Close enough to meet. Never close enough to find.
Who we are
Cloverfields-Tech operates Pulse and is the responsible party for your personal information under South Africa's Protection of Personal Information Act, 2013 (POPIA), and the data controller where the GDPR applies.
Contact us about anything in this policy at cloverfields.tech@gmail.com.
The short version
- On the map, other people never see where you are — only a rough distance band, like “120 m”, and a pin that is deliberately offset. The only way anyone gets your exact position is if you hand it to them, by starting a live location share in a chat.
- Your messages are end-to-end encrypted. We cannot read them.
- We do not sell your personal information, and we never have.
- We do not use your content or messages to train machine learning models.
- Most of what you create on Pulse expires on purpose — a pulse in 60 seconds, a meetup chat 48 hours after the meetup, a travel circle when the trip ends.
- You can delete your account, and everything it contains, at any time.
What we collect, and why
Information you give us
- Account. Your email address and a password, or an identifier from Google or Apple if you sign in that way. Needed to create and secure your account.
- Your date of birth. Pulse is not for under-18s, so we ask for a date rather than a tick box and check it when your account is created. It is never shown to another user, and it is not used to work out what to show you — only to confirm you are old enough to be here.
- Profile. Your name, username, photo, bio, gender and interests. Shown to other users — that is the point of it. You choose what to fill in beyond a name.
- Content. Moments, meetups you create or join, comments, photos, videos, voice notes and messages.
- Reports and blocks. When you report someone we keep your report, what you reported, and the surrounding context, so we can act on it.
- Correspondence. What you write to support, so we can answer it.
Location
With your permission, Pulse collects your device's precise location. Nobody is shown it on the map: what other people see there is a distance band and a pin that is deliberately offset from where you actually are. The precise figure stays on our side, where it is used to work out that band and to place hotspots correctly.
The exception is when you hand it over yourself, which is the bullet on live location below. We would rather name that plainly than claim a blanket “never” the app does not keep.
- While you are using the app, to show who and what is nearby, and to calculate the distance bands other people see.
- To tell you a friend is close. Your last known position is compared with those of people you are connected with — nobody else — and you are told when one is inside a distance you choose, up to 1 km. It uses the position the app last sent while you were using it, and stops considering one more than 15 minutes old, so it does not track you when the app is closed. You can turn it off entirely in Settings → Notifications, and it never runs in ghost mode.
- In the background, only in two cases: while you are actively sharing live location in a chat, and while a meetup you joined is running. Both stop on their own, and you can stop them yourself at any time. Nothing else on Pulse tracks you in the background.
- When you deliberately share it. Starting a live location share in a chat sends your exact position — not a band, not an offset pin — to that one person, and keeps it updating for as long as the share runs, up to eight hours. Sending a one-off location pin does the same thing once. You start both, you can stop them at any time, and they end on their own. A Moment is also pinned to the exact place you posted it, and that pin is part of the post.
- Never while ghost mode is on. Ghost mode makes you invisible and stops your location being shared with anyone.
You can withdraw location permission in your phone's settings at any time. Nearby discovery is the core of Pulse, so most of the app stops working without it — but nothing stops you keeping your account.
Information collected automatically
- Device and app. Device model, operating system version, app version, language and time zone, and a device identifier — used to deliver notifications, diagnose faults and detect abuse.
- Push token. Issued by Apple or Google so we can deliver a notification when a pulse arrives.
- Diagnostics. Crash reports and performance data through Firebase Crashlytics.
- Usage. Aggregate analytics through Firebase Analytics — which screens are opened and which features are used. Used to see what works, not to profile you.
- IP address and log data. Kept briefly for security, rate limiting and abuse prevention.
Purchases
There are none. Pulse is free, there is nothing to buy inside it, and we take no payments — so there is no payment data for us to hold, and no billing processor in the list below. If that ever changes, this policy changes first, and the payment itself would be taken by Apple or Google rather than by us.
What we never do
We never put your exact location on the map for another user, and we never hand it to anyone you have not deliberately shared it with. We never sell or rent your personal information. We never use your private messages, photos or content to train machine learning models. We do not run advertising networks inside Pulse, and we do not track you across other companies' apps and websites.
Our legal grounds
Under POPIA we process your information because it is necessary to perform the contract between us (running the app you signed up for), because you consented (location, camera, microphone, photos, calendar, notifications — each asked for separately and withdrawable), because we have a legitimate interest (keeping Pulse safe, preventing abuse and fraud, fixing crashes), or because the law requires it. Where the GDPR applies, these correspond to Article 6(1)(b), (a), (f) and (c) respectively.
Who your information goes to
We do not sell your information. We share it only with service providers who process it on our instructions, under contract:
- Supabase — authentication and file storage for profile photos and media.
- Google Firebase — push notifications (Cloud Messaging), crash reporting (Crashlytics) and product analytics.
- Google and Apple — if you use their sign-in.
- OpenFreeMap— serves the map tiles your device downloads. Your device's IP address is visible to them as part of that request; your Pulse identity is not.
- Vercel — hosts this website and our share links.
We may also disclose information where the law compels us to, to enforce our Terms, or to protect someone from harm. If Pulse is ever sold or merged, your information may transfer to the buyer, who stays bound by this policy — we will tell you before that happens.
Other Pulse users see what you would expect them to: your profile, your content, and a distance band — plus anything you have deliberately handed them, such as a live location share in a chat. Nothing beyond that.
Where your information goes
Our providers store data on servers outside South Africa, including in the European Union and the United States. We transfer it under section 72 of POPIA, relying on the provider being bound by contractual terms that give your information a level of protection substantially similar to POPIA, and — where the GDPR applies — on the European Commission's Standard Contractual Clauses.
How long we keep it
- Pulses: 60 seconds, then gone.
- Meetup chats: deleted 48 hours after the meetup ends.
- Travel circles: deleted when the trip ends.
- Location: your current position is held only as long as it takes to serve the map. We do not keep a location history.
- Profile and content: until you delete them or delete your account.
- Date of birth: for as long as the account exists, and deleted with it. Keeping it is what lets us show that the account passed the age check, rather than asking you to prove it again.
- Reports and safety records: up to 24 months after the account closes, so that a banned user cannot simply return. This is the one thing that outlives deletion.
- Records the law requires us to keep, such as transaction records: for the statutory period.
Security
Messages are end-to-end encrypted, which means they are encrypted on your device and can only be read on the devices in the conversation — we hold no key and cannot read them, so we also cannot recover them for you. Everything in transit uses TLS. Credentials are held in the device's secure keystore. Access to production systems is limited to people who need it.
No system is perfectly secure. If a breach affects your personal information we will notify you and the Information Regulator (South Africa) as POPIA requires.
Your rights
You can ask us to:
- tell you what personal information we hold about you, and give you a copy;
- correct anything inaccurate or incomplete;
- delete your account and the information in it — see how to delete your account;
- stop processing based on legitimate interests, or on consent you have withdrawn;
- send your information to another service in a portable format.
Email cloverfields.tech@gmail.com from the address on your account. We reply within 2 business days and complete requests within 30 days. It is free, unless a request is repetitive or excessive.
We do not make decisions about you by purely automated means that produce legal or similarly significant effects.
Complaints
Please raise it with us first. If we cannot resolve it, you may complain to the Information Regulator (South Africa) at https://inforegulator.org.za or complaints.IR@justice.gov.za. If you are in the EEA or the UK, you may complain to your local supervisory authority.
If you are in the EEA or the UK
Everything above applies to you, and the GDPR gives you the same rights under different names: access, rectification, erasure, restriction, portability, and objection — including the right to object at any time to processing based on our legitimate interests. You may withdraw consent whenever you like, which does not affect processing already carried out. Our transfers out of the EEA rely on the Standard Contractual Clauses; ask us for a copy.
Children
Pulse is for adults. You must be at least 18 to use it, and we do not knowingly collect information from anyone younger. If you believe a minor is using Pulse, tell us at cloverfields.tech@gmail.com and we will remove the account.
This website
getpulse.chat sets no advertising or tracking cookies. We use Vercel Analytics, which measures page views without cookies and without building a profile of you. If you join the waitlist we store the email address you give us, for that purpose only, and you can have it removed by asking.
Changes
We will update this policy as Pulse changes. The effective date at the top always tells you which version you are reading. If a change materially affects your rights we will tell you in the app or by email before it takes effect, rather than quietly editing this page.
Contact
Cloverfields-Tech
cloverfields.tech@gmail.com