PulseCheck Privacy Policy
Last updated: June 13, 2026
PulseCheck ("PulseCheck," "we," "us," or "our") is operated by Steradian Labs. This policy explains what information the PulseCheck app collects, how we use it, who processes it on our behalf, and the choices and rights you have. Questions: pulsecheck@steradianlabs.com.
The short version
PulseCheck generates personalized, motivational notifications and insights based on your wearable health data. We do not require a name, email, or password to use the app. We do not sell or rent your data, we do not use it for cross-app advertising or tracking, and you can permanently delete everything from within the app at any time (Settings, "Delete my data").
Information we collect
- Anonymous account identifier. On first launch the app generates a random identifier (a UUID) stored on your device. It links your preferences and notification history to your installation. It is not your name, email, phone number, or any real-world identity.
- Wearable health metrics (via WHOOP, with your authorization). When you connect your WHOOP account, we read daily metrics such as recovery, heart rate variability (HRV), resting heart rate, sleep, strain, and workouts. These metrics are fetched on demand to generate your notification and are not stored on our servers. We retain only the resulting notification text and a small set of summary values shown on the shareable card. As part of connecting, we read your WHOOP profile solely to obtain your WHOOP account identifier; we do not store your WHOOP name or email, only that account identifier.
- Generated notifications. The notification text we create for you, along with its associated voice and timestamp, so you can view your history and create shareable cards.
- Push notification token. If you enable notifications, Apple provides a device token we use to deliver them.
- Purchase status. Whether you have unlocked PulseCheck Pro, and the Apple transaction identifier used to validate and restore the purchase. Payments are handled entirely by Apple; we never receive or store your card or payment details.
- First-party usage analytics. Anonymous, aggregated product analytics tied to the anonymous identifier: app version, platform, session identifiers, event names (for example, a screen viewed or a purchase completed), and timestamps. These contain no personal content and no message text. We use our own analytics; there is no third-party advertising SDK.
- Diagnostic and error logs. Technical error information used to keep the app working. We do not log message content, tokens, or other sensitive data.
What we do not collect
We do not ask you for, or store, your name, email address, phone number, or password (the app has no login). We do not collect precise location, your contacts, the advertising identifier (IDFA), or biometric identifiers, and we do not track you across other companies' apps or websites.
How we use your information
- Generate your personalized, motivational notifications and insights.
- Deliver those notifications and build your shareable cards.
- Provide and restore your PulseCheck Pro purchase.
- Measure and improve the product through anonymous analytics.
- Diagnose and fix errors, and keep the service secure and reliable.
How notifications are generated (Google / Gemini)
To create the text of your notifications, we send a concise, de-identified summary of the relevant wearable metrics (for example, a recovery percentage, sleep duration, or workout strain) together with your chosen voice style to Google's Gemini API, which returns the generated text. We do not send your identity to Google: no name, email, account identifier, WHOOP account details, or device token are included. Google processes this data as our service provider to perform the generation and, per Google's API terms for paid services, does not use it to train its models. We do not use this data for advertising.
How we share information
We do not sell or rent your personal information, and we do not share it for advertising or cross-app tracking. We share data only with service providers who process it on our behalf, under contract and only to operate PulseCheck:
- Google (Gemini API): generates notification text from de-identified metrics, as described above.
- WHOOP: the source of the wearable metrics you authorize us to read.
- Supabase: our managed database, which stores your preferences, notification history, and anonymous analytics.
- Railway: our application hosting provider.
- Apple: push notification delivery and In-App Purchase processing.
We may also disclose information if required by law, regulation, or valid legal process, or to protect the rights, safety, and security of our users and our service.
Data retention and deletion
We retain your data while you use the app. You can permanently delete your account and all associated data at any time from within the app: Settings, "Delete my data." This removes your account record, notification history, WHOOP connection and tokens, and registered devices from our servers. You may also contact pulsecheck@steradianlabs.com to request deletion. Deleting the app from your device stops further collection. Anonymous analytics and error events carry no identity and may be retained in aggregate.
Your rights and choices
You can disconnect WHOOP, turn notifications off, and delete all of your data from within the app. Depending on where you live, you may have additional rights described below. Because the app uses an anonymous identifier rather than a verified account, we fulfill access and deletion requests through the in-app controls and your device.
California (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, the right to request deletion, and the right to not be discriminated against for exercising your rights. We do not sell or share your personal information as those terms are defined under California law, and we honor Global Privacy Control signals where applicable. You can exercise your deletion right in the app or by emailing pulsecheck@steradianlabs.com.
Europe, the UK, and EEA (GDPR/UK GDPR)
If you are in the EEA or UK, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. Our legal bases are: the performance of our contract with you (to provide the app's core features), your consent (for connecting WHOOP and enabling notifications), and our legitimate interests (to secure, measure, and improve the service). You may withdraw consent at any time and may lodge a complaint with your local supervisory authority.
Security
We use industry-standard measures to protect your information, including encryption in transit (HTTPS), access controls, and trusted infrastructure providers. WHOOP authorization uses OAuth, so we never see your WHOOP password. No method of transmission or storage is completely secure, but we work to protect your information and limit what we retain.
Children
PulseCheck is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact pulsecheck@steradianlabs.com and we will delete it.
International data transfers
We operate in the United States, and our service providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards for international transfers.
Changes to this policy
We may update this policy from time to time. We will revise the "Last updated" date above and, for material changes, provide notice within the app where appropriate.
Contact
Steradian Labs pulsecheck@steradianlabs.com