Privacy Policy

Version 1.0 · Last updated July 07, 2026

This Privacy Policy explains how Pulzera ("we", "us", "Pulzera") collects, uses, and shares personal data when you use our heartbeat monitoring service at pulzera.com and app.pulzera.com.

1. What data we collect and why

We collect only the data needed to provide the service:

If the ping payloads you choose to capture contain personal data of your own users, you are the data controller for that content and we process it on your behalf. Do not send special-category data (health, biometric, etc.) in ping payloads.

We process this data for the following purposes:

PurposeWhy / when
Provide the service you signed up forWhenever you use Pulzera - creating checks, receiving pings, viewing dashboards.
Send transactional emails (verification, password reset, alert notifications)When you verify your address, reset a password, or a check triggers an alert.
Bill paid plansOnly if you subscribe to a paid plan, to charge and issue receipts.
Detect and prevent abuse (rate limits, anomaly detection)Continuously, to keep the service available and secure for all users.
Comply with tax / accounting record-keepingAfter a paid transaction, for the retention period local law requires.

2. Cookies and local storage

We use only strictly necessary cookies - the kind required to sign you in and keep you signed in. We do not use cookies (or any other technology) for tracking, advertising, or analytics, and we embed no third-party trackers, analytics SDKs, or social pixels. Because all our cookies are strictly necessary, no cookie-consent banner is required.

NamePurposeLifetime
pulzera_sessionKeeps you signed in after login. Contains only an opaque random token - no personal data, no profiling.Until sign-out; up to 30 days if you choose "Remember me", otherwise cleared 8 hours after login or when you close the browser.
pulzera_oidcTemporary security cookie used only during single sign-on (Google / Microsoft) to complete the login redirect safely.10 minutes; discarded as soon as sign-in finishes.
pulzera_csrfProtects our forms (such as the contact and unsubscribe pages) against cross-site request forgery. Contains no personal data.Session; cleared when you close the browser.

Both cookies are HttpOnly (unreadable by page scripts) and sent only over HTTPS.

We also store some interface preferences in your browser's local storage, including those below. These are not cookies and are never sent to our servers - they stay on your device, hold no identifier, and identify no one.

Stored valueWhat it remembers
ThemeLight / dark / system appearance choice
SidebarCollapsed or expanded
Selected projectYour last-viewed project
Alert railMini or full view
Dashboard checklistExpanded or collapsed
Events periodYour last-selected time-range filter

Our contact form uses Cloudflare Turnstile to tell humans from bots. Turnstile is a privacy-preserving check that does not use tracking cookies or profile you for advertising; to run the check it processes limited technical signals (such as your IP address and browser characteristics). We use it to prevent spam and abuse, which does not require a consent banner. To run the check, Cloudflare may set its own strictly-necessary cookie on its domain; it is used only to complete the security challenge, not to track or profile you, and is governed by Cloudflare's privacy policy.

3. List of Data Sub-processors

Pulzera uses these third-party products to run the service:

We send our own transactional email (verification, password reset, and alert notifications) from our own mail service running on our hosting infrastructure, so no separate email provider is involved.

We never sell personal data, and we do not share it with advertisers.

4. International transfers

Some of our sub-processors are based in the United States (Cloudflare and Stripe). Where your personal data is transferred outside the European Economic Area, that transfer is protected by appropriate safeguards - the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. Our hosting (Hetzner) is located in the EU.

If you connect a third-party alert channel (such as Slack, PagerDuty, Pushover, Gotify, or a webhook), alert content may be transferred to wherever that service operates. Because you choose these destinations, that transfer is under your control.

5. How long we keep data

6. Security

Passwords and per-check authentication tokens are hashed. Sessions use HTTP-only cookies. On plans that support it, captured ping headers and body payloads can be encrypted at rest with AES-256-GCM with a user-provided key/password. The application uses HTTPS.

7. Changes to this policy

We may update this policy at any time without individual notice. The current version is always available at this page, with the "Last updated" date at the top. Please review it periodically; we may, at our discretion, additionally announce material changes by email or in-app notice.

8. Contact

Privacy questions: reach us through our contact form.


See also: Terms of Service.