Skip to content

Privacy · By Architecture

Health data that stays yours.

Pulsyn’s AI runs on your phone. By default, your biometrics never reach our servers because we never built them to receive any. Data only leaves your device if you turn on cloud backup, export it yourself, or plug in a third-party app.

  • On-Device AI
  • AES-256
  • Zero Data Training
Classification // Personal Data Policy Document Ref: PRV-001

Your data leaves your body for nothing.

We built Pulsyn so you never have to trust us.

Every health insight stays on your device.

Privacy is architecture, not policy.

Where Your Data Lives

Three places. One of them is optional.

Rune 1

Sensor data

Heart rate, motion, temperature. Captured on your finger.

Bluetooth LE

Your phone

On-device AI

Insights are computed here. Storage is encrypted with a key only you hold.

Optional · Encrypted

Optional cloud

Off by default

Turn on backups if you want to. We hold ciphertext, not the key.

Your phone does the AI work and stores the results locally. If you turn on backups, your phone encrypts everything before it leaves, so the cloud only ever sees scrambled bytes.

Four Commitments

The rules we hold ourselves to.

  • 01

    On-device AI

    The model that reads your biometrics runs on your phone, not on a server we control. Inference happens locally by default. Pro users who opt into cloud AI get zero-retention processing — queries answered and immediately discarded, never stored or used for training.

  • 02

    Zero knowledge

    If you turn on cloud sync, your phone encrypts your data before it leaves. We store ciphertext we cannot read. The key stays on your device, with you.

  • 03

    No data training

    Your biometrics are not used to train AI models. Not ours. Not a third party. Not in aggregate. Your readings are yours.

  • 04

    Data portability

    Export everything in standard formats whenever you want. Delete your account and the data is gone within 30 days, not buried in a backup.

Hard limits

What we will never do

Promises are easy. These are the lines we have built the product to make impossible to cross.

  • We will not sell your data. Not anonymized, not aggregated, not at all.

  • We will not train AI models on your biometrics, ever.

  • We will not read your encrypted backups. The keys live on your phone.

  • We will not run advertising trackers, fingerprinting, or third-party pixels.

  • We will not disclose your data to insurers, employers, or governments unless legally required. We will challenge overbroad requests where we can.

  • We will not lock you in. Export everything, anytime, in plain JSON.

Under the hood

The cryptography behind it

Standard primitives. Audited libraries. No homegrown cryptography. Here is what is doing the work.

AES-256-GCM

Every health record is encrypted on your device before it touches storage or the network.

SQLCipher

The local database file is encrypted at rest. A stolen phone reveals nothing without your passcode.

Argon2id

Your passphrase is stretched with a memory-hard function, which makes brute-force attacks impractical.

TLS 1.3

When data does move, it moves over modern transport encryption with forward secrecy.

Read the policy in full, or see the ring it was written for.