PULSE · Trust & transparency

Privacy Policy

Understand what information PULSE handles, how connected services work, and the choices available to you.

Last updated: September 14, 2026

1. About this policy

This policy describes how PULSE handles information through pulsewithcare.com, including our practitioner directory, accounts, appointment requests and connected services. It does not replace a healthcare practitioner’s own privacy notice. Contact support@pulsewithcare.com with questions or privacy requests.

2. Information we collect

  • Account and profile information, such as name, email address, profile photo, contact details and information you provide during onboarding. Password-based accounts use password verification data; Google sign-in provides basic identity information such as name, email and profile image.
  • Practitioner information, including practice details, specialties, services, location, professional identifiers and documents submitted for review.
  • Appointment information, including patient and practitioner identities, service, requested date and time, status, and notes or reasons you choose to provide.
  • Files you upload, including profile photos, practitioner documents and patient health records, together with file names, types and sizes.
  • Membership and payment references, subscription status and transaction information received from Stripe. Payment-card details are handled by Stripe rather than stored as full card numbers in PULSE.
  • Reviews, saved practitioners, account preferences, support communications and technical information used for sessions, security and troubleshooting, such as browser information, IP addresses and service logs.

3. How information is used

We use information to operate accounts, display practitioner profiles, support discovery and appointment requests, review practitioner applications, process memberships, deliver transactional messages, respond to requests, and maintain the security and reliability of the service. Public profile details and reviews may be visible to visitors and search engines. Avoid placing private information in public profile fields or reviews.

4. Google sign-in and Calendar

Google sign-in and practitioner Calendar connection are separate features. Calendar access is optional and requires the practitioner’s authorization. PULSE requests the calendar.events permission and stores access and refresh tokens to maintain the connection. The permission permits event access, but the current integration creates and deletes PULSE appointment events in the connected practitioner’s primary calendar; it does not import the calendar’s full event list or provide live availability.

When a practitioner confirms a request, PULSE sends the patient’s name, service, appointment times and any patient booking note to Google as event content. Cancellation triggers an attempt to remove the associated event. We retain the associated Google event identifier and connection information to support synchronization. Calendar sharing settings may make event information visible to others who can access that calendar. Do not include information in a booking note that you do not want shared this way.

PULSE’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not used for advertising, sold to data brokers, or used to train generalized artificial intelligence or machine-learning models. Access is limited to providing the requested features and permitted security, support or legal purposes.

You can revoke PULSE access through your Google Account connections. Revocation stops future authorized access but does not automatically erase events already created or records stored in PULSE. Contact us to request deletion of stored connection information. You can remove remaining events in Google Calendar. Reconnection may be required to resume synchronization.

5. Sharing and service providers

Appointment details are available to the participants and authorized administrators managing the service. Practitioner review documents are available to the submitting practitioner and authorized administrators. Patient health-record downloads are restricted through the application to the owning patient; uploading a record does not automatically share it with a practitioner. Authorized technical operators may need access to maintain or secure the underlying systems.

We use infrastructure and service providers to operate PULSE: hosting and PostgreSQL database infrastructure, Cloudflare R2 for file storage, Resend for transactional email, Stripe for payments, and Google for authorized sign-in and Calendar features. Relevant information is transmitted to these services to perform those functions. Booking email messages can contain appointment information; practitioner request emails can include patient notes. Separate administrative booking alerts omit patient notes.

Information may also be disclosed when required by applicable law, to address fraud or security issues, or to protect people’s rights and safety. Third-party services process information under their applicable terms and privacy policies, and processing may occur outside your country.

6. Storage, retention and security

Account and application records are stored in our database. Uploaded files are stored in a private R2 bucket and accessed through application routes; profile photos are publicly viewable while document and record routes enforce access checks. We use authentication and role-based controls, but no online system can guarantee absolute security.

We retain information as needed to operate your account and the features you use, address disputes, maintain security and meet applicable obligations. Retention depends on the information and purpose; we do not promise a single deletion period for every category. Unclaimed uploads expire after 24 hours and are removed by scheduled cleanup. Deletion requests may require identity verification. Copies held in service-provider records, logs or backups, where applicable, may remain until their retention cycles end or as required by law.

7. Your choices and requests

You can edit available profile fields, delete uploaded health records, and use account-deletion controls in account settings. You may also email support@pulsewithcare.com to request access, correction or deletion, or ask about other rights available under applicable law. Do not email passwords, payment-card details or medical documents with an initial request.

Account deletion does not itself remove events already held in Google Calendar or replace subscription cancellation with Stripe. Practitioners should manage any active subscription before deleting their account. Transactional messages are used for account and service operations; turning off a connected feature does not necessarily stop unrelated account messages.

8. Cookies and local preferences

PULSE uses session cookies and browser storage for authentication, security and interface preferences. Blocking necessary cookies can prevent sign-in and other account features. Connected providers may use their own cookies when you interact with their services.

9. Children and sensitive information

PULSE is not intended for children to independently create accounts or submit personal information. If you believe a child has provided information without appropriate authorization, contact us. Only upload information you are entitled to provide, and avoid unnecessary medical detail in appointment notes, public content or support messages. PULSE is not an emergency service.

10. Policy updates and contact

We may update this policy as the service changes. The date above identifies the latest revision; material changes will be communicated as required by applicable law. For questions about this policy or data handling, email support@pulsewithcare.com.