Privacy Policy
Last updated: 31 July 2026
Pulsebase ("Pulsebase", "we", "us") is an iOS app that helps you keep your Apple Health and fitness data as open files you own, sync those files to a cloud account you control, and explore them. This policy explains what data the app touches, where it goes, and what it never does.
The short version: Pulsebase has no backend server. Your health data stays on your device and in the cloud storage you connect. We do not collect it, sell it, or use it for advertising. The only time data leaves your device is (1) when you sync to your own cloud, and (2) when you actively use an AI feature, which sends the minimum needed to answer your request to the AI provider.
Data the app works with
With your explicit permission, Pulsebase reads data from Apple Health, which may include workouts, heart rate, distance, routes and location associated with activities, and related health and fitness metrics. This data is processed on your device and stored there as local files. Pulsebase does not receive a copy of it on any server we operate — we don't have one.
Cloud sync (Google Drive, Dropbox, iCloud, OneDrive)
Cloud sync is optional and off until you turn it on. When you connect a provider, Pulsebase uses that provider's official OAuth sign-in so you authorise access directly with them; we never see your password.
- Where your data goes: your files are uploaded to your own account with the provider you chose. They are not routed through, copied to, or stored on any Pulsebase infrastructure.
- What access is used for: access is used solely to create and update the Pulsebase data folder in your account so your dataset stays mirrored across your devices. We request the narrowest scope that makes this work.
- Google user data: Pulsebase's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Drive data for advertising, do not sell it, and do not allow humans to read it except as required for security or to comply with law.
- Revoking access: you can disconnect a provider inside the app at any time, and you can revoke Pulsebase's access from your provider's own security settings (for example, your Google Account or Dropbox connected-apps page).
AI features
Pulsebase includes optional AI features (such as a coach and chart/summary generation). These run only when you invoke them. Depending on the feature, the app sends a prompt and the specific query results or context needed to produce an answer to a third-party AI provider (Google Gemini). Where a feature is designed to keep your data on-device, only the generated instructions — not your underlying health records — are exchanged. AI features are never used to process your data in the background.
The AI features require your own Google Gemini API key, which you enter in the app. Your key is stored only on your device, in the iOS Keychain, and is used to send requests directly to Google using your key. Without a key, the AI features are disabled and no data is sent to any AI provider.
Data sent to the AI provider is handled under that provider's terms and privacy policy. Please review Google's Gemini API terms for how they process API requests.
How Google treats those requests depends on which tier your key is on, and because you supply your own key that choice is yours. On Google's free tier, Google may use what it receives — the derived summaries and prompts described above — to improve its own products, and that content may be reviewed by people. Enabling billing on your Google Cloud project moves your key to the paid tier, where Google does not use API requests to train its models. In either case, only derived values leave your device; your raw health records are never sent.
Other services
- Weather: to show conditions for a workout, the app may request weather data for the activity's time and approximate location from a public weather API. No account or identifier is attached to these requests.
- Location names: place names for your activities are resolved on-device using Apple's geocoding.
What we don't do
- We don't run a server that collects or stores your health data.
- We don't sell or rent your data, and we don't use it for advertising or profiling.
- We don't include third-party analytics or tracking SDKs that harvest your data.
Data retention and deletion
Because your data lives on your device and in your own cloud account, you are in control of retention. Deleting the app removes its on-device data. To remove synced files, delete the Pulsebase folder in your cloud provider and/or revoke access as described above.
Children
Pulsebase is not directed to children under 13 (or the minimum age required in your country) and is not intended for their use.
Changes to this policy
If this policy changes, we'll update the date above and post the revised version at this URL.
Contact
Questions about privacy? Email privacy@pulsebaseapp.com.