Privacy
This page describes the current private staging build. It is not a final production privacy policy or legal advice.
Pre-launch notice: this draft must be reviewed and completed by qualified legal counsel before any public production launch.
Current private staging
PULSEVATE uses Supabase for account authentication and tenant-isolated cloud state, Railway for the authenticated API, and Netlify for the staging site and web app. A user-matched local cache supports hydration and recovery; the authenticated cloud snapshot is the source of truth. Account export and deletion are available through authenticated API flows.
Claude requests
When Claude mode is enabled, the bounded context required for the requested feature is sent through the authenticated PULSEVATE API to Anthropic. Provider keys stay server-side. Operational AI usage records contain counts, token/cost estimates, model, result category, and timing only; they do not store raw prompts, onboarding prose, Pattern text, or generated Quest copy.
Payments and analytics
The current staging billing integration uses Stripe TEST MODE only and cannot create a live charge. Subscription entitlement is derived on the server from signed Stripe test webhooks. First-party funnel analytics are stored server-side with an allowlisted event schema and bounded UTM attribution; free-form behavioral prose is not accepted.
Before production
A production policy must still identify the operator, lawful bases, all processors, retention periods, security measures, user rights, international transfers, age requirements, and a verified contact channel. Those decisions require the user and qualified legal counsel and are not invented here.