Your trust is our top priority. Pulse is built with enterprise-grade security to protect your data at every layer.
π 256-bit TLS Encryption
β OAuth 2.0 Certified
π‘οΈ GDPR Compliant
All data transmitted between your browser and our servers is encrypted using industry-standard TLS/HTTPS protocols. Passwords are hashed using bcrypt with 12 rounds of salting.
We use NextAuth.js with OAuth 2.0 for secure authentication via Google and Microsoft. We never see or store your email provider passwords.
Sensitive data including access tokens and refresh tokens are stored exclusively in our encrypted PostgreSQL database with row-level access controls. Session JWTs contain only user identification data.
OAuth access tokens are managed through our centralized TokenManager, automatically refreshing expiring tokens to maintain secure API access without user intervention.
All incoming Stripe webhooks are cryptographically verified using HMAC signatures to prevent unauthorized payment modifications and ensure data integrity.
Middleware-based route protection ensures users can only access their own data. Free, Pro, and Business tier restrictions are enforced at the API level to prevent unauthorized feature access.
All user inputs are validated and sanitized before processing. API endpoints enforce strict type checking and reject malformed requests to prevent injection attacks.
Application hosted on enterprise-grade infrastructure with automated backups, DDoS protection, and 99.9% uptime SLA. Database connections use SSL/TLS encryption.
Per-user token quotas prevent abuse and ensure fair resource allocation. API routes implement timeout protections and rate limit error handling.
AI providers are contractually bound to strict data protection agreements. We minimize data transmission and never use your data for model training or advertising.
We never sell, rent, or share your personal data with third parties for marketing or advertising purposes. Your data is yours alone.
Pulse follows GDPR, CCPA, and Google API Services User Data Policy requirements. We maintain strict data minimization and purpose limitation principles.
We only access the minimum data needed to provide our service. Email and calendar data is processed solely for user-facing features you explicitly enable.
You can revoke access, export your data, or request complete deletion at any time. Your privacy settings are always in your control.
We explicitly commit to never selling, renting, or sharing your personal data with third parties for marketing, advertising, or any purposes unrelated to the core Pulse service.
Third-Party Data Sales
Advertising Partners
Your Data Ownership
Pulse's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use your Google data exclusively to provide and improve user-facing features within Pulse.
European General Data Protection Regulation compliant
California Consumer Privacy Act compliant
Payment Card Industry standards via Stripe
You can request a copy of all personal data we hold about you at any time.
Request complete account and data deletion through Settings or by contacting support.
Export your data in machine-readable format to transfer to another service.
Revoke Pulse's access to your Google/Microsoft accounts anytime through your account permissions.
We're committed to transparency. If you have specific security questions or concerns, our team is here to help.
Last updated: October 23, 2025