Privacy Policy
Draft — last updated 2026-07-18. This page is a starting point and has not been reviewed by a lawyer.
1. Who we are
Pulse is operated by an Australian sole trader (GST-registered), providing subscription analytics for app developers. This policy explains what data we collect through the Pulse dashboard, API, and SDKs, and how we use it.
2. What we collect
Depending on how you use Pulse, we process:
- Billing webhook events — from providers you connect, such as Apple App Store Server Notifications and Stripe webhooks. This includes subscription, transaction, and customer identifiers needed to compute revenue and churn metrics.
- Product telemetry events — sent by the Pulse SDKs (web, iOS, Android) that you install in your own app, such as feature usage and session events.
- Account data — your name, email, and authentication details (managed by our identity provider, Clerk), and payment details for your own Pulse subscription (managed by Stripe — we do not store card numbers).
3. Why we collect it
We use this data to operate the Service: computing MRR, churn, funnel, and recovery metrics; delivering alerts; providing the dashboard and read API; billing you for your Pulse subscription; and maintaining the security and reliability of the Service.
4. Subprocessors
We share data with the following subprocessors, each for the purpose listed:
- Vercel — Application hosting
- Neon — Postgres database
- Clerk — Authentication
- Stripe — Payments and tax calculation
- PostHog — Product analytics
- Inngest — Background job processing
- Sentry — Error monitoring
5. Data retention
Billing events form an append-only revenue ledger. As the system of record for your revenue, it is retained for the life of your account and is not deleted on a fixed schedule. If you request erasure, the identifying fields on these records are anonymised (see “Your rights” below) while the underlying revenue figures are kept for accounting and tax purposes.
Product telemetry events are automatically deleted after a fixed retention window of 12 months (365 days). Aged events are purged on a daily job; nothing is retained beyond that window.
6. Your rights
You can, at any time:
- Access your data through the dashboard or the read API.
- Export your data using the dashboard’s export feature or the read API.
- Request erasure of a customer or your account. Erasure anonymises the identifying fields on your ledger records (so revenue history stays intact for accounting) and removes personal data elsewhere.
7. Security
Every account’s data is isolated from every other account at the database level. Webhook payloads are verified against the sending provider’s signature before we process them.
8. Contact
Questions about this policy, or to exercise your rights above: [CONTACT EMAIL — Reuben to fill]
See also our Terms of Service.