Privacy policy

Your results are encrypted before they're saved.

This page explains exactly what the Pulse app and this website handle, where it's stored, who can read it, and what your choices are. Every claim here describes how Pulse actually works today.

Last updated October 10, 2026

In short

  • Pulse reads your lab-report PDFs in your own browser. Your results aren't uploaded anywhere to be processed.
  • Everything is encrypted on your device with AES-256-GCM before it's saved or synced. The server only ever holds ciphertext.
  • The key that unlocks your data comes from your password, on your device. It's never sent to the server, so the server can't read your results, and neither can we.
  • There are no analytics, ads, tracking pixels or third-party scripts in the app. Your data isn't sold, rented or shared.
  • There's no password recovery. That's the cost of a server that holds no key. Keep your password safe and download encrypted backups.
What happens when you import a report
Your browserReads the PDF and parses the results
Your browserEncrypts everything with your data key
Your deviceSaves the encrypted copy locally
Pulse serverStores the ciphertext. It can't open it.

Privacy by design

Your results are read on your device.

PDF reading uses a bundled copy of PDF.js that runs in the page. Detecting the report format, parsing results, merging them into one history per biomarker, drawing charts and running the calculators all happen in your browser. None of it needs your results to leave the device.

The server is a shelf, not a reader.

The server stores sealed boxes and checks that you own them. It can't open them. That's what lets your vault open on both a laptop and a phone without carrying a backup file between them.

One vault per deployment.

Each Pulse deployment holds one person's vault. Creating it requires a setup secret held by whoever runs the deployment, so no one else can create an account on it.

Your data isn't the business model.

Pulse doesn't run ads, build profiles or sell data. The app's security policy only allows the page to connect to Pulse's own server, so it can't quietly send your data anywhere else.

What the app handles

Everything below is stored inside your encrypted archive:

  • Lab reports you import as PDF files, and the results read from them: values, units, the reference range printed on each report, and collection dates.
  • Your original PDFs, kept beside the parsed results so you can always check a number against its source.
  • Notes you write on a result or a draw.
  • Figures you type in: age or birth date, height, weight, waist, a diabetes answer and sex on the Calculators page, plus your weight log.
  • Context you log: supplement runs, imaging entries such as ultrasound or FibroScan, and dated events.

Pulse doesn't ask for your name, address, insurance details or a phone number.

How encryption works

1

Your password is stretched. When you unlock, your browser runs PBKDF2-SHA-256 with 600,000 iterations over your password and a random 16-byte salt, producing 512 bits.

2

The result is split in two. The first half becomes a key-encryption key that never leaves your device. The second half is a sign-in token. Only a SHA-256 hash of that token is sent to the server.

3

A data key does the encrypting. Your archive and PDFs are encrypted with a random 32-byte data key. The key-encryption key only wraps that data key, so changing your password re-seals 32 bytes instead of re-encrypting your whole history.

4

Every record is sealed separately. Each saved record uses AES-256-GCM with a fresh 12-byte IV. GCM also authenticates the data, so a tampered record fails to decrypt instead of quietly loading.

What this means in practice

  • A full copy of the server's database would reveal a public salt, an iteration count, an encrypted check value and a hash of the sign-in token. None of these is your key. Guessing your password would still cost 600,000 iterations per guess.
  • Passwords must be at least 15 characters and are checked against a list of common passwords.
  • The unlocked data key and sign-in token live only in the page's memory. They're never written to browser storage. Reloading the page or closing the tab locks the vault, and it also locks itself after 30 minutes without interaction.
  • There's no recovery. Because nobody else holds your key, a forgotten password can't be reset and the archive can't be decrypted. An encrypted backup protects against losing a device, not against losing the password.

Where data is stored

WhereWhatForm
Your browser: local storageThe archive (results, notes, typed figures, logs), cached so Pulse opens instantly and works offlineEncrypted
Your browser: IndexedDBYour source PDFsEncrypted
Server: Cloudflare D1The archive and vault metadata (salt, iteration count, wrapped data key, check value, token hash), plus an index of stored PDFsEncrypted archive; metadata can't reveal your key
Server: Cloudflare KVYour source PDFs, each stored under a fingerprint of its own contentsEncrypted
Page memory onlyThe unlocked data key and sign-in tokenNever saved; cleared on lock

Changes are written to your device first and then pushed to the server, so a dropped connection can't lose an import. Each write carries a revision number, which stops an older copy from overwriting a newer one.

What the server can see, stated plainly

  • Each stored PDF is labelled with a SHA-256 fingerprint of the original, unencrypted file, plus its size and when it was saved. The fingerprint reveals nothing about the contents, but someone who already had an identical copy of that file could confirm it's stored.
  • The server can see when the archive last changed and how large it is.
  • It can't see your results, notes, figures, report names or dates.

Who can access what

  • You can read your data on any device where you unlock the vault with your password, or with Face ID on a device where you've enrolled it.
  • The server, and anyone operating it, can read only the encrypted data and the metadata listed above. They can't decrypt it.
  • Cloudflare, which hosts the app, keeps standard request logs (time, address requested, IP address, browser details, response status) to run and protect the service, under Cloudflare's own privacy policy. Those logs never contain lab results, because results never travel unencrypted.
  • Every data request to the server must come from the same site and carry the vault's sign-in token, except the one request that fetches the salt and settings needed to unlock.
  • Delivery is locked down. Every response carries a strict Content Security Policy, HSTS, protection against being framed by other sites, a no-referrer policy and cross-origin isolation. Public preview URLs for older versions are turned off.

Your devices and Face ID

Face ID or another passkey is optional. If you turn it on for a device, the data key is wrapped a second time under a secret your device's authenticator produces at unlock and never writes down. That device stores a credential identifier and the encrypted key, nothing readable. The biometric check happens inside your device, and nothing about your face or fingerprint reaches Pulse. Your password always still works, and changing it switches Face ID off until you set it up again.

The optional assistant connector

Pulse includes an optional local MCP server that lets Claude or Codex answer questions about your lab history. It's the one place your data is decrypted outside the browser, so here's exactly what it does:

  • It runs on your own Mac, started by your assistant. It doesn't listen on any network port.
  • It reads your vault password from your macOS login Keychain, fetches the encrypted archive the same way the browser does, and decrypts it in memory. Neither the key nor the decrypted data is written to disk.
  • Each tool answers one narrow question and returns only what was asked for. Those answers become part of your conversation with that assistant and are handled under that assistant provider's own terms.
  • It can add or change supplement runs, imaging entries, events and draw notes when you ask, but never lab results. It can be set to read-only, and it doesn't read your source PDFs.
  • It forgets the decrypted data after 30 minutes idle, or as soon as you ask it to lock.

If you never set it up, none of this applies.

MyChart

MyChart sync isn't available yet. When it is, and only if you choose to connect it, you'll sign in on your hospital's own MyChart page, so Pulse never sees your MyChart password. Pulse will ask for read-only access to your lab results. That access will be kept in page memory for a single import and then discarded, and results will be encrypted in your browser like any imported PDF. You'll be able to revoke access from your MyChart account at any time. This page will be updated before the feature ships.

Third parties

ServiceUsed forWhat it receives
CloudflareHosting the app and storing encrypted data (Workers, D1, KV)Encrypted data, and standard request logs including IP address
VercelHosting this websiteStandard request logs including IP address. No lab data.
Google FontsLoading this website's typefacesYour IP address and browser details when the fonts load. No lab data.
UpstashStoring waitlist email addressesThe email address you submit
ResendEmailing us when someone joins the waitlistThe email address you submit

The app itself loads no third-party scripts and connects only to its own server. If you use the optional assistant connector, the answers it gives go to the assistant provider you chose.

Export and deletion

  • Encrypted backup: download a backup file from Settings at any time and restore from it later. It stays encrypted.
  • CSV and printed reports: made in your browser. They're not encrypted once saved, so treat them like any private medical document.
  • Deleting a report removes it from your archive and deletes its encrypted PDF from the server and from that device.
  • Deleting everything: email us and we'll delete the vault from the server. Clearing the site's data in your browser removes the local copy on that device.

This website and the waitlist

Email collection

When you join the waitlist, we collect only the email address you type. It's stored with Upstash so we can send your invite, and a notification is sent to us through Resend. We won't sell it, share it for marketing, or add it to unrelated lists. We'll use it to send your invite and occasional updates about Pulse, and you can unsubscribe at any time.

Cookies and analytics

This website sets no cookies and runs no analytics, ad tags or tracking pixels. The fonts load from Google Fonts, which receives your IP address and browser details when they load.

Retention

Waitlist emails are kept until you unsubscribe, ask us to delete them, or the waitlist closes. Hosting providers keep their request logs for their own limited periods.

Where data is located, and Do Not Track

The website, the app's servers and the waitlist store run on infrastructure in the United States, or on Cloudflare's global network for the app. Because this website and the app run no tracking, there's nothing for a browser's Do Not Track signal to switch off.

Not medical advice

Pulse is a personal record. Its charts and calculators describe your own numbers and cite published research. They aren't a diagnosis or a reason to start, stop or change a treatment.

Your choices

  • See or export your data at any time from inside the app.
  • Correct notes, typed figures and logs directly in the app.
  • Delete individual reports in the app, or ask us to delete your vault or waitlist entry.
  • Unsubscribe from waitlist emails at any time.

Because the server can't read your vault, we can't look up, correct or hand over its contents for you. Only you can, by unlocking it.

Changes and contact

If anything here changes, we'll update this page and the date at the top. Material changes, such as a new service that receives data, will be described here before they take effect.

Questions or requests: pulse.bloodwork@agentmail.to

Bring your whole history.Leave the PDFs behind.

Join the waitlist and we'll email you when your invite is ready.