Privacy

Your data, and your team’s candor, protected.

Pulsings handles two kinds of people’s data: organizers who run pulses, and the team members who answer them. This statement explains what we collect, why, and how it’s protected.

Working draft · last updated 2026-06-24

Note. This is a working draft of our privacy approach intended to describe how the product handles data. It is not legal advice and will be reviewed with counsel before launch.

Who this covers

Two groups: organizers, who create an account and run pulses, and members, who are invited to answer a short, anonymous check-in. Members do not create an account; they enter through a single-use link.

What we collect

  • Organizer account data: email address and the pulse name, cadence, and settings you configure.
  • Roster data: the team-member email addresses (and an optional preferred language) you add to a pulse so we can deliver invitations.
  • Check-in answers: the 1–5 scores and short comments a member submits in a cycle. These are sensitive personal data — and they carry no member reference, so they cannot be linked back to a person.
  • Operational data: minimal logs and AI-usage metering needed to run, secure, and bill the service.

How we use it

  • To run the pulse cycles you configure.
  • To deliver invitations and the member check-in experience.
  • To synthesise responses into anonymous, segment-safe trends and themes.
  • To secure the service, prevent abuse, and meter usage.

Confidentiality of member answers

This is the heart of the product. An organizer never sees an individual’s answers. A response is stored with no member or invite reference, and completion is tracked separately from content, so a timestamp cannot be joined to an answer. A cycle’s content is withheld entirely until enough people have responded. The one disclosed exception: an optional “urgent” note, which is reworded and stripped of identifying details before it reaches the organizer.

Legal basis

We process personal data on the bases permitted under the GDPR, typically the performance of a contract (running the pulse) and legitimate interests (securing and improving the service). Members are told up front, before they answer, that their responses are anonymous. The organizer’s organisation is generally the data controller for member data; we act as a processor on their instructions.

Where your data lives

Our data stores, AI models, and email delivery all operate in the EU region. The one exception is card payments, processed by Stripe in the US under EU Standard Contractual Clauses. Data is encrypted in transit and at rest.

Sub-processors

  • Supabase (EU): managed database, authentication, and storage.
  • Anthropic: AI models under zero-retention, no-training terms.
  • Resend (EU): transactional email delivery.
  • Stripe (US): card payments and subscription billing (US, under EU Standard Contractual Clauses).

Retention

We keep personal data for as long as needed to run a pulse and meet legal obligations, then delete or anonymise it. You can request deletion of a pulse’s data at any time (see your rights below).

Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal data, and you may object to or restrict certain processing. To exercise any of these, email privacy@pulsings.com and we’ll respond within the timeframes the GDPR requires.

Cookies

We use only the cookies strictly necessary to keep you signed in and to keep the service secure. We do not use advertising cookies.

Changes

We’ll update this statement as the product matures and post the revised date at the top. Material changes will be communicated to account holders.

Contact

Questions about privacy? Email privacy@pulsings.com.