Legal

Privacy Policy

Last updated July 26, 2026. This policy explains what personal data Pulser collects, why we collect it, and the rights you have over it under applicable U.S. privacy laws.

1. Who we are

Pulser ("Pulser", "we", "us") is a subscription-based web application providing market data visualization and portfolio tracking tools to retail investors. We are the "business" responsible for the personal information described in this policy.

Contact: contact@usepulser.com

2. What data we collect

We only collect data we need to run the service. We do not sell your personal information, we do not run third-party ad networks, and we do not build advertising profiles.

  • Account data: email address (used as your login), subscription plan.
  • Usage data: portfolios you create, watchlists, comparison sets, custom DCF inputs, and any settings you change for better user experience.
  • Payment data: handled entirely by Stripe. We never see or store your card number, CVV, or full bank details. We receive only a subscription status (active / canceled / past due) and a reference to the Stripe customer record.
  • Support data: messages you send via the Contact form, plus the page URL you sent them from.
  • Technical logs: server-side logs of API requests (timestamps, endpoint, status code, your internal user ID). Retained 7 days.

3. How we use your data

  • To provide the service (auth, gating features by plan, computing your portfolio analytics).
  • To process payments and manage your subscription via Stripe.
  • To respond to support requests.
  • To detect and prevent fraud, abuse, and security incidents (e.g. rate limiting, blocking bypass attempts).
  • To comply with legal obligations (tax records, regulator or law-enforcement requests).

We do not use your data to train machine-learning models, to send your information to third-party marketers, or to build behavioral advertising profiles.

4. How we share data

We share strictly necessary data with the following service providers. None of this sharing constitutes a "sale" or "share" of personal information as those terms are defined under state privacy law — we do not receive money or other valuable consideration for it, and it is not used for cross-context behavioral advertising.

  • Our cloud hosting provider — hosting, authentication, storage, compute, and content delivery. Infrastructure is operated in data centers located in the United States.
  • Stripe, Inc. — subscription billing, payment processing, invoicing, tax calculation. See stripe.com/privacy.
  • Our market data provider — supplies the prices, financial statements, and reference data we display. We do not send them your personal data; we only forward the ticker symbol you requested.

We may also disclose personal information if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of Pulser, our users, or the public. If Pulser is involved in a merger, acquisition, or asset sale, personal information may be transferred as part of that transaction.

We will publish an updated list of service providers at this URL whenever it changes. You can request the current list at any time from contact@usepulser.com.

5. Where your data lives

Primary storage is in the United States. Stripe may process payment data outside the United States as needed to provide its services. We do not otherwise transfer personal data outside the United States.

6. How long we keep it

  • Account data: while your account is active, plus 30 days after deletion to honor reactivation requests.
  • Portfolios, watchlists, settings: deleted within 30 days of account closure.
  • Payment records and invoices: retained 7 years for tax and accounting compliance, as required by applicable federal and state law.
  • Support messages: 2 years from last reply.
  • API and security logs: 7 days.

7. Your privacy rights

Depending on where you live, state privacy laws — including California's CCPA/CPRA, Virginia's VCDPA, Colorado's CPA, Connecticut's CTDPA, Utah's UCPA, and similar laws in other states — may give you the right to:

  • Know what personal information we hold about you and how it's used.
  • Access a copy of that information.
  • Correct inaccurate personal information.
  • Delete your account and associated data ("right to be forgotten" / right to delete).
  • Port your data in a machine-readable format.
  • Opt out of the sale or "sharing" of personal information, and of targeted advertising and certain profiling. As noted above, we do not sell or share your data today, so there is nothing to opt out of.
  • Not be discriminated against for exercising any of these rights.
  • Designate an authorized agent to make a request on your behalf.
  • Appeal a denied request, where applicable state law provides for an appeal.

To exercise any of these rights, email contact@usepulser.com. We will verify your request using the email address tied to your account and respond within the time required by applicable law (typically 45 days, with a possible extension). You may also lodge a complaint with your state Attorney General or, in California, the California Privacy Protection Agency.

8. Cookies and local storage

We do not use third-party tracking cookies, analytics pixels, or advertising trackers. We use:

  • Session storage for your authentication tokens (cleared when you close the browser).
  • Local storage for your preference of "Keep me signed in" (only if you explicitly check the box).
  • First-party cookies set by our infrastructure for session continuity. No cross-site tracking.

Because we don't sell or share personal information or use tracking/advertising cookies, there is nothing to opt out of — but we honor Global Privacy Control (GPC) signals as an opt-out preference signal where applicable state law requires it.

9. Security

All traffic is over HTTPS (TLS 1.2+). Payment-processor API keys and webhook secrets are kept in an encrypted secret store with role-based access. Security-relevant events are logged to our infrastructure.

If we discover a security breach affecting your personal information, we will notify you and any required state regulators without unreasonable delay, as required by applicable state breach-notification laws.

10. Children

Pulser is not directed at children under 13 and we do not knowingly collect personal information from children under 13, consistent with the Children's Online Privacy Protection Act (COPPA). If you believe a child has created an account, please contact us and we will delete the account.

11. Changes to this policy

We may update this policy to reflect new features, legal changes, or service-provider changes. Material changes will be announced by email to your account address at least 14 days before they take effect. The current version is always available at usepulser.com/privacy.

12. Contact

Privacy questions, rights requests, or complaints: contact@usepulser.com