Legal

Privacy Policy

Last updated: August 5, 2026

1. Introduction

PulsAPI Inc. ("PulsAPI," "we," "us," or "our") operates the PulsAPI platform at pulsapi.com, which provides unified cloud service status monitoring, incident tracking, and SLA analytics. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services. For the purposes of the EU and UK General Data Protection Regulation (GDPR), PulsAPI Inc. is the data controller of your personal data.

By accessing or using PulsAPI, you agree to the terms of this Privacy Policy. If you do not agree, please do not use our services.

2. Information We Collect

Account Information

When you create a PulsAPI account, we collect your name, email address, and password (stored as a bcrypt hash, we never see or store the plain text). If you sign up via GitHub or Google OAuth, we receive your name, email address, and profile avatar URL from that provider. We never store your OAuth access token beyond the authentication session. If you use a magic link, we collect your email address to deliver the sign-in link.

Billing Information

Paid subscriptions are processed by Stripe. Stripe collects your payment card details directly, they never touch our servers. We store only your Stripe customer reference, plan tier, and billing history.

Usage Data

We automatically collect information about how you interact with PulsAPI, including the services you monitor, dashboard configurations, alert preferences, notification history, and feature usage. This data helps us operate the platform and provide personalized experiences.

Service Monitoring Data

PulsAPI crawls publicly available status pages from cloud providers (e.g., AWS, Stripe, GitHub, Vercel, Cloudflare) to aggregate operational status, incident timelines, and uptime metrics. This data is sourced from public endpoints and is not personal information.

Device & Log Data

When you access PulsAPI, our servers automatically log standard technical information including your IP address, browser type and version, operating system, referring URL, pages visited, and access timestamps.

Support & Communications

If you contact support or sales, we keep the correspondence and any information you choose to include so we can resolve your request.

3. How We Use Your Information

  • Provide, operate, and maintain your PulsAPI dashboard and alert configurations
  • Send real-time incident notifications via email, Slack, or Discord based on your alert routing rules
  • Calculate and display SLA metrics, MTTR, and uptime percentages for your monitored services
  • Process payments and manage subscriptions for paid plans
  • Send account-related communications (password resets, security alerts, plan changes)
  • Analyze usage patterns to improve features, performance, and reliability
  • Detect and prevent fraud, abuse, and security threats
  • Comply with legal obligations (e.g., tax and accounting rules for billing records)

4. Legal Bases for Processing (GDPR)

Where the GDPR applies, we rely on the following legal bases under Article 6:

  • Performance of a contract (Art. 6(1)(b)), creating and operating your account, dashboards, alerts, and subscriptions; processing payments.
  • Legitimate interests (Art. 6(1)(f)), securing the platform, preventing fraud and abuse, maintaining server logs, and improving reliability and features in ways you would reasonably expect. You may object at any time (see Section 10).
  • Legal obligation (Art. 6(1)(c)), retaining billing records for tax and accounting compliance.
  • Consent (Art. 6(1)(a)), optional product analytics (Google Analytics 4; it stays off unless you opt in via Your Privacy Choices) and marketing emails, where required. Consent can be withdrawn at any time without affecting prior processing.

5. Cookies & Local Storage

By default PulsAPI uses only first-party, strictly-necessary cookies and a few local-storage preferences:

  • Essential cookies: two httpOnly session cookies (pb_access, 15 minutes; pb_refresh, 45 days) that keep you signed in. They are SameSite=Strict, Secure in production, and unreadable by JavaScript. Disabling them prevents sign-in.
  • Functional storage: local-storage entries for your theme preference, a session-token fallback for API clients, and the record of your privacy choices.
  • Optional analytics: Google Analytics 4, set only if you accept it. Until then it stores nothing on your device and sends no identifiers.
  • No ad trackers: we use no advertising cookies, cross-site trackers, remarketing, or social media pixels, and Google's advertising features are disabled.

The complete inventory, every name, purpose, and lifetime, is in our Cookie Policy.

6. How We Share Information

We do not sell personal information and do not share it for cross-context behavioral advertising. We disclose personal data only to processors acting on our instructions, and only what each needs:

  • Stripe: payment processing for paid subscriptions. Stripe handles payment card data under its own Privacy Policy. We never store your full card number.
  • GitHub & Google: OAuth authentication. We only access your basic profile and email address.
  • Google Analytics: aggregate usage measurement, only if you opt in. It receives page URLs, referrer, approximate location derived from IP, and device or browser type. IP addresses are truncated by Google before storage, advertising features and data sharing for ads are disabled, and we never send it your name, email, or any account identifier. Withdraw consent at any time in Your Privacy Choices.
  • Slack & Discord: alert delivery via webhook URLs you configure. We send incident data to the destinations you provide.
  • Infrastructure providers: cloud hosting and email delivery vendors that run the platform under data processing agreements.

We may also disclose information if required by law, to protect our rights or users' safety, or as part of a merger or acquisition (in which case this policy continues to apply and we'll notify you of any change).

7. Data Retention

We retain your account data for as long as your account is active. Incident history and SLA metrics are retained for 90 days on Pro plans and 30 days on Free plans. Server logs are kept for a limited period for security and diagnostics. If you delete your account, your personal data is removed or anonymized immediately and residual copies are purged within 30 days, except where retention is required by law (e.g., billing records for tax compliance).

8. Data Security

All data transmitted between your browser and PulsAPI is encrypted via TLS (HTTPS). Passwords are hashed using bcrypt. Sessions use short-lived access tokens delivered in httpOnly, SameSite=Strict cookies. Our infrastructure runs on secured cloud environments with regular security audits and monitoring.

While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

9. Your Rights & Choices

Everyone, regardless of jurisdiction, can exercise these rights, most of them self-serve:

  • Access & portability: download a machine-readable copy of your data anytime from Account settings ("Download my data").
  • Correction: update your profile details in Account settings.
  • Deletion: delete your account in Account settings, or email us.
  • Opt-outs: manage tracking preferences (there is nothing to opt out of today, and it stays that way unless you opt in) on Your Privacy Choices.

For anything you can't do self-serve, restriction, objection, or requests about data not tied to an account, email privacy@pulsapi.com. We verify requests by confirming control of the relevant email address and respond within 30 days.

10. European Privacy Rights (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights regarding your personal data, in addition to everything in Section 9:

  • Access (Art. 15), obtain confirmation of what personal data we process and a copy of it.
  • Rectification (Art. 16), have inaccurate data corrected.
  • Erasure (Art. 17), have your data deleted ("right to be forgotten").
  • Restriction of processing (Art. 18), limit how we use your data while a dispute is resolved.
  • Data portability (Art. 20), receive your data in a structured, commonly used, machine-readable format (our JSON export satisfies this).
  • Objection (Art. 21), object to processing based on legitimate interests or to direct marketing.
  • Withdraw consent (Art. 7(3)), at any time, where processing is based on consent.

To exercise any of these rights, use the self-serve tools in Section 9 or email privacy@pulsapi.com. We respond within one month as the GDPR requires. You also have the right to lodge a complaint with your local data protection supervisory authority; we'd appreciate the chance to address your concern first, but you may contact them at any time.

11. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), gives you specific rights. This section is our notice at collection and describes those rights.

Categories of Personal Information

In the preceding 12 months we have collected the following categories of personal information. We collect them directly from you, automatically from your use of the Service, and from OAuth providers you choose to sign in with; we use them for the purposes in Section 3 and retain them per Section 7.

CategoryExamplesCollectedDisclosed to
IdentifiersName, email address, IP addressYesService providers (hosting, email delivery, payments)
Customer records (Cal. Civ. Code §1798.80(e))Account credentials (password stored as a bcrypt hash); payment card details are collected and held by Stripe, not usYesPayment processor (Stripe)
Commercial informationPlan tier, subscription and trial history, billing eventsYesPayment processor (Stripe)
Internet or other network activityPages visited, features used, dashboard configuration, server access logsYesHosting provider
Geolocation dataCoarse location inferred from IP address (never precise GPS)Yes (coarse only)Hosting provider
Sensitive personal informationAccount log-in credentials (hashed); nothing elseLog-in credentials onlyNo one
Protected classifications, biometric data, audio/visual data, professional or education information, inferencesN/ANoN/A

No Sale or Sharing

We have not sold or shared personal information (as the CCPA defines those terms, including for cross-context behavioral advertising) in the preceding 12 months, and we do not sell or share personal information, including that of consumers under 16. We use sensitive personal information (hashed log-in credentials) only to provide the Service, which does not require a "Right to Limit" notice.

Your Rights

  • Right to know, what personal information we collect, use, and disclose.
  • Right to access, a copy of your personal information (self-serve export in Section 9).
  • Right to correct, inaccurate personal information.
  • Right to delete, subject to statutory exceptions (self-serve deletion in Section 9).
  • Right to opt out of sale or sharing, we don't sell or share, and you can still record the preference on Your Privacy Choices.
  • Right to non-discrimination, we never penalize you for exercising your rights.

Exercise these rights self-serve (Section 9), via Your Privacy Choices, or by emailing privacy@pulsapi.com. We verify requests by confirming control of the email address associated with the account and respond within 45 days. You may designate an authorized agent to submit requests on your behalf; we will ask for written proof of authorization. We honor the Global Privacy Control signal as a valid opt-out request.

12. Do Not Track & Global Privacy Control

We honor the Global Privacy Control (GPC) signal: when your browser sends it, we treat it as an opt-out of any sale or sharing of personal information. Because we do not track visitors across other sites, there is no behavior to change in response to legacy "Do Not Track" headers, but our no-tracking practices already exceed what DNT asks for.

13. International Data Transfers

PulsAPI is operated from the United States. If you access our services from outside the US, your information may be transferred to and processed in the US. For transfers from the EEA, UK, and Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) with our processors, alongside technical measures like TLS encryption.

14. Children's Privacy

PulsAPI is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of PulsAPI after changes constitutes acceptance of the revised policy.

16. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Privacy Policy