Privacy Policy
Last updated: 7 August 2026
PULS3 is made by PULS3 PTY LTD (ACN 696 197 412) in Australia. This policy explains what data the app handles, what leaves your phone and why, who else touches it, and what you can delete. We wrote it to be read, not skimmed past.
1. The short version
- Your health data, chat history, and coaching plans live on your phone.
- When you talk to your coach, that conversation goes to a cloud model to generate the reply. We do not store your conversations on our servers for that. The call happens, the reply comes back, and the content is gone from our infrastructure.
- If you sign in, the app backs up your conversations and household food settings to our servers so you can restore them. That data is encrypted on your phone before it uploads.
- Some features send specific data to specific services. Each one is listed below. None of them is advertising. We do not sell your data, and we never will.
2. Data the app collects
- Health and activity data you allow, from Apple Health and, if you connect it, your Oura Ring.
- Your profile and preferences: goals, fitness level, life stage, communication style, reminders.
- Your coaching interactions: chat messages, logged actions, plans, and meal or household settings you enter, including details about household members such as names, ages, and allergies.
- Your email address, and phone number if you give one, when you register.
- Crash reports and usage events, described in sections 6 and 7.
You can use the app without an account. Without one, nothing in this list is tied to your identity on our servers.
3. What stays on your phone
The app's working memory is local: the health database, chat history, coaching plans, agent memory, and preferences all live in on-device storage. Apple Health data is read on your phone with your permission and stays in that local database. You can export all local data as JSON, and you can delete all local data, in Settings.
4. Coaching conversations and the cloud model
Generating a coaching reply needs a cloud model. When you send a message, your phone sends the conversation and the context the coach needs (relevant parts of your profile, goals, and recent health summaries) to our server, which passes it to a model provider through OpenRouter. Today's providers are OpenAI and Google models; the exact model can change as we improve the product.
We do not store the content of these requests or replies on our servers. Our server keeps operational counts (how many requests, how fast, error rates) with no health topics in them. The model providers process your message to produce the reply; we choose providers whose terms do not allow training on this data.
Some coach abilities call other services through our server:
- Web search sends the search query to Brave Search.
- Reading a web page sends that page's address to Jina Reader.
- Food lookups check our own nutrition database first, then USDA FoodData Central, using the food name.
- UV and air quality use your approximate location, sent to Open-Meteo. This only happens if you allow location access.
- Recipe images send the recipe title to an image model via OpenRouter.
Each of these sends only what the feature needs, and none of them includes your name or contact details.
5. Account, backup, and sync
If you sign in (with Apple, or an email link), two things change:
- We store your registration: email address, phone number if given, your region, your consent choices, and basic anti-abuse records. This lives on our registration server so we can verify you and contact you about PULS3. Sign-in emails are delivered by Resend, our email provider.
- The app backs up your conversations and household food settings (household members, allergies, food notes, pantry and grocery lists, goals) to our sync server so you can restore them on a new phone. The sensitive fields are encrypted on your phone before upload; the server stores the encrypted form. Backups are stored with Cloudflare, in an Australian or United States region depending on where you are.
If you never sign in, no backup happens and no registration exists.
6. Crash and error reports
When the app crashes or hits an error, a report goes to Sentry, our crash reporting service. It contains technical details (device model, OS version, app version, what the app was doing) and a random install identifier generated on your phone. It is not linked to your account, email, or health data, and reports contain no health topics.
7. Usage events
The app records events like "screen viewed" or "conversation started" and uploads them in batches to our own server, at most every few hours. They carry the app version and an account or install identifier, not chat content. Our server keeps daily totals, not a browsable activity feed. Deleting all local data also deletes the queued events on your phone.
We use these events to see whether the product works: which features get used, where people get stuck, whether coaching quality holds up.
8. Oura Ring (optional)
If you connect Oura, you approve access on Oura's own site. The app then pulls your daily readiness and sleep data from Oura's servers onto your phone, where it is treated like any other local health data. The access token is stored in the iOS Keychain. You can disconnect Oura in Settings at any time; disconnecting revokes the token.
9. Emails we send
- Sign-in emails when you use an email link to sign in.
- Weekly report email, only if you turn it on. Your phone builds a summary of your week (counts of movement, sleep, and food wins, and your training week). Our server turns that into an email and sends it, then discards the content, keeping only delivery records. Every one has an unsubscribe link.
- A check-in email if you have been away, only if re-engagement messages are on. It is a generic template and contains no health data.
All email is delivered by Resend. Resend processes your email address and the content of each message in order to deliver it.
10. Feedback you send us
If you submit feedback in the app, the feedback text plus your app version, device model, and user identifier are filed into Linear, the issue tracker our team works in. Do not put anything in a feedback message you would not want on our team's board.
11. Purchases
Subscriptions are handled by Apple through the App Store. Apple processes the payment; we never see your card details. We receive transaction status so the app knows what you have bought.
12. Who else touches your data
| Service | What it processes | Why |
|---|---|---|
| Cloudflare | Model-call traffic, sync backups, usage totals | Runs our servers |
| OpenRouter, OpenAI, Google | Conversation content, transiently | Generates coaching replies |
| Sentry | Crash reports with install ID | Crash reporting |
| Resend | Email address, email content | Delivers our email |
| Oura | Your Oura account data, if connected | You connect it |
| Brave Search | Search query text | Coach web search |
| Jina Reader | Web page addresses | Coach page reading |
| USDA FoodData Central | Food names | Nutrition lookups |
| Open-Meteo | Approximate location | UV and air quality |
| Linear | Feedback text and device info | Handles your feedback |
| Apple | Payments, Sign in with Apple, Apple Health permissions | Platform services |
Most of these services run in the United States.
We do not sell personal or health data. We do not share it with advertisers or data brokers. No service in this table receives more than the table says.
13. Your controls
- Export all local data as JSON in Settings.
- Delete all local data in Settings. This wipes the local database, reminders, cached sign-in state, and queued usage events.
- Ask us to delete your server-side data: registration, and any sync backups. Contact us at team@puls3.app and we will confirm when done.
- Disconnect Oura in Settings.
- Turn the weekly report email off in Settings or via its unsubscribe link.
- Turn re-engagement messages off in Settings.
14. Retention
Local data stays until you delete it. Sync backups and registration stay until you ask us to delete them or your account is deleted. Crash reports and usage totals are kept only as long as we need them to operate the product. Server-side diagnostic rows, where enabled in testing environments, expire after 14 days.
15. Security
Sensitive backup fields are encrypted on your phone before upload. Tokens live in the iOS Keychain. Server traffic uses TLS. No system is perfect; keep your device updated and protected with a passcode.
16. Australian privacy law
We are an Australian company and handle personal information, including health information, under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You can ask us for access to the personal information we hold about you, ask us to correct it, or complain about how we handled it. If you are not happy with our answer, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
17. Household members and children
You can add household members, including children, to plan food for your household. Their details (name, age, allergies, food notes) are entered by you, live on your phone, and are included in encrypted sync backups if you sign in. Only add details you are entitled to share.
18. Not medical care
PULS3 is a coaching app. It does not diagnose or treat anything, and it is not a medical device. For medical concerns, see a qualified professional.
19. Changes to this policy
When this policy changes in a way that matters, we will tell you in the app before the change applies, and this page will show the new date.
20. Contact
Privacy questions and deletion requests: team@puls3.app.