Privacy Policy
Last updated: 3 September 2026
PULS3 is made by PULS3 PTY LTD (ACN 696 197 412) in Australia. This policy explains what data the app handles, what leaves your phone and why, who else touches it, and what you can delete. We wrote it to be read, not skimmed past.
1. The short version
- Your health data, chat history, and coaching plans live on your phone.
- When you talk to your coach, that conversation goes to a cloud model to generate the reply. We do not keep a readable server copy as part of that model request.
- If you sign in and test a beta build, you can make a separate choice to share new coaching messages and replies for product improvement. This is off by default. Shared copies expire within 14 days.
- Product analytics is also optional and off by default. It does not include conversation text, health readings, photos, or contacts.
- If you sign in, the app backs up your conversations and household food settings to our servers so you can restore them. That data is encrypted on your phone before it uploads.
- Some features send specific data to specific services. Each one is listed below. None of them is advertising. We do not sell your data, and we never will.
2. Data the app collects
- Health and activity data you allow, from Apple Health and, if you connect it, your Oura Ring.
- Your profile and preferences: goals, fitness level, life stage, pregnancy or postpartum status, sexual or urinary health details you choose to share, communication style, and reminders.
- Your coaching interactions: chat messages, logged actions, plans, and meal or household settings you enter, including details about household members such as names, ages, and allergies.
- Your email address, and phone number if you give one, when you register.
- Crash reports and optional product analytics, described in sections 6 and 7.
You can use the app without an account. Without one, nothing in this list is tied to your identity on our servers.
3. What stays on your phone
The app's working memory is local: the health database, chat history, coaching plans, agent memory, and preferences all live in on-device storage. Apple Health data is read on your phone with your permission and stays in that local database. You can export all local data as JSON, and you can delete all local data, in Settings.
4. Coaching conversations and the cloud model
Generating a coaching reply needs a cloud model. When you send a message, your phone sends the conversation and the context the coach needs (relevant parts of your profile, goals, and recent health summaries) to our server, which passes it to a model provider through OpenRouter. Today's providers are OpenAI and Google models; the exact model can change as we improve the product.
We do not keep a readable server copy as part of the model request. If you sign in, the separate sync feature can keep an encrypted backup of the conversation, as section 5 explains. Our server keeps account-linked daily model usage totals for billing and capacity planning. These totals include the model, request and failure counts, token totals, and reported cost. They stay until account deletion. We also keep unlinked per-request service-health records, such as the request time, model route, token count, speed, status, and error code, for up to 90 days. Neither record contains message text, health readings, or health topics. We can keep service totals that no longer identify you. The model providers process your message to produce the reply. We set each model request to deny data collection for training. The request fails if no provider meets that rule.
OpenRouter can keep non-text request metadata, such as the model, token counts, and latency. We do not send it your PULS3 account identifier.
Signed-in beta testers can separately choose to share new coaching messages and replies for up to 14 days. A small, restricted PULS3 team may review this content to find bugs, confusing steps, and quality or safety problems. This content can include health details. We reduce common direct identifiers, such as email addresses and phone numbers, before human review. We also audit each access. Each saved copy includes your signed-in account reference and a random PULS3 device identifier so we can diagnose and delete the right copies. This choice is off by default. Refusing it does not limit the app. Turning it off stops new capture and asks our server to delete saved copies linked to your account.
Some coach abilities call other services through our server:
- Web search sends the search query to Brave Search.
- Reading a web page sends that page's address to Jina Reader.
- Food lookups check our own nutrition database first, then USDA FoodData Central, using the food name.
- UV and air quality use your precise location, sent to Open-Meteo through an authenticated request to our server. Our cache rounds it to about one kilometre and expires within six hours. This only happens if you allow location access.
- Recipe images send the recipe title to an image model via OpenRouter.
Each of these sends only what the feature needs, and none of them includes your name or contact details.
5. Account, backup, and sync
If you sign in (with Apple, or an email link), two things change:
- We store your registration: email address, phone number if given, your region, your consent choices, and basic anti-abuse records. This lives on our registration server so we can verify you and contact you about PULS3. Sign-in emails are delivered by Resend, our email provider.
- The app backs up your conversations and household food settings (household members, allergies, food notes, pantry and grocery lists, goals) to our sync server so you can restore them on a new phone. The sensitive fields are encrypted on your phone before upload; the server stores the encrypted form. Backups are stored with Cloudflare, in an Australian or United States region depending on where you are.
If you never sign in, no backup happens and no registration exists.
6. Crash and error reports
After you accept this policy, the app sends crash, hang, and error reports to Sentry. These reports contain technical details such as the device model, operating system, app version, error route, and timing. A masked replay can be attached to an error. It hides text and images. We do not send a stable app identifier from PULS3, an account identifier, email address, screenshot, view hierarchy, conversation text, or health reading with automatic reports. Sentry uses its own random app-installation identifier to measure crash-free release health. We do not connect it to your PULS3 account or use it for advertising. We remove URL queries and request headers before an error report leaves the app.
After a crash, you can choose to send us a written note. The note is attached to the crash report in Sentry. The screen asks you not to include health or contact details.
7. Optional product analytics
PULS3 asks before it collects product analytics. The choice is off by default. If you agree, the app records events such as screens viewed, actions, timing, outcomes, app version, performance, and broad health areas you open. It does not include conversation text, health readings, photos, or contacts. The events carry a random PULS3 device identifier and, when you are signed in, an account identifier. The device identifier can remain in the iOS Keychain across a reinstall. Delete all local data removes it. Events upload in batches to our server.
We use this data only to operate and improve PULS3. It tells us what works, what people use, and where they get stuck. Short event samples expire within 7 days. The server also keeps account-linked daily totals. Account deletion removes those linked totals. We can keep totals that no longer identify you.
You can change this choice in Settings. Turning it off stops new collection and deletes queued events from your phone. Refusing it does not limit the app.
8. Oura Ring (optional)
If you connect Oura, you approve access on Oura's own site. The app then pulls your daily readiness and sleep data from Oura's servers onto your phone, where it is treated like any other local health data. The access token is stored in the iOS Keychain. You can disconnect Oura in Settings at any time; disconnecting revokes the token.
9. Emails we send
- Sign-in emails when you use an email link to sign in.
- Weekly report email, only if you turn it on. Your phone builds a summary of the week that ended (counts of planned and completed movement, sleep, and food items, plus a behaviour-language description of your training week). Our server turns that into an email and sends it, then discards the content, keeping only delivery records. Every one has an unsubscribe link.
- A check-in email if you have been away, only if re-engagement messages are on. It is a generic template and contains no health data.
All email is delivered by Resend. Resend processes your email address and the content of each message in order to deliver it.
10. Feedback you send us
If you submit feedback in the app, the feedback text plus your app version, device model, and user identifier are filed into Linear, the issue tracker our team works in. Do not put anything in a feedback message you would not want on our team's board.
11. Purchases
Subscriptions are handled by Apple through the App Store. Apple processes the payment; we never see your card details. StoreKit gives the app verified subscription status so it knows what you have bought. This status stays on your device and is not sent to a PULS3 server.
12. Who else touches your data
| Service | What it processes | Why |
|---|---|---|
| Cloudflare | Model-call traffic, sync backups, optional beta conversation copies, product analytics | Runs our servers |
| OpenRouter | Conversation content for each model call and non-text request metadata | Routes model requests |
| OpenAI, Google | Conversation content for each model call | Generates coaching replies |
| Sentry | Unlinked crash, hang, error, and performance data; a random app-installation identifier; crash feedback you choose to send | Keeps the app working |
| Resend | Email address, email content | Delivers our email |
| Oura | Your Oura account data, if connected | You connect it |
| Brave Search | Search query text | Coach web search |
| Jina Reader | Web page addresses | Coach page reading |
| USDA FoodData Central | Food names | Nutrition lookups |
| Open-Meteo | Precise location for the request; about one-kilometre precision in our short cache | UV and air quality |
| Linear | Feedback text and device info | Handles your feedback |
| Apple | Payments, Sign in with Apple, Apple Health permissions | Platform services |
Most of these services run in the United States.
We do not sell personal or health data. We do not share it with advertisers or data brokers. No service in this table receives more than the table says.
13. Your controls
- Export all local data as JSON in Settings.
- Delete all local data in Settings. This wipes the local database, reminders, cached sign-in state, the random PULS3 device identifier, local retention counters, and queued usage events.
- Delete your account in Settings. This deletes your registration, encrypted sync backups, account-linked analytics and model usage totals, and beta conversation copies.
- Turn product analytics off in Settings. This stops new collection and clears queued events from your phone.
- Turn beta conversation review off in Settings. This stops new capture and asks our server to delete saved copies linked to your account.
- Disconnect Oura in Settings.
- Turn the weekly report email off in Settings or via its unsubscribe link.
- Turn re-engagement messages off in Settings.
14. Retention
Local data stays until you delete it. Sync backups and registration stay until you delete your account. Optional beta conversation copies expire within 14 days. Turning that choice off asks our server to delete them sooner. Short product analytics samples expire within 7 days. Account-linked daily analytics and model usage totals stay until account deletion. We can keep totals that no longer identify you. Unlinked model service-health records expire within 90 days. We keep Sentry reports only while we need them to find and fix technical faults. Feedback records expire within 90 days.
15. Security
Sensitive backup fields are encrypted on your phone before upload. Tokens live in the iOS Keychain. Server traffic uses TLS. No system is perfect; keep your device updated and protected with a passcode.
16. Australian privacy law
We are an Australian company and handle personal information, including health information, under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You can ask us for access to the personal information we hold about you, ask us to correct it, or complain about how we handled it. If you are not happy with our answer, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
17. Household members and children
You can add household members, including children, to plan food for your household. Their details (name, age, allergies, food notes) are entered by you, live on your phone, and are included in encrypted sync backups if you sign in. Only add details you are entitled to share.
18. Not medical care
PULS3 is a coaching app. It does not diagnose or treat anything, and it is not a medical device. For medical concerns, see a qualified professional.
19. Changes to this policy
When this policy changes in a way that matters, we will tell you in the app before the change applies, and this page will show the new date.
20. Contact
Privacy questions and deletion requests: [email protected].