PulseCheck Privacy Policy
Last updated: June 13, 2026PulseCheck ("PulseCheck," "we," "us," or "our") is operated by Steradian Labs. This policy
explains what information the PulseCheck app collects, how we use it, who processes it on our
behalf, and the choices and rights you have. Questions: [email protected].The short versionPulseCheck generates personalized, motivational notifications and insights based on your
wearable health data. We do not require a name, email, or password to use the app. We do not
sell or rent your data, we do not use it for cross-app advertising or tracking, and you can
permanently delete everything from within the app at any time (Settings, "Delete my data").Information we collect- Anonymous account identifier. On first launch the app generates a random identifier
(a UUID) stored on your device. It links your preferences and notification history to your
installation. It is not your name, email, phone number, or any real-world identity.
- Wearable health metrics (via WHOOP, with your authorization). When you connect your
WHOOP account, we read daily metrics such as recovery, heart rate variability (HRV), resting
heart rate, sleep, strain, and workouts. These metrics are fetched on demand to generate your
notification and are not stored on our servers. We retain only the resulting notification
text and a small set of summary values shown on the shareable card.
- Generated notifications. The notification text we create for you, along with its
associated voice and timestamp, so you can view your history and create shareable cards.
- Push notification token. If you enable notifications, Apple provides a device token we
use to deliver them.
- Purchase status. Whether you have unlocked PulseCheck Pro, and the Apple transaction
identifier used to validate and restore the purchase. Payments are handled entirely by
Apple; we never receive or store your card or payment details.
- First-party usage analytics. Anonymous, aggregated product analytics tied to the
anonymous identifier: app version, platform, session identifiers, event names (for example,
a screen viewed or a purchase completed), and timestamps. These contain no personal content
and no message text. We use our own analytics; there is no third-party advertising SDK.
- Diagnostic and error logs. Technical error information used to keep the app working. We
do not log message content, tokens, or other sensitive data.What we do not collectWe do not collect your name, email address, phone number, or password (the app has no login).
We do not collect precise location, your contacts, the advertising identifier (IDFA), or
biometric identifiers, and we do not track you across other companies' apps or websites.How we use your information- Generate your personalized, motivational notifications and insights.
- Deliver those notifications and build your shareable cards.
- Provide and restore your PulseCheck Pro purchase.
- Measure and improve the product through anonymous analytics.
- Diagnose and fix errors, and keep the service secure and reliable.How notifications are generated (Google / Gemini)To create the text of your notifications, we send a concise, de-identified summary of the
relevant wearable metrics (for example, a recovery percentage, sleep duration, or workout
strain) together with your chosen voice style to Google's Gemini API, which returns the
generated text. We do not send your identity to Google: no name, email, account
identifier, WHOOP account details, or device token are included. Google processes this data
as our service provider to perform the generation and, per Google's API terms for paid
services, does not use it to train its models. We do not use this data for advertising.How we share informationWe do not sell or rent your personal information, and we do not share it for advertising or
cross-app tracking. We share data only with service providers who process it on our behalf,
under contract and only to operate PulseCheck:- Google (Gemini API): generates notification text from de-identified metrics, as
described above.
- WHOOP: the source of the wearable metrics you authorize us to read.
- Supabase: our managed database, which stores your preferences, notification history,
and anonymous analytics.
- Railway: our application hosting provider.
- Apple: push notification delivery and In-App Purchase processing.We may also disclose information if required by law, regulation, or valid legal process, or to
protect the rights, safety, and security of our users and our service.Data retention and deletionWe retain your data while you use the app. You can permanently delete your account and all
associated data at any time from within the app: Settings, "Delete my data." This removes
your account record, notification history, WHOOP connection and tokens, and registered
devices from our servers. You may also contact [email protected] to request deletion.
Deleting the app from your device stops further collection. Anonymous analytics and error
events carry no identity and may be retained in aggregate.Your rights and choicesYou can disconnect WHOOP, turn notifications off, and delete all of your data from within the
app. Depending on where you live, you may have additional rights described below. Because the
app uses an anonymous identifier rather than a verified account, we fulfill access and
deletion requests through the in-app controls and your device.California (CCPA/CPRA)If you are a California resident, you have the right to know what personal information we
collect and how we use and disclose it, the right to request deletion, and the right to not be
discriminated against for exercising your rights. We do not sell or share your personal
information as those terms are defined under California law, and we honor Global Privacy
Control signals where applicable. You can exercise your deletion right in the app or by
emailing [email protected].Europe, the UK, and EEA (GDPR/UK GDPR)If you are in the EEA or UK, you have the right to access, correct, delete, restrict, or object
to the processing of your personal data, and to data portability. Our legal bases are: the
performance of our contract with you (to provide the app's core features), your consent (for
connecting WHOOP and enabling notifications), and our legitimate interests (to secure, measure,
and improve the service). You may withdraw consent at any time and may lodge a complaint with
your local supervisory authority.SecurityWe use industry-standard measures to protect your information, including encryption in transit
(HTTPS), access controls, and trusted infrastructure providers. WHOOP authorization uses OAuth,
so we never see your WHOOP password. No method of transmission or storage is completely secure,
but we work to protect your information and limit what we retain.ChildrenPulseCheck is not directed to children under 13, and we do not knowingly collect personal
information from children under 13. If you believe a child has provided us information, contact
[email protected] and we will delete it.International data transfersWe operate in the United States, and our service providers may process data in the United
States and other countries. Where required, we rely on appropriate safeguards for international
transfers.Changes to this policyWe may update this policy from time to time. We will revise the "Last updated" date above and,
for material changes, provide notice within the app where appropriate.ContactSteradian Labs
[email protected]