Privacy Policy

Last updated: 31 July 2026

Pulsebase ("Pulsebase", "we", "us") is an iOS app that helps you keep your Apple Health and fitness data as open files you own, sync those files to a cloud account you control, and explore them. This policy explains what data the app touches, where it goes, and what it never does.

The short version: Pulsebase has no backend server. Your health data stays on your device and in the cloud storage you connect. We do not collect it, sell it, or use it for advertising. The only time data leaves your device is (1) when you sync to your own cloud, and (2) when you actively use an AI feature, which sends the minimum needed to answer your request to the AI provider.

Data the app works with

With your explicit permission, Pulsebase reads data from Apple Health, which may include workouts, heart rate, distance, routes and location associated with activities, and related health and fitness metrics. This data is processed on your device and stored there as local files. Pulsebase does not receive a copy of it on any server we operate — we don't have one.

Cloud sync (Google Drive, Dropbox, iCloud, OneDrive)

Cloud sync is optional and off until you turn it on. When you connect a provider, Pulsebase uses that provider's official OAuth sign-in so you authorise access directly with them; we never see your password.

AI features

Pulsebase includes optional AI features (such as a coach and chart/summary generation). These run only when you invoke them. Depending on the feature, the app sends a prompt and the specific query results or context needed to produce an answer to a third-party AI provider (Google Gemini). Where a feature is designed to keep your data on-device, only the generated instructions — not your underlying health records — are exchanged. AI features are never used to process your data in the background.

The AI features require your own Google Gemini API key, which you enter in the app. Your key is stored only on your device, in the iOS Keychain, and is used to send requests directly to Google using your key. Without a key, the AI features are disabled and no data is sent to any AI provider.

Data sent to the AI provider is handled under that provider's terms and privacy policy. Please review Google's Gemini API terms for how they process API requests.

How Google treats those requests depends on which tier your key is on, and because you supply your own key that choice is yours. On Google's free tier, Google may use what it receives — the derived summaries and prompts described above — to improve its own products, and that content may be reviewed by people. Enabling billing on your Google Cloud project moves your key to the paid tier, where Google does not use API requests to train its models. In either case, only derived values leave your device; your raw health records are never sent.

Other services

What we don't do

Data retention and deletion

Because your data lives on your device and in your own cloud account, you are in control of retention. Deleting the app removes its on-device data. To remove synced files, delete the Pulsebase folder in your cloud provider and/or revoke access as described above.

Children

Pulsebase is not directed to children under 13 (or the minimum age required in your country) and is not intended for their use.

Changes to this policy

If this policy changes, we'll update the date above and post the revised version at this URL.

Contact

Questions about privacy? Email privacy@pulsebaseapp.com.