Privacy Policy

Last updated: 24 September 2026

PULS3 is made by PULS3 PTY LTD (ACN 696 197 412) in Australia. This policy explains what data the app handles, what leaves your phone and why, who else touches it, and what you can delete. We wrote it to be read, not skimmed past.

1. The short version

2. Data the app collects

You can use the app without an account. Without one, nothing in this list is tied to your identity on our servers.

Before PULS3 uses any health details, the app asks for your agreement on its own screen, “Your health details”, separate from the Terms. We record your answer, the version of that screen, and the time. Until you agree, the app does not read Apple Health or Oura, sends nothing to the AI model, and backs nothing up. Coaching needs these details, so the app cannot coach you without that agreement.

3. What stays on your phone

The app's working memory is local: the health database, chat history, coaching plans, agent memory, and preferences all live in on-device storage. Apple Health data is read on your phone with your permission and stays in that local database. If you allow it, the app also writes the energy, protein, carbohydrate, and fat of meals you log into Apple Health. You can export all local data as JSON, and you can delete all local data, in Settings.

4. Coaching conversations and the cloud model

Generating a coaching reply needs a cloud model. When you send a message, your phone sends the conversation and the context the coach needs (relevant parts of your profile, goals, and recent health summaries) to our server, which passes it through OpenRouter to a company that runs the model. Today the models come from OpenAI and Google. OpenAI models run first on Microsoft Azure or Amazon Bedrock, and Google models run on Google. The exact model and host can change as we improve the product.

We do not keep a readable server copy as part of the model request. If you sign in, the separate sync feature can keep an encrypted backup of the conversation, as section 5 explains. Our server keeps account-linked daily model usage totals for billing and capacity planning. These totals include the model, request and failure counts, token totals, and reported cost. They stay until account deletion. We also keep unlinked per-request service-health records, such as the request time, model route, token count, speed, status, and error code, for up to 90 days. Neither record contains message text, health readings, or health topics. We can keep service totals that no longer identify you. The model providers process your message to produce the reply. We set each model request to deny data collection for training. The request fails if no provider meets that rule. PULS3 does not collect, use, or sell personal data to train large language models.

OpenRouter can keep non-text request metadata, such as the model, token counts, and latency. We do not send it your PULS3 account identifier.

Signed-in people can separately choose to share new coaching messages and replies for up to 30 days. A small, restricted PULS3 team may review this content to find bugs, confusing steps, and quality or safety problems. This content can include health details. We reduce common direct identifiers, such as email addresses and phone numbers, before human review. We also audit each access. Each saved copy includes your signed-in account reference and a random PULS3 device identifier so we can diagnose and delete the right copies. This choice is off by default. Refusing it does not limit the app. Turning it off stops new capture and asks our server to delete saved copies linked to your account.

Some coach abilities call other services through our server:

Each of these sends only what the feature needs, and none of them includes your name or contact details.

5. Account, backup, and sync

If you sign in (with Apple, or an email link), two things change:

If you never sign in, no backup happens and no registration exists.

6. Service health reports

After you accept this policy, the app sends a small set of service health reports to Sentry, whether or not you turn product analytics on. They tell us the app is working, and they are how we find out when it is not. They are:

These reports contain technical details such as the device model, operating system, app version, whether the install came from the App Store or TestFlight, error route, reason code, and timing. A masked replay can be attached to an error. It hides text and images. They never contain conversation text, health readings, health topics, safety check results, your email address, your Apple identifier, or your account identifier.

Each report carries a one-way hash of the random PULS3 device identifier, so we can count how many phones a fault affects. The hash cannot be turned back into the identifier. If you have turned product analytics on, we could match a report to analytics from the same phone. We do not match it to your account or email, and we do not use it for advertising. Deleting all local data resets the device identifier and the hash with it. We remove URL queries and request headers before a report leaves the app.

After a crash, you can choose to send us a written note. The note is attached to the crash report in Sentry. The screen asks you not to include health or contact details.

7. Optional product analytics

PULS3 asks before it collects product analytics. The choice is off by default. If you agree, the app records events such as screens viewed, actions, timing, outcomes, app version, performance, and broad health areas you open. It does not include conversation text, health readings, photos, or contacts. The events carry a random PULS3 device identifier and, when you are signed in, an account identifier. The device identifier can remain in the iOS Keychain across a reinstall. Delete all local data removes it. Events upload in batches to our server.

We use this data only to operate and improve PULS3. It tells us what works, what people use, and where they get stuck. Short event samples expire within 7 days. The server also keeps account-linked daily totals. Account deletion removes those linked totals. We can keep totals that no longer identify you.

You can change this choice in Settings. Turning it off stops new collection and deletes queued events from your phone. Refusing it does not limit the app.

Our website

puls3.app uses Cloudflare Web Analytics to count visits. It does not set cookies, store anything in your browser, or follow you to other sites. It records the page you open, the site that sent you, your browser and device type, and your country, and shows us totals only. It does not identify you, and it is not connected to the app or to a PULS3 account.

8. Oura Ring (optional)

If you connect Oura, you approve access on Oura's own site. The app then pulls your daily readiness and sleep data from Oura's servers onto your phone, where it is treated like any other local health data. The access token is stored in the iOS Keychain. You can disconnect Oura in Settings at any time; disconnecting revokes the token.

9. Emails we send

All email is delivered by Resend. Resend processes your email address and the content of each message in order to deliver it.

10. Feedback you send us

If you submit feedback in the app, our server stores the feedback text with your app version, device model, and user identifier for up to 90 days. Linear, the issue tracker our team works in, gets only a note that feedback arrived: its category, severity, app version, and a reference number. It never gets what you wrote.

When you flag a coach reply with a thumbs-down, you can choose to attach that conversation to your report. This is off by default; turning it on is your consent for that one report. The attached messages can include health details, are not sent to Linear, and are read only by a small PULS3 team to understand what went wrong. Attached conversations expire within 90 days.

11. Purchases

Subscriptions are handled by Apple through the App Store. Apple processes the payment; we never see your card details. StoreKit gives the app verified subscription status so it knows what you have bought. This status stays on your device and is not sent to a PULS3 server.

12. Who else touches your data

ServiceWhat it processesWhy
CloudflareModel-call traffic, sync backups, optional conversation review copies, product analytics, website visit countsRuns our servers and website
OpenRouterConversation content for each model call and non-text request metadataRoutes model requests
AI model hosts: today Microsoft Azure and Amazon Bedrock (OpenAI models) and Google (Gemini models)Conversation content for each model callGenerates coaching replies
SentryService health reports (crashes, app start, sign-in, token, purchase, and slow-call faults); a one-way hash of the PULS3 device identifier; crash feedback you choose to sendKeeps the app working
ResendEmail address, email contentDelivers our email
OuraYour Oura account data, if connectedYou connect it
Brave SearchSearch query textCoach web search
Jina ReaderWeb page addressesCoach page reading
USDA FoodData CentralFood namesNutrition lookups
Open-MeteoPrecise location for the request; about one-kilometre precision in our short cacheUV and air quality
LinearFeedback category, severity, app version, and reference numberTracks your feedback
ApplePayments, Sign in with Apple, Apple Health permissionsPlatform services

Most of these services run in the United States. Model requests can also run in the European Union.

We do not sell personal or health data. We do not share it with advertisers or data brokers. No service in this table receives more than the table says.

13. Your controls

14. Retention

Local data stays until you delete it. Sync backups and registration stay until you delete your account. Optional conversation review copies expire within 30 days. Turning that choice off asks our server to delete them sooner. Short product analytics samples expire within 7 days. Account-linked daily analytics and model usage totals stay until account deletion. We can keep totals that no longer identify you. Unlinked model service-health records expire within 90 days. Service health reports in Sentry expire within 90 days. Feedback records, including any conversation you choose to attach to one, expire within 90 days. Website visit counts are totals that do not identify you.

15. Security

Sensitive backup fields are encrypted on your phone before upload. Tokens live in the iOS Keychain. Server traffic uses TLS. No system is perfect; keep your device updated and protected with a passcode.

16. Australian privacy law

We are an Australian company and handle personal information, including health information, under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You can ask us for access to the personal information we hold about you, ask us to correct it, or complain about how we handled it. If you are not happy with our answer, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

17. US consumer health data laws

Washington, Nevada, and Connecticut have laws that protect consumer health data. Our Consumer Health Data Privacy Policy lists the health data we collect, where it comes from, who receives it, and how to see, stop, correct, or delete it, including how to appeal our decision. We give those rights to every user, wherever they live. Send requests under that policy to adam@puls3.app.

18. Household members and children

You can add household members, including children, to plan food for your household. Their details (name, age, allergies, food notes) are entered by you, live on your phone, and are included in sync backups if you sign in. Names, allergies, and food notes are encrypted on your phone before upload; age is not. Only add details you are entitled to share.

19. Not medical care

PULS3 is a coaching app. It does not diagnose or treat anything, and it is not a medical device. For medical concerns, see a qualified professional.

20. Changes to this policy

When this policy changes in a way that matters, we will tell you in the app before the change applies, and this page will show the new date.

21. Contact

Privacy questions and deletion requests: adam@puls3.app.