Legal

Cookie Policy

Last updated: October 7, 2026

1. The Short Version

PulsAPI stores first-party, strictly-necessary cookies, the ones that keep you signed in, plus a few local-storage entries for preferences like your theme. None of those require consent under the GDPR or the ePrivacy Directive.

We also use Google Analytics 4 to understand which pages people actually use. If you are in the EU, EEA, UK or Switzerland, it is off until you accept it, and if you choose “Essential only” it stays that way. Everywhere else it is on by default, and you can switch it off at any time in Your Privacy Choices. If your browser sends a Global Privacy Control signal, it starts off wherever you are. While it is off it stores nothing on your device and sends no identifiers. We do not use advertising cookies, cross-site trackers, or remarketing, and Google's advertising features are disabled for this property.

2. What We Store, Exactly

NameTypePurposeDurationCategory
pb_accessCookie (httpOnly)Short-lived session token that keeps you signed in. Sent only to our API, never readable by JavaScript.15 minutesStrictly necessary
pb_refreshCookie (httpOnly)Long-lived token used to silently renew your session so you don't have to sign in every 15 minutes.45 daysStrictly necessary
pb_token / pb_userLocal storageFallback session token and cached profile for API clients and environments without cookie support. Cleared on sign-out.Until sign-outStrictly necessary
themeLocal storageRemembers your light/dark appearance preference.Until clearedFunctional
pb_consentLocal storageRecords the privacy choices you made in the consent notice, so we don't ask again and can honor them.Until clearedStrictly necessary
_gaCookie (Google Analytics)Set only while analytics is on (see section 1). Distinguishes one browser from another so we can count visitors and see which pages get used.2 yearsAnalytics (optional)
_ga_B267JFZ8X6Cookie (Google Analytics)Set only while analytics is on (see section 1). Keeps track of the current session so a visit isn't counted twice.2 yearsAnalytics (optional)

Auth cookies are httpOnly (JavaScript cannot read them), SameSite=Strict (they are never sent on cross-site requests), Secure in production, and scoped to our API path only.

3. What We Don't Use

  • No third-party advertising or retargeting cookies
  • No cross-site tracking or fingerprinting
  • No social media pixels
  • No analytics before you opt in if you are in the EU, EEA, UK or Switzerland, and none at all once you switch it off

Analytics is the only optional category, and you can turn it on or off at any time, wherever you are, in Your Privacy Choices. Turning it off takes effect immediately.

4. Third-Party Services That Set Their Own Cookies

These third parties may set cookies under their own policies:

  • Google Analytics, only while analytics is on (see section 1). It then sets the _ga cookies listed above (see Google's Privacy Policy).
  • Stripe, when you open the billing checkout, Stripe may set cookies for payment processing and fraud prevention (see Stripe's Privacy Policy).
  • Google / GitHub sign-in, if you authenticate with Google or GitHub, those providers use their own cookies during the OAuth flow.

5. Managing Cookies

You can review your choices anytime on Your Privacy Choices, and you can delete or block cookies through your browser settings. Blocking the strictly-necessary cookies will prevent you from staying signed in. We also honor the Global Privacy Control browser signal as an opt-out of any sale or sharing of personal information (we don't sell or share either way).

6. Contact

Questions about this policy? Email privacy@pulsapi.com or see our full Privacy Policy.

Cookie Policy