Privacy Policy
Last updated · October 5, 2026
Pulse is a desktop app for developers and small teams, with its own cloud that holds what a team shares. This document says exactly what stays on your computer, what goes to our servers, who can read it, how long it is kept and how to delete it.
01The short version
- What belongs to a team lives in the Pulse cloud, on AWS in Frankfurt (EU): teams, pull requests and cards mirrored from GitHub and Trello, the search's knowledge base and the audit trail. It is not end-to-end encrypted: the server reads that content to deliver the features.
- What is only yours stays on your computer, in an encrypted database whose keys sit in the system keychain, behind a PIN.
- AI runs on your own account (Claude or Codex, by subscription or API key), straight from your computer to the provider. Pulse never receives your key or your subscription login.
- From your AI usage, only numbers reach Pulse — tokens, duration, model, agent, equivalent cost — for internal analysis and product improvement. Never what you asked, the code or the answer.
- We do not sell, rent or share your data with anyone beyond what is described here. No ads, no advertising profile.
- You delete your account in the app itself, and what is yours goes with it.
This summary is here to be read, not to replace the sections below. Where the two differ, the detailed sections apply.
02Who is responsible
Pulse (the app, identifier tech.mussi.pulse.v2), its cloud (cloud.pulse.mussi.tech) and this site (pulse.mussi.tech) are run by Marcelo Mussi, an independent developer trading as mussi.tech, in Brazil. Under the LGPD this is the controlador; under the GDPR, the data controller.
When a team uses Pulse to handle data about clients or colleagues, whoever administers the team decides what to connect and what comes in; for that data we act as processor, following what the team configures.
For any privacy question, request or complaint, write to marcelo@mussi.tech.
03What we handle, in one table
| Data | Where it lives and why |
|---|---|
| Account: e-mail, password (hash only), display name, photo | In the cloud. So you can sign in and teammates can see who is who. The photo is only visible to people who share a team with you. |
| Teams: name, members, roles, invitations | In the cloud. An invitation keeps the invited e-mail and a hash of the code; it is valid for 7 days. |
| Mirrored work: pull requests, reviews, conversations, cards, comments | In the cloud, from the GitHub and Trello the team connected. To show the team's work in one place and let the agents work on it. |
| Knowledge base: excerpts of PR, card and comment text | In the cloud, with a numeric vector for each excerpt. For the one search. Details in Knowledge base. |
| Search history: what you searched in ⌘K and what you opened from the results | In the cloud, on your account, to redo a search on any computer. Only you read it — not the team owner, not Pulse. You turn it off or delete it all in Settings › Account › Privacy and terms. |
| AI usage: numbers about each call your account made | In the cloud, for internal analysis. Details in AI usage and what goes to Pulse. |
| Team audit trail: who did what and when | In the cloud, hash-chained and never edited. It never holds a token, a diff or a comment. |
| App version and platform | In the cloud, to know which version each person runs and roll features out safely. |
| What is only yours: your AI account credentials, local keys, PIN, local cache | Only on your computer. Details in What stays on your computer. |
We use no analytics tools, trackers, third-party crash reporting or telemetry beyond what this table lists.
04What stays on your computer
The app keeps what is only yours in a SQLCipher database (SQLite encrypted with AES-256) in your user folder. Its two 256-bit keys are generated on your computer and live in the system keychain (Keychain on macOS, Secret Service on Linux), never in a file.
Only in the keychain: the API keys and subscription logins of your AI accounts, your Pulse session's refresh token and, if the team runs its own GitHub App on the computer, that App's private key. The app opens with a 6-digit PIN (stored as an Argon2id hash), locks itself after 5 minutes by default and accepts Touch ID on macOS — we do not collect fingerprints.
When you set the PIN you get a recovery key (RK1-…), shown once. There is no universal support key: losing the computer, the keychain and that key together can make local data unrecoverable — for you and for us.
05What lives in the Pulse cloud
The Pulse cloud runs on a machine of ours on AWS in Frankfurt (eu-central-1), with a Postgres database and files in S3, all encrypted at rest (EBS and S3 with KMS keys). Every row is separated by team or by person in the database itself: you only read what belongs to your teams and to you.
It is not end-to-end encrypted. The server reads the team's content to mirror it, search it and hand it to the agents. That is why this policy says exactly who reads what.
The GitHub and Trello tokens you or your team connect are kept encrypted in the database vault (Supabase Vault). Server keys live in AWS Secrets Manager. Nobody reaches the machine over public SSH; administrative access goes through AWS Systems Manager and is logged.
06GitHub and Trello
Every integration is optional and starts with a click of yours, on the provider's own screen, which shows the permissions before you accept.
| Connection | What Pulse does with it |
|---|---|
| Team GitHub (the Pulse GitHub App, installed by the team) | Reads the pull requests, reviews, conversations and CI status of the repositories the team picks, and receives their events. Posts a review, comment, approval or merge only when someone on the team says so, or when the team turns on an automation that says so. |
| Personal GitHub (sign-in with your account) | Used only when you click to act with your own account — approving a PR as yourself, for instance. Never by automation. |
| Team Trello and personal Trello | Mirrors boards, lists, cards (name, description, checklist, labels, members, attachment names) and comments. Cards in finished lists only from the last 180 days. |
Data from these services also follows their own policies. Disconnecting in Pulse stops the sync; to revoke for good, remove the access on GitHub or Trello too.
07Knowledge base and search
For the one search, Pulse splits the text of pull requests (title, description, conversation and review decisions), cards and comments into excerpts and computes a vector for each on Amazon Bedrock, with the Cohere Embed v4 model, in a European AWS region. At search time, only the phrase you typed goes to Bedrock. Bedrock does not keep that text or use it to train models.
The index lives in our cloud, separated by team and person. An item leaves the index the moment it leaves the mirror — a removed PR, an archived card, an ignored list — and everything of a team goes if the team is deleted.
08AI on your account
Pulse's agents (code review, summary, Ask, Answer, list mapping) use your own AI account — Anthropic (Claude) or OpenAI (Codex) — by subscription or API key. Calls go from your computer straight to the provider; they do not pass through our servers.
What goes to the provider is what the agent needs for that task: a PR's diff, a card's text, search results. The provider handles it under the terms of your account with them. A PR's content is passed as delimited data, never as an instruction to the agent.
Some agent results come back to the team's cloud, because that is what they are for: a PR summary, a review posted on GitHub by the team's App.
We do not use your key or your subscription. They stay only on your computer; the agents run there, on your account, when you or your team ask. Pulse never receives the key or the login. AI output is a suggestion, not a fact: review it before acting.
09AI usage and Pulse's own cost
When each AI call made with your account finishes, the app sends Pulse only numbers and names of things: when it started, how long it took, whether it worked, provider, model, mode (subscription or key), which agent, tokens and the equivalent API cost, and the team you were in. Never what you asked, code, the AI's answer, a repository, PR or card name, or your key.
We use it to analyse and improve Pulse: shape the plans, measure cost and agent quality. Pulse's administrators see these numbers by team and by person, with the e-mail; your team does not see your individual usage. Internal use: we do not share or sell this data. The full detail is in AI usage and what goes to Pulse.
Separately, we record what Pulse pays — the search's vectors on Bedrock — by team and person, for plan limits and cost control.
10E-mails
Pulse sends e-mail from no-reply@pulse.mussi.tech, through Amazon SES in Frankfurt, only to: confirm sign-up, reset a password and invite someone to a team (with hourly and daily limits). We do not send marketing.
11Weather in the app
If you use the weather in the header, the app sends the device location or the city you chose, rounded to 2 decimal places (about 1 km), straight from your computer to Open-Meteo (forecast and city search) and BigDataCloud (place name). None of it passes through our servers. In Settings, you can pick the city by hand instead of the device location.
12On what basis we handle this data
Under the LGPD the legal bases are: performance of a contract (art. 7, V — account, teams, the integrations' mirror, search and service e-mails), consent (art. 7, I — each integration you connect and the weather, revocable at any time) and legitimate interest (art. 7, IX — security, the team audit trail and the internal analysis of AI usage to improve Pulse, with numbers only and without overriding your rights).
Where the GDPR applies, the corresponding bases are performance of a contract, consent and legitimate interests. You may object to the AI usage analysis by writing to us.
14How long things are kept
| Data | Kept for |
|---|---|
| Account, teams and mirrored work | While the account or team exists. Items that leave GitHub or Trello leave the mirror and the index. |
| Each AI call (usage) and each vector Pulse paid for | 90 days |
| Search history (searches and opened results) | 90 days, at most the 60 newest searches and 30 opened; gone sooner if you delete it |
| Daily usage sums | 12 months |
| Monthly usage sums (numbers only, by team and person) | No limit, while the account exists |
| Team audit trail | No limit; it stays even if a person leaves, so the team knows who did what |
| Server logs | 30 days |
| Trello events and invitation rate records | 7 and 2 days |
| Database backups | Up to 12 months, encrypted; what you delete leaves them within that time |
15How it is protected
- TLS on every call; TLS 1.2 minimum and HSTS on the Pulse cloud.
- Encryption at rest: disks and files with KMS keys, tokens in the database vault, a SQLCipher local database.
- Isolation by team and person in the database itself (RLS), checked by automated tests.
- Attempt limits on sign-in, sign-up and password recovery.
- Short-lived credentials for server services; no container reads the machine's credentials directly.
- A verified daily backup (restored and checked every night) and a recovery drill every month.
- A team audit trail chained by hash, which nobody edits.
No system is perfectly secure. If you believe you have found a vulnerability, tell us at marcelo@mussi.tech before disclosing it publicly.
16Your rights, and how to use them
Under the LGPD, the GDPR and equivalent laws, you may ask for access, correction, deletion, portability, restriction, objection and withdrawal of consent.
- Delete your account — in Settings › Account, in the app itself. What is yours goes: profile, photo, connected accounts, AI usage and the personal index. Teams where you are the only owner are deleted with everything in them. In team records that remain (who decided something, who invited), your link is removed; the audit trail keeps the name it recorded.
- Correct — name and photo in Settings; the rest, on request.
- Withdraw — disconnecting an integration stops its sync; picking the city by hand stops sending the device location.
- Access, portability and objection — on request.
For anything you cannot do yourself, write to marcelo@mussi.tech. We answer within 15 days. You may also complain to the ANPD in Brazil, or to the data protection authority of your country in the EU or the UK.
17International transfers
The operator is in Brazil; the data lives in the European Union (Frankfurt, with backup copies in Ireland). Cloudflare serves from the edge closest to you, and the AI providers you connect handle calls where they operate, under your account's terms. These transfers rely on TLS and on the suppliers' contractual safeguards, including Standard Contractual Clauses where applicable.
18Children and teenagers
Pulse is a professional tool for adults. It is not aimed at anyone under 18 and we do not knowingly collect their data. If you know of such a case, write to us and we will delete it.
19Changes to this policy
If this policy changes in a meaningful way — a new kind of data, a new purpose, a new supplier — the date at the top is updated and we tell you in the app before the change applies. Continuing to use Pulse after that means the updated policy applies.
Questions about this document
Write to marcelo@mussi.tech and the answer comes from the person who wrote both the document and the app.