Privacy & data
Last updated: 21 July 2026
The short version. Pulse sends one signal: a heart. No text, no photos, no location, no address book. The server knows which two devices are linked and nothing about who you are.
What the server stores
- A random device number and a random secret, created on first launch. Not linked to a phone number, e-mail or account.
- A push token issued by Google Firebase, needed to deliver the signal.
- A six-character pairing code that expires after ten minutes.
- The number of the device you are paired with.
- The time of your last signal, used only to block flooding.
That is the entire database. There is no name field, no e-mail field, no location field.
What stays only on your phone
- Your partner's name — you type it for yourself, it is never sent anywhere.
- The history of sent and received signals.
- Sound and vibration preferences.
Uninstalling the app removes all of it.
What is never collected
- Location, at any time.
- Contacts, photos, microphone, camera.
- Message content — there is none. A signal carries only its type.
- Analytics, advertising identifiers, behavioural tracking.
Who else sees the data
Delivery relies on Google Firebase Cloud Messaging. Google receives the push token and the fact that a message was delivered to a device. Their handling is covered by the Firebase privacy documentation. No other third party is involved. Nothing is sold, shared or transferred.
Security
- All traffic runs over HTTPS.
- Every request is authenticated with the device secret.
- Pairing codes expire after ten minutes and stop working once a pair is linked.
- Server keys and the database are not reachable from the web.
Deleting your data
Uninstall the app to remove everything held on the device. To have the server record removed as well, write to the address below and include your pairing code.
Children
Pulse is not intended for children under 13.
Changes
If this page changes, the date at the top changes with it.