Privacy Policy
Last updated: October 10, 2026
This policy explains how Pulse OS ("we", "us", "our") collects, uses, and protects your personal data when you use our platform at https://pulseosclick.com.
1. Information We Collect
We collect information you provide directly and information generated by your use of the platform:
- Account data: name, email address, username, and password (stored as a bcrypt hash — we never store your plaintext password)
- Workspace data: tasks, projects, goals, comments, files, and other content you create or upload
- Attendance & HR data: clock-in times, leave records, and attendance status entered by you or your workspace admin
- Usage data: pages visited, features used, timestamps of actions, and IP address (for security and rate-limiting). Feature use is kept as daily counts per person (for example "3 comments on 10 October"), never the content itself
- Payment data: billing name, email, and payment method details — processed by Stripe; we do not store card numbers on our servers
- Communications: any messages you send to our support team
2. How We Use Your Information
We use your data solely to provide and improve the Pulse OS service:
- Authenticating you and keeping your session secure
- Delivering the features of the platform (tasks, projects, reports, etc.)
- Sending transactional emails (password reset, billing receipts, notifications you opt in to)
- Processing payments and managing your subscription
- Diagnosing errors and improving performance
- Understanding which features are used, so we can improve them and offer help to workspaces that get stuck
- Complying with legal obligations
We do not sell your personal data. We do not use your data to serve third-party advertising.
3. Data Sharing
We share data only with:
- Stripe — payment processing (their privacy policy: stripe.com/privacy)
- Hosting provider — Hostinger, for server infrastructure
- Email provider — SMTP service used to send transactional emails
- Law enforcement — only when required by a valid legal order
Within your workspace, your workspace admin can see all member data, tasks, and attendance records. Other members see only what your admin has granted them access to.
4. Cookies
We only use first-party cookies that the platform needs to work:
- Session cookie (PHPSESSID) — strictly necessary. Keeps you signed in while you use the platform. Ends when you close your browser. HttpOnly, Secure, SameSite=Lax.
- Stay-signed-in cookie (pulse_remember) — strictly necessary. Remembers this device so you don't have to sign in again. Lasts up to 90 days, renewed each time you use the platform, and is removed when you sign out. It holds a random code only; we store just a scrambled (hashed) copy of it. HttpOnly, Secure, SameSite=Lax.
- Cookie notice (pulse_consent) — remembers that you've seen our cookie notice, so it isn't shown again. Lasts 1 year. Contains no personal data.
Your display settings (such as theme and sidebar state) are kept in your browser's local storage on your device, not in cookies. Your Preferences, and the fact that you've seen the cookie notice, are also saved to your account so they follow you to other devices.
We do not use advertising, analytics or cross-site tracking cookies. You can block cookies in your browser settings, but you won't be able to sign in without the session cookie.
5. Data Retention
We retain your data for as long as your account is active. When you delete your account:
- Your personal profile data is deleted within 30 days
- Workspace content (tasks, comments) may be retained in anonymised form for workspace history if other members exist
- Billing records are retained for 7 years as required by tax law
- Backups are purged on a rolling 30-day cycle
- Daily feature-usage counts are deleted after 13 months
6. Your Rights (GDPR / CCPA)
Depending on your location, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your account and personal data
- Portability — receive your data in a machine-readable format
- Restriction — ask us to limit how we process your data
- Objection — object to processing based on legitimate interest
To exercise any of these rights, email us at support@dreambuildr.com. We will respond within 30 days. To delete your account directly, use Settings → Account → Delete Account inside the app.
7. Data Security
We take reasonable technical and organisational measures to protect your data:
- All connections encrypted via HTTPS / TLS
- Passwords hashed with bcrypt
- Session cookies are HttpOnly and Secure
- Rate limiting on authentication endpoints
- Database access restricted to application server only
No system is 100% secure. If you believe your account has been compromised, contact us immediately at support@dreambuildr.com.
8. Children's Privacy
Pulse OS is a business productivity tool intended for users aged 16 and over. We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, contact us and we will delete it promptly.
9. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page and notify workspace admins by email if the changes are material. Continued use of the platform after changes constitutes acceptance.
10. Contact Us
For any privacy-related questions or requests: