Privacy Policy
Last updated: August 3, 2026
TL;DR — Your Data is Yours
- • By default, your health data stays on your device and is never sent to us
- • All biometric data is processed locally using on-device AI
- • We only collect your email and shipping address for your order
- • Optional Pro cloud sync stores your health data encrypted (AES-256-GCM) on EU servers — only if you turn it on
- • We NEVER sell your data or use it to train AI models
- • No Google Analytics, no tracking cookies, no advertising pixels. Our self-hosted Umami analytics is cookie-free and does not build personal profiles.
- • You can export or delete your data anytime
1. Who We Are (Data Controller)
This Privacy Policy explains how Pulsyn Inc. ("Pulsyn", "we", "us", or "our") collects, uses, stores, and protects your personal data when you visit our website, place a pre-order, or use the Pulsyn app and Rune 1 smart ring.
For the purposes of the EU and UK General Data Protection Regulation (GDPR / UK GDPR), Pulsyn Inc. is the data controller of the personal data described in this policy.
Legal entity: Pulsyn Inc. (Delaware C Corporation)
Registered address: 701 Tillery Street, Unit 12-3559, Austin, TX 78702, United States
Privacy / data protection contact: privacy@pulsyn.tech
General support: support@pulsyn.tech
Pulsyn is a US-incorporated company. Where required for EU/EEA and UK data subjects, an Art. 27 representative will be designated and named here. Until then, you may direct all data protection enquiries to the privacy contact above.
2. Our Privacy Philosophy
At Pulsyn, privacy isn't a feature — it's the reason we exist. We built the Rune 1 smart ring because we believed health technology shouldn't require surrendering your most personal data to a corporation.
Most health wearables collect your biometric data by default, send it to their servers, and use it to train models, sell insights, or lock you into subscriptions. We think that's wrong. Your body produces data that belongs to you.
So we built Pulsyn the other way around: health data is processed on your device by default, and it only leaves your phone if you deliberately turn on Pro cloud sync — in which case it travels and is stored encrypted. The rest of this policy explains exactly what that means, without the hand-waving.
3. Core Privacy Principles
On-Device by Default
Health data is processed on your device. Nothing is sent to us unless you turn on cloud sync.
Zero Data Selling & No AI Training
We never sell your data or use your health data to train AI models. Ever.
You Own Your Data
Export, delete, or transfer your data anytime. No questions asked.
4. What Data We Collect
We collect the minimum data necessary to fulfill your order, run your account, and communicate with you. Health and biometric data is handled separately and is covered in Section 5.
Order Information
- Email address: Order confirmations, shipping updates, and product announcements
- Shipping address: To deliver your Rune 1 ring
- Payment information: Processed securely by Stripe (we never store card numbers)
- Order details: Ring size, color preference, and order status
Account Information
- Email address: For account access and important notifications
- Password: Hashed and salted by our authentication provider; never stored in plain text
- Optional profile info: Name and preferences you choose to provide
Technical Information
- Device type and operating system (iOS or Android version)
- App version and anonymized crash reports (which exclude your health values)
- IP address (for security and fraud prevention only, not linked to health data)
5. Health & Biometric Data (Special Category)
This is the most important section of this policy.
Your Rune 1 ring communicates directly with your phone over Bluetooth, and your health data is processed and stored on your device by default. We do not receive it — unless you choose to enable Pulsyn Pro cloud sync, in which case it is stored with us in encrypted form (explained below). We are transparent about this because being accurate matters more than a tidy slogan.
Health and biometric data is treated as special category data under GDPR Art. 9 and UK GDPR, and as Sensitive Personal Information under CCPA/CPRA and equivalent state laws. We only process it on the basis of your explicit consent, and on-device-by-default means most of it is never "processed by us" at all.
What Your Ring Collects
- Heart rate and heart rate variability (HRV)
- Blood oxygen saturation (SpO2)
- Skin / body temperature variations
- Sleep stages and patterns
- Activity, steps, and workout data
- Stress and recovery scores
- Menstrual cycle tracking (if enabled)
- Any AI-generated health insights
By default, all of this is processed entirely on your device using our on-device AI, and stored locally in an encrypted database. It never leaves your phone unless you explicitly enable cloud sync or use cloud AI.
Optional Cloud Sync (Pulsyn Pro)
Cloud sync is a Pro-tier, opt-in feature. If you turn it on, your health data is synced to our cloud so you can back it up and use it across devices. Here is exactly how it works:
- Encrypted before it leaves your device using AES-256-GCM authenticated encryption, and transmitted over TLS.
- Stored encrypted at rest with our cloud provider (Supabase), acting as our data processor.
- Encrypted with an app-managed key. The encryption key is derived using PBKDF2-HMAC-SHA256 from your account identifier and an application secret. This protects your data strongly against a database breach. To be precise and honest: this is not a zero-knowledge / "we hold no keys" design — Pulsyn is technically capable of decrypting synced health data. We do not access it to read, analyse, sell, or train on it, and access is restricted, logged, and limited to what is necessary to operate the sync service.
- Stored in the EU (Frankfurt region), on SOC 2 Type II audited infrastructure.
- Fully under your control. You can turn cloud sync off at any time in Settings → Privacy, and delete your synced data.
If you keep cloud sync off (the default), none of the above applies — your health data simply stays on your device.
Cloud AI (Pulsyn Pro)
If you use the cloud AI assistant (a Pro feature), the relevant context for your question is sent — over an authenticated, encrypted connection — to our cloud inference service, which runs on Supabase Edge Functions, to generate your answer. It is used only to produce that response and is not retained for training. On-device AI, which keeps everything local, remains available and is the default.
Where Your Data Lives
- On-device (default): Health data stays on your phone in an encrypted local database. No cloud.
- Cloud sync (Pro, opt-in): Encrypted with an app-managed key, stored at rest on EU servers (Frankfurt), processed by Supabase on our behalf.
- Cloud AI requests (Pro): Context sent to our Supabase Edge Function inference service to generate your answer. Not retained for training.
Zero Training Commitment
We will never use your biometric data to train AI models. Not our models, not third-party models, not anonymized aggregates. Your health data exists solely to serve you.
6. How We Use Your Data
The limited data we collect is used exclusively for:
- Order fulfillment: Processing, shipping, and delivering your Rune 1
- Communication: Order status updates, shipping notifications, and important product announcements
- Customer support: Responding to your questions and resolving issues
- Account & sync: Operating your account and, if you enable it, your encrypted Pro cloud sync
- Security: Fraud prevention and protecting your account
- Product improvement: Aggregated, anonymized purchase and usage data to understand demand (never your health values)
We do not sell, rent, or trade your personal information to third parties. Ever.
7. Legal Basis for Processing (GDPR / UK GDPR)
For users in the EU/EEA and UK, we process your personal data on the following legal bases:
| Processing Activity | Legal Basis | Reference |
|---|---|---|
| Order fulfillment, shipping, account management | Performance of a contract | Art. 6(1)(b) |
| Customer support, fraud prevention, security monitoring | Legitimate interests | Art. 6(1)(f) |
| Marketing communications | Consent (easily withdrawn) | Art. 6(1)(a) |
| Tax records, warranty & regulatory compliance | Legal obligation | Art. 6(1)(c) |
| Health / biometric data (cloud sync & cloud AI) | Explicit consent | Art. 9(2)(a) |
Health and biometric data is special category data. We process it only with your explicit consent, given when you opt in to cloud sync or cloud AI. You can withdraw that consent at any time by disabling the feature, with no effect on the lawfulness of processing before withdrawal.
8. Third-Party Services
We use a small number of trusted providers to operate our business. Each processes only the minimum data required, under a data processing agreement.
| Service | Purpose | Data Processed | Location |
|---|---|---|---|
| Stripe | Card payments | Payment info (tokenized) | US (Privacy) |
| Supabase | Auth, orders & blog database, encrypted Pro health sync, cloud AI | Email, order data, encrypted health data (Pro) | EU — Frankfurt (Privacy) |
| Resend | Order & transactional email | Email address | US (Privacy) |
| Umami | Website analytics (cookieless), including sampled session replay and heatmaps on limited public pages | Aggregated page views, coarse custom events, Core Web Vitals, and (when recording is on) interaction recordings of selected informational pages: no cookies, not linked to orders or accounts; typed form values are never captured | Self-hosted (EU) |
| Apple Health | Optional health integration | User-initiated, on-device sync | On-device (Privacy) |
| Google Fit / Health Connect | Optional health integration | User-initiated, on-device sync | On-device (Privacy) |
Apple Health and Google Fit / Health Connect integrations are user-initiated and disabled by default. You choose what to share, and the data syncs directly on your device — it does not pass through our servers.
Mobile App SDKs
The Pulsyn app deliberately avoids advertising and tracking SDKs. It contains no advertising SDKs, no Google Firebase, and no third-party analytics SDKs. For reliability, the app uses a crash and error reporting tool that captures diagnostic information (such as error types and app state) but is configured to exclude your health values (heart rate, HRV, SpO2, stress, temperature) from reports.
9. International Data Transfers
Pulsyn Inc. is based in the United States, while our primary database and any encrypted Pro health sync are hosted in the EU (Frankfurt). Personal data may therefore be transferred across borders. We protect those transfers as follows:
- Standard Contractual Clauses (SCCs): EU transfers to US-based processors and to us rely on the EU SCCs (Commission Implementing Decision 2021/914).
- UK transfers: safeguarded by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs.
- Adequacy: where a recognised adequacy decision or the EU-US / UK-US Data Privacy Framework applies, we rely on it.
- Data Processing Agreements: binding DPAs are in place with each processor (Stripe, Supabase, Resend).
- Data residency: our primary database and Pro health sync are deployed in the EU (Frankfurt region).
US-based processors (Stripe, Resend) never receive your health data. Your encrypted Pro health data is stored in the EU.
10. Data Storage & Security
We implement multiple layers of security to protect your data:
Encryption Standards
- AES-256-GCM: Authenticated encryption for health data synced to the cloud (Pro). Galois/Counter Mode provides both confidentiality and integrity.
- On-device database encryption: Health data stored on your phone is held in an encrypted local database.
- PBKDF2-HMAC-SHA256 key derivation: Cloud-sync encryption keys are derived with a strong, iterated key-derivation function from your account identifier and an application secret. This protects synced data against database compromise.
- TLS 1.2+: Transport-layer security for all network communication.
A note on honesty: our cloud sync is encrypted-at-rest with an application-managed key, not a zero-knowledge design. That means Pulsyn is technically capable of decrypting synced health data, but we contractually and operationally commit not to access it except as strictly necessary to run the service, and never to sell it or train models on it.
Infrastructure Security
- Hosted on SOC 2 Type II audited infrastructure — independently verified for security, availability, and confidentiality
- Encrypted databases with AES-256 at rest and strict access controls
- Row-level security and least-privilege access policies on our database
- Regular security reviews
- Two-factor authentication (2FA) available for accounts
- Employee access strictly limited and logged
11. Data Retention
We retain your data only as long as necessary:
| Data Type | Retention Period | Reason |
|---|---|---|
| Order data | 7 years | Tax and legal requirements |
| Email communications | 3 years after last contact | Support continuity |
| Support tickets | 2 years after resolution | Support history |
| Analytics data | Aggregated & not linked to identity | Not linked to identity, account, or order |
| Health data (default) | Never sent to us | Stays on your device |
| Health data (Pro cloud sync) | Until you delete it / disable sync | Stored encrypted for your backup |
Account deletion: all associated data is permanently removed within 30 days, except where legal retention (e.g. tax records) is required.
12. Your Rights
You have full control over your data. Depending on where you live, you have the following rights — and we honour them for everyone:
- Access: Request a copy of all data we hold about you. Email privacy@pulsyn.tech with subject "Data Access Request", or export directly from the app.
- Rectification / Correction: Update any inaccurate information via your account settings or by contacting us.
- Erasure / Deletion: Request complete deletion of your data. Email privacy@pulsyn.tech with subject "Deletion Request", or delete from app settings.
- Portability: Export your data in standard formats (JSON, CSV) directly from the app.
- Restriction: Ask us to restrict processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interests by contacting us.
- Withdraw consent: Withdraw consent for any consent-based processing (e.g. cloud sync, cloud AI, marketing) at any time, without affecting prior processing.
- Complaint: Lodge a complaint with your local data protection authority (e.g. your EU supervisory authority, or the UK ICO) if you believe your rights have been violated.
We respond to all requests within 30 days. For urgent matters, we aim to respond within 48 hours.
13. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you specific rights regarding your personal information.
Do Not Sell or Share My Personal Information
Pulsyn does not sell your personal information, and does not share it for cross-context behavioral advertising. We never have, and we have no business model that depends on it. Because we do not sell or share, there is nothing to opt out of — but if that ever changed, we would provide a clear opt-out mechanism here first.
Categories of Personal Information We Collect
- Identifiers: name, email address, shipping address, IP address
- Commercial information: orders placed, products purchased
- Internet activity: aggregated website analytics and, on a small sample of public content pages, session replay and heatmaps (no profiles, not linked to your identity or account)
- Sensitive Personal Information: health and biometric data — only if you enable Pro cloud sync, and only with your consent
Sensitive Personal Information & the Right to Limit
Health and biometric data is Sensitive Personal Information under the CPRA. We use it solely to provide the service you asked for (your own health tracking and, if enabled, your encrypted backup) — never to infer characteristics about you, never for advertising, and never sold or shared. Because we already limit our use to these permitted purposes, the "Limit the Use of My Sensitive Personal Information" right is honoured by design. You can also disable cloud sync at any time.
Your California Rights & Non-Discrimination
You have the right to know, delete, and correct your personal information, to opt out of sale/sharing (not applicable, as we do none), and to limit use of Sensitive PI. We will never discriminate against you for exercising any of these rights. To make a request, email privacy@pulsyn.tech.
14. UK GDPR Addendum
If you are in the United Kingdom, your personal data is protected under the UK GDPR and the Data Protection Act 2018. The rights described in Section 12 apply to you in full.
- Supervisory authority: you may complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
- International transfers from the UK are safeguarded by the UK IDTA or the UK Addendum to the EU SCCs, or by an applicable adequacy / Data Bridge mechanism.
- UK representative: where required, a UK representative will be appointed and named here.
15. Canada & Australia
Canada (PIPEDA)
If you are in Canada, we handle your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA). We obtain your express consent for any collection or use of biometric/health data, and you may access, correct, or withdraw consent at any time by contacting privacy@pulsyn.tech. You may also complain to the Office of the Privacy Commissioner of Canada.
Australia (Privacy Act 1988 / APPs)
If you are in Australia, we handle your personal information in accordance with the Australian Privacy Principles (APPs). Biometric and health information is "sensitive information" and is collected only with your consent. You may request access (APP 12) or correction (APP 13), and complain to the Office of the Australian Information Commissioner (OAIC). Cross-border disclosures are made only where the recipient is bound by substantially similar protections.
16. Cookies & Analytics
We use Umami, a self-hosted, open-source analytics platform, to understand how visitors use our site. It is configured to be privacy-first:
- Self-hosted: Analytics data is sent to our own Umami instance, not to a third-party analytics service.
- Cookie-free tracking: Umami does not set tracking cookies or advertising identifiers. We still set a strictly necessary session cookie for the shopping cart (see below).
- No cross-session identity: We do not link your visits or sessions together to identify you, and we do not track you across other websites or apps.
- No personal profiles: We do not link analytics data to your email, order, health information, or account, and we do not build personal profiles from it.
- Coarse events only: Custom events use broad labels such as button names, page sections, and content areas. They do not include free-form text, URLs with query strings, or anything you type.
- Core Web Vitals: We collect basic page performance metrics to keep the site fast.
- Do Not Track: Where your browser sends a Do Not Track signal, our analytics respect it.
Session Replay & Heatmaps
We use Umami session replay and heatmaps to see how visitors interact with a limited set of public content pages. Recording is switched on only when we deliberately enable it for the live site, and only on pulsyn.tech and www.pulsyn.tech. When it is active, it works as follows:
- Sampled: about 15% of sessions are recorded today, and never more than 20%.
- Limited pages only: recording runs only on selected informational pages such as About, FAQ, Blog, and similar content pages.
- Sensitive pages excluded: pages with forms or sensitive flows are never recorded, including product, docs, checkout, reservation, contact, and unsubscribe pages.
- No query or hash URLs: recording does not run on any address that includes a query string or a hash fragment.
- Short recordings: the current configuration caps each recording at 5 minutes, and recording stops if you navigate away to a page outside this set.
- Do Not Track: if your browser sends a Do Not Track signal, the recorder is not loaded and nothing is recorded.
Typed form values are never captured. Anything you type into form fields (text boxes, dropdowns, and similar controls) is masked, and password fields are always masked.
Text that is already shown on the page can still appear in a recording. That is why we keep recording to a short list of informational pages and refuse any address with a query string or hash: form-bearing and sensitive pages stay out of scope.
Cookies We Use
| Cookie | Purpose | Duration | Required |
|---|---|---|---|
| session | Shopping cart functionality | Session | Yes (strictly necessary) |
What We Do NOT Use
- Google Analytics or similar third-party analytics
- Facebook Pixel or social media tracking
- Advertising cookies or retargeting pixels
- Third-party tracking scripts of any kind
- Browser fingerprinting
- Sale or sharing of analytics data
17. Children's Privacy
Pulsyn's products and services are not directed at children. We do not knowingly collect personal information from children under 13 (United States) or under 16 (EU/EEA), in line with applicable law. Our products are intended for adults.
If you believe a child has provided us with personal data, please contact us immediately at privacy@pulsyn.tech and we will promptly delete it.
18. Changes to This Policy
If we make material changes to this privacy policy, we will notify you via email (if you've provided one) and update the "Last updated" date at the top of this page.
Minor clarifications or formatting changes will not trigger notification but will be reflected in the updated date.
We will never reduce your privacy protections without your explicit consent.
This Privacy Policy forms part of, and should be read alongside, our Terms of Service and Warranty & Returns Policy.
19. Contact Us
If you have any questions about this privacy policy, your data, or Pulsyn's privacy practices:
Privacy Inquiries: privacy@pulsyn.tech
General Support: support@pulsyn.tech
Postal: Pulsyn Inc., 701 Tillery Street, Unit 12-3559, Austin, TX 78702, United States
Response Time: Within 48 hours for privacy matters
Our Commitment to You
Privacy is not an afterthought at Pulsyn — it's the foundation of everything we build. Your health data stays on your device by default, and if you choose to sync it, it travels and is stored encrypted, under your control.
Thank you for trusting us with your health journey. We take that responsibility seriously — including the responsibility to describe exactly how it works.
