Privacy Policy
Version 1.0 · Last updated July 07, 2026
This Privacy Policy explains how Pulzera ("we", "us", "Pulzera") collects, uses, and shares personal data when you use our heartbeat monitoring service at pulzera.com and app.pulzera.com.
1. What data we collect and why
We collect only the data needed to provide the service:
- Account data: your email address, display name, password hash, and authentication factors (passkey credential IDs, TOTP secrets, recovery-code hashes).
- Billing data (paid plans): billing email, company name, VAT ID, address, country - all optional unless you subscribe. Payment card data is handled by Stripe and never reaches our servers.
- Service data: projects, checks, alert destinations, the delivery records of alerts we send (recipient, time, and outcome), and the pings your monitored jobs send to us. The request body, headers, and caller IP address are stored with a ping only if you enable capture for that check; caller IPs are always processed transiently for rate-limiting and abuse prevention, even when capture is off.
- Operational data: session identifiers, login timestamps, IP address and User-Agent on auth events for abuse detection.
If the ping payloads you choose to capture contain personal data of your own users, you are the data controller for that content and we process it on your behalf. Do not send special-category data (health, biometric, etc.) in ping payloads.
We process this data for the following purposes:
| Purpose | Why / when |
|---|---|
| Provide the service you signed up for | Whenever you use Pulzera - creating checks, receiving pings, viewing dashboards. |
| Send transactional emails (verification, password reset, alert notifications) | When you verify your address, reset a password, or a check triggers an alert. |
| Bill paid plans | Only if you subscribe to a paid plan, to charge and issue receipts. |
| Detect and prevent abuse (rate limits, anomaly detection) | Continuously, to keep the service available and secure for all users. |
| Comply with tax / accounting record-keeping | After a paid transaction, for the retention period local law requires. |
2. Cookies and local storage
We use only strictly necessary cookies - the kind required to sign you in and keep you signed in. We do not use cookies (or any other technology) for tracking, advertising, or analytics, and we embed no third-party trackers, analytics SDKs, or social pixels. Because all our cookies are strictly necessary, no cookie-consent banner is required.
| Name | Purpose | Lifetime |
|---|---|---|
pulzera_session | Keeps you signed in after login. Contains only an opaque random token - no personal data, no profiling. | Until sign-out; up to 30 days if you choose "Remember me", otherwise cleared 8 hours after login or when you close the browser. |
pulzera_oidc | Temporary security cookie used only during single sign-on (Google / Microsoft) to complete the login redirect safely. | 10 minutes; discarded as soon as sign-in finishes. |
pulzera_csrf | Protects our forms (such as the contact and unsubscribe pages) against cross-site request forgery. Contains no personal data. | Session; cleared when you close the browser. |
Both cookies are HttpOnly (unreadable by page scripts) and
sent only over HTTPS.
We also store some interface preferences in your browser's local storage, including those below. These are not cookies and are never sent to our servers - they stay on your device, hold no identifier, and identify no one.
| Stored value | What it remembers |
|---|---|
| Theme | Light / dark / system appearance choice |
| Sidebar | Collapsed or expanded |
| Selected project | Your last-viewed project |
| Alert rail | Mini or full view |
| Dashboard checklist | Expanded or collapsed |
| Events period | Your last-selected time-range filter |
Our contact form uses Cloudflare Turnstile to tell humans from bots. Turnstile is a privacy-preserving check that does not use tracking cookies or profile you for advertising; to run the check it processes limited technical signals (such as your IP address and browser characteristics). We use it to prevent spam and abuse, which does not require a consent banner. To run the check, Cloudflare may set its own strictly-necessary cookie on its domain; it is used only to complete the security challenge, not to track or profile you, and is governed by Cloudflare's privacy policy.
3. List of Data Sub-processors
Pulzera uses these third-party products to run the service:
- Cloudflare - edge network and security (content delivery, DDoS protection, HTTPS, and Turnstile bot protection).
- Hetzner - hosting.
- Stripe - card payments (paid plans only; card data never reaches our servers).
- Third-party alert destinations - deliver alerts you configure (Slack, Pushover, PagerDuty, Gotify, webhooks), only for the channels you set up.
We send our own transactional email (verification, password reset, and alert notifications) from our own mail service running on our hosting infrastructure, so no separate email provider is involved.
We never sell personal data, and we do not share it with advertisers.
4. International transfers
Some of our sub-processors are based in the United States (Cloudflare and Stripe). Where your personal data is transferred outside the European Economic Area, that transfer is protected by appropriate safeguards - the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. Our hosting (Hetzner) is located in the EU.
If you connect a third-party alert channel (such as Slack, PagerDuty, Pushover, Gotify, or a webhook), alert content may be transferred to wherever that service operates. Because you choose these destinations, that transfer is under your control.
5. How long we keep data
- Account data: kept until you delete your account, or (for free accounts) until we deactivate it after more than 12 months of inactivity (we will warn you first where we have a working email address). After deletion or deactivation, personal fields are anonymized within 30 days; business records required for tax/accounting are kept for 10 years per local law.
- Ping payloads: retained per check up to your plan's limits (a set number of recent pings, and in any case no longer than one year); see our pricing page for the limits that apply to you.
- Service data: projects, checks, alert destinations, and the delivery records of alerts we send are kept for as long as your account and the related checks exist, and are removed when you delete them.
- Operational logs (login attempts, IP addresses): kept for 30 days for security analysis.
6. Security
Passwords and per-check authentication tokens are hashed. Sessions use HTTP-only cookies. On plans that support it, captured ping headers and body payloads can be encrypted at rest with AES-256-GCM with a user-provided key/password. The application uses HTTPS.
7. Changes to this policy
We may update this policy at any time without individual notice. The current version is always available at this page, with the "Last updated" date at the top. Please review it periodically; we may, at our discretion, additionally announce material changes by email or in-app notice.
8. Contact
Privacy questions: reach us through our contact form.
See also: Terms of Service.