Privacy Policy
Last updated: 17 September 2026 · Applies to the Pulse Cloud web service at https://pulsehk.net
Pulse Cloud is a self-service portfolio tracking dashboard for the US, Hong Kong, mainland China and Taiwan markets. This page explains, in plain language, what personal data the web service collects, why we need it, who processes it on our behalf, how long we keep it, and how you can get it back or have it deleted.
If anything here is unclear, email chunpulseyung@gmail.com and we will answer.
1. What we collect
Account data
- Email address — used as your login identifier.
- Password — authentication is handled by Supabase Auth. Your password is hashed and stored by Supabase; Pulse never stores or logs it in plain text. If you sign in with Google, we receive your email address and account identifier from Google and no password at all.
- Last-active timestamp — updated at most once a minute while you are signed in, so the dashboard can show how many users are online.
Your portfolio content
- Transactions — ticker symbol, market, buy/sell type, date, number of shares, price, commission and fees, and any notes you add.
- Watchlist — your categories, the tickers in them, and any target prices or alerts you set.
- Portfolio settings — cash balance and the currency settings you choose.
- Preferences — interface language, primary and secondary currency, selected market indices, and AI-audit preferences (provider, model, prompt strictness, custom prompt text and timeout).
AI provider API key (optional)
If you use the AI portfolio audit you may save your own API key from an AI provider (for example Google Gemini, OpenAI or DeepSeek). That key is stored in your profile and is used only to call your chosen provider when you press the audit button. It is never used for anything else, never shown to other users, and is removed when you delete it in Settings or delete your account. Any portfolio summary that is sent to that provider is governed by that provider's own privacy terms — we recommend reviewing them.
Payment data
Pro subscriptions are billed by Stripe. Payments are made on Stripe's own checkout page: your card number, expiry date and CVC never reach Pulse's servers, and we cannot see them. We receive only the subscription status, the Stripe customer and subscription identifiers, and the expiry date of your Pro access so we can unlock the Pro features.
Technical data
Our hosting provider's infrastructure records standard request logs (IP address, user agent, requested path, timestamp) for security, abuse prevention and debugging. These logs also record the API endpoints you call, for example whether you requested a portfolio export.
We also keep short usage records in our own database — which action was performed and when — so that we can enforce per-tier usage limits and detect abuse. These records are tied to your account and are deleted when the account is deleted.
2. Why we use it
- To create and secure your account and keep you signed in.
- To store and display your portfolio, watchlist, performance figures and settings — the entire point of the service.
- To price the holdings and watchlist symbols you track by requesting market data from our data provider.
- To run the AI audit with the provider and key you selected.
- To take subscription payments, determine your tier, and provide support when you contact us.
- To keep the service running, prevent abuse and rate-limit excessive automated traffic.
We do not sell your personal data, we do not rent it, and we do not use your portfolio content to advertise to you.
3. Processors we rely on
- Supabase — authentication and the PostgreSQL database that stores your account, portfolio, watchlist and settings. Access is scoped to your account: every database query the application runs is filtered by your user ID, and row-level security policies are enabled on the data tables as an additional layer.
- Stripe — payment processing, subscription billing and invoices.
- Our cloud hosting provider — runs the FastAPI application and serves these pages.
- Yahoo Finance — the source of the market prices shown in the dashboard. Ticker symbols needed to price your holdings and watchlist are requested from it; your email address, account identifier, password and payment details are never sent.
- Your chosen AI provider — only when you run an audit, and only with the key you supplied.
Each of these providers processes data under its own terms. We choose providers that take security seriously and we limit what we send them to what the feature needs.
4. Cookies and local storage
sb-access-token— a session cookie set on our domain after sign-in (path/, 1-hour lifetime,SameSite=Lax). It lets the server render your dashboard for your session. It is cleared when you sign out.- Supabase session storage — the Supabase client library keeps your session (access and refresh tokens) in your browser's local storage under
sb-*keys, so a page refresh does not sign you out. - Language preference — the language you choose in the dashboard is saved to your Pulse profile (so it follows you between devices); the interactive demo's language switch is kept in
sessionStoragefor the current browser session only. - No third-party advertising or analytics trackers — at the time of writing there is no advertising pixel, no AdSense script and no third-party analytics tracker loaded on this site. If that changes, this section will be updated first and, where required, your consent will be requested before anything loads.
5. How long we keep it
- Account, portfolio, watchlist and settings — kept while your account is open. Delete the account and this content is removed; we aim to complete deletion within 30 days of a verified request.
- Saved AI API key — kept until you clear it in Settings or delete your account.
- Payment and invoice records — Stripe retains these as required for tax and accounting purposes; they are kept out of reach of ordinary deletion because the law requires it.
- Hosting request logs — short-lived and rotated by the hosting provider.
6. Security
Traffic to this site is served over TLS. Authentication, storage and row-level access control are handled by Supabase. Passwords are hashed, card details are handled entirely by Stripe, and your API key is only readable by your own account. That said, no online service can promise perfect security: please use a unique password, keep your email account secure and tell us immediately if you suspect your account was accessed by someone else.
7. Your rights
- Access and portability — use the Export feature in the dashboard (it calls
/api/export) to download your portfolio and watchlist as JSON at any time. - Correction — transactions, watchlist entries and settings are editable from the dashboard; email us for anything you cannot change yourself.
- Deletion — email chunpulseyung@gmail.com from your registered address and we will delete your account and its content, except records we are legally required to retain.
- Objection or restriction — tell us what you object to and we will stop the relevant processing or explain why we must continue.
8. Children
Pulse Cloud is a financial tracking tool intended for adults. It is not directed at children and we do not knowingly accept accounts from anyone under 18. If you believe a child has created an account, contact us and we will remove it.
9. International transfers
Your data is stored with Supabase and payments are processed by Stripe; both operate infrastructure in multiple regions, so your data may be processed outside Hong Kong. We rely on these providers' contractual and technical safeguards for those transfers.
10. Changes to this policy
We may update this policy as the service evolves — for example when a new feature changes what we store. The "Last updated" date at the top always shows the current version, and material changes will be highlighted on the dashboard or by email.
11. Contact
Privacy questions, data requests and complaints: chunpulseyung@gmail.com.
Not financial advice. Pulse Cloud is an informational and educational portfolio-tracking tool. Nothing on this site — including prices, P&L figures, returns, stop-loss levels or AI-generated analysis — is financial, investment, tax or legal advice, and none of it is a recommendation to buy or sell any security. Market data may be delayed, incomplete or wrong. Always do your own research and consider consulting a licensed professional before making investment decisions.