Version: 1.0.0
Last updated: 26 August 2026
1. Who we are and what this Policy covers
Sadra Makhmali is the individual controller and operator of the Pulsing service under the name “Pulsing” (“Pulsing,” “we,” “us,” or “our”). This Policy applies to the Pulsing mobile applications, websites, APIs, administrative services, and related communications that link to it (the “Services”).
Contact: team@pulsegroup.top
Safety reports: info@pulsegroup.top
2. Personal data we collect
Account and authentication data
We process your mobile number, one-time-code challenge and delivery status, account identifiers, username, acceptance and onboarding status, session identifiers, device and app information, login and logout history, and security events. One-time codes are protected and short-lived; we do not store them as readable authentication credentials.
Profile and discovery data
Depending on what you provide and the features you use, we process your display name, username, profile image, biography, links, birth date, gender, profession, interests, account visibility, subscription and verification status, selected locations, and privacy preferences. Public-profile and Pulse information is visible to the audience shown in the product. Private-profile access remains subject to the connection and privacy rules described in the Services.
Pulse, matching, and location data
We process the goals, descriptions, categories, timing, audience, participation preferences, profession and interest selections, and location information attached to Pulses. We use these data to publish Pulses, apply eligibility and privacy rules, generate matching and discovery results, and display map results. Private map results use an approximate, privacy-protective location rather than exposing the stored coordinate directly, but no location-sharing feature can eliminate all risk.
Connections, messages, and safety data
We process connection requests and status, conversations, messages, replies, delivery and read state, blocks, reports, report details, moderation decisions, appeals or support correspondence, and limited evidence needed to protect users and enforce the Terms. Hiding or deleting a conversation from your view does not necessarily erase the shared message record. Messages may be retained for safety, dispute, fraud-prevention, legal, and service-integrity purposes. The ordinary administrative dashboard does not provide staff with a message-reading feature, but we may preserve or disclose relevant records where required or permitted by law.
Verification data
For optional verification, we may process a contact email, email one-time-code status, location, profession, interests, consent version, provider outcome, verified birth date, and verified gender. A submitted national code is used transiently to call the identity-verification provider and is not stored, hashed, placed in analytics, or intentionally logged by Pulsing. Names and the raw identity response returned by that provider are discarded. After successful verification, the verified birth date and gender may be retained and locked to protect the integrity of the verification result.
Payments and subscriptions
We process product, store or payment-provider identifiers, purchase and subscription status, transaction references, entitlement periods, limited verification results, refunds or reversals, and anti-fraud records. Payment-card or bank-account credentials are collected by the relevant payment provider or app store, not by Pulsing.
Media and files
We process profile images and other media you choose to upload, including technical metadata needed to validate, store, resize, deliver, secure, and delete those files. Do not upload identity documents or sensitive information unless a feature expressly requests them.
Notifications and communications
We process push-registration tokens, notification preferences, delivery status, email address where a feature requires it, unsubscribe state, and communications you request or consent to receive. Marketing messages are sent only where permitted and include the available opt-out method. Operational, safety, or account-security messages may still be sent when necessary to provide the Services.
Pre-registration data
If you pre-registered, we process the contact information and requested username supplied at registration, reservation status and dates, import or validation status, and related communication history. We use this information to protect the reserved username, contact you about availability, and complete the pre-registration scenario described when you registered.
Technical and security data
When you use the Services, we process connection and request metadata such as IP address or a privacy-protective derivative, timestamps, language and locale, app version, device and platform information, response status, rate-limit signals, crash or error context, and security events. We limit production logs and redact authentication codes, national codes, secrets, and other fields that are not needed for operations.
Landing-site data
The public pulsegroup.top landing site does not currently provide account creation or advertising cookies. Its hosting, DNS, and security providers may nevertheless process ordinary web-request data such as IP address, browser information, requested URL, and security signals to deliver and protect the site.
3. How we obtain data
We obtain data directly from you, automatically from your device and use of the Services, from another user when they interact with or report you, from a pre-registration record you previously submitted, and from service providers such as app stores, payment processors, identity-verification providers, messaging providers, and security or infrastructure providers.
4. Why we process personal data
We process personal data to:
Create, authenticate, secure, and recover accounts and sessions;
Provide profiles, Pulses, discovery, matching, connections, chat, notifications, verification, subscriptions, and support;
Respect visibility, blocking, safety, and communication preferences;
Detect abuse, fraud, prohibited content, security incidents, and violations of the Terms;
Review reports, enforce decisions, preserve evidence, and protect the rights and safety of users and others;
Process purchases, validate entitlements, reconcile provider events, and maintain financial and audit records;
Operate, troubleshoot, measure, back up, restore, and improve the Services;
Send requested service, security, support, and consented marketing communications;
Comply with law, valid legal process, regulatory duties, and the establishment, exercise, or defence of legal claims.
Depending on the context and applicable law, we rely on performance of our agreement with you, your consent, compliance with legal obligations, protection of vital interests, and our legitimate interests in providing, securing, improving, and enforcing the Services. Where consent is required, you may withdraw it for future processing, but this does not make earlier lawful processing invalid.
5. Automated systems and AI providers
Pulsing uses rules and automated systems to rank or suggest Pulses and people, enforce eligibility and privacy, detect suspicious activity, and assist with content moderation. When the AI features are enabled, the text of usernames, biographies, or Pulse intent and description fields may be sent to our configured AI service provider for moderation or intent analysis. We do not use verification national codes for AI processing. Automated output can be incomplete or wrong; reports and available review processes help us correct material errors.
6. When data is shared
Other users and the public
Information you publish is shared with the audience indicated in the Services. Connection, privacy, subscription, verification, blocking, and discovery rules may change which fields another user can see. Recipients may copy information despite our rules, so do not publish data that is unnecessary for the interaction.
Processors and service providers
We share only the data reasonably needed for providers to perform services for us. Depending on the enabled feature, these providers include ArvanCloud for compute, content delivery, object storage, and AI services; Cloudflare for DNS, content delivery, web security, landing-site hosting, and inbound email routing; Kavenegar for SMS delivery; Mailerino for email delivery; Google Firebase for push notifications; api.ir for identity verification; and Apple, Google Play, Cafe Bazaar, SibApp, Zarinpal, or other displayed stores and payment providers for purchase validation and payment processing.
Professional advisers and authorities
We may disclose relevant information to professional advisers, insurers, auditors, courts, regulators, law enforcement, emergency services, or other competent authorities when legally required or permitted, necessary to respond to an imminent safety threat, or necessary to establish, exercise, or defend legal claims.
Business changes
If the Services or their assets are reorganized, financed, sold, or transferred, data may be disclosed under appropriate confidentiality and legal protections. We will provide notice where required.
We do not sell personal data. We do not permit providers to use personal data for their own direct marketing on our behalf unless you have received the required notice and choice.
7. International processing and transfers
Pulsing and its providers may process data in Iran, the United Arab Emirates, the European Economic Area, the United States, or other countries in which the relevant provider operates. These countries may have different privacy laws. Where applicable law requires a transfer mechanism or additional safeguards, we use contractual, technical, organizational, consent-based, or other legally recognized measures appropriate to the transfer. Internet routing and content-delivery networks may process technical request data in several locations.
8. Retention and deletion
We retain personal data only for as long as reasonably needed for the purposes described in this Policy, including while your account is active and for applicable safety, fraud-prevention, accounting, backup, dispute, and legal periods afterward. Retention differs by category:
One-time-code and temporary idempotency records expire automatically after short operational periods;
Sessions expire or are revoked under the configured security periods, while a limited authentication history may remain for account security;
Temporary AI-processing media is scheduled for deletion after the configured short processing window;
Media that you specifically remove or replace is detached from your profile and scheduled for storage cleanup. Account deletion makes account media unavailable through ordinary account use, while stored records or objects may remain for the limited retention grounds in this section;
Billing, verification outcome, moderation, safety, and audit records may remain longer when needed for integrity, fraud prevention, legal compliance, or claims;
Messages and shared conversation records may remain after a user hides or deletes their local view, as described above;
Backups are protected and rotate under an operational retention schedule; deleted data disappears from backups as those copies expire unless preservation is legally required.
You can request account deletion in the application. Deletion revokes active sessions and removes or deactivates account data from ordinary use, but does not override the limited retention grounds above. You must cancel app-store subscriptions separately where the store requires it.
9. Your choices and rights
Depending on applicable law, you may have rights to receive information about processing; access or obtain a copy of your data; correct inaccurate data; delete data; restrict or object to processing; withdraw consent; receive portable data; and complain to a competent authority. Some rights are subject to lawful exceptions, including the rights and safety of others, fraud prevention, legal obligations, and legal claims.
You can update many profile and privacy fields in the application, manage sessions and notifications, block users, request account deletion, and use email unsubscribe controls. To make another privacy request, contact team@pulsegroup.top from information reasonably capable of verifying your account. We will not ask you to send a one-time login code, password, or unnecessary identity document by email.
10. Security
We use technical and organizational safeguards appropriate to the nature and risk of the data. These include access controls, encryption for selected sensitive fields and communications, secret management, network restrictions, rate limiting, abuse protection, logging controls, backups, patching, and separation of public and private storage. No system or transmission is completely secure. Protect your device and one-time codes, close unknown sessions, and report suspected compromise promptly.
11. Age limit
The Services are for adults aged 18 or older. We do not knowingly provide the Services to children. If we learn that an underage person has created an account contrary to the Terms, we may restrict the account and take appropriate deletion or preservation steps. A verification flow that detects an under-18 result may retain only the bounded records needed to enforce the age restriction and determine when eligibility can be reconsidered.
12. Changes to this Policy
We may update this Policy as the Services, providers, or law change. We will update the version and date and provide appropriate notice of material changes. Where law requires consent for a new processing purpose, we will seek it before that processing begins.
13. Contact
Controller and operator: Sadra Makhmali, an individual operating Pulsing
Privacy and general requests: team@pulsegroup.top
Safety reports: info@pulsegroup.top