← Back to PulseID

Privacy Policy

Last updated: August 30, 2026

Introduction

PulseID ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we handle your information when you use our mobile application.

PulseID is designed with privacy at its core. Heart-rate data, photos, and videos are processed on your device and are not uploaded to PulseID servers.

Our Privacy Commitment

We do NOT collect, store, or transmit your biometric or health data to any external servers.

Information We Collect

Account & Subscription

When you create an account or purchase a subscription, we collect your email address and subscription status. Payment processing is handled entirely by Apple—we never receive your payment details.

Health & Biometric Data

With your explicit consent, PulseID accesses heart rate data from:

This data is accessed solely to display your heart rate on screen and overlay it on photos/videos. The data is processed entirely on your device and is never uploaded, stored, or transmitted externally.

Camera & Photo Library

We request access to:

Media you create stays on your device unless you choose to share it.

Device Information

We collect device model, operating system version, app version, and platform. This data is used solely to diagnose crashes, reproduce bugs, and monitor app stability—it is never used for advertising or tracking.

Approximate Location

City and country may be derived automatically by our hosting provider (Cloudflare) from your IP address for abuse prevention and service security. We do not collect GPS coordinates.

How Your Data is Used

Your data is used solely to provide app functionality:

Your photos and videos are not transmitted to or stored on PulseID servers.

Data Storage

Account data: Stored securely on our servers while your account is active.

Health data: Processed on your device only—never stored on our servers.

Media: Photos and videos are processed on your device and are not stored on PulseID servers.

Legal Basis for Processing (GDPR)

If you are in the European Economic Area, we process your data under the following legal bases:

Data Sharing

We do not sell, rent, or trade your personal data. We do not use your data for advertising.

Data Storage & International Transfers

Account data is stored securely on servers in the United States via Cloudflare (encrypted in transit and at rest). If you are located outside the United States, your data will be transferred to and processed in the United States. International transfers are conducted based on Standard Contractual Clauses (SCCs) as approved by the European Commission.

Health and biometric data, photos, and videos are processed on your device and are never transmitted to or stored on PulseID servers.

Data Retention

We retain your account data while your account is active. You can delete your account from the Profile screen in PulseID. Account deletion removes the account, sessions, linked sign-in accounts, and subscription records held by PulseID.

Service Providers

We share limited personal data with service providers only as needed to operate PulseID:

App telemetry may include app version, platform, feature event names, success or failure, processing duration, and subscription status. Authentication telemetry may include an account identifier, email address, and sign-in method so we can diagnose signup and sign-in issues. Operational telemetry does not include heart-rate values, health records, photos, videos, chat content, or advertising identifiers.

We do not use personal data for advertising, and we never sell personal information. Health and biometric data is never shared with these providers.

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

If you are in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority.

For California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

To exercise these rights, contact us at [email protected].

For Washington State Residents (My Health My Data Act)

Washington's My Health My Data Act provides additional protections for health data. Under this law:

Data Breach Notification

In the event of a data breach affecting your personal data, we will notify affected users and relevant authorities in accordance with applicable law, including GDPR (72-hour notification to supervisory authorities) and applicable US state breach notification laws.

Children's Privacy

PulseID is not intended for children under 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children under this age.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the app. Continued use of the app after non-health-related changes constitutes acceptance of the updated policy. Material changes to how we process health and biometric data will require renewed consent.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

[email protected]