Legal

Privacy Policy

Last updated: 2026-02-15

This Privacy Policy explains what data PeakPulse360 collects, how we use it, and your rights.

1. What we collect

  • Account data: name, email, hashed password.
  • Training data: workouts, recovery and wellness logs, meals, mental-wellbeing entries, AI chat history.
  • Form journal photos: images you upload, stored in private object storage with short-lived signed URLs.
  • Payments: processed by Stripe — we receive transaction status and metadata but never your full card number.
  • Integrations: when you connect Strava, we store OAuth tokens to fetch your activities. You can disconnect anytime.
  • Technical: minimal logs (IP, user-agent, error traces) for security and reliability.

2. How we use it

  • To operate and personalize the Service (readiness score, AI coaching, calendar).
  • To process payments and manage subscriptions.
  • To respond to your support requests.
  • To detect and prevent abuse and to comply with legal obligations.

3. AI processing

When you chat with Pulse or request an AI meal plan, the messages are sent to our LLM provider (Anthropic) to generate the response. We do not allow your data to be used to train models. Conversations are stored in your account so you can revisit them.

4. Sharing

We do not sell your personal data. We share data only with:

  • Sub-processors needed to operate the Service (hosting, payments, AI model provider, object storage).
  • Authorities when legally required.

5. Security

  • HTTPS in transit. Passwords hashed with bcrypt.
  • JWT-based authentication.
  • Photos served via short-lived signed URLs (10 min) scoped to your user.

6. Your rights

Depending on your jurisdiction (e.g. GDPR, CCPA), you have rights to access, correct, export, or delete your data. Email peakpulse360@gmail.com and we will respond within 30 days.

7. Retention

We keep your data while your account is active. Deletion requests remove personally identifiable data from active systems; some records may persist in backups for up to 90 days.

8. Children

PeakPulse360 is not intended for users under 16. We do not knowingly collect data from children.

9. Changes

We will notify you of material changes via email or in-app notice.

Questions? Contact us.

Made with Emergent