Consumer Health Data Privacy Policy
Effective 24 September 2026. Last updated: 24 September 2026
This policy covers consumer health data: information linked to you that says something about your physical or mental health. It is written for the Washington My Health My Data Act, Nevada's consumer health data law, and the consumer health data rules in the Connecticut Data Privacy Act. Those laws protect people in Washington, Nevada and Connecticut. PULS3 gives the same rights, through the same process, to everyone who uses the app, wherever you live.
PULS3 is made by PULS3 PTY LTD (ACN 696 197 412), an Australian company. Our Privacy Policy covers all the other data the app handles.
- Most of your health data stays on your phone.
- When you talk to the coach, your message and the health details it needs go through our server to an AI model that writes the reply.
- We do not sell health data, we do not use it for advertising, and we do not use it to train AI models.
- To see, stop, fix, or delete your health data, use the controls in the app or email [email protected]. We answer within 45 days.
1. The health data we collect, and how we use it
| What we collect | Where it is kept | How we use it |
|---|---|---|
| Apple Health readings you allow: sleep, heart rate, heart rate variability, resting heart rate, steps, active energy, walking and running distance, weight, body fat, lean mass, waist size, food energy and nutrients, water, blood glucose, VO2 max, workouts and workout effort, menstrual flow (asked for separately), date of birth (we keep only an age range), and biological sex | Your phone | To build your daily plan, see how sleep, recovery and training affect each other, adjust the plan, and give the coach what it needs to answer you |
| Oura readings, if you connect your ring: readiness (including body temperature change), sleep (including lowest heart rate), blood oxygen, and resilience (including a stress score) | Your phone | The same as Apple Health readings |
| Health details you tell us: goals, fitness level, injuries and surgeries, food needs, life stage, pregnancy or postpartum status, fertility, perimenopause or menopause, hormones and cycle regularity, clinician-managed hormone treatment, prostate or testicular health, any sexual or urinary health details you choose to share, medicines, supplements, hormones and peptides you take (with dose and schedule), symptoms, and check-ins on energy, mood and stress | Your phone | To fit the coaching to your body and your stage of life |
| Food you log: meals, estimated energy and nutrients, and meal photos | Your phone. If you allow it, the app also writes each meal's energy, protein, carbohydrate and fat into Apple Health | To track food against your goals and plan meals |
| Lab reports and test results you add | Your phone | To explain results and use them in your plan, when you ask |
| Coaching conversations: your messages and the coach's replies, which can include any health detail you share | Your phone. If you sign in, a backup on our servers. Message text and conversation titles are encrypted on your phone before upload; when each message was sent, and whether it came from you or the coach, are not | To answer you and keep track of what you have said |
| What the app works out from the data above: memory notes, plans, goal reviews, scores, and a safety check of every coach reply | Your phone | To keep the coaching consistent and safe |
| Details you enter about people in your household: names, ages, allergies, medical notes, and food likes and dislikes | Your phone. If you sign in, a backup on our servers. Names, allergies, medical notes and food preferences are encrypted before upload; age, role and a few household settings are not | To plan meals that are safe and suitable for everyone you cook for |
| Only if you turn on product analytics: which broad health areas you open or plan in, such as sleep, nutrition, mood or women's health; counts of safety checks on coach replies; and whether you kept or skipped planned items such as sessions and meals | Our servers. Daily totals are linked to your account if you are signed in, until you delete your account. Kept-or-missed events expire after 14 days, and counts of food feature use after 180 days | To learn what helps people and where they get stuck |
| Only if you turn on conversation review: copies of new coaching messages and replies | Our servers, for up to 30 days | So a small PULS3 team can find bugs and quality or safety problems |
| Only if you send feedback: what you write, and a conversation if you choose to attach one | Our servers, for up to 90 days | To fix what went wrong |
| Only if you turn on the weekly email: counts of planned and completed movement, sleep and food items, and a one-line summary of your training week | Our server checks the counts and then discards them. The email carries the one-line summary | To send your weekly email |
The app works on most of this data on your phone. When you ask the coach something, your phone sends your message, the recent conversation, and the health details the coach needs through our server to an AI model, which writes the reply. Our server passes the request on and does not keep a readable copy of it, unless you have turned on conversation review.
We collect health data only to give you the coaching you asked for, or, for the optional items above, because you turned them on. We do not use it for advertising. We do not sell it. We do not use it to train AI models.
2. Where the data comes from
- You, when you talk to the coach, log food, add lab results, or answer questions about yourself.
- Apple Health on your phone, for the types you allow.
- Oura, if you connect your ring.
- The app, which works out plans, scores and memory notes from the data above.
- The AI model, which writes the coach's replies.
- You, about the people in your household. They do not give it to us themselves.
3. The health data we share
We send health data only to service providers that do work for us, so the features you use can run. We list all of them below, even where the law would not call it sharing.
- Coaching requests: your message, the recent conversation, and the health details the coach needs for that reply. This can include any kind of data in section 1, and it includes a meal photo or lab report page when you send one.
- Backups of your conversations and household details, if you sign in. Message text, names, allergies, medical notes and food preferences are encrypted on your phone before upload. A household member's age and role, a few household settings, and when each message was sent are not.
- Conversation review copies, product analytics, and feedback, if you turn these on or send feedback.
- The one-line summary of your training week in the weekly email, if you turn the email on.
- Search words, web addresses and food names the coach uses when it looks something up for you. These can relate to your health question. They do not include your name or contact details.
4. Who receives it
| Who | What they do for us | What they receive |
|---|---|---|
| Cloudflare | Runs our servers and databases | Every coaching request as it passes through, backups (encrypted field by field, as section 3 describes), conversation review copies, product analytics, feedback, and the weekly email summary |
| OpenRouter | Sends each coaching request to an AI model | Each coaching request. It can keep details that are not message text, such as the model used and the request size. We do not send it your account identifier |
| Companies that run the AI models: today Microsoft (Azure) and Amazon (Amazon Bedrock) for OpenAI models, and Google for Gemini models | Run the AI models that write the coach's replies | Each coaching request. Every request is set to deny data collection for training, and fails if no host meets that rule. If our first choices are unavailable, OpenRouter can use another host that meets the same rule |
| Resend | Delivers our email | Your weekly email, including the summary of your training week |
| Brave Search and Jina Reader | Web search and page reading for the coach | Search words and web addresses, without your name or contact details |
| USDA FoodData Central | Food lookups | Food names, without your name or contact details |
- Sentry receives our crash and error reports. It receives no health data and no safety check results, apart from anything you type into the optional note after a crash, which the app asks you not to do.
- Linear, our issue tracker, gets a note that you sent feedback: its category, severity, app version and a reference number. It never gets what you wrote.
- Oura sends your ring data to the app. We send no health data to Oura.
- The app reads Apple Health and, if you allow it, writes food entries to Apple Health on your phone. Apple's privacy terms cover Apple Health.
- We do not share health data with any affiliate.
- We do not sell health data.
- We do not use geofences, virtual boundaries around a place, to track people, collect health data, or send messages.
- No other company collects health data about you over time, or across other websites and apps, through PULS3.
5. Your rights, and how to use them
You can ask us to:
- Confirm whether we collect, share or sell your health data, and give you a copy of it. With the copy, we list every company we shared it with, and give you an email address or web form for each one.
- Stop collecting and sharing it. This withdraws your consent.
- Delete it.
- Correct it.
- Give you a copy in a machine-readable form you can move to another service.
Connecticut law also lets you opt out of targeted advertising, the sale of your data, and some automated decisions. PULS3 does none of these. We will not treat you differently for using any of your rights.
Do it yourself in the app
- Get a copy. Settings, Export Local Data (JSON), gives you a file containing a copy of the app's database and settings on your phone. Photos you attached are not included.
- Stop collection. Turn off PULS3's access to Apple Health in your iPhone's Settings, under Health. In PULS3's Settings, disconnect Oura, and turn off Share product analytics, Share conversations (conversation review) and the weekly email. Turning off Share conversations also asks our server to delete the saved copies.
- Correct. Edit or delete food you logged, view and delete what the coach remembers in Settings, Memory, or tell the coach what has changed.
- Delete from your phone. Settings, Delete All Local Data, removes everything the app stores on your phone.
- Delete from our servers. Settings, Delete Account, removes what our servers hold for your account: your registration, backups, product analytics linked to your account, conversation review copies, feedback records, and usage totals.
Ask us by email
Email [email protected] for anything the app cannot do: a copy of what our servers hold, the list of companies that received your data, a correction, or deleting server data without deleting your account. Say which of these you want.
- If you have a PULS3 account, send the email from the address linked to it. If you used Hide My Email with Sign in with Apple, we will write to that hidden address, which Apple forwards to you, and ask you to confirm.
- If we cannot confirm the request is yours, we will ask for the least extra information we need. We will never ask for a password, and you do not need to create an account.
- If you use PULS3 without an account, nothing on our servers is tied to your name or email. Tell us what you need and roughly when you used the feature, for example when you sent feedback, and we will try to find it. Without an account we may not be able to.
How long it takes
- We answer every request within 45 days of receiving it.
- We finish a deletion within 30 days of confirming the request is yours, and never later than 45 days after we received it.
- If a request is complex, or you send several, we can take up to 45 more days once. We will tell you, and why, within the first 45 days.
- Our database provider keeps an automatic restore history for up to 30 days. Deleted data can stay in that history for up to 30 days, and then it is gone.
- Requests are free. We can refuse a request, or charge a reasonable fee, only if requests are plainly unfounded, excessive or repeated, and we will explain why.
Deleting data held by our service providers
When you ask us to delete your data, we delete it from our servers and tell each company in section 4 about your request. OpenRouter and the AI model hosts never receive your email or account identifier. They can see your first name if you told it to the coach, because it is part of the conversation. They cannot match a deletion request to you.
If we say no: appeals
If we refuse all or part of a request, you can appeal. Reply to our decision, or email [email protected] with "Appeal" in the subject line. We will reply in writing within 45 days, saying what we did or did not do, and why.
If we turn down your appeal, you can complain to your state's Attorney General:
- Washington: atg.wa.gov/file-complaint
- Nevada: ag.nv.gov/Complaints/File_Complaint
- Connecticut: portal.ct.gov/AG/Common/Complaint-Form-Landing-page
6. Where the state laws differ
Where Washington, Nevada and Connecticut set different rules, we follow the stricter one for everyone:
- Deletion within 30 days of confirming the request, from Nevada.
- Appeal answers within 45 days, from Washington and Nevada. Connecticut allows 60.
- The rights to correct your data and to get a copy you can move, from Connecticut.
- Free requests. Washington and Nevada require at least two free requests a year, and Connecticut one.
7. Changes to this policy
If this policy changes in a way that matters, we will tell you in the app before the change applies, and this page will show the new date.
8. Contact
Health data requests, appeals and questions: [email protected]. PULS3 PTY LTD, Melbourne, Australia.