Pulsity

Privacy Policy

Updated 18 September 2026

This policy explains what data Pulsity collects, why, and how it is handled. It covers the mobile app and this website.

Who we are

Pulsity, Mumbai, India, is the controller of the personal data described here. You can reach us at privacy@pulsity.app.

Health and fitness data

With your explicit permission, Pulsity reads health and fitness data from Apple Health on iOS and Android Health Connect on Android — including steps, heart rate, heart-rate variability, sleep, blood oxygen, resting heart rate, body temperature, distance and active calories.

We ask only for the permissions the features you use actually need, and you can withdraw any of them at any time in your phone's settings. Withdrawing a permission stops the reading immediately; it does not delete data already stored, which you can remove separately.

Health data is never used for advertising, never sold, and never shared with data brokers. We do not use it to build advertising profiles or transfer it to third parties for their own purposes.

What else we collect

  • Account details — your phone number, name, date of birth, height and weight. The phone number identifies your account; the rest personalises your baseline.
  • Things you enter — logged activity, trades or decisions, region and altitude, and your notification preferences.
  • Technical data — device model, operating system, app version, language, and diagnostic logs when something crashes.
  • Subscription status — which plan you are on and when it renews. Card details are handled by Apple, Google or the payment provider and never reach our servers.

How your data is used

  • To calculate your personal baseline and detect readings that fall outside it.
  • To show your dashboard, trends, readiness score and alerts, and to answer questions you ask the in-app assistant about your own data.
  • To send the notifications you have switched on, and to respect your quiet hours.
  • To keep the service working — authentication, abuse prevention, and fixing crashes.

We do not use your health data to make automated decisions with legal effects. Pulsity supports your own judgement; it does not replace a doctor, and it does not diagnose, treat or monitor any condition.

Legal bases

Where the GDPR or the UK GDPR applies, we rely on your explicit consent for health data, on performance of a contract for running your account and subscription, and on legitimate interests for security and fixing faults. Where India's DPDP Act applies, we process on the basis of the consent you give when you grant health permissions.

Who we share it with

We do not sell your data. We share it only with the service providers that make the app work, and only as much as each one needs:

  • Cloud hosting and database providers that store your account.
  • Push notification services, to deliver alerts to your device.
  • Crash and error reporting, to tell us what broke — diagnostic data only, never health readings.
  • Apple and Google, who process subscription payments under their own privacy policies.

We may also disclose data where the law requires it, and we will tell you unless we are legally prevented from doing so.

Where it is stored

Data is encrypted in transit with HTTPS and stored on servers operated by our hosting provider. If your data is transferred outside your country, we use the safeguards required by your local law, such as standard contractual clauses.

How long we keep it

Your readings stay while your account is open, because the baseline depends on history. Delete your account from the app and we remove your profile, readings and preferences within 30 days, except where a law requires us to keep a record for longer.

Your rights

You can, at any time:

  • See and export your data — Profile → Export My Data, which hands you everything as a file.
  • Correct your profile from Profile → Edit Profile.
  • Delete your account and all its data from Profile → Delete My Account.
  • Withdraw consent by turning off health permissions in your phone's settings.
  • Object or complain — write to us, and if you are not satisfied, to your local data protection authority.

Security

Connections use HTTPS. Sessions use short-lived access tokens with rotating refresh tokens, and login codes are stored hashed. On your phone, tokens are held in the operating system's secure store. No system is perfect, so if a breach affects you we will tell you and the relevant authority within the time the law allows.

Children

Pulsity is not for people under 16, and we do not knowingly collect their data. If you believe a child has created an account, write to privacy@pulsity.app and we will remove it.

Changes to this policy

When this policy changes we update the date at the top, and for anything that materially affects you we tell you in the app before it takes effect.

Contact

Questions about your data, or a request under any of the rights above: privacy@pulsity.app.