Pulsewith / Privacy
Privacy policy
Effective date: September 11, 2026
What you share with each other matters. This policy explains what Pulsewith collects, how it is used, and the choices available to you.
On this page
01. Who we are
Pulsewith is operated by Çagdas Can, established in Finland. The operator is responsible for the personal information described in this policy.
Postal address: Sarvastonkaari 3 H34 00840 Helsinki FinlandPrivacy contact: privacy@pulsewith.com
This policy covers the Pulsewith app, its supporting services, and our legal website. Read our Terms of service for the rules that apply to using Pulsewith.
02. Information we handle
Your account and connection
When you begin using the app, our authentication service assigns an account identifier even if you have not added a sign-in method. We call this an anonymous sign-in, but information linked to that identifier is not anonymous data.
We handle your display name, partner alias, profile color, onboarding answers, relationship connection, invitation codes and their expiry, and related timestamps. If you protect your account with Apple or email, we also handle the identity information supplied through that method, which may include an email address or Apple relay address.
Check-ins and preferences
We handle mood selections, check-in times, reactions, and any optional "why" note you choose to share. Notes receive the encryption protection described below. We also handle preferences such as quiet hours and time zone, and device push tokens when you enable notifications.
Subscriptions
Apple handles App Store payments. RevenueCat and our backend process information needed to recognize your subscription, including customer and transaction identifiers, product, purchase and renewal status, trial eligibility or status, and subscription dates. We do not receive your full payment card details from Apple.
App usage and technical information
Our analytics events can include screens and onboarding steps, app and operating-system versions, device model, account and couple identifiers, invitation events, subscription events, and bounded error codes.
Product analytics are sent automatically. The app currently does not offer an analytics opt-in or opt-out setting.
The updated app omits mood and reaction selections from PostHog events. Check-in and reaction events record usage and timing, not the selected option. Onboarding events omit answer values. Check-in analytics can still include whether a note was added and a note-length range. These usage events remain linked to pseudonymous account or couple identifiers; they are not anonymous statistics at collection. Our analytics event schema does not include the text of your private notes.
Earlier app versions may have sent mood or reaction values to PostHog. Updating the app does not itself erase historical provider records. Those records remain subject to the applicable retention and deletion process described below.
Hosting and service providers may process technical connection information, such as IP addresses, request times, and security logs, when your device connects to them. Our PostHog event configuration disables IP-based geolocation and does not set an IP address as an event property; this does not prevent network-level processing by providers.
Support and the website
If you contact us, we receive your email address and the information you send. Please avoid sending private relationship notes, passwords, or payment card details. Our legal pages do not embed analytics scripts, advertising trackers, forms, or remote fonts. Our hosting provider still processes requests needed to deliver and protect the website.
03. Private notes and encryption
The optional "why" text is encrypted on your device before it is sent to the backend. The backend stores ciphertext and a nonce rather than the readable note. The app uses a shared couple key, stored in device secure storage, so paired devices can decrypt the note.
This protection applies to note text, not to every piece of account data. Mood and reaction codes, timestamps, profile information, and relationship or subscription metadata are not protected by this end-to-end note encryption.
Information your partner can view may remain on their device or in copies they make. Device displays, widgets, notifications, screenshots, and an unlocked device can expose information outside the protection of server-stored ciphertext. Protect your device and notification settings. Losing encryption keys can make historical notes unreadable; account sign-in recovery does not guarantee recovery of those keys.
We use technical and organizational safeguards to protect the service, but no service can guarantee absolute security.
04. How we use information
- Provide accounts, consensual partner pairing, check-ins, reactions, and the shared app experience.
- Deliver notifications you enable and respect your notification preferences.
- Recognize purchases, restore access, and maintain subscription entitlements.
- Provide account recovery, respond to support and privacy requests, and send necessary service emails.
- Use product analytics to understand onboarding drop-off, feature usage, subscription conversion, and technical failures so we can improve Pulsewith.
- Maintain service reliability, prevent abuse, and meet applicable legal obligations.
- Use aggregate mood counts from check-ins held in our application database to evaluate and improve the available selection, including whether to add or replace options.
Legal bases
Where the GDPR applies, we rely on performance of our contract with you for processing necessary to provide accounts, partner pairing, check-ins and reactions, subscription access, notifications you enable, and related support. We rely on our legitimate interests in protecting and improving Pulsewith for proportionate security and abuse prevention, the product analytics described above, and aggregate reporting used to improve mood options, where those interests are not overridden by your interests or fundamental rights and freedoms. We rely on legal obligations for processing required by applicable law, including handling applicable privacy-rights requests. Our automatic product analytics are not based on an analytics-consent choice in the app.
06. International processing
Our Supabase project is hosted in North Virginia, United States, and our PostHog project uses its United States region. Providers may process information in other locations under their applicable service arrangements. Your information may therefore be processed outside the country where you live.
Where applicable data-protection law requires safeguards for transfers outside the European Economic Area, the safeguards depend on the destination and service involved. The data-processing terms for covered processing by Supabase, PostHog, RevenueCat, Resend, and Cloudflare provide for European Commission-approved Standard Contractual Clauses for relevant restricted transfers. These clauses impose data-protection obligations on the parties. Providers may also rely on applicable adequacy decisions for qualifying transfers. The Gmail inbox used for support and privacy correspondence operates under Google's consumer terms and Privacy Policy, not a Google Workspace business data-processing agreement. Google's published transfer framework describes the mechanisms it uses, including adequacy decisions and Standard Contractual Clauses where applicable.
You can read Google's international-transfer framework. Contact privacy@pulsewith.com for details of safeguards applicable to your information or a copy of applicable Standard Contractual Clauses and their completed annexes. Where required, we provide these free of charge, with only legally permitted redactions to protect confidential information.
07. Retention and deletion
We retain account information and check-in history for as long as needed to provide Pulsewith and its history features. We manually review retained personal information at least once a year and remove information that is no longer needed, subject to applicable legal requirements. We do not apply an automatic one-year expiry to app history or automatically delete accounts after one year of inactivity. The annual review does not postpone our handling of deletion requests.
You can request account deletion from Settings in the app or contact privacy@pulsewith.com if you cannot access your account. We may need information to verify that the request concerns your account.
The in-app deletion flow removes your authentication account and account-owned app records from the active database, ends your active relationship connections, and attempts cleanup of your associated RevenueCat customer records. Any failed provider cleanup needs manual follow-up by us.
To complete provider follow-up, we retain a restricted deletion-request record containing necessary account and provider identifiers, any available account email used to locate correspondence, the request time, and cleanup status. It does not contain your moods or private notes. We remove this operational record when the required follow-up is complete and its identifiers are no longer needed.
Your partner keeps their own account and their own records. Deletion cannot remove screenshots, exports, or other copies already held by another person. Backup copies, security and audit records, provider records, and records retained for legal reasons can follow separate retention schedules. In-app deletion does not automatically erase all historical PostHog or other external-provider records. Records outside the automated flow require manual follow-up by us as part of handling the deletion request, subject to applicable retention exceptions; you do not need to submit a second request for that follow-up.
Deleting your account does not cancel an App Store subscription. Manage or cancel it separately in your Apple subscription settings. Apple maintains its own purchase records under its policies and applicable law.
08. Your choices and rights
You choose whether to add a private note, enable notifications, connect a partner, and add a sign-in method. You can change notification permissions in your device settings and manage available preferences in the app.
Depending on where you live and the law that applies, you may have rights to access or obtain a copy of your information, correct it, request deletion or restriction, object to certain processing, and receive portable data. Where processing relies on consent, you may withdraw that consent without affecting the lawfulness of earlier processing. These rights may have legal limitations.
Where the GDPR applies and processing relies on legitimate interests, you may object for reasons relating to your particular situation, including to the analytics described above. We must stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims. The absence of an in-app analytics setting does not remove this right.
Contact privacy@pulsewith.com to exercise a right or ask about analytics processing. We may verify your identity before acting. Where applicable, you may complain to your local data protection authority. We will not discriminate against you for exercising applicable privacy rights.
09. Age requirements
Pulsewith is intended for people aged 18 or older. If you believe a child below that age has provided personal information, contact privacy@pulsewith.com so we can investigate and take appropriate action.
10. Changes and contact
We may update this policy as the service or our obligations change. We will update the effective date and provide any additional notice or choices required by applicable law before relevant changes take effect.
Privacy questions: privacy@pulsewith.com
App support: support@pulsewith.com