PulseNote Privacy Policy

Effective date: August 16, 2026

PulseNote is a study-notes app with spaced-repetition reminders, operated by Thomas Verdier ("PulseNote", "we", "us"). This policy explains what data the app handles, why, and the choices you have. It describes what the app actually does today — nothing more.

The short version

1. Data you give us

Account data (only if you create an account)

Content you sync (only while signed in)

When you are signed in, the app syncs your study content to our servers so your devices stay consistent:

Help and feedback (whether or not you are signed in)

If you choose Help & feedback, we receive the category and message you submit, any screenshots you select, and your app version, build number, device platform, operating-system version, and app language. If you are signed in, we associate the request with your account and use your verified account email for replies. If you are signed out, you may provide a reply email, but it is optional. We do not collect a device identifier for anonymous support requests.

2. Data collected automatically

The app contains no analytics, advertising, or tracking SDKs, and nothing that records what you read or how you use it. Apart from the crash reports described above, an install with no account makes no network requests on its own — only when you open or create a shared-note link, or deliberately submit a help request.

3. Data that stays on your device

We do not collect your location, contacts, calendar, or any data from other apps.

4. How we use data

Purpose Data used Legal basis (GDPR)
Provide the service: accounts, sync, sharing Account data, synced content Contract
Transactional email: verification codes, password resets, security notices (e.g. a new sign-in method linked) Email address Contract
Respond to help requests and improve PulseNote Help-request content, optional reply email, screenshots, limited diagnostics Contract or legitimate interest
Security: rate limiting, abuse and account-takeover prevention IP address, request metadata, security metadata Legitimate interest
Reliability: fixing errors Error reports (credentials stripped) Legitimate interest
Legal compliance Whatever the obligation requires Legal obligation

We send no marketing emails — automated mail is triggered by an account or help action, and human mail is a reply to a request you sent us. We do not sell or rent personal data, and we do not share it with anyone for advertising.

5. Shared notes

Sharing is per-note and opt-in. When you create a share link:

6. Service providers

We use a small number of infrastructure providers to run PulseNote. They process data only to provide their service to us:

Provider What they do for us Where
Render Hosts our API and database (notes, accounts, help requests) United States (Virginia)
Cloudflare Network security/proxy, and private R2 object storage for note images and support screenshots United States / global network
Resend Sends transactional mail and notifications to our support inbox United States
Sentry Error monitoring (credential-scrubbed) United States
Google Sign-in with Google (only if you use it), and the Google Workspace mailbox that receives and answers support@pulsenoteapp.com Per Google's policy
Apple Sign in with Apple (only if you use it) Per Apple's policy

7. International transfers

Our servers are located in the United States. If you use PulseNote from the EEA, UK, or elsewhere, your data is transferred to and processed in the US. Our providers rely on recognized safeguards for such transfers (such as the EU–US Data Privacy Framework and/or Standard Contractual Clauses).

8. Retention

9. Deleting your account

You can delete your account directly in the app (Account → Delete account). Deletion is immediate and permanent: your notes, images, recall history, settings, share links, linked in-app help requests and screenshots, sessions, and account record are removed from our servers. Support correspondence already delivered to our mailbox follows the support-email retention period above. Copies of notes that other users imported from your share links remain with those users. Residual traces in encrypted backups age out automatically within the backup window.

If you can't use the app, email us (contact below) from your account's email address and we will delete the account for you.

10. Your rights

Depending on where you live (e.g. GDPR in the EEA/UK, CCPA in California), you have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. Most of this you can do directly in the app — your notes are editable and exportable by you, and deletion is built in. For anything else, email us and we will respond within 30 days. We verify requests via your account email. We never discriminate against you for exercising your rights, and we do not "sell" or "share" personal information as defined by the CCPA.

If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.

11. Security

All traffic between the app and our servers is encrypted with TLS. Passwords are bcrypt-hashed; session tokens and reset codes are stored only as hashes; note images and support screenshots live in private storage; and the API enforces rate limits and sign-in lockouts. On your device, credentials are kept in the operating system's secure storage. No system is perfectly secure, but we design so that a single failure exposes as little as possible.

12. Children

PulseNote is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has created an account, contact us and we will delete it.

13. Changes to this policy

When we change this policy, we will update the effective date above and post the new version at the same address. For material changes, we will notify you in the app or by email before they take effect.

14. Contact

PulseNote — operated by Thomas Verdier Email: support@pulsenoteapp.com

For data-protection requests about an account, write from the account's email address so we can verify it's you. For an anonymous help request, include the request details and any reply address you supplied so we can locate it.