Rune 1
Sensor data
Heart rate, motion, temperature. Captured on your finger.
Privacy · By Architecture
Pulsyn’s AI runs on your phone. By default, your biometrics never reach our servers because we never built them to receive any. Data only leaves your device if you turn on cloud backup, export it yourself, or plug in a third-party app.

We built Pulsyn so you never have to trust us.
Every health insight stays on your device.
Privacy is architecture, not policy.
Where Your Data Lives
Sensor data
Heart rate, motion, temperature. Captured on your finger.
On-device AI
Insights are computed here. Storage is encrypted with a key only you hold.
Off by default
Turn on backups if you want to. We hold ciphertext, not the key.
Your phone does the AI work and stores the results locally. If you turn on backups, your phone encrypts everything before it leaves, so the cloud only ever sees scrambled bytes.
Four Commitments
01
The model that reads your biometrics runs on your phone, not on a server we control. Inference happens locally by default. Pro users who opt into cloud AI get zero-retention processing — queries answered and immediately discarded, never stored or used for training.
02
If you turn on cloud sync, your phone encrypts your data before it leaves. We store ciphertext we cannot read. The key stays on your device, with you.
03
Your biometrics are not used to train AI models. Not ours. Not a third party. Not in aggregate. Your readings are yours.
04
Export everything in standard formats whenever you want. Delete your account and the data is gone within 30 days, not buried in a backup.
Hard limits
Promises are easy. These are the lines we have built the product to make impossible to cross.
We will not sell your data. Not anonymized, not aggregated, not at all.
We will not train AI models on your biometrics, ever.
We will not read your encrypted backups. The keys live on your phone.
We will not run advertising trackers, fingerprinting, or third-party pixels.
We will not disclose your data to insurers, employers, or governments unless legally required. We will challenge overbroad requests where we can.
We will not lock you in. Export everything, anytime, in plain JSON.
Under the hood
Standard primitives. Audited libraries. No homegrown cryptography. Here is what is doing the work.
Every health record is encrypted on your device before it touches storage or the network.
The local database file is encrypted at rest. A stolen phone reveals nothing without your passcode.
Your passphrase is stretched with a memory-hard function, which makes brute-force attacks impractical.
When data does move, it moves over modern transport encryption with forward secrecy.
