Privacy Policy
Last updated: July 17, 2026
1. Who We Are
Puls ("Puls", "we", "us") is an AI-powered social media content platform operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. We are the data controller for the personal data described in this policy. For any privacy question or request, contact privacy@puls.work.
2. Information We Collect
- Account data — name, email address, and password (stored hashed by our authentication provider).
- Brand & profile data — information you provide about your business: company name, niche, offerings, target audience, tone of voice, and content preferences.
- Content you create or upload — prompts, drafts, generated posts, images, videos, and content you import for repurposing.
- Connected social account data — when you connect a social account we store the account identifier, account name, and encrypted OAuth tokens so we can publish on your behalf. We also retrieve performance data (likes, comments, shares, impressions) for posts published through Puls.
- Billing data — subscription tier and status, and a Stripe customer reference. Card details are collected and stored by Stripe, never by us.
- Usage & technical data — feature usage counts, log data, approximate location derived from IP, browser and device information, and aggregate analytics.
- Communications — messages you send us and email delivery/engagement events.
3. How We Use Your Data & Legal Bases
Where GDPR or similar laws apply, we rely on the following legal bases:
- Performance of a contract — providing the service: generating content, publishing to your connected accounts, scheduling, analytics, billing, and support.
- Legitimate interests — securing the service, preventing abuse and fraud, monitoring errors and performance, improving the product using aggregate usage data, and sending service and onboarding emails to customers.
- Consent — optional marketing communications and any optional features that require it. You can withdraw consent at any time.
- Legal obligation — tax, accounting, and responding to lawful requests.
We do not sell your personal data, and we do not use your data for third-party advertising.
4. AI Processing
To generate and review content, Puls sends the content you submit — together with your brand profile and relevant context — to the AI providers listed on our Subprocessors page (currently Google Gemini for generation, Anthropic Claude for review, and optionally Perplexity for trend research). These providers process the data under their API terms to provide the service. We do not use your content to train our own foundation models. Avoid submitting sensitive personal data (e.g. health or financial details about identifiable people) in prompts.
5. Connected Social Accounts
Social platform connections use OAuth: you authorize Puls on the platform itself and we never see your platform password. OAuth tokens are encrypted with AES-256-GCM before storage and are used only to publish content you approved and to fetch performance metrics for that content. You can disconnect any platform at any time from Dashboard → Accounts, which deletes the stored tokens, or revoke Puls from the platform's own security settings.
6. Data Retention
We keep your data while your account is active. If you delete your account, your profile, content, connected-account tokens, and usage records are deleted promptly (residual copies in encrypted backups roll off within about 30 days). Billing records are retained as long as tax and accounting law requires. Aggregate, non-identifying analytics may be retained. Content already published to your social accounts remains on those platforms under their policies.
7. Deleting Your Data
You can delete your data in the following ways:
- Full account deletion — go to Dashboard → Settings → Delete account. This permanently deletes your profile, posts, connected accounts, and usage data, and cancels any active subscription.
- Disconnect a platform — remove a single social connection (and its stored tokens) from Dashboard → Accounts.
- By request — email privacy@puls.work from your account email and we will delete your data and confirm within 30 days.
Facebook, Instagram & Threads users: if you remove the Puls app from your Meta account settings, Meta notifies our data deletion endpoint and we automatically delete the associated connection data and provide a confirmation code. You can also use either method above at any time.
8. Sharing & Subprocessors
We share personal data only with the service providers needed to run Puls — hosting, database, payments, AI, email, background jobs, and error monitoring. The current list, with purposes and regions, is maintained on our Subprocessors page. Each provider is bound by data protection terms. We may also disclose data where required by law, or as part of a merger or acquisition (in which case this policy continues to apply to your data).
9. International Transfers
Our subprocessors are primarily located in the United States and the EU. Where personal data of EEA, UK, or Swiss residents is transferred outside those regions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the EU-U.S. Data Privacy Framework where the provider is certified, and equivalent UK/Swiss mechanisms.
10. Security
Data is stored with Supabase (PostgreSQL) with row-level security so each user can only access their own records. OAuth tokens are encrypted with AES-256-GCM before storage and are never exposed to the browser. All traffic is encrypted in transit (TLS). Payments are processed by Stripe (PCI-DSS Level 1) — we never store card numbers. No system is perfectly secure; if a breach affects your personal data we will notify you and regulators as required by law.
11. Your Rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal data, to restrict or object to certain processing, and to withdraw consent at any time. You can exercise most of these directly in your dashboard, or by emailing privacy@puls.work. We respond within the timelines required by law (generally 30 days). EEA/UK residents may lodge a complaint with their local supervisory authority. California residents may exercise equivalent rights under the CCPA/CPRA — we do not sell or "share" personal information as defined there.
12. Cookies
We use strictly necessary cookies for authentication and session management, plus privacy-preserving analytics and error monitoring. We do not use advertising or cross-site tracking cookies. Details are in our Cookie Notice.
13. Age Requirements
Puls is a business tool and is not directed at children. You must be at least 18 years old (or the age of majority where you live) to create an account, as set out in our Terms of Service. We do not knowingly collect data from anyone under 16; if we learn we have, we will delete it.
14. Changes to This Policy
We may update this policy as the product or the law changes. Material changes will be announced by email or in-app before they take effect, and the "Last updated" date above always reflects the current version.
15. Contact
Privacy requests: privacy@puls.work. General questions: hello@puls.work. Postal: [LEGAL ENTITY NAME], [REGISTERED ADDRESS].