Privacy Policy
Pulse turns one tap into a gentle vibration on one other person's phone. It is built for two people, and it is built to know as little about them as possible. There are no accounts, no profiles, no analytics, and no advertising.
What Pulse stores
To deliver a tap from one phone to the other, the Pulse server keeps a small record for each connection:
- A random device identifier. The app generates a random UUID the first time it launches and stores it on your device. It is not your Apple ID, not the advertising identifier, and not tied to your device hardware. Deleting the app discards it.
- A display name. Whatever you type when you set up the app, up to 30 characters. It is shown only to the one person you are connected with. It does not need to be your real name.
- A six-character invite code, randomly generated, which admits exactly two phones and then closes permanently.
- A session token, randomly generated, so the server can tell your phone apart from the other one.
- A push notification token issued by Apple, used only to deliver a vibration to the other phone.
- Timestamps. When each phone joined, when it was last seen, and when each tap was sent. A tap carries no content — only the moment it happened. The server keeps at most the 500 most recent taps per connection.
What Pulse does not collect
- No email address, phone number, or real name.
- No location data.
- No contacts, photos, microphone, or camera access.
- No message content — a tap has no content to collect.
- No advertising identifier and no tracking across apps or websites.
- No analytics, crash reporting, or behavioural profiling.
Pulse contains no third-party SDKs. Nothing in the app reports to an analytics, advertising, or attribution service.
How the information is used
Solely to connect two phones and deliver a tap between them. The data is never used to build a profile, never sold, never rented, and never used for advertising or marketing.
Who it is shared with
Only Apple. Delivering a notification requires sending the push token and the notification to the Apple Push Notification service. Apple's handling of that data is governed by Apple's own privacy policy. Pulse shares data with no one else.
How long it is kept
When you disconnect, your device's record — including its display name and push token — is removed from the connection. Once both phones have left, the connection and its entire tap history are deleted from the server. Older taps are discarded automatically once a connection exceeds 500 of them.
Deleting your data
Disconnect inside the app, or delete the app and ask us to remove the connection. Because Pulse holds no account and no email address, please include your six-character invite code so the right connection can be found. If you are unable to provide it, we may be unable to identify your data.
Security
All traffic between the app and the server uses encrypted HTTPS connections. Session tokens and invite codes are generated with a cryptographically secure random number generator. Stored data is kept in a file readable only by the server process. No system is perfectly secure, but Pulse is designed to hold so little that there is very little to lose.
Children
Pulse is not directed at children under 13, and we do not knowingly collect information from them.
Notifications
Pulse asks for notification permission so a tap can reach you when the app is closed. You can decline or revoke it in iOS Settings at any time; the rest of the app continues to work.
Changes
If this policy changes, the date at the top of this page will be updated. Material changes will be noted in the app.
Contact
Questions about privacy, or requests to delete data: 0xshxyz@gmail.com.