protection authority (e.g., ICO in the UK, CNIL in France, AEPD in Spain, Garante in Italy, ANPD in Brazil, OAIC in Australia, OPC in Canada, PIPC in South Korea, PPC in Japan).

11. California (CCPA / CPRA) Notice at Collection

Categories of personal information collected in the past 12 months: identifiers (email, account ID); internet activity (App usage); inferences (goal progress patterns); user-generated content (goals, notes, photos). Purpose: providing and improving the Service.

We do NOT sell personal information and do NOT share for cross-context behavioral advertising. There is therefore no "Do Not Sell or Share My Personal Information" link required — but you may still request access, deletion, correction, or limitation of sensitive PI use via meir56885@gmail.com.

Sensitive personal information collected: none. We do not retain or use sensitive PI for purposes other than those permitted by 11 CCR § 7027(m).

Retention periods: see Section 8.

Right to limit: as we do not use sensitive PI for inferring characteristics, no limitation right applies.

Authorized agents may submit requests on your behalf with proof of authorization.

12. EEA / UK / Switzerland (GDPR)

If you are in the EEA, the UK, or Switzerland: you have rights under GDPR, UK GDPR, and the Swiss FADP. Lawful bases are listed in Section 4. The controller is Pulse. The Service does not engage in automated decision-making producing legal or similarly significant effects on you. You may lodge a complaint with your supervisory authority. Our EU representative under GDPR Art. 27 (if and when designated) is available on request at meir56885@gmail.com.

13. United Kingdom

UK GDPR + Data Protection Act 2018 apply. Our UK representative (if designated) is available on request at meir56885@gmail.com. You may complain to the Information Commissioner's Office (ico.org.uk).

14. Canada (PIPEDA + Quebec Law 25)

Pulse complies with the Personal Information Protection and Electronic Documents Act and Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25). Quebec residents have rights to data portability, deindexation, and notification of automated decision-making (we do not engage in qualifying ADM).

15. Brazil (LGPD)

Pulse processes personal data of Brazilian residents in accordance with the Lei Geral de Proteção de Dados (Lei 13,709/2018). Lawful bases are described above. You may exercise LGPD rights (Art. 18), including Brazilian DPO (Encarregado) matters, via meir56885@gmail.com. You may file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).

16. Other Jurisdictions

We respect, and process data in accordance with, applicable data-protection laws including:

  • Australia — Privacy Act 1988 and Australian Privacy Principles.
  • New Zealand — Privacy Act 2020.
  • India — Digital Personal Data Protection Act 2023.
  • Japan — Act on the Protection of Personal Information (APPI).
  • South Korea — Personal Information Protection Act (PIPA).
  • China — Personal Information Protection Law (PIPL) — note that Service availability in mainland China may be limited.
  • Singapore — Personal Data Protection Act (PDPA).
  • Hong Kong — Personal Data (Privacy) Ordinance (PDPO).
  • UAE — Federal Decree-Law 45/2021.
  • Saudi Arabia — Personal Data Protection Law.
  • South Africa — Protection of Personal Information Act (POPIA).
  • Nigeria — Nigeria Data Protection Regulation (NDPR).
  • Israel — Protection of Privacy Law 5741-1981.

Local rights provided by these laws are available to residents of the respective jurisdictions; contact meir56885@gmail.com to exercise them.

17. Children's Privacy (COPPA, GDPR-K, etc.)

The Service is not directed to children under 13 (or under 16 in the EEA Member States that have set 16 as the digital-services consent age). We do not knowingly collect personal information from children below the applicable age. If you believe a child has provided us personal information, contact meir56885@gmail.com and we will delete it without undue delay.

18. Marketing & Anti-Spam

We do not currently send marketing emails. If we do in future, you will be able to unsubscribe via a link in every message. We comply with CAN-SPAM (US), CASL (Canada), the Spam Act 2003 (Australia), the ePrivacy Directive (EU), and applicable laws.

19. Cookies / Tracking Technologies

The mobile App does not use cookies. We do not embed any analytics SDKs, advertising SDKs, fingerprinting libraries, or cross-app tracking technologies. We do not engage in tracking as defined by the Apple App Tracking Transparency framework.

20. Automated Decision-Making

AI output (roadmaps, probabilities, coach messages) is generated automatically but does NOT produce legal or similarly significant effects on you within the meaning of GDPR Art. 22 or analogous laws. You may disregard, modify, or delete any AI output at any time. We do not engage in solely-automated profiling that has legal effect.

21. Data Breach Notification

In the event of a personal-data breach likely to result in a risk to your rights or freedoms, we will notify the competent supervisory authority within the timeframes required by applicable law (e.g., 72 hours under GDPR Art. 33) and will notify affected individuals where required.

22. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be disclosed in-App with a revised "Effective" date. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.

23. Contact

All privacy questions, complaints, and rights requests — including EEA/UK/Swiss and Brazilian (LGPD) Data Protection Officer matters and US legal notices — go to a single address: meir56885@gmail.com.

© Pulse
About · Support · Privacy Policy · Terms of Use · meir56885@gmail.com