Privacy Policy
Effective
Pulse turns your own Google Health data into recovery, strain and sleep scores. This page explains what the hosted Pulse app collects, why, and how you stay in control of it. Short version: your data is used only to show you your scores. It is never sold, never used for ads, and never shared.
Who this covers
Pulse is open-source software (source on GitHub, licensed under the PolyForm Noncommercial 1.0.0 license). Anyone can run their own copy.
This policy covers the hosted instance at pulsefit.portlabs.in ("the hosted app"). It is run by the Pulse project maintainer for personal, family and testing use. In this policy, "we" means that maintainer, and "you" means a person with an account on the hosted app.
If you use a copy of Pulse that someone else runs, that person is responsible for your data, not us. Self-hosters are the data controllers for their own instances and should give their users their own privacy policy.
This website (pulse.portlabs.in) is a public information site. It has no accounts and collects no health data.
Your Pulse account
When you sign up and use the hosted app, we store:
- Account details: your name, username and email address.
- Your password, stored only as a salted scrypt hash. We cannot see or recover your password.
- Sessions: a session record for each device you sign in on, with its IP address and browser user agent. We keep these for security, so you stay signed in and so suspicious sign-ins can be spotted.
- Rate-limit counters, short-lived records that slow down repeated sign-in attempts and other abuse.
- Your profile: birth date, sex, height, time zone and, if you enter it, your measured maximum heart rate. Scores need these to be accurate. You can also upload a profile photo.
- What you enter in Pulse: journal answers, dashboard layout, settings, and the entries you log (see below).
Data from Google
Pulse gets your health data from Google Health, the service your Fitbit Air syncs to. You connect your own Google account through Google's sign-in and consent screen, and you choose what to allow. Pulse asks for these kinds of access:
Sign-in basics
- Your Google account's email address, name and profile photo, so Settings can show which Google account is connected.
Health data Pulse reads
- Activity and fitness: steps, workouts, active minutes, calories and similar activity data.
- Health metrics and measurements: heart rate, heart rate variability, resting heart rate, blood oxygen, breathing rate, skin temperature, weight and body measurements.
- Sleep: sleep sessions and sleep stages.
- ECG: ECG results (the classification and average heart rate, never the waveform).
- Irregular rhythm notifications: whether and when an irregular heart rhythm alert happened.
- Nutrition: food, hydration and nutrition logs.
- Profile: the age on your Google Health profile, used to suggest your birth year during setup.
- Settings: the list of devices paired with your Google Health account, so Pulse can tell you when no Fitbit device is connected.
Data Pulse writes to Google Health
Pulse asks for write access to nutrition, health metrics and measurements, mindfulness, logged symptoms and reproductive health. It uses this only to save the entries you log in Pulse (water and food; weight and body fat; mood; symptoms; menstrual periods and ovulation tests, shown only on female profiles), and to delete them again if you delete them in Pulse. Pulse never writes anything you did not log yourself, and never changes or deletes data it did not create.
Pulse also stores a Google refresh token on the server so it can keep syncing in the background. It is never sent to your browser. You can cut off access at any time (see Your choices).
How Pulse uses your data
Pulse uses your data only to provide the features you see in the app:
- computing your recovery, strain, sleep and stress scores, baselines, trends and reports;
- showing your health data, journal and logged entries back to you;
- saving what you log to your Google Health account;
- keeping your account secure and the service running.
Specifically, Pulse does not:
- sell your data, or transfer it to data brokers or information resellers;
- use your data for advertising, including personalised or retargeted ads;
- use your data to train artificial intelligence or machine learning models;
- use your data to decide on credit, lending, insurance or employment;
- let people read your data, except as described below.
No human reads your health data unless you ask us to (for example, to help you with a support problem and you give your consent), it is needed for security (for example, investigating abuse), or the law requires it.
Google API Services User Data Policy
Pulse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, this means data from Google is used only to provide and improve the user-facing features of Pulse described on this page. It is not transferred to anyone else, except as needed to provide those features, to comply with the law, or as part of a merger or acquisition with your consent. It is not used for ads, not sold, and not read by humans except as listed above.
Storage and security
- Your data is stored in the hosted app's own PostgreSQL database, on a server the maintainer runs. It is not stored with a cloud analytics or data company.
- Every connection to the app uses HTTPS.
- Each user can see only their own data. Passwords are hashed, and sign-in attempts are rate-limited.
- Database backups are encrypted.
No system is perfectly secure. If we learn of a breach that affects your data, we will tell you without undue delay.
Retention and deletion
- While you use Pulse, your data is kept so your scores, baselines and history work.
- Raw Google responses are archived for up to 30 days to help fix sync problems, then deleted automatically. The processed data stays until you delete it.
- Disconnecting Google revokes Pulse's access, so no new data is read or written. Data already synced stays in your Pulse account until you delete it.
- Switching to a different Google account deletes the data synced from the previous one.
- Deleting your account in Settings › Account permanently deletes your account and everything linked to it: profile, sessions, tokens, synced Google data, scores, journal and logged entries.
- Backups are kept for about 14 days, so deleted data is fully gone from backups within that time.
Entries you logged in Pulse and saved to Google Health stay in your Google account until you delete them there, because Google holds them, not Pulse.
Your choices and rights
- See and export your data at any time: the app's data page exports it as CSV or JSON.
- Correct your profile and account details in Settings.
- Disconnect Google in Settings, or remove Pulse's access from your Google account at myaccount.google.com/permissions.
- Delete your account and all your data in Settings › Account.
- Ask us for a copy of your data, a correction, or deletion by emailing work.adityajindal@gmail.com. Depending on where you live, you may have further rights under laws such as India's Digital Personal Data Protection Act or the GDPR. We will honour them.
Cookies and analytics
The hosted app uses only the cookies it needs to keep you signed in and secure. It has no advertising, no third-party analytics and no trackers.
This website (pulse.portlabs.in) may count page views with Umami, a privacy-friendly analytics tool that we host ourselves. It uses no cookies, collects no personal data, and does not track you across sites.
Children
Pulse is not for children under 13. The app requires an age between 13 and 100. If you believe a child under 13 has created an account, email us and we will delete it.
Not medical advice
Pulse is a wellness tool, not a medical device. Its scores are estimates and are not a diagnosis or medical advice. Talk to a doctor about any health concern.
Changes to this policy
If we change this policy, we will update the effective date above. For important changes, especially any new use of Google data, we will tell you in the app or by email first and, where required, ask for your consent.
Contact
Questions or requests about privacy: work.adityajindal@gmail.com.
See also the Terms of Service.