Privacy Policy
Last updated: 2026-05-04
What we collect
PulseBoard collects only what we need to provide the service: your name, email, Google OAuth subject ID, the organisation you belong to, and the daily updates and tickets you create.
What we don't collect
We don't track you across the web. We don't sell data. We don't train LLMs on your data — even when you bring your own LLM key.
Data residency
PulseBoard runs in a single region in the United States. We do not currently offer EU residency, an India region, or a self-hosted deployment. If region matters to you, ask us before you sign up rather than after.
PulseBoard is operated by an Indian entity, so for Indian customers this is a cross-border transfer. India's Digital Personal Data Protection Act, 2023 permits transfers except to countries restricted by government notification, and the United States is not currently restricted.
Sub-processors
- Vercel — application hosting
- Neon — the Postgres database your organisation's data lives in
- OpenAI — writes digests, classifies blockers, and drafts client reports
- Resend — transactional email delivery
- Google and Microsoft — only if you choose to sign in with them
Your rights
Export your tickets, time, people, projects and clients as CSV from the buttons on those pages. For deletion, or for anything the export does not cover, email privacy@pulseboard.io for any request.
Your rights under the DPDP Act (India)
If your employer uses PulseBoard, they are the Data Fiduciary and we process on their instructions — so access, correction and erasure requests are answered by them, and we assist. You may still raise a grievance with us directly, and we will acknowledge it and respond within the period the Act requires.
Contact
Data Protection Officer: dpo@pulseboard.io
Grievance Officer (DPDP Act, 2023): grievance@pulseboard.io. The Act requires a named individual here before we take Indian customers — that name must replace this address before launch.