← Back to Pulse
PULSE
Privacy Policy
Last updated: [insert date you publish this]
This is a starting draft, not a finished legal document.
It was written to accurately describe what Pulse actually does today, based on a review of the product's code -
but it has not been reviewed by a lawyer. Please have it checked before publishing, especially if any of your
customers or their members are outside the US (GDPR in the EU/UK, and similar laws elsewhere, add requirements
this draft doesn't fully cover). Anywhere you see a highlighted placeholder like
this, fill in your own details before publishing.
Pulse ("Pulse", "we", "us") is a membership-retention tool for small fitness businesses - gyms, studios,
climbing gyms, martial arts schools, and similar. This policy explains what information Pulse collects, how it's
used, and who it's shared with.
Pulse is used in two ways, and this policy covers both:
- As our direct customer - you're a gym owner or staff member with a Pulse login. We are the
data controller for your own account information.
- As data about your members - you upload your members' data (from a CSV export) into Pulse
for analysis. For that data, you (the gym) are the data controller, and Pulse acts as your data processor /
service provider - we process it on your behalf and under your instructions, we don't use it for our own
purposes. If one of your members wants to know what data you hold about them in Pulse, or wants it deleted,
they should contact you directly - you control that data, and can view, export, or delete it in the app at any
time.
Information we collect
Account information (from you, the gym owner/staff):
- Email address
- Password - never stored or seen by us in plain text; handled entirely by our authentication
provider, Supabase Auth, using industry-standard hashing
- Your gym/business name, and your role (owner or staff)
Member data (uploaded by you, about your gym's members):
- Whatever your CSV export contains - typically name, membership type, join date, visit history, and
optionally price/billing details, extra services used, and a member ID/number
- The risk assessment Pulse generates for each member (a risk level, a plain-language reason, and a
suggested action)
- Any outreach notes or contact history your staff log against a member in the CRM tool
Usage information: we log which features are used and when (e.g. "an analysis was run",
"a chat message was sent") to understand product usage. These logs record the type of event and a timestamp,
not the content of what was analysed or discussed.
Chat messages: if you use Pulse's in-app help assistant, your messages - and, when relevant,
the member/CRM data currently on your screen - are sent to our AI provider to generate a response (see "Who we
share data with" below).
How we use information
- To provide the product - running your risk analyses, storing your snapshots and CRM history, and keeping
your account secure
- To respond to questions asked through the in-app help assistant
- To understand how the product is used, so we can improve it
- To communicate with you about your account (e.g. password resets, team invites)
We do not sell your data, or your members' data, to anyone. We do not use your members' data to train any AI
model or for any purpose beyond providing the Pulse service to you.
Who we share data with
We use a small number of service providers ("sub-processors") to run Pulse. We don't share data with anyone
beyond what's needed to operate the product:
- Anthropic (api.anthropic.com) - processes the member data you submit for analysis, and
your in-app chat messages, to generate results. See Anthropic's own privacy policy for how they handle data
sent to their API.
- Supabase - hosts our database and handles account login/authentication. Your account data
and your uploaded member data are stored here.
- Cloudflare - hosts the Pulse website and the server-side component that relays requests to
Anthropic (so our AI provider's access key is never exposed in your browser). Cloudflare, like any web host,
processes standard connection data (e.g. IP address) as part of serving the site.
Data hosting region: [confirm which region your Supabase project and
Cloudflare services are configured in, and state it here].
Data retention
We keep your account data and your uploaded member data for as long as your account is active. Saved analysis
snapshots and CRM history are kept until you delete them (Pulse has an in-app option to clear saved history) or
your account is closed. We don't currently apply an automatic deletion schedule beyond that -
[decide on and state a retention period if you want one, e.g. "deleted within 90 days
of account closure"].
Security
- All traffic to Pulse is encrypted in transit (HTTPS)
- Passwords are never stored by us - authentication is handled by Supabase Auth
- Each gym's data is isolated at the database level, so one gym's staff cannot see another gym's data
- Our AI provider's API key is held only on our server-side component, never in your browser
No system is 100% secure, and we can't guarantee absolute security - but we've built Pulse with these
protections in place from the start.
Your rights
If you're a Pulse account holder (a gym owner or staff member), you can contact us to access, correct, or
delete your own account information. If you're a member of a gym that uses Pulse, we are not the right point of
contact - please reach out to that gym directly, since they control what data about you is in the system.
[If any of your customers or their members may be in the EU/UK/California or elsewhere
with its own privacy law, add the specific rights those laws require you to state here - e.g. GDPR's rights to
access, rectification, erasure, restriction, portability, and objection; or CCPA's rights to know, delete, and
opt out of sale (Pulse doesn't sell data, but CCPA still requires this be stated).]
Children's privacy
Pulse itself is intended for use by business owners and staff, not children. Some of the fitness businesses
using Pulse (e.g. martial arts schools) may have members under 18 - that data is provided to us by the gym, not
collected by us directly from a minor.
Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page and, where
appropriate, let account holders know directly.
Contact us
Questions about this policy, or requests regarding your own account data:
[insert a contact email address].
Pulse is a product of [your legal business name, if you have
one].