Legal · Privacy

Privacy Policy

What The Pulse collects, why, who processes it, and how to get it deleted. Written plainly, because you should not need a lawyer to know what happens to your email address.

Effective 9 September 2026 · Applies to thepulse.fun, its API and the account dashboard

1. Who we are

The Pulse ("we") operates thepulse.fun, The Pulse Rolex Index, the associated data API and the account dashboard. For anything in this policy, write to hello@thepulse.fun. We answer privacy requests within 30 days.

2. What we collect

Account data. When you create an account we store your email address, the date the account was created, and, if you choose one, a password. Passwords are stored only as a salted hash (PBKDF2, 210,000 iterations); we cannot read them. If you sign in with Google, GitHub or Facebook we store the identifier that provider assigns to you and the name it shares, so we can recognise you next time.

API keys and usage. Each API key is a random token linked to your account. We count successful API requests per account and per key, per day, to enforce plan limits and to show you your own usage. We do not log the content of your requests beyond the endpoint called.

Billing. If you subscribe to a paid tier, payment is handled by Stripe. We store Stripe's identifiers for your customer and subscription and the subscription status. Card numbers never reach our systems.

Security counters. To stop abuse we keep short-lived counters keyed by IP address (sign-ups per day, sign-in emails and failed passwords per hour). They expire within 24 hours and are not linked to your account history.

Sign-in emails. When you ask for a sign-in code we generate a one-time code and link valid for 15 minutes and send them to your email address through our email provider.

Interest forms. If you leave your email on the data and pricing page we record the email and the option you picked (collector, developer, enterprise) so we can follow up.

Server logs. Our hosting provider keeps standard request logs (IP address, user agent, URL, time) for a limited period to operate and secure the service.

What we do not collect. We do not run advertising or third-party analytics trackers on thepulse.fun, we do not buy data about you, and we do not sell or rent your data to anyone.

3. Signing in with Google, GitHub or Facebook

When you choose a social sign-in we ask the provider only for your basic profile: name, email address and whether that email is verified. We use it to create or find your account. We never post on your behalf, never read your contacts, repositories, friends or files, and never ask for those permissions.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can disconnect our access at any time from your Google account permissions, GitHub authorized OAuth apps or Facebook settings; your Pulse account remains and you can still sign in with your email.

4. How we use your data

  • To run your account: sign you in, issue and revoke API keys, show your usage.
  • To enforce plan limits and prevent abuse of the API and the sign-in system.
  • To bill paid plans and handle cancellations and refunds.
  • To answer support requests and tell you about changes that affect your account, your keys or the API. We do not send marketing email unless you ask for the weekly report.
  • To keep the service secure and to comply with law.

5. Cookies and local storage

We set no tracking cookies. The dashboard keeps your session token in your browser's local storage so you stay signed in; "Sign out" removes it. Our hosting provider may set strictly functional cookies, and Stripe sets its own cookies on its checkout and billing pages, governed by Stripe's privacy policy.

6. Who processes data for us

ProviderPurposeData involved
NetlifyHosting, serverless functions, data storage, form captureAll account and usage data; request logs
StripePayments and subscriptionsEmail, card details (held by Stripe only), billing status
ResendSending sign-in codes and account emailsEmail address, message content
Google, GitHub, MetaOptional identity providersOnly when you choose to sign in with them: name, email, provider id

These providers act on our instructions and are bound by their own contractual and legal obligations. Data is processed on servers operated by these providers, primarily in the United States. We do not share your personal data with anyone else except when the law requires it.

7. How long we keep it

Account data, API keys and usage history are kept while your account is active. Security counters expire within 24 hours. Sign-in codes expire after 15 minutes and are deleted once used. When you delete your account we delete it and its keys within 30 days; billing records that we must keep for tax and accounting reasons are retained for the legally required period.

8. Your rights

You can see, correct, export or delete your data. Most of it is visible in your dashboard today; for anything else, or to delete your account, email hello@thepulse.fun from the account address. If you are in the EU, UK, California or another place with a privacy law, you have the rights that law gives you, including the right to complain to your local authority. We do not use automated decision-making about you.

9. Security

All traffic is encrypted in transit. Passwords are hashed, sign-in codes are single use, sessions expire after 30 days and can be ended everywhere from Settings, and API keys can be revoked instantly. No system is perfect; if we learn of a breach affecting your data we will tell you without undue delay.

10. Children

The Pulse is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, tell us and we will delete it.

11. Changes to this policy

If we change what we collect or how we use it, we will update this page and the effective date, and for material changes we will email account holders. Earlier versions are available on request.

See also our Statement of Compliance and Methodology.