Privacy Policy
clearpulse is a personal sales intelligence tool. We take your privacy seriously. This policy explains what data we collect, how we use it, and what rights you have.
1. What data we collect
- Account information. Your name and email address when you sign in via OAuth (currently Google; additional providers will be supported).
- Deal and contact data you enter. Company names, contacts, deal stages, notes, and any other information you add to your pipeline. This data is yours — you create it, you own it.
- Email metadata and content (with your permission). If you connect your Gmail account, clearpulse reads email threads and metadata to surface context for your deals. This requires your explicit OAuth consent. You can revoke access at any time from your Google account settings.
- Calendar events (with your permission). If you grant calendar access, clearpulse reads upcoming events to surface meeting prep and follow-up reminders. Read-only.
- Usage logs. We record which features you use (e.g. sequences sent, AI queries run) for debugging and service improvement. Logs do not include the content of your deals or emails.
- Session cookie. A single session cookie keeps you signed in. We do not use advertising cookies or tracking pixels. See the Cookies section below.
2. How we use your data
- To provide the service. Your deal, contact, and email data is used to power your pipeline view, Now tab rankings, AI-assisted drafts, and research features.
- To improve AI features. We may use anonymised, aggregated usage patterns (e.g. which card types are most actioned) to improve how the product prioritises your work. We do not train AI models on the content of your deals, emails, or contacts. Your data is never used to train a shared model.
- To contact you. If you join the waitlist or sign up, we will email you about product updates and your account. You can unsubscribe at any time.
- For security and debugging. Usage logs and error traces help us identify and fix bugs. Access is restricted to the founder and is not shared externally.
3. Data processors (who handles your data)
We use a small number of third-party services to run clearpulse. Each processes your data only to the extent needed to provide their service:
- Supabase— our database and authentication backend. Your deal, contact, and log data is stored in a PostgreSQL database hosted by Supabase. Row-level security ensures one user cannot access another's data. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Supabase is a US-based company compliant with GDPR and SOC 2 Type II.
- Vercel— our hosting platform. The clearpulse application runs on Vercel's serverless infrastructure, protected by Cloudflare CDN. Vercel is SOC 2 Type II certified and GDPR-ready. Application logs may be stored on Vercel for up to 30 days.
- Google — authentication and (optionally) Gmail and Calendar access via OAuth. Google processes only the data needed to authenticate your account and, if you connect Gmail/Calendar, to return email threads and events to clearpulse. clearpulse does not store Google credentials — only a refresh token in your Supabase account row, encrypted at rest.
- AI inference services.When you use AI features (email drafts, deal summaries, research), your query and relevant deal context are sent to a third-party AI inference provider to generate the response. We do not name the specific provider in this policy as it may change. Queries are not used to train the provider's models. We minimise the data sent: only the context needed for the specific query.
- Search and embedding services. The company research feature uses third-party search and embedding services to find publicly available company information. Queries include only the company name and industry — no personal deal data is sent.
- Cloudflare. Our domain (clearpulse.app) is protected by Cloudflare CDN and DDoS protection. Cloudflare may log anonymised request metadata (IP addresses, browser type) for security purposes.
No personal data is sold to third parties. No advertising networks receive your data. We do not use advertising or cross-site tracking analytics (no Google Analytics, no Mixpanel, no Segment). We use Vercel Web Analytics, a cookieless, first-party page-view counter that does not set tracking cookies, does not collect personal data, and does not share data with advertisers.
4. Data retention
Your data persists in clearpulse until you delete your account. You can export all your data as JSON at any time from Settings → Account → Download my data. You can delete your account and all associated data via Settings → Account → Delete account, or by sending a deletion request to support@clearpulse.app. Deletion removes your deals, contacts, notes, sequences, and log data. Backups are purged within 30 days.
Email threads and calendar events fetched from Google are stored only while your Gmail or Calendar connection is active. Revoking access in Google Account Settings stops new data from being fetched; previously stored data is deleted on account deletion.
5. Your rights
If you are located in the European Union or European Economic Area, you have rights under the General Data Protection Regulation (GDPR):
- Right of access (Art. 15). You can request a copy of all personal data we hold about you.
- Right to rectification (Art. 16). You can correct inaccurate personal data directly inside the app, or ask us to correct it.
- Right to erasure (Art. 17). You can request deletion of your data at any time. See Data Retention above for how to do this.
- Right to data portability (Art. 20). You can export your data as JSON from Settings at any time.
- Right to object (Art. 21). You can object to any use of your data beyond what is strictly necessary to provide the service.
- Right to restrict processing (Art. 18). You can ask us to pause processing your data while a dispute is being resolved.
To exercise any of these rights, email support@clearpulse.app. We will respond within 30 days. If you believe your rights have not been honoured, you have the right to lodge a complaint with your national data protection authority.
The legal basis for processing your data is: performance of a contract (providing the service you signed up for), and legitimate interest (usage logging for security and debugging). We do not rely on consent as a basis for core service processing, so withdrawal of consent does not affect your ability to use the product.
6. Security
- Encryption in transit. All data between your browser and clearpulse is encrypted via TLS 1.2 or higher (HTTPS enforced; HTTP is not accepted).
- Encryption at rest.Your database is encrypted at rest using AES-256 via Supabase's managed infrastructure.
- Row-level security. Every database table enforces row-level security (RLS). Your data is scoped to your user ID at the database level — not just at the application layer. Even if a bug existed in the application, the database would reject cross-user reads.
- Authentication. Access uses OAuth (currently Google). There are no username/password credentials to leak. Session tokens are short-lived and refreshed automatically.
- Rate limiting and CAPTCHA. All API endpoints are rate-limited. The waitlist form is protected by Cloudflare Turnstile to prevent abuse.
No security system is perfect. If you discover a vulnerability, please report it responsibly to support@clearpulse.app.
7. Cookies
clearpulse uses the minimum cookies necessary:
- Session cookie. A Supabase-issued JWT stored as an HTTP-only cookie keeps you signed in. It is essential for the service to work and does not track you across sites.
- Theme preference. A
cp_themevalue is stored inlocalStorage(not a cookie) to remember whether you prefer dark or light mode. It never leaves your device.
We do not use advertising cookies or third-party tracking pixels. Our only analytics (Vercel Web Analytics) is cookieless — it sets no cookie and stores nothing that identifies you across visits or sites. A brief informational notice appears on first visit to explain this. It is dismissed by clicking “Got it” and never reappears.
8. Children
clearpulse is a professional tool designed for adults. We do not knowingly collect data from anyone under 18 years of age. If you believe a minor has provided data to us, please contact us and we will delete it promptly.
9. Changes to this policy
If we make material changes to this policy, we will update the “Last updated” date at the top and notify active users by email at least 14 days before the change takes effect. Continued use of clearpulse after that date constitutes acceptance of the updated policy.
10. Contact
Data controller: Danny Reszka, trading as clearpulse.
Email: support@clearpulse.app
For data deletion requests, access requests, or any privacy question, email the address above. We aim to respond within 5 business days and are required to respond within 30 days under GDPR.