Last updated: 2026-07-27
1. Identity and scope
This Privacy Policy describes how the PulseIQ product ("PulseIQ", "we", "us") handles information when you use the PulseIQ web application and related APIs.
PulseIQ is operated by Richard Robinson, operating Pulse IQ as an individual operating the product. These pages do not assert a separate registered business entity form.
2. Information you supply
Depending on how you use PulseIQ, you may provide:
- Account information such as email address and display name
- Organization, workspace, and Project information
- Creative Spec, scripts, storyboards, and related metadata
- Uploaded or selected media used in preparation and assembly
- Publishing package metadata you enter (titles, captions, privacy choices)
3. Application and infrastructure data
PulseIQ also processes:
- Authentication and session data needed to keep you signed in
- Workspace and tenant identifiers used for isolation
- Job, Progress, pipeline, and audit-lineage records
- Security, diagnostic, and operational logs
- Usage and budget telemetry where those features are enabled
4. Google and YouTube data
PulseIQ does not currently hold Google or YouTube user data for Publishing while provider connections remain zero and OAuth credentials are not configured. Google user data is accessed only after you connect an account through Google OAuth in an approved later phase.
After you complete OAuth, PulseIQ may process, according to the scopes you grant and features you use:
- Authorized channel identity and destination metadata
- Access and refresh tokens (encrypted server-side)
- Granted OAuth scopes
- Upload and processing status, video identifiers, and publication status
- Metadata you explicitly choose to publish
5. How Google user data will be used
When Google connection is enabled, use is limited to user-requested features:
- Connecting the selected channel
- Identifying the publishing destination
- Uploading a user-approved video
- Checking upload and processing status
- Displaying publication history
- Refreshing authorization when permitted
- Disconnecting and supporting revocation
PulseIQ's use of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.
6. Storage and security
- Provider tokens are designed to be stored only after OAuth is enabled, using authenticated encryption (AES-256-GCM) with a server-only vault key and key versioning—not in plaintext database columns.
- Provider API calls are intended to run server-side.
- Tenant isolation scopes access by organization and workspace membership.
- Media is stored privately; signed URLs are ephemeral, not permanent columns.
No system is perfectly secure. We take reasonable measures and continuously improve controls; we do not guarantee absolute security.
7. Sharing and subprocessors
PulseIQ uses infrastructure and service categories such as:
- Cloud application hosting
- Managed databases
- Private object storage for media
- AI-generation providers when those features are used
- Connected publishing platforms after you authorize them
We do not sell your personal information. A formal public subprocessor schedule may be published later; current infrastructure includes providers such as Vercel, Neon, and Vercel Blob, and may include other configured services.
8. Retention
- Provider credentials: intended to be removed or revoked on disconnect according to implemented disconnect flows once OAuth is enabled.
- Publishing history and Progress: may be retained for workspace history while the Project exists.
- Immutable audit / lineage / security records: may remain for integrity and accountability even when editable content or credentials change. Not every record can be deleted.
- User-created content: retained while your account and Projects exist, subject to deletion requests and product capabilities.
9. User controls
See Data Controls for disconnect, Google Account third-party access removal, deletion requests, and schedule handling. You can also manage Google Account permissions at myaccount.google.com/permissions.
10. Limited Use
PulseIQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
11. Children
PulseIQ accounts and the service are intended for people age 18 or older. If you are under 18, do not create an account or use PulseIQ.
12. Changes and contact
We may update this policy as the product changes. Material changes will be reflected by updating this page and the last-updated date; additional notice methods may be added later.
Questions about this policy: support@pulse-iq.cc. This address is a public support contact (email routing), not a claim of a traditional hosted mailbox product.