Privacy Policy
Last updated: 12 August 2026 · Version: privacy-2026-08-12
Version: privacy-2026-08-12 · Effective: 12 August 2026
This is an English rendering of the binding German original published at https://pulsque.com/datenschutz. It is intended to be substantively equivalent. In case of discrepancy, the German version governs.
1. Controller
The controller for personal data processed in the PulsQue app and on pulsque.com is:
Benjamin Dudli, sole proprietorship Adresse auf Anfrage (address on request) Switzerland Email: info@pulsque.com
Full postal address on request: we provide the controller's full postal address on request. An email to info@pulsque.com is sufficient; we reply without undue delay.
For any data protection matter, including exercising your rights, an email to info@pulsque.com is sufficient.
2. Scope and applicable law
PulsQue is operated by a provider established in Switzerland and is also directed at users in the European Economic Area. We therefore apply both the revised Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR). Where the two regimes impose different requirements, we apply the stricter one.
3. Data we process
Account and master data: email address, password hash managed by the authentication service, internal user ID, display name, registration and email confirmation timestamps, language setting, app version.
Health-related data (special categories): sex, date of birth, height, weight and body measurements, activity level and goal; training sessions, exercises, sets, repetitions, loads and notes; nutrition entries, calories, macronutrients, water intake, recipes, nutrition plans and shopping lists; sleep data; steps and active calories; heart rate, resting heart rate and heart rate variability; blood pressure readings; cycle data including bleeding, symptoms, mood and energy; injuries, complaints, medication and health-related notes; supplements and intake records; body photos with date and pose; the content of your conversations with the AI coach.
Optional community data (Base): public profile, posts, comments, reactions, squad memberships, direct messages and media you upload there. Community use is voluntary and separate from the rest of the feature set.
Technical data: push token, device language, operating system version, app and runtime version, and server-side access and rate-limiting counters.
4. Purposes and legal bases
Account, sign-in and provision of the app — performance of the user contract, Art. 6(1)(b) GDPR.
Processing of your health data (training, nutrition and calories, weight and body measurements, sleep, steps, vital signs, blood pressure, cycle, injuries, supplements, body photos, coach history) and the import from Apple Health or Android Health Connect — solely on the basis of your explicit consent under Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR and Art. 6(6) and (7) FADP. Without that consent no health data processing takes place. Importing from Apple Health or Health Connect additionally requires your explicit authorisation at operating system level; we read only the categories you release and send no data back to Apple or Google. You can find the full consent text at https://pulsque.com/health-einwilligung.
AI coach and AI-assisted analyses — on the basis of your consent under Art. 9(2)(a) GDPR insofar as health data is involved. See section 7.
Photo and voice recognition for meals, recipes and shopping lists — performance of the user contract, Art. 6(1)(b) GDPR, and, where the content is health-related, on the basis of your consent under Art. 9(2)(a) GDPR.
Community features (Base) — performance of the user contract, Art. 6(1)(b) GDPR. Content that you publish yourself and that permits inferences about your health is manifestly made public by you within the meaning of Art. 9(2)(e) GDPR.
Push notifications — on the basis of your consent, Art. 6(1)(a) GDPR, given through your device's system prompt. You can withdraw it at any time in the operating system or in the app settings.
Security, abuse prevention and rate limiting — on the basis of our legitimate interest in stable and abuse-free operation, Art. 6(1)(f) GDPR.
Compliance with legal obligations, in particular for access and erasure requests — Art. 6(1)(c) GDPR.
5. Waiting list on pulsque.com
On this website you can join the waiting list with your email address to be informed about the app launch and the launch of the Base community. This processing is independent of using the app — you do not need an account for it.
Purpose and legal basis
The sole purpose is notification about the launch of the app and the Base community. The legal basis is your consent under Art. 6(1)(a) GDPR (in Switzerland: Art. 31(1) FADP). We use the address for nothing else, do not pass it on and do not sell it.
Confirmation procedure (double opt-in)
After submitting the form you receive an email with a confirmation link. Only once you click that link is the sign-up considered given and you are added to the mailing list. Without confirmation we send you no further messages. This rules out anyone entering your address without your involvement.
What data arises
- Email address — the item in question.
- Time of sign-up and of confirmation as well as the text version of the consent — we must be able to demonstrate the consent (Art. 7(1) GDPR).
- User agent of your browser — part of the same record.
- Origin of the sign-up — a technical marker for which form you signed up through and, if you state it, your preferred platform (Android or iOS).
- Country, browser language and time zone — the country as a two-letter country code (such as "DE" or "US") as derived from the connection by our operator Cloudflare, plus the language setting and time zone of your browser. We store no IP address and no more precise location. The sole purpose is the question of which countries and languages it is worth offering PulsQue in. The legal basis is our legitimate interest in sensible product planning, Art. 6(1)(f) GDPR.
- How you heard about us — only if you answer the voluntary question after confirmation. It is a choice from a few options (search, social media, recommendation, blog, podcast, other), not free text, and you may simply skip it.
- Pseudonyms of your IP address and your email address — we store neither the IP in clear text nor the address a second time, but in each case only a value formed with a secret key that cannot be reversed. They serve solely to limit bulk sign-ups and are deleted after 72 hours at the latest.
Recipients
- Supabase Inc. — storage of the entry. Database and storage region Zurich (Switzerland); details and the legal basis of the transfer in sections 8 and 9.
- Sendinblue SAS (Brevo), Paris — dispatch of the confirmation and waiting-list emails, EU servers.
- Cloudflare, Inc. — delivery of the website as well as the spam protection "Turnstile" on the form. For this Turnstile processes IP address and technical browser characteristics; it sets no advertising cookies and creates no user profile.
Retention
An unconfirmed entry captured through this form is deleted automatically after 30 days. A confirmed entry remains stored until you unsubscribe; at the latest twelve months after the app launch we review the records and delete what is no longer needed. If you unsubscribe we keep the address as a suppression record so that it is not contacted again by mistake; on request we delete that record as well.
Withdrawal
You may withdraw your consent at any time with effect for the future (Art. 7(3) GDPR) — via the unsubscribe link at the end of every email, via the page https://pulsque.com/abmelden or informally to info@pulsque.com. The lawfulness of processing carried out until then remains unaffected.
6. Payments and subscriptions
PulsQue is currently provided without a paid subscription. We process no payment, card or invoicing data. Once a paid offering is introduced, it will be handled through the Apple App Store or Google Play; we will receive only the subscription status from there, never full payment data. This policy will be amended and republished before any such introduction.
7. AI processing
Some app features use large language and vision models, routed to the respective model provider through the service OpenRouter Inc. (USA). This applies in particular to meal recognition from photos, voice and text capture of meals and shopping lists, recipe and training plan import, and the daily impulse. For recipe import from videos and for semantic food search we additionally use application programming interfaces of Google LLC (USA); community image moderation runs through Google Cloud Vision, and image generation for community posts through fal.ai.
Some AI features also process health data. This concerns the AI coach, the analyses of your nutrition and training data, meal recognition, the voice capture of meals, and the generation of recipe and exercise content. In doing so we transmit only the values the respective feature needs, and no master data such as name, email address or postal address. Depending on the feature, what is transmitted comprises nutrition and training values, body measurements, goals and the entries you write in the coach yourself.
The recipient is OpenRouter Inc., United States, which forwards the request to the respective model provider; for individual features we additionally use Google LLC, United States. Both transfers are based on standard contractual clauses under Art. 46(2)(c) GDPR. The requests are transmitted for the duration of the processing and are not stored by us at the provider; we store the result in your account until you delete it or your account.
You control which data categories the AI coach may use in the settings under Privacy. Your selection is enforced server-side and can only be set more narrowly by the app, never more broadly. If you withdraw your consent to health data processing, the health-related AI features cease to be available.
There is no automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you. All AI output consists of non-binding suggestions.
8. Recipients and processors
- Supabase Pte. Ltd (Singapore; database and storage region Zurich, Switzerland) — authentication, database, file storage, server-side functions.
- Cloudflare Inc. (USA) — content delivery network and attack protection as well as the spam protection "Turnstile" on the waiting-list form (processes IP address and technical browser characteristics, sets no advertising cookies and creates no user profile).
- Google LLC (USA) — optional sign-in with a Google account, AI interfaces for video import, semantic search and image moderation.
- OpenRouter Inc. (USA) — routing of AI requests to model providers.
- Features and Labels Inc. (fal.ai) (USA) — image generation for community posts.
- Expo, Inc. (USA) — delivery of app updates and dispatch of push messages via the Expo push service.
- Brevo SAS (France) — dispatch of system and newsletter emails.
- Hostinger International Ltd. (Kaunas, Lithuania; EU servers) — hosting of this website pulsque.com.
- Anthropic, Inc. (PBC) (San Francisco, USA) — AI inference for internal marketing workflows. No requests from the app are transmitted to Anthropic; only marketing content curated by the provider. Third-country transfer to the USA on the basis of standard contractual clauses.
- Telegram FZ-LLC (United Arab Emirates) — only if you actively link the optional Telegram coach.
- Open Food Facts (France) — public product database; no personal data is transmitted, only product or barcode queries.
- Apple Inc. and Google LLC — as the source of your health data on the device and as operators of the app stores.
A crash and error reporting service (Sentry) is contained in the app code but is fully disabled. No crash or telemetry data is transmitted to that service.
9. Transfers to third countries
Your database and file content is stored primarily in Switzerland (Zurich region). Transfers to recipients in the USA are based on the European Commission's Standard Contractual Clauses together with the Swiss addendum, and on the data processing agreements concluded with those providers. Linking Telegram is voluntary; the United Arab Emirates are not covered by an adequacy decision, which is why that transfer rests solely on your explicit consent given by actively creating the link.
10. Retention
- Account, health, training, nutrition and community data: until you delete it or until your account is deleted. You can delete individual entries yourself at any time.
- Body photos: by default encrypted on your device only; additionally in our storage only if you explicitly share them with a coach, until you delete them.
- Images from meal recognition: for analysis only, less than ten minutes.
- Coach history: until your account is deleted.
- Rate-limit and AI quota counters: aggregated usage rows three days, completed reservations at least 35 days and, depending on the evaluation window, up to 95 days; general call counters 35 days.
- Non-account counters based on synthetic IP characteristics: 48 hours.
- Telegram link: until unlinking, then immediate deletion; link tokens ten minutes; the bot's processing markers seven days.
- Waiting-list sign-ups: unconfirmed 30 days, confirmed until withdrawal — details in section 5.
- Records of access and erasure requests: twelve months, solely to demonstrate compliance to the supervisory authority.
- Records of consent given and withdrawn: for as long as required to meet the accountability obligation. These records contain no health values, only version, language, app version and timestamp.
If you delete your account, all records linked to your user ID are removed through a cascading deletion.
11. What we no longer process
Earlier versions of the app contained an analysis of raw genetic data and a capture of laboratory findings and blood values. Both features have been removed from the app. We no longer process genetic data or laboratory findings. Existing holdings from the test phase are being deleted; reintroducing these features would require separate, freshly obtained consent and a new version of this policy. Blood pressure readings that you enter yourself are unaffected and remain part of the app.
12. Your rights
You have the right of access, rectification, erasure, restriction of processing and data portability, and the right to object to processing based on legitimate interests (Art. 15 to 21 GDPR, Art. 25 et seq. FADP).
Withdrawal of consent: you can withdraw your consent to the processing of health data at any time with effect for the future — in the app under Settings, Privacy. Withdrawal triggers the deletion of the operational health data collected. Legally required, access-restricted records of the consent itself may be retained. The lawfulness of processing carried out before withdrawal is unaffected.
You can trigger access, export and deletion of your account directly in the app under Settings, Privacy; these remain available even if you do not confirm the legal notices or the health data consent. Alternatively an email to info@pulsque.com is sufficient.
Right to lodge a complaint: in Switzerland you may contact the Federal Data Protection and Information Commissioner (FDPIC). In the European Economic Area you may lodge a complaint with the supervisory authority of your habitual residence, place of work or the place of the alleged infringement.
13. Minimum age
PulsQue is directed at persons aged 16 and over. We do not knowingly process data of children under 16. If we become aware of such an account, we delete it.
14. Security
We secure the connection with TLS throughout and encrypt data at rest. Access to records is restricted at database level on a per-row basis to the respective account. Body photos are additionally encrypted symmetrically on the device. Server-side functions with elevated privileges are limited to clearly defined tasks and are logged.
15. Changes to this policy
If the scope of processing changes, we publish a new version with a new version code. If the change concerns your health data, we obtain your consent again. The version in force at any given time is available at https://pulsque.com/datenschutz.