Privacy Policy
Effective July 9, 2026
This is a plain-language, accurate-as-of-today description of what PulseFlow actually collects and does with it — not a generic template. PulseFlow is in early access and this product is still evolving, so this policy will be updated as new features (like billing, or additional publishing channels) ship. We'll bump the effective date above whenever that happens.
What we collect
If you join the waitlist:your email address, and an optional free-text note about what you're working on. That's it — we don't ask for your name, company, or anything else at this stage.
If your account is approved: a username and a password, which we store only as a salted, iterated cryptographic hash — we never store or can retrieve your actual password.
Cookies, if you're a logged-in user:
pf_session— an opaque session token (HttpOnly, secure), used to keep you logged in. It doesn't contain any personal data itself; your account info stays server-side.pf_session_exists— a non-sensitive marker (just the value "1") so the app can tell you're logged in without reading the session token.
Your session token is also cached in your browser's local storage so the app can authenticate API requests — this stays on your device and isn't sent anywhere except back to PulseFlow's own servers.
What we don't collect
- No third-party analytics or ad-tracking scripts of any kind — we don't use Google Analytics, Meta Pixel, or anything similar.
- No payment or financial information — PulseFlow doesn't process payments today.
- No persistent access logs tied to your IP address — the only IP-based data we keep is a short-lived rate-limiting counter (auto-expires within minutes) to prevent abuse of login and content-generation endpoints.
How we use what we collect
Waitlist submissions are used to review and approve access requests. Account credentials authenticate you into the product. We send transactional emails — a welcome email, password resets, and waitlist-approval notices — through our email provider, Resend. We don't sell, rent, or use your data for advertising, and we don't share it with anyone beyond what's listed below.
Third-party services we use
Depending on how you use PulseFlow, some data (research queries, drafted content, or published articles) passes through the following services so the product can actually work:
- AI providers (DeepSeek, Anthropic, Google Gemini) — process research queries and generate drafted content and images.
- Search providers (SearXNG — self-hosted, Brave Search, Exa, Jina Reader) — used to research trending topics and source material.
- Langfuse (self-hosted) — records traces of AI model calls (prompts and outputs) for our own debugging and quality monitoring.
- WeChat Official Account API — only when you explicitly publish content to WeChat through PulseFlow.
- Resend — delivers transactional emails on our behalf (see above).
- Firebase Hosting & Google Cloud Storage— host the application and store generated images.
Where your data is stored
PulseFlow's servers and database are hosted in Singapore. We don't currently replicate data to other regions.
How long we keep it, and your rights
Waitlist submissions are kept until they're reviewed and acted on. You can ask us to access, correct, or delete any personal data we hold about you at any time by emailing founders@pulseflow.run.
Children
PulseFlow isn't directed at, or intended for use by, children under 13.
Changes to this policy
If our data practices change in a meaningful way, we'll update this page and the effective date above. We'll do our best to flag material changes directly to registered users.
Contact
Questions about this policy or your data? Email founders@pulseflow.run.