PulseLock

Privacy Policy

Privacy Policy

PulseLock keeps widget, wallpaper, alert, and smartwatch data useful while limiting what appears on locked-device surfaces.

Effective date: 2026-05-10

This Privacy Policy explains how PulseLock processes information for PulseLock, including the mobile app, lock screen widgets, home screen widgets, wallpapers, alerts, watch features, and related backend services.

Information We Process

First-Party Usage Measurement

PulseLock measures its own website, API, and app usage without sending these measurements to a third-party analytics service. The website sets HttpOnly first-party random visitor and 30-minute session cookies so repeat page views can be deduplicated. The server stores only one-way identifiers, daily page-view counts, the number of HTML response bytes it served, and hourly aggregate API request/response-byte totals without an API visitor identity. The mobile app reports a random installation identifier after an authenticated session starts and when the app returns to the foreground; the server stores only a one-way hash, platform, app version, build number, first-seen time, and daily activity. These measurements are used for private service operations and capacity planning, not advertising profiles.

Optional Mobile Diagnostic Reports

Mobile error reporting is disabled unless both the installed app and the private service configuration explicitly enable it. When enabled, the app sends an authenticated, bounded technical error report to PulseLock's own backend. The app and backend remove obvious credentials, token values, URL query secrets, email addresses, account identifiers, and device identifiers before retention. Reports are grouped by a server-generated fingerprint, limited per account, retained for no more than 30 days, included in account data exports, and deleted with the account. PulseLock does not send these reports to a third-party error-monitoring service.

App Privacy and Data Safety

Store privacy labels and data safety disclosures must match this policy and the app's actual behavior. PulseLock names the app and developer in this policy, explains the categories of data processed, and keeps privacy and account deletion links publicly reachable for app review and users.

How We Use Information

Financial, Weather, and Air-Quality Data

Provider data requests for market, weather, and air-quality information are processed through the backend. The mobile app, widgets, watch app, watch widgets, complications, and tiles do not store provider API keys and do not call market, weather, air-quality, or billing providers directly.

Widgets, Watches, and Locked Devices

Widget and watch payloads are designed to be safe to render while a device is locked. Portfolio values are not shown on locked-device surfaces unless you explicitly enable that display. Watch tokens are scoped to watch snapshot APIs and are separate from normal mobile login tokens. Watch pairing identifiers and token hashes stay server-side; app and widget responses use limited references instead of returning raw device hashes.

Purchases and Subscriptions

Purchases are handled by app store services and RevenueCat. We receive purchase identifiers, entitlement state, subscription status, renewal status, and refund or cancellation events needed to grant, restore, audit, or remove paid access. We do not receive your full payment card number.

Sharing

We share information only with service providers needed to run the product, such as cloud hosting, database, cache, queue, email, push notification, billing entitlement, analytics, and app store services. We do not sell personal information.

Third-Party Services

PulseLock may use service providers for hosting, database, cache, email, push delivery, RevenueCat entitlement synchronization, app store purchase processing, market data, weather data, air-quality data, analytics, and security monitoring. Provider availability and privacy practices can affect related features.

Retention

We keep account, purchase, entitlement, audit, and support records for as long as needed to provide the service, meet legal and app store obligations, prevent fraud, resolve disputes, and maintain accurate billing history. Cached provider snapshots and operational logs are retained for limited periods based on operational and security needs. Optional mobile diagnostic reports are retained for no more than 30 days. First-party daily usage and web-session records are normally retained for 400 days. The one-way installation record remains so cumulative installs stay deduplicated; it does not contain the original installation identifier.

Account Deletion

You can request account deletion in the app from Account and privacy controls, or by contacting privacy@askrs.com. Deletion removes or anonymizes account data that is no longer needed. Records required for billing, fraud prevention, legal compliance, store reconciliation, security, or dispute handling may be retained for the required period.

Children

PulseLock is not directed to children under 13. If you believe a child provided personal information, contact us so we can review and remove it when required.

Your Choices

Security

We use technical and organizational safeguards designed to protect account, entitlement, widget, watch, alert, and support information. These safeguards include scoped tokens, server-side provider keys, rate limits, validation, stale-data fallbacks, and limited public API payloads. No internet service can guarantee complete security, so you should keep device access, app store accounts, and email accounts protected.

International Processing

Information may be processed in countries where we or our service providers operate. We use appropriate safeguards when required for cross-border processing.

Changes

We may update this Privacy Policy as the service changes. The effective date above shows when this page was last updated.

Contact

For privacy requests, contact privacy@askrs.com. For general support, contact support@askrs.com.