Privacy Policy
Last updated July 14, 2026
This policy explains what Pulse collects, why, and what you can do about it. The short version: we collect as little as possible, we never sell your data, and we don't run ads or third-party analytics trackers.
Who is responsible
Pulse is run by an independent developer who decides how and why your data is handled (the "data controller"). You can reach us using the contact details at the end of this page.
What we collect
Account details: your email address, and — if your sign-in provider shares them — your name and avatar. We also store which provider you used (Google, GitHub, email, or Telegram) and a provider identifier, so we can recognise you next time.
Your habit data: the habits, check-ins, notes, streaks, categories, and share links you create.
Preferences: your language and time zone, so your day rolls over correctly and the app speaks your language.
Technical data: your IP address and basic request information, used briefly to deliver pages, keep the service secure, and prevent abuse.
Reminders: if you turn on notifications, we store a push subscription or your Telegram chat identifier, so we can send the reminders you asked for.
Why we use it
We use your data to provide Pulse and do what you ask of it — signing you in, saving and syncing your habits, and showing your history. This is how we deliver the service you signed up for.
We also use limited data to keep Pulse secure and prevent abuse (our legitimate interest), to send the sign-in links and reminders you request, and to meet legal obligations. We don't use your data for advertising or profiling.
Signing in
When you sign in with Google, GitHub, or Telegram, we receive a small amount of profile information from them, such as your email and name. Email sign-in works through a one-time link sent by our email delivery provider.
Each provider handles your data under its own privacy policy, which we don't control.
Who we share data with
We do not sell your data, and we don't share it for anyone else's marketing.
To run Pulse we rely on a few trusted providers who process data on our behalf under agreements: cloud hosting and databases (including Cloudflare for edge storage and delivery), an email provider for sign-in links, and notification delivery for web push and Telegram messages.
We may also disclose data if the law genuinely requires it, or to protect the rights, safety, and security of our users and the service.
Where your data is handled
Pulse runs on cloud infrastructure that may store or process data in countries other than the one you live in. Where data crosses borders, we rely on appropriate safeguards to protect it.
How long we keep it
We keep your data for as long as your account is active. When you delete your account, we erase your habits, logs, shares, and account details.
Small amounts of information may linger briefly in security logs or backups before they rotate out in the normal course.
Your rights
You can access and download your data (there's a one-tap export in Settings), correct it, and delete your account and everything in it — also from Settings.
Depending on where you live, you may also have the right to object to or restrict certain processing, and to withdraw consent for reminders at any time by turning notifications off. If you're in the EU or UK, you can also complain to your local data protection authority.
To exercise any right, use the in-app controls or email us.
How we protect your data
Traffic is encrypted in transit (HTTPS). Your session lives in a sealed, http-only cookie that your browser's scripts can't read, and we store credentials only as one-way hashes — never in plain text.
Your offline copy of your habits is kept locally on your device and is cleared automatically when you sign out.
Cookies and local storage
Pulse uses only essential first-party cookies: a secure session cookie to keep you signed in, plus small cookies that remember your language, your time zone, a hint that you were signed in, where to send you after login, and whether you've seen the cookie notice.
To work offline, Pulse also keeps a cache of your habits on your device, in your browser's storage; it's cleared when you sign out. We don't use advertising cookies or third-party analytics.
Children
Pulse isn't intended for children under 16, and we don't knowingly collect data from them. If you believe a child has given us their data, contact us and we'll delete it.
Changes to this policy
We may update this policy as Pulse changes. If a change is significant, we'll make a reasonable effort to tell you. The date at the top shows when it last changed.
Contact
Questions about your privacy or this policy? Email us at pulseapp@googlegroups.com