Privacy policy
Last updated:
This describes what Pulsgram holds about you, why it holds it, and when it goes away. It is written so you can check it, not so you can skim it. Where a rule has a consequence you will not like, it is written down rather than buried.
- We have no email address for you. You sign in with your phone number and a code. There is no email field in our database.
- Your address book never leaves your phone. Only one-way fingerprints of numbers are sent, matched, and thrown away.
- Message content never appears in our admin panel, our logs, or a push notification. That is enforced by automated tests, not by good intentions.
- Messages delete themselves after 24 hours unless both of you mark them to Keep.
- Deleting your account really deletes it, with a short list of exceptions we set out below, each with a reason.
- This website sets no cookies, runs no analytics, and loads nothing from anyone else — the fonts you are reading are served from our own server.
1. Who we are
Pulsgram is operated by ANDIAMO SOFTWARE S.R.L., a company registered in Romania. For everything in this policy, we are the data controller.
| Company | ANDIAMO SOFTWARE S.R.L. |
|---|---|
| Tax ID (CUI) | RO51032570 |
| Trade register | J2024049027004 |
| Registered office | strada Principală nr. 100, Beldiu, Teiuș, Alba, 515901, Romania |
| contact@andiamo.ro | |
| Phone | +40 723 593 474 |
We have not appointed a data protection officer. We are a small company and
the law does not require one of us. Every request about your data goes to
contact@andiamo.ro — the same address as everything
else, read by the same people. We deliberately do not publish a separate
privacy@ address: an address that exists only in a policy is a dead letterbox,
and you would find that out at the worst possible moment.
2. What we hold, why, and for how long
Everything below is what we have. If a category is not in this table, we do not collect it.
| What | Why | Legal basis | How long |
|---|---|---|---|
| Phone number, plus a keyed fingerprint of it (HMAC-SHA256 with a secret only our server holds) | It is your account. There is nothing else to log you in with, and it is how a friend's app finds you. | Performance of our contract with you | The number: until you delete your account. The fingerprint: survives in the few records listed in §10. |
| Date of birth | The 16+ check at sign-up. | Our legal obligation, and our contract with you | Until you delete your account. It cannot be edited afterwards, by you or by us. |
| Username, display name, avatar, language, timezone | Your profile, as other people see it, and knowing when your day ends. | Contract | Until you delete your account. |
| Messages — text and images | Delivering them. That is the app. | Contract | 24 hours, then the content is erased. Kept by both of you: for as long as the conversation exists. See §4. |
| Conversation metadata — who talks to whom, BPM, timestamps, exchange counts | The heartbeat mechanic the whole product is built on. | Contract | Until the conversation is deleted or you delete your account. |
| Daily Pulse entries — your photo or line, and who has seen it | The Daily Pulse feature. | Contract | Until midnight in the recipient's own timezone. Then the entry and its files are deleted. |
| Device record — platform, app version, a stable install identifier, push token, last seen | Delivering notifications, and stopping one person from farming free rewards with a hundred fake sign-ups. | Contract, and our legitimate interest in not being defrauded | Until you delete your account. The install identifier survives inside invite records — §10. |
| Login code records — the number, when a code was asked for, how many attempts, and a hashed copy of the code (never the code in readable form) | Signing you in, and stopping brute force and SMS pumping. | Our legitimate interest in the security of the service | 90 days. |
| Purchases — subscription and pack events from the store, your entitlements, your defibrillator ledger | Giving you what you paid for, and keeping books that add up. | Contract, and our legal obligation to keep accounting records | Detached from your account when you delete it, and kept as accounting records for 5 years. We never see your card. |
| Reports — the reason, what the reporter wrote, and metadata about what was reported | Dealing with harassment, spam and worse. | Our legitimate interest, and other users', in a service that is not a free-fire zone | Kept after account deletion, reduced to a minimal snapshot. See §10. |
| Blocks | Keeping someone away from you. | Contract | Until you delete your account. |
| Invite records — a phone fingerprint and an install identifier for each sign-up that counted toward someone's invite reward | Free defibrillators are earned by inviting three real people. Without this, one person with one phone earns them forever. | Our legitimate interest in preventing fraud | Kept indefinitely after account deletion, as a keyed fingerprint — never the readable number. There is no expiry date, and that is the point: a record that expires would let the same phone claim the same one-per-person reward again after waiting. See §10. |
| Usage counters — which days you were active, per-account totals, and daily aggregates for the whole service | Knowing whether the product works at all, without watching individuals. | Our legitimate interest in running and improving the service | Per-account rows go when your account goes. The daily aggregates carry no identifiers and survive. |
| Server logs — IP address, browser or app user-agent, the address requested, timing | Security, abuse, and finding out why something broke at 3am. | Our legitimate interest in the security and availability of the service | Rotated automatically as they fill up — days, not months. They are never joined to your account. |
| Emails you send us | Answering you. | Our legitimate interest in supporting our own product | As long as the matter is open, and up to 2 years after. |
Where the basis is our legitimate interest, you can object — see §13. Where the basis is our contract with you, refusing means we cannot run the account; there is no version of Pulsgram that works without knowing which number is yours.
3. What we do not do
- We do not collect email addresses from users. Sign-in is a phone number and a six-digit code. Our
userstable has no email column at all, so there is nothing to leak, sell, or accidentally add to a mailing list. We never email you — the app tells you things through notifications instead. - We do not upload your address book. See §6.
- We do not read your messages. The admin panel physically cannot: no screen, no query, and no export in it touches message text or images. The same rule covers our logs and our push notifications. Automated tests scan the source code on every change and fail the build if anyone adds a screen, a log line, or a notification that could carry message content. That is why we are willing to write it here.
- We do not use analytics or advertising SDKs. No Google Analytics, no Firebase Analytics, no Facebook SDK, no attribution or ad network, in the app or on this website. The numbers we watch are counted by our own server.
- We do not sell, rent or share your data with anyone for their own purposes. The companies in §9 process data on our instructions and for nothing else.
- We do not build profiles about you and no decision affecting you is taken automatically by a machine — a suspension or a ban is a person reading a report and deciding.
4. How messages live and die
A message expires 24 hours after it is sent. It starts fading visibly at 12 hours, so you can see it going. At 24 hours the text and any images are erased from our database and the image files are deleted from disk.
The exception is Keep, and it needs both of you. One person marking a message is a request; the other person marking it too is what stops the clock. A kept message has no expiry, and once it is permanent it cannot be un-kept.
For a few days after a message expires, an empty record of it remains — no text, no image, no file — carrying only its identifier, so that a phone which was offline does not resend the same message twice. That record is destroyed after 7 days.
When a conversation reaches 0 BPM it flatlines, and 48 hours later its history is deleted: every message that was not kept by both of you, and every image that belonged to them. Kept messages survive, because they were never on the clock. A defibrillator used inside those 48 hours brings the conversation back with everything intact; after that there is nothing to bring back, for us either.
Photos and videos you send are stored on a private disk, outside anything the web server can reach. The app gets a signed link that stops working after six hours. A link that leaks expires; it does not become a permanent public URL.
Raw Mode — the live, letter-by-letter mode you can turn on inside a conversation — stores nothing at all. What you type is relayed to the other phone and never written to any database or file, not even as a "last state" for reconnecting. All we keep is the fact that you both agreed to switch it on.
5. Your phone number
We store your phone number. We have to: it is your account, it is where the login code goes, and there is no username-and-password behind it to fall back on.
Alongside it we store a keyed fingerprint of the number — HMAC-SHA256 computed with a secret that lives only in our server's configuration, never in the database. Anyone who ends up with a copy of our database and not that secret cannot turn those fingerprints back into phone numbers by guessing, which is exactly the situation that matters. The fingerprint is what survives in the anti-fraud and moderation records described in §10 — the readable number does not.
Inside our admin panel a phone number is only ever shown masked, and support staff cannot see the full number. Searching for an account by phone number hashes what is typed before it touches the database.
6. Finding friends, without your address book
When you tap "sync contacts", your phone reads your contacts, normalises each number, and computes a SHA-256 fingerprint of each one. Only those fingerprints are sent to us — never names, never numbers, never anything else from your address book.
Our server compares them against fingerprints of the numbers already registered with Pulsgram, returns the profiles that matched, and discards the list. Nothing you sent is written to disk. We do not learn who else is in your contacts, and we cannot build a social graph from people who never signed up.
Two limits protect everybody, including you: at most 1,000 fingerprints per request, and 5,000 different fingerprints per day. They exist because a fingerprint lookup is also a way to ask "does this number have an account", and nobody should be able to ask that a million times.
Being precise about this, because we would rather you trust the accurate claim than the flattering one: the fingerprints your phone sends are plain SHA-256 of the number, which is the only thing a phone can compute without holding our server secret. We do not store them, and matching is done against numbers we already have — but a SHA-256 of a phone number is not a secret in the way a password hash is. The protection here is that we throw the list away, not that the maths is irreversible.
7. Notifications
Push notifications are delivered by OneSignal. What we hand them is: your internal Pulsgram user number, your device's push token, and the text of the notification — which we write and translate ourselves, on our server, before it leaves.
The text never contains a message. "Ana sent you 5 messages" is the whole of it — a name, a count, a type. Your notifications are read on a lock screen by whoever is standing next to you, and that shaped the rule. The consequence, stated plainly: the sender's display name and the fact that a conversation happened do pass through OneSignal, because a notification with neither would be useless.
You can mute individual conversations, turn off categories of notification, and set quiet hours, from inside the app. Turning off notifications at the operating-system level also works and we will stop being able to reach that device.
8. Payments
Everything you buy is bought from Apple or Google, in their store, with the payment method they already hold. We never see your card number, your name as it appears on it, or your billing address.
RevenueCat sits between the stores and us: it receives the purchase events and tells our server that an account is entitled to Puls+ or to a pack of defibrillators. What it holds about you is an anonymous identifier and the purchase history attached to it.
We keep the purchase events, the entitlement state, and the ledger of every defibrillator credited or spent. When you delete your account, those records are detached from you and kept as accounting records — Romanian law requires us to be able to show what we were paid and for what.
9. Reports, blocks and moderation
When you report someone, we receive: the reason you picked, whatever you wrote in your own words, who you reported, and — for a reported message — metadata only: its type, when it was sent, and which conversation it was in. Not the message. Our moderators genuinely cannot read it, and we would rather handle reports with one hand tied than build a panel that can read everybody's messages.
What a moderator can do: nothing, a warning, a temporary suspension, a permanent ban, or — for reports about self-harm — sending help resources. Every action is written down with a reason, and that record survives the account it was about. We do not tell you what we did about another person's account.
Blocking is separate and immediate: the other person can no longer write to you, you both disappear from each other's search and contact matching, and they are not told. Note the thing people find surprising: blocking does not stop the conversation's heartbeat. It decays and dies like any other.
10. Who else touches your data
A short list, because every name on it is a copy of something about you sitting on somebody else's computer.
| Who | What they get | Where |
|---|---|---|
| OneSignal — push notifications | Your internal user number, your device push token, and the already-written notification text. Never message content. | United States |
| RevenueCat — purchase infrastructure | An anonymous purchase identifier and the purchase events behind it. | United States |
| Apple and Google — the app stores | Your purchase and your payment details, as their own controllers. Their privacy policies apply to that, not ours. | Global |
| Our SMS provider — Twilio or Vonage | Your phone number and the six-digit login code, for the seconds it takes to deliver it. | United States / European Union |
| Our hosting provider | The server the whole service runs on, so technically everything — under a data processing agreement, with no access for their staff in normal operation. | European Union |
| Our email provider | Only our own internal alerts, which contain account numbers and never any content. If you write to us, it also holds that correspondence. | European Union |
OneSignal and RevenueCat are American companies, so that data leaves the European Union. The transfer relies on the standard contractual clauses adopted by the European Commission. If you want the details of a specific agreement, ask us and we will tell you what we have.
We are also required to hand over data to Romanian authorities when they ask for it lawfully — a court order, or a properly issued request from the police. We would tell you if we were allowed to.
11. Deleting your account
You can delete your account from inside the app, or by writing to us. The full instructions are on the delete account page. It is not a flag on a row that stays in our database — the account and its data are erased.
What is destroyed: your profile, your avatar, your friendships, your friend requests, your blocks, your devices and push tokens, your Daily Pulse entries and their photos, all your conversations, and every message in them, including the ones you both marked Keep. That last one has a cost worth stating out loud: a kept message belongs to two people, and when you delete your account the other person loses it too. We decided a privacy-first product deletes the copy rather than keeping half of it alive.
What survives, and why. This is the honest list:
| What stays | Why | Legal basis |
|---|---|---|
| Purchase and subscription events, detached from your account | They are accounting records. Last month's revenue is not allowed to rewrite itself because someone left. | Legal obligation (accounting), kept 5 years |
| Moderation reports about you or filed by you, reduced to a minimal snapshot: an internal id, the username, a phone fingerprint and the date | Otherwise deleting your account would become a way to wipe the evidence and come back with a clean record. The fingerprint is what lets us recognise a banned person returning. | Legitimate interest in safety and in enforcing a ban |
| A phone fingerprint and an install identifier in the anti-fraud records for the sign-up bonus and for invite rewards | Delete, re-register, collect the free defibrillator again — repeat. The fingerprint is the only thing that closes that loop. | Legitimate interest in preventing fraud |
| The deletion request itself: an internal id, a phone fingerprint, and when you asked | Proof that we did what you asked, when you asked it. | Legal obligation (accountability under the GDPR) |
| Daily aggregate counters — how many people used the app on a given day | They contain no identifier of any kind and cannot be traced back to a person. | No longer personal data |
None of those survivors contain a readable phone number, a message, or a photo. They are fingerprints, counters and dates.
Export your data before you delete, not after. Deleting the account also deletes any export archive we generated for you. The right to a copy of your data and the right to erasure cancel each other out if you use them in the wrong order.
12. Getting a copy of your data
In the app: Settings → Privacy → Export my data. We build a ZIP archive and give you a download link. The link works for 72 hours, then the archive is deleted from our server.
The archive contains your profile, your friends, your friend requests, the blocks and reports you made, your conversations' metadata, the messages you sent with their content, your Daily Pulse entries, your defibrillator ledger, your subscription state, your pauses, your devices and your invites — plus a plain-text file explaining every section.
It does not contain the messages other people sent you. Those are their words, in a conversation, and a data request of yours is not allowed to become a way of extracting somebody else's side of it. It also does not tell you who blocked or reported you.
The download link is signed rather than password-protected, which means anyone holding the link can use it until it expires. Do not forward it. If you would rather have the archive another way, write to us.
13. Your rights
Under the GDPR you can ask us to:
- Give you a copy of the personal data we hold about you — in the app, or by email if you prefer.
- Correct anything wrong. Language and timezone are editable in the app, and your display name is editable wherever the app offers the field. Profile pictures do not exist yet — the product has no way to upload one, so there is nothing of that kind to correct. Your username, date of birth and phone number are not editable, by design; if one of them is genuinely wrong, write to us and we will do it for you.
- Delete your account and its data, subject to §11.
- Port your data — the export is a machine-readable JSON archive, made for exactly this.
- Restrict what we do with your data while a dispute about it is open.
- Object to processing based on our legitimate interest. Tell us which processing and why; we will stop unless we can show a compelling reason not to, and we will explain either way.
Write to contact@andiamo.ro. We answer within 30 days at the outside — that is the legal deadline and we treat it as one, not as a target. Requests are free; we will only charge for one if it is repeated and obviously excessive, and we would tell you before doing so.
Since your account has no email address attached, we may have to ask you to prove you are the person the account belongs to. The way we do that is described on the delete account page — and it never involves sending us a login code.
Complaining about us
If you think we have handled your data badly, tell us first — it is faster and we would rather fix it. You do not have to. You can complain directly to the Romanian supervisory authority:
| Authority | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) |
|---|---|
| Address | B-dul General Gheorghe Magheru nr. 28-30, Sector 1, 010336, Bucharest, Romania |
| anspdcp@dataprotection.ro | |
| Phone | +40 318 059 211 |
| Website | www.dataprotection.ro |
If you live in another EU country, you can also complain to your own national authority.
14. Age
Pulsgram is for people aged 16 and over. You give your date of birth when you sign up and the app refuses to create the account if it puts you under 16. We do not verify identity documents — nobody in this category of app does — so the check is only as honest as the answer.
If you are a parent or guardian and you believe a child under 16 has an account, write to contact@andiamo.ro and we will delete it. Tell us the phone number the account uses; that is the only way we can find it.
15. Keeping it safe
- Everything travels over HTTPS. The site and the API refuse plain HTTP.
- Photos are stored on a private disk that the web server cannot serve from, and are handed out only through signed links that expire in six hours.
- The secret used to fingerprint phone numbers lives in the server's configuration, never in the database, and is not in our source code.
- Login codes are stored hashed, expire in five minutes, and allow five attempts.
- Access to the admin panel is limited to named accounts with roles, every moderation action is logged with the person who took it, and the panel cannot reach message content by construction.
- Backups of the database are encrypted and stored separately from the server.
None of that makes a breach impossible. If one happens and it puts you at risk, we will tell you and the supervisory authority, within the deadlines the law sets.
16. This website
No cookies. pulsgram.com sets none — not for analytics, not for advertising, not for "preferences". There is no cookie banner because there is nothing to consent to.
No analytics. No Google Analytics, no Plausible, no Matomo, no pixel of any kind. We do not know how many of you read this page.
Nothing loads from anyone else. The fonts you are reading are served from our own server, deliberately. Linking a font from Google would send your IP address to Google on every page view — a page that contradicts its own privacy policy is worse than an ugly one. There are no external scripts, no embedded videos, no third-party frames. Open your browser's network tab and check; every request goes to pulsgram.com.
One exception, and it is not tracking. The invitation page at
pulsgram.com/i/… saves the invite code from the address into your browser's
localStorage, under the key pulsgram.invite. It does this so the
code survives a trip to the App Store or Google Play — neither store can carry it across for
you. Nothing else is stored, the value never leaves your browser, no request is made to our
server about it, and clearing your browser data removes it. That page also asks your browser
which language it prefers, so it can show itself in Romanian or English, and sends the answer
nowhere.
Our web server keeps standard access logs — IP address, what was requested, when — for security and debugging. They rotate away in days and are not connected to any account.
17. Changes to this policy
When we change something here, the date at the top changes. If a change actually matters to you — a new company processing your data, a new category of data, a longer retention — we will tell you in the app before it takes effect, not by quietly editing this page.
This policy is published in English and Romanian. Both say the same thing. If they ever contradict each other, the Romanian version is the one that governs, because that is the law we operate under.