Privacy

Terms · Privacy · DPA · Legal noticesLast updated 8 September 2026.This notice describes how Pulse handles personal data. It is not legal advice. If you install the tracker on your own site, your notice, lawful basis and consent rules still depend on your site, audience and which optional features you enable.

Two roles

Pulse, operated by Pierre Ousset (hello@getpul.dev), is the controller for accounts on getpul.dev: email address, workspace membership, site settings, billing status and messages we send you. Pulse is the processor for analytics events collected from websites where a customer installs the tracker. That processing is described in the DPA.

Default tracker

Default counting uses no analytics cookies or browser storage. Do Not Track and Global Privacy Control stop the tracker from sending events or fetching rule configuration. Paths exclude query strings and referrers keep only the origin. Default visitor counts use a daily HMAC of the site, UTC day, truncated IP and coarse browser information, with a new per-site secret each day. These counting identifiers are not reused the next day. Raw IP addresses are not written to the analytics database.

Opt out

Open the site with #pulse-ignore or ?pulse_ignore=1, or use Settings → Tracking. That sets localStorage.pulse_ignore in this browser. That flag is a local preference, not an identifier.

Revenue attribution (opt-in)

When enabled, the script stores a UUID in sessionStorage for the current tab only and sends it with events. Pulse stores a hash of that UUID, never the raw value. Stripe customer emails are not copied into analytics. Enable this only after you check the rules that apply to your checkout.

Optional identity integration

If your integration calls pulse.identify with an external user ID, Pulse stores a stable hash scoped to the site. Unlike the default daily visitor hash, this value can link identify events across days. It is not used by default visit counting, but it remains stored with the event. Do not send an email address or other directly identifying value; review this integration and describe it in your own notice before using it.

Location processing

Pulse uses the geographic information supplied by its hosting platform when available. If country information is missing, it sends the visitor’s raw IP address to ipwho.is to resolve an approximate country, region and city. The result is cached in server memory under that IP and can be reused for up to six hours. This is external IP processing, even though the raw IP is not saved in Postgres. The raw IP is also used transiently for rate limiting.

What we do not do

No canvas or WebGL fingerprinting and no session replay. Default daily counting does not create a persistent identity across days; optional identity and revenue integrations have the separate behavior described above.

Optional experience measurements

Tracker extras can record click coordinates for aggregated heatmaps and Web Vitals measurements. Heatmaps do not record input values, page screenshots or session-replay video. These features require the full tracker to be enabled in site settings.

Account and billing data

To create an account we process your email address and send a one-time sign-in code. We store workspace and site configuration, member emails and roles, and billing state (plan, trial dates, subscription status and provider identifiers). Payment card details are handled by Whop or Stripe, not stored by Pulse. Team invites and login codes are sent by email.

Cookies on getpul.dev

getpul.dev sets only cookies needed to run the product: a language preference (pulse_locale), a workspace preference (pulse_ws), and session cookies for signed-in accounts. They are not used to count visits or build advertising profiles. The default Pulse tracker on customer sites does not set analytics cookies. Because these getpul.dev cookies are strictly necessary for the requested service, we do not show a marketing-cookie banner.

Subprocessors

The hosted service uses Vercel for application hosting and edge geolocation headers, Neon or another PostgreSQL host for the database, Resend for transactional email, Whop for new Pulse subscriptions, and Stripe for legacy Pulse billing and for customer revenue events when you connect Stripe. If platform country data is missing, a geolocation fallback sends the raw IP to ipwho.is. Optional Slack digests send report content to Slack when you configure them. Other payment webhooks you connect (Lemon Squeezy, Polar, Paddle, Creem, Dodo, Whop) receive only what you enable.

International transfers

Some providers may process data in the United States or other countries. We rely on their published transfer tools, including Standard Contractual Clauses where they offer them. Details of analytics processing are in the DPA.

Retention

Account data is kept while the account exists. Analytics events are kept for the life of the workspace unless you delete the site or account. Site deletion removes events, payments, funnels and secrets for that site. Login codes expire in minutes. Language and workspace cookies last up to one year or until you clear them.

Your rights

Depending on where you live, you may ask to access, correct, delete or export personal data we hold as controller, or to object or restrict certain processing. Email hello@getpul.dev. You may also contact your local data protection authority. For analytics collected from a customer’s website, contact that customer; Pulse will assist them under the DPA.

Contact

Privacy questions: hello@getpul.dev. Operator: Pierre Ousset. Related pages: terms of use, DPA and legal notices.