PULSE

Privacy Policy

Last updated: 31 August 2026

This Privacy Policy explains how PULSE ("we", "us"), operated by Zachary Alexander, collects and uses personal data. PULSE is an independent service and is not affiliated with Whatnot, Inc.

1. Data we collect

2. Cookies and data stored in your browser

PULSE sets four first-party cookies. There are no third-party cookies, no advertising cookies, and no cross-site trackers:

PULSE also uses your browser's localStorage to remember functional preferences on your device. These stay in your browser; they are not sent to us and are not shared with anyone:

Clearing your browser's cookies and site storage removes all of the above.

3. How we use data

We do not sell your personal data.

4. Service providers

We share the minimum necessary data with providers that operate the Service, including Stripe (payments), Apple (purchases made inside the iOS app are sold and processed by Apple), Expo (push notification delivery for the mobile app, which in turn hands the message to Apple's push service), RevenueCat (in-app subscription management — it receives your device identifier and, once you sign in, your email address as the account key), Resend (email delivery), Hetzner (hosting) and Cloudflare (CDN and DNS). They process data on our behalf under their own terms.

We also use an internal operations alerting channel (a chat webhook) that notifies us of events we must act on — a new support ticket, a failed payment, a delivery failure. Those notifications can contain your email address and the text of a support message you sent us, so that we can answer you. Nothing from the market data or your saved settings is sent there, and it is not used for analytics or advertising.

Where your data is processed. Our servers are located in Germany. If you are in the United States, your data is transferred to and processed in the EU; if you are in the EEA or UK, it stays there.

5. Data retention

Account and billing records are retained for as long as your account is active and as required for legal, tax, and accounting purposes. Raw market-data snapshots that power our analytics are retained for approximately 14 days and then compacted into anonymous aggregates; this market data is keyed to public shows and sellers, not to you. Other horizons we enforce automatically: support tickets are deleted 180 days after they are closed; interest-form leads and the record of emails we sent you, 12 months; first-party analytics (pageviews and funnel events), 90 days; mobile crash reports, 30 days. Support-chat logs are retained only as long as needed to operate and improve support and are then deleted or anonymized.

Free-trial fraud prevention. When a free trial is used we keep a non-reversible record that a trial was consumed — a salted, irreversible hash of the email address and the opaque card fingerprint Stripe derives (never the card number). This record is kept after an account is deleted, with the link to your account removed, so that deleting and re-creating an account cannot be used to take repeated free trials. It contains nothing readable and cannot be used to identify or contact you.

6. Your rights and deletion

You may request access to, correction of, or deletion of your personal data. You can delete your account (and the personal data associated with it) from within the Service, or by emailing us at [email protected]. Deletion removes your account and its personal data, including your password, sign-in sessions and trusted-device records. The one exception is the non-reversible free-trial-prevention record described in section 5, which is retained without any link to your identity. Deleting your account does not automatically cancel an active subscription — cancel via the Stripe billing portal to stop future charges. Depending on where you live (e.g. the EEA/UK), you may have additional rights under the GDPR or similar laws; contact us to exercise them.

7. Security

Passwords are stored only as salted, memory-hard scrypt hashes; API keys, session and device-trust tokens, and one-time sign-in codes are stored only as one-way hashes — never in readable form. The raw API key is shown once at creation and delivered to you by email. Payment details stay with Stripe, IP addresses are stored in our database only in salted, irreversibly hashed form, and transport is encrypted (HTTPS). No method of storage or transmission is perfectly secure, but we take reasonable measures to protect your data.

8. Children

The Service is intended for businesses and adults; it is not directed to children and we do not knowingly collect data from them.

9. Changes

We may update this Policy; the "Last updated" date above reflects the latest version.

10. Contact

Zachary Alexander · [email protected] · 2232 Dell Range Blvd, Suite 303 #1595, Cheyenne, WY 82009, United States