Pulse Privacy Policy

Effective date: 5/22/25

At-a-glance (TL;DR)

  • We collect account details, usage analytics, and optional health inputs so that the Pulse apps can deliver personalised coaching and core functionality.
  • We rely on vetted processors—Clerk (authentication), Supabase (storage), Stripe (billing), OpenAI/Anthropic/Google via OpenRouter (model services), Mailgun (email), and Vercel (hosting & analytics)—under data protection agreements.
  • Cookies help keep you signed in and measure product performance; you can manage analytics preferences in-app or through your browser/device settings.
  • You can access, correct, delete, or export your information and opt out of marketing by emailing admin@progressiveperformancep2.com or using available account controls.
  • If you are a Coaching Client, your coaching-related photos/videos may be used for marketing and promotional purposes as described below and in our Terms.

1. Who we are

Progressive Performance Personal Training LLC ("Pulse," "we," "us," or "our") operates the Pulse web and mobile applications, the site located at https://pulse.progressiveperformancep2.com, and related coaching, analytics, and support services (collectively, the "Services"). We are the controller of personal data processed through the Services unless stated otherwise.

You can reach our privacy team at admin@progressiveperformancep2.com or via the contact details in Section 17.

2. Information we collect

CategoryExamplesHow we obtain itPrimary purposes
Identity & contact dataName, email address, preferred name, pronouns, timezoneProvided by you during sign-up or when updating your profileCreate and administer your account, deliver notifications, and provide customer support
Account & profile detailsFitness goals, training experience, availability, preferences, tags, team assignmentsDirectly supplied by you or your coach within the appPersonalise training plans, match you with coaches, and tailor content
Authentication & security metadataSession identifiers, multi-factor settings, device fingerprints, login historyGenerated automatically by Clerk and our systems when you access the ServicesSecure account access, detect suspicious activity, and troubleshoot authentication issues
Payment & subscription dataBilling name, billing email, payment method token, Stripe customer ID, invoices, refund historyCollected by Stripe when you subscribe or update billing preferencesProcess payments, manage renewals, comply with tax/financial regulations
Coach & support communicationsDirect messages, check-ins, attachments, progress reports, support ticketsSubmitted by you, your assigned coach, or generated through in-app collaboration toolsEnable coaching services, maintain conversation history, respond to support requests
Fitness & wellness inputsWorkout logs, nutrition entries, sleep and recovery notes, uploaded photos/videosEntered by you, imported from optional integrations, or uploaded through program featuresGenerate personalised plans, track progress, surface insights for you and your coach; and, for Coaching Clients, support testimonials and promotional use as described in Sections 3 and 7
Device & usage dataIP address, device/OS type, app version, event logs, crash diagnostics, cookie identifiersCollected automatically when you interact with the Services and via Vercel analyticsMaintain performance, debug issues, understand feature adoption, and secure the platform
Integrations & synced dataOptional connections such as Google Fit or other wearables, assistant-generated insights, imported schedulesShared only when you authorise integrations or upload files containing this informationAugment your training experience, automate data entry, and provide richer analytics

Sensitive or special-category data

Some information you choose to provide—such as training load, injuries, body measurements, or images—may constitute health or biometric data under applicable laws. We process this data to deliver the Services you request (including coaching, progress tracking, and analytics) and, where required by law, based on your explicit consent or other valid lawful basis. If you are a Coaching Client, additional terms may apply to coaching media and promotional use as described below and in our Terms.

Sources of data

We collect data directly from you, automatically through cookies and similar technologies, from your assigned coach or organisation administrators, and from third parties when you authorise integrations or when we receive analytics from service providers (e.g., Stripe, Clerk, Vercel).

3. How we use your data

Service delivery. We operate, maintain, and improve the Services, authenticate you, sync information across devices, and provide the training programs, community, and communication tools you request.

Personalisation & insights. We tailor programs, recommend adjustments, summarise progress, and surface insights to you and your coach (including via assistant and automated features).

Communications. We send transactional messages (e.g., account changes, program updates), respond to support requests, and—where permitted—deliver optional marketing or product education content.

Testimonials & promotional media (Coaching Clients). If you are a Coaching Client, we may use your coaching-related photos, videos, and related content for advertising, marketing, education, and promotional purposes in accordance with our Terms. Where required by law (including certain jurisdictions’ rules for sensitive data), we will obtain any additional consent required before using such content for marketing.

Analytics & product research. Aggregated or pseudonymised data helps us understand feature adoption, troubleshoot issues, and inform roadmap decisions. We do not sell personal information.

Safety, security & compliance. We monitor for abuse, enforce our Terms, protect the integrity of our systems, and comply with legal obligations or requests from competent authorities where required.

4. Legal bases (GDPR / UK GDPR)

Processing purposeKey dataLawful bases
Account creation and accessIdentity data, authentication identifiersContract (Art. 6(1)(b)); Legitimate interests for fraud prevention (Art. 6(1)(f))
Coaching, training, and assistant-guided recommendationsProfile information, program data, health inputs, chat contentExplicit consent for health/sensitive data (Art. 9(2)(a)); Contract (Art. 6(1)(b))
Payments, subscriptions, invoicingBilling profiles, transaction metadataContract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c))
Product analytics, quality, and reportingUsage events, device diagnosticsLegitimate interests (Art. 6(1)(f))
Marketing communicationsContact details, engagement metricsConsent (Art. 6(1)(a)); Legitimate interests for similar products (where permitted)
Security, fraud prevention, and enforcing policiesAuthentication metadata, usage logs, audit trailsLegitimate interests (Art. 6(1)(f)); Legal obligation (Art. 6(1)(c))
Handling legal requests or disputesRelevant account, payment, and communication recordsLegal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f))

5. Third-party processors & integrations

ProviderService providedData sharedProcessing regions
ClerkAuthentication, user management, multi-factor securityIdentifiers, login metadata, device informationUnited States and other regions per Clerk's infrastructure
SupabaseDatabase, file storage, backupsProgram data, profile content, uploaded mediaUnited States or EU datacenters depending on deployment
StripePayment processing, invoicing, subscription managementBilling identifiers, transaction metadata, partial payment method detailsUnited States and other locations consistent with Stripe's global services
OpenAILLM-powered chat, plan generation, and analysisPrompts, contextual data, generated responsesUnited States (with global infrastructure per provider policies)
AnthropicAutomated reasoning and summarisationChat transcripts, structured prompts, plan summariesUnited States (subject to Anthropic's regional hosting commitments)
Google (via OpenRouter)Gemini model access for program analysis and insightsPrompts, anonymised workout context, generated outputsUnited States and other regions described in OpenRouter/Google terms
OpenRouterModel routing, retries, and fallbacks across model providersPrompts and metadata necessary to fulfil assistant requestsUnited States (per OpenRouter documentation)
MailgunTransactional and operational email deliveryEmail address, message content, delivery metadataUnited States and EU regions used by Mailgun
VercelHosting, edge delivery, first-party analyticsIP addresses, usage metrics, device/browser detailsGlobal CDN locations managed by Vercel

We require each processor to protect personal data and only process it on our documented instructions.

6. International data transfers

If personal data is transferred outside your jurisdiction (for example, to the United States), we rely on appropriate safeguards such as Standard Contractual Clauses, service-provider certifications, or your explicit consent where applicable.

7. How we use assistant and automated features

Pulse routes certain prompts, progress summaries, and plan data to OpenAI, Anthropic, and Google Gemini (via OpenRouter) to generate recommendations or analyses. These requests are sent using server-side API keys and include only the context required to provide the requested response. We implement controls to avoid storing prompts longer than necessary and rely on our providers' published API terms, which state that submitted data is not used to train their public models. If this ever changes, we will update this notice and provide you with choices before continuing the processing.

Assistant outputs may occasionally be inaccurate or incomplete. Coaches review critical recommendations, and users should apply personal judgement when acting on automated suggestions.

7A. Mental Health Scope & emergency disclaimer

The Services may include mindset, behaviour-change, wellness, or similar coaching content, reflective exercises, educational materials, and check-ins. These are educational and supportive only.

The Services are not psychotherapy, clinical mental health treatment, medical care, or crisis intervention, and are not intended to diagnose, treat, prevent, or cure any mental health condition. Use of the Services does not create a therapist–client or doctor–patient relationship.

We are not an emergency resource. If you are in crisis or at risk of harming yourself or others, call 911 (or your local emergency number) or go to the nearest emergency department.

8. Cookies & analytics

  • Essential cookies. Clerk authentication cookies keep you signed in and maintain session security. These are required for the Services to function.
  • Analytics. We use Vercel Web Analytics and in-app telemetry to understand usage trends. These rely on pseudonymous IDs and aggregated reporting.
  • Your controls. You can adjust analytics preferences in available account settings, decline optional cookies via browser/device tools, or use private-browsing modes. Some features may not function without essential cookies.

9. Security

  • Data is transmitted over HTTPS/TLS and stored in Supabase with encryption at rest. Access to production systems requires authenticated service accounts and role-based permissions.
  • Application logs and audit trails help us monitor unusual activity. Automated checks detect anomalies such as rapid login attempts or suspicious API usage.
  • We regularly review access privileges, patch dependencies, and follow secure coding practices. No system is completely secure; please notify us immediately at the contact information below if you suspect unauthorised access.

10. Data retention

We keep personal data only for as long as necessary to provide the Services and fulfil the purposes outlined above. Typical retention periods include:

  • Account records. Retained while your account is active and for up to 24 months after closure to support audits, dispute resolution, and backups.
  • Payment data. Stored in Stripe according to statutory financial retention requirements.
  • Coach communications & uploads. Retained while you or your organisation maintain access, then deleted or anonymised during scheduled cleanup.
  • Analytics logs. Aggregated and minimised on a rolling basis, typically within 13 months.

Backups may persist for limited periods consistent with our disaster-recovery processes before they are overwritten.

11. Your privacy rights

EU/UK individuals. You may request access, rectification, erasure, restriction, portability, or object to processing. Where we process data based on consent, you may withdraw it at any time without affecting prior lawful processing.

United States residents. Residents of California, Colorado, Connecticut, Utah, Virginia, and other states with privacy laws may exercise rights to know, delete, correct, opt out of targeted advertising or "sharing," and appeal declined requests.

All users. You can manage marketing communications, update profile information, and request deletion of sensitive uploads through in-app settings or by contacting us.

12. Exercising your rights

Submit privacy requests by emailing admin@progressiveperformancep2.com. We will verify your identity (or agency if acting on behalf of another individual) before fulfilling the request. We aim to respond within 30 days and will explain any extension or denial along with available appeal options.

13. Preference signals & Do Not Track

We honour browser- or device-based opt-out signals (such as Global Privacy Control) for applicable jurisdictions by disabling targeted advertising features and limiting analytics to essential measurements. We do not currently respond to legacy "Do Not Track" headers where no consistent industry standard exists.

14. Automated decision-making

Pulse does not make decisions with legal or similarly significant effects solely through automated processing. Coaches and users can review and override automated suggestions before they are applied to training programs.

15. Children

The Services are designed for individuals 18 years and older. We do not knowingly collect personal data from children. If you believe a child has provided personal data, please contact us so we can delete it.

16. Changes to this policy

We may update this Privacy Policy to reflect changes in laws, Services, or data practices. When we make material changes, we will notify you via email or in-app alerts at least 30 days before the new policy takes effect and indicate the updated effective date.

17. Contact us

Email: admin@progressiveperformancep2.com

Progressive Performance Personal Training LLC

2110 Dry Ridge Rd, Grove City, Ohio, 43123

Pulse