Pulse Tracker is a heart-rate tracker that connects to a fitness band over Bluetooth. This policy covers the Android app and this website, where the same account and rooms work in a browser, and it applies to everyone using the service today.
The controller of your personal data is the independent developer behind Pulse Tracker ("we"). Any privacy question or request: support@pulsetracker.pro — that address is read by the person who wrote the app, and we answer everything that arrives there.
The app reads your heart rate, step count and the band's battery level over Bluetooth, and keeps on the phone the band's address and name, its authentication key, your settings and your recorded sessions. None of that is uploaded — we never see it. It stays until you delete a session, use "Delete all logs", or uninstall.
| What | Why | Legal basis |
|---|---|---|
| Name, username, email, password hash, region, whether the terms were accepted and the address confirmed | The account itself: signing in, and letting others recognise you | Contract — Art. 6(1)(b) |
| A sign-up in progress, with a hashed one-time code, before an account exists | Confirming the address is yours | Pre-contract steps — Art. 6(1)(b) |
| One record per signed-in device: when it signed in and its User-Agent | Keeping you signed in; letting you end other devices from the profile | Contract; security — Art. 6(1)(b), (f) |
| Heart-rate readings with timestamps, linked to your username, while you are in a room | Showing your pulse to that room and recording its session | Explicit consent — Art. 9(2)(a) |
| Anonymous usage statistics and crash diagnostics (released Android app only) | Seeing that the app works and fixing what breaks | Consent, asked for on first launch — Art. 6(1)(a) |
| A visit to a public page of this site: which page, where you arrived from, your device and rough location. Never the signed-in part of the site | Seeing how many people find the site, and where they come from | Consent, asked in a bar at the foot of the page before anything is sent — Art. 6(1)(a) |
| Your IP address, counted in memory only and never stored | Stopping password and code guessing | Legitimate interest — Art. 6(1)(f) |
| Our own record of a public page being opened or a link on it pressed: the page, where you came from, which link, your IP address, your browser and device as its user agent describes them, and your language. Kept on our own server and sent to nobody | Knowing what the site is used for, and what is broken on it | Legitimate interest — Art. 6(1)(f). Nothing is stored on your device for this, so there is nothing to consent to; it is separate from the Google counter, which you can refuse |
Your pulse is health data — a special category under Article 9. It leaves your phone only when you join a room, only for that room, and only while you are in it, and only because you agreed to that in as many words before the first time it happened. Leaving the room withdraws that consent. It is never used for advertising and never sold.
In the browser we keep four things in local storage on this domain — your sign-in token, a copy of your own profile, your language choice, and where analytics stands for you. We set no cookies of our own. With analytics on, Google sets its own on the public pages; with it off, nothing from Google is ever requested — not the script, not a single call — and that is remembered, so a decision to stop is permanent until you clear this site's data.
You are asked before anything is sent, wherever you are. Only the EEA, the UK and Switzerland require that, and we do it everywhere anyway — one rule is easier to state truthfully than two. Refusing costs you nothing: every page works identically either way.
Our own visit records are not on this list because they go to nobody: they are written to the same server that serves you the page, read only by us, and deleted after 90 days.
That is the complete list. We do not sell personal data, do not share it with advertisers, and do not profile anyone. Two of those recipients are outside the EEA — Resend in the United States and Google — and both transfers rest on the European Commission's standard contractual clauses, which form part of their processing terms.
Delete account, in the app or on the site, removes your name, username, email address, password and every session at once, and the account can never sign in again. What stays is a blank placeholder row and the readings attached to it, so the rooms you took part in keep their charts. We call that de-identified rather than anonymous, and the difference matters: those readings no longer carry anything about who you are, but they remain grouped under one placeholder with their room and their timestamps, so someone who knew who was in that room at that hour could still reason about them. If you would rather have all of it gone, ask us — we erase the readings too, and then there is nothing left at all.
Counting visits is the one thing here you can switch on and off yourself, and this is the switch. It applies to this browser only, takes effect immediately, and is remembered until you clear this site's data.
You may ask us for a copy of your data, for its correction or erasure, for a restriction of processing, for a portable export, or object to processing we base on a legitimate interest. Where we rely on consent — room readings, and analytics — you can withdraw it at any time, which does not affect what was lawful before: leave the room, turn the app's switch off in Settings, or use the switch in section 5 above for this site. There is no form and no fee: write to support@pulsetracker.pro, and we answer within one month.
Nothing about you is decided automatically here: no profiling, no scoring. If you think we handle your data wrongly you can complain to the data protection authority of the country you live in.
Passwords are bcrypt hashes, never plain text. Traffic runs over HTTPS. Tokens live in the phone's encrypted keystore, or the browser's local storage. Admin access to the server is restricted and every attempt logged.
The app is not directed at children and we do not knowingly collect data from anyone under 16 in the European Economic Area, or under 13 where national law sets that lower limit. Tell us if that has happened and we will delete it.
Bluetooth — to find and talk to your band; scanning is declared neverForLocation
and the app never uses location. Notifications — the ongoing-measurement notification.
Foreground service — measuring while the app is in the background. Display over other
apps — the optional floating widget. Vibrate — haptic feedback.
We may update this policy; the effective date changes with it, and a material change makes the app and the site ask you to accept it again. Questions and requests: support@pulsetracker.pro.