PRIVACY NOTICE
Your data. Your control.
PULSE processes only the account and health information required for the features you enable. We do not sell your data, we do not show ads, and we do not track you across other apps or websites. This notice explains what we collect, why, and the controls you have.
Who we are and what this covers
This notice covers the PULSE iOS application and the PULSE website. PULSE is a personal fitness system for training, recovery, nutrition and progress tracking. Questions and privacy requests: youareaviss@gmail.com.
Data we collect
- Account: email address, name, password (stored only as a salted Argon2 hash), timezone, units and language preferences.
- Profile: birthdate, sex, height, body weight, body-fat estimate and training experience that you enter.
- Content you create: workout logs, training programs, nutrition entries, water intake, meal photos you submit for analysis, and your conversations with the AI coach.
- Consent records and device-connection metadata for sources you link.
Apple Health and HealthKit
Apple Health access is optional and controlled per data type by iOS. With your permission PULSE reads: sleep stages, steps, heart rate, resting heart rate, heart-rate variability, active energy, weight and workouts. PULSE writes only the weight measurements and completed strength workouts you explicitly choose to export. Imported records are linked to your PULSE account and used solely for app functionality and personalized fitness insights, such as your readiness score.
HealthKit data is never used for advertising or marketing, never sold, and never shared with data brokers or with third parties for their own purposes. You can change HealthKit permissions in the Health app or iOS Settings at any time, revoke PULSE health-import consent in the app, and permanently delete your account and server data.
Oura and connected devices
Connecting a device such as an Oura ring is optional and uses the provider’s OAuth authorization. Access tokens are encrypted at rest and are used only to import the data you authorized, such as sleep sessions. You can disconnect a provider at any time, which stops all further imports.
AI coach and meal analysis
The AI coach and photo meal analysis require a separate, explicit consent in the app and stay off until you grant it. When you use them, the minimum necessary context — such as your profile summary, recent training and recovery aggregates, and your message or meal photo — is processed by OpenAI or Anthropic as our configured AI provider, acting on our instructions. When an approved Model Context Protocol (MCP) integration is enabled, the coach can also use only the allowlisted, read-only tools configured for that service. Your data is not used to train consumer AI models. Each coach visit starts a new chat; prior chats and remembered facts remain visible and deletable in the app. Messages with emergency symptoms are redirected to professional care instead of being answered by AI.
Why we process data
- Deliver training, nutrition, recovery and synchronization features you enable.
- Generate explainable, non-medical coaching recommendations.
- Secure accounts, prevent abuse and operate the service.
PULSE does not invent metrics: readiness and recovery insights are computed only from data you actually connect or enter.
Sharing and subprocessors
We share data only with the infrastructure providers required to run PULSE: Render (API and database hosting), Vercel (website hosting), and the consent-gated AI provider configured for the coach (OpenAI or Anthropic). We never sell personal data, never share it for advertising, and use no third-party analytics or tracking SDKs in the app.
Security
All traffic is encrypted in transit with TLS. Passwords are hashed with Argon2id. Sensitive provider credentials are encrypted at rest with AES-256-GCM. Access tokens are short-lived and refresh tokens rotate on use.
Retention and deletion
We keep your data while your account exists. In Settings you can export your data and permanently delete your account, which removes your server-side data. Data stored on your device inside Apple Health is governed by iOS and remains under your control in the Health app.
Your rights
You can access, export, correct and delete your data, and withdraw any consent, directly in the app or by contacting us. Depending on your region you may have additional rights under laws such as the GDPR or CCPA; we honor requests to exercise them at youareaviss@gmail.com.
Children
PULSE is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.
Changes and contact
We will update this notice when our practices change and revise the effective date below. Material changes are announced in the app. Privacy requests: youareaviss@gmail.com.