Overview
Pulse is developed by Ivan Shakhorski ("we," "us"), who is the data controller for the personal data described in this policy. Pulse is a habit tracker: you create daily or weekly activities, log completions, add notes, and optionally invite friends — by QR code or link — to track shared activities together, where everyone in the group can see each other's progress.
Because that shared-progress feature is central to how Pulse works, this policy pays particular attention to what becomes visible to other people, not just to us.
Information we collect
Account information
When you sign in with Sign in with Apple or Sign in with Google, we receive your name, email address, a unique account identifier, and — if your provider supplies one — a link to your profile picture, via Firebase Authentication. If you choose Apple's private email relay, we only ever see the relay address, not your real one.
If your provider gives us no name, Pulse asks you for a display name at the moment one is about to become visible to someone else — when you send an invite, or join someone else's activity — rather than at sign-in. Until then, no name is stored for you. You can change your display name at any time in Settings.
Activity & habit data
The content you create in Pulse: activity names, schedule type (daily or weekly), completion history, streaks, and any notes you attach to a completed day.
Shared activity data
If you create or join a shared activity, your completions, streaks, and notes for that activity are visible in real time to every other member of that activity — that's the point of sharing. Leaving a shared activity stops future updates from being shared, but does not retroactively hide what other members have already seen.
Invite links
An invite link or QR code carries a token and a snapshot of the activity it invites to — its name, description, schedule, daily goal, and how many people are in it — so whoever receives it can see what they are joining before they accept. It does not expose your other activities or your account details. Links stop working 30 days after they are created, any member can replace a link with a fresh one (which immediately invalidates the old one), and we record which account redeemed which token so a link cannot be reused after it is replaced.
Diagnostic data
Pulse contains no analytics, advertising, attribution, or tracking SDK. We do not record which screens you open or how often you use the app. What exists is the ordinary operational logging every hosted service produces: Firebase records requests to authentication, the database, and push delivery, including the originating IP address and timestamps, and our server-side functions log the outcome of operations such as an account deletion cascade. We use these to keep the service running and to investigate faults, not to profile you.
Push notification token
If you enable notifications, your device registers a token with Apple's push notification service, which we store against your account so we can reach that device. It is used only for Pulse's own notifications — today, telling the other members of a shared activity that someone completed it, which means the notification carries your display name and the activity's name to their devices. We don't see the content of other apps' notifications. Signing out removes that device's token from your account before the session ends, so a device you have handed on cannot keep receiving your notifications, and deleting your account removes every token it holds.
How we use it
- Operate core features: authenticate you, sync your activities across devices, and keep shared activities up to date for every member.
- Send the notifications you've enabled — today, telling the members of a shared activity when one of them completes it.
- Keep the service running, diagnose faults, and protect it from abuse.
- Respond to support requests sent to our contact email.
We do not sell your personal data, and we do not use it for third-party advertising.
Legal basis for processing
Under the GDPR, we need a legal basis for each way we use your data. Here's ours:
| Data | Legal basis |
|---|---|
| Account & activity data | Contract — needed to provide the Pulse service you signed up for |
| Shared activity data | Contract — needed to run the shared-activity feature you chose to use |
| Diagnostic & operational logs | Legitimate interest — keeping the service running, secure, and debuggable, balanced against your privacy |
| Push notifications | Consent — you opt in, and can withdraw at any time in Settings |
Service providers
Pulse runs on Google Firebase, which provides authentication, database storage, server-side functions, and push delivery on our behalf. Firebase processes data under Google's own terms and security practices; see Google's Privacy Policy for how they handle it. Sign in with Apple additionally involves Apple as the identity provider, and Apple's push notification service delivers the notifications you opt into. We use no advertising, attribution, or analytics SDKs, and there are no other processors.
Storage & security
Your data is stored on Firebase's infrastructure and encrypted in transit between your device and our servers. Access to production data is limited to what's needed to operate and support the app. No system is perfectly secure, but we don't collect more than Pulse needs to function.
Retention
We keep your account and activity data for as long as your account is active. Deleting your account, from Settings inside the app, removes your data as follows:
- Your profile — your name, email, profile picture link, and push tokens are deleted from our database, and your sign-in account is deleted from Firebase Authentication.
- Activities you own — deleted outright, along with their complete history for everyone in them, including other members' completions and notes, and their invite links. The app tells you this before you confirm. If you would rather a shared activity survive you, hand it over to another member first: an owner can pass ownership on from the members list, and an activity you no longer own is treated below as one you joined.
- Activities you joined — the activity itself continues for its other members, and you are removed from it. Completions and notes you already contributed to that activity stay part of the group's shared history, because removing them would rewrite a record other people rely on. They remain stored against your former account identifier, which no longer resolves to a name or to a live account.
Invite links expire 30 days after they are created, and the record of a redeemed token is deleted together with the activity it belongs to. Backups and operational logs may retain deleted data for a short period before they age out.
Your rights
Built into the app, available any time:
- Delete your account — in Settings, under Advanced. Your provider will ask you to sign in again to confirm it is you; nothing is deleted unless that succeeds, and cancelling leaves everything untouched. What is removed is described under Retention.
- Change your display name — in Settings. The new name replaces the old one everywhere it is shown to other members.
- Leave a shared activity — stops future syncing of your progress to that group.
- Replace an invite link — minting a fresh link for an activity immediately invalidates every copy of the old one.
- Turn off notifications — in Pulse's Settings or your device's system settings.
If you're in the EU/EEA or UK, the GDPR also gives you these rights over your personal data — and we honor them for every Pulse user, wherever you are:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct data that's inaccurate or incomplete.
- Erasure — delete your account and personal data. You can do this yourself in Settings ▸ Advanced, without asking us; email ivanwanwas@icloud.com if you would rather we did it, or if you want data removed that in-app deletion leaves behind.
- Restriction — ask us to limit how we use your data while a request is being resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest, such as our operational logging.
To exercise any of these, email ivanwanwas@icloud.com — we'll respond within a reasonable time. If you're not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority. If you're outside the EU/EEA — for example under the CCPA — similar rights to access, delete, and correct your data apply; contact us and we'll help.
Children
Pulse is not directed at children, and we don't knowingly collect information from anyone under 16 — or the digital consent age set by your country's law, which in some EU member states is as low as 13. If you believe a child has created an account, contact us and we'll remove it.
International data transfers
Pulse runs on Google Firebase, which may process and store data in the United States or other countries outside the EU/EEA and UK. When we transfer personal data out of the EU/EEA, UK, or Switzerland, we rely on safeguards recognized under the GDPR — such as the European Commission's Standard Contractual Clauses, which Google implements for its Firebase and Google Cloud services.
Changes to this policy
If we make material changes, we'll update the effective date above and, where appropriate, notify you in the app. Continued use of Pulse after a change means you accept the updated policy.
Contact
Ivan Shakhorski
Developer of Pulse: Track Your Momentum