Privacy Policy
How PulseStats handles account, research, billing, contact, cookie, and provider information.
This policy distinguishes necessary product storage, optional consented analytics and Session Replay, and inactive marketing tracking.
Introduction
PulseStats is operated by the operator of PulseStats. This Privacy Policy explains how PulseStats handles information for the current crypto research and backtesting product.
Effective date: July 15, 2026. Last updated: July 21, 2026.
Information Collected Directly
PulseStats collects information you provide directly or create while using the product.
- Email address and authentication/account identifiers.
- Requested account-service events such as password reset requests.
- Contact-form submissions and related message content.
- User-created strategies, configured research rules, setup alerts, saved research, backtest results, and optimizer results.
- Billing and subscription status when Stripe billing is configured.
- Usage-limit and application activity records needed to operate the service.
Information Collected Automatically
Some information is collected automatically by the application and infrastructure providers as part of operating the service.
- Authentication and session data required to keep you signed in.
- Infrastructure data such as IP address, device, browser, request logs, and security logs handled by hosting and platform providers.
- Necessary cookies and storage used for authentication, sessions, security, analytics consent preferences, and essential guest workflows.
- Optional GA4 and PostHog product analytics are collected only after Product Analytics consent is granted. Session Replay additionally requires its separate optional preference.
- When analytics is enabled and permitted, PulseStats uses pseudonymous pg_v1 and pa_v1 identifiers rather than sending raw Supabase account UUIDs to analytics providers. Pseudonymous data is not the same as anonymous data.
- PulseStats limits analytics properties to approved research-workflow context, opaque analytics/session identifiers, coarse device type, and approximate country/city reporting. Geographic reporting is approximate. Client payloads exclude full URLs, query strings, fragments, referrers, raw user-agent, detailed browser/OS versions, screen dimensions, raw IP properties, and fine geographic fields.
- Google Tag Manager, Google Ads, Meta Pixel, and other marketing trackers are not currently used.
- When separately permitted and configured, Session Replay is limited to approved product routes and masks inputs and private or user-entered text. Auth, Billing, Admin, legal, Contact, Blog, API, and other non-allowlisted routes are not intentionally replayed.
Purposes Of Processing
- Create and authenticate accounts.
- Send requested transactional account-service emails such as password reset links.
- Provide the research workspace, scanner, strategies, backtests, optimizer, saved research, setup alerts, and shareable research links.
- Enforce usage limits and protect product availability.
- Administer billing and subscriptions when billing is configured.
- Respond to support, privacy, legal, and billing requests.
- Maintain security, diagnose service issues, and prevent abuse.
- Run product analytics or marketing attribution only when those systems are enabled and permitted.
Service Providers
PulseStats uses service providers to operate the application. Provider use depends on the feature and whether that provider is configured.
- Supabase: Authentication and database. Used for account authentication, session handling, and application database storage.
- Vercel: Hosting and deployment. Used to host and deliver the PulseStats web application.
- Stripe: Billing. Used for checkout, payment processing, subscription administration, and billing portal flows.
- Email provider: Contact delivery. Email delivery provider selection and production delivery remain pending.
- PostHog: Product analytics. Optional product analytics and separately consented, masked, route-limited Session Replay, enabled only after a user grants the relevant preferences.
- Google Analytics 4: Product and acquisition analytics. Optional product, landing, and normalized campaign measurement, enabled only after a user grants Product Analytics preferences.
- Future marketing providers: Marketing tracking. Google Tag Manager, Google Ads, Meta Pixel, and other marketing trackers are not currently used.
Cookies And Local Storage
- Necessary storage includes authentication, session, security, and the versioned first-party cookie that remembers your privacy preference. The preference cookie contains no user or analytics identity.
- Optional analytics storage may be used only after Product Analytics consent is granted. Session Replay also requires its separate preference.
- Marketing trackers are not currently used and Marketing consent cannot be granted in the current preferences.
- Cookie preferences are available globally. Withdrawing Product Analytics stops future provider delivery and clears analytics browser storage where technically supported. It does not automatically erase data already accepted by a provider.
Data Retention
PulseStats retains information only as reasonably necessary for the purposes described in this policy. The planned operational targets are approximately 24 months for privacy-safe daily aggregates, approximately 14 months for provider event analytics, and approximately 30 days for Session Replay. Provider-side retention settings must be configured to match these targets and may affect actual provider-held retention.
Legal, accounting, fraud-prevention, dispute-resolution, and security needs may require longer retention. Historical provider data is not automatically erased when browser consent is withdrawn.
Data Security
PulseStats uses reasonable administrative, technical, and organizational measures intended to protect information. No system is completely secure, and PulseStats cannot guarantee absolute protection.
User Rights And Choices
Self-service account deletion is not currently implemented. Data deletion requests are support-assisted. The current account consent preference is deleted with the account, no consent-history table is maintained, and the browser preference can be replaced through Cookie preferences. Provider and aggregate deletion follow separate privacy processes.
PulseStats does not intentionally send raw payment information, raw strategy names, alert content, internal record identifiers, or user-entered private text to analytics providers.
Analytics does not change PulseStats's research-only nature and is not used to execute orders or provide investment recommendations.
- Request access, correction, or deletion support through Contact Us.
- Withdraw consent where consent-based processing is available.
- Update or withdraw optional Product Analytics and Session Replay preferences through Cookie preferences.
- Use Contact Us for privacy, data deletion, legal, and billing questions.
International Processing
PulseStats providers may process information outside your province, state, or country. Different privacy and government-access laws may apply in those locations.
Children
PulseStats is not designed for children. A specific age threshold has not been configured in the product policy yet.
Changes
PulseStats may update this policy from time to time. Material updates may be communicated through the site, product, or email where appropriate.
Contact
You can contact PulseStats through /contact. No separate legal contact email is currently displayed.
Contact Us
Use the Contact page for privacy requests, data deletion requests, legal questions, billing questions, or product support.
Contact Us