Controller: David Sedacca, sole proprietor, United States
Contact: privacy@pulselist.io
Applies to: PulseList for iPhone, version 1.0
Offered in: the United States first, then further markets
The controller is established in the United States, and the app is sold in the United States first. Which privacy law governs is decided by where the controller is and where the people using it are — not by which storefront the download came from. §7 sets out the rights that follow.
Last updated: 19 August 2026
PulseList reads things on your iPhone — the screenshots and photos you choose, the
Reminders lists you tick, the calendars you tick — and turns them into one short list of
what needs you. All of that happens on your iPhone.
This version of PulseList contains no code that can reach the internet. There is no
account, no server, no sync and no analytics. Nothing you photograph, type, say or connect
is sent anywhere, because there is nowhere for it to be sent.
That is not a promise about our intentions. It is a property of the app, and it is checked
on every build: scripts/check-no-network.sh fails the build if any part of the shipped
app so much as references a networking symbol, and scripts/proof-egress.sh watches the
running app and reports every network socket it holds. It holds none.
We are the controller for the limited purposes described here. **In practice, in this
version, we hold nothing about you at all.** We have no account for you, no email address,
no identifier and no copy of anything you capture. If you deleted the app right now, there
would be nothing anywhere for us to delete, because nothing ever left your phone.
Each of these is a separate decision you make, and PulseList works without any of them.
| What | When | Why |
|---|---|---|
| A photo you hand over | You tap and pick one | Read the text on it. Uses Apple's picker, which runs outside PulseList and returns only the picture you chose. No photo-library permission is involved. |
| Your photo library | Only if you connect it | Find recent screenshots and photos so you do not have to hand each one over. Read-only in use; iPhone offers no read-only setting for photos, so the permission you grant is wider than what PulseList does with it. |
| Apple Reminders | Only the lists you tick | Show reminders you already keep alongside everything else. PulseList never writes to Reminders. |
| Apple Calendar | Only the calendars you tick | Show the few events that ask something of you before they happen. PulseList never adds, changes or deletes an event. |
For Reminders and Calendar, iPhone's permission is wider than our use of it. We enforce
read-only in our own code and prove it on every build by inspecting the shipped binary for
write calls, rather than asking you to take our word for it.
On your iPhone, using text recognition built into iOS. No text, image, reminder or event is
sent off the device for processing, and no artificial-intelligence service is contacted,
because the app cannot contact anything.
Stored on your iPhone only, in a container shared between PulseList and its widget:
account numbers and similar are detected and covered before anything is analysed or
saved;
Photos;
It stays until you delete it or delete the app. There is an in-app control that erases
everything and tells you what it erased.
Detection is automated and not perfect, so PulseList masks more than it needs to rather
than less. We do not claim that all sensitive data is removed.
PulseList Plus is sold through Apple's In-App Purchase. **Apple processes the payment; we never
see your card, your address or your Apple Account.** Apple tells us only whether a
subscription is active, and that check happens on your device. Apple's own privacy policy
governs what Apple collects.
Under the CCPA/CPRA in California, and under the comparable state privacy laws now in
force elsewhere in the United States, you have rights to know, to delete, to correct, and
to opt out of the sale or sharing of your personal information. **We sell and share
nothing, and we have nothing to disclose, because we hold nothing.** We do not process
your information for targeted advertising, and we do not profile you.
You can exercise the substance of these rights on the device rather than by asking us:
export everything PulseList holds as a file, or erase all of it, from within the app.
Because it never leaves your iPhone, that export and that deletion are complete — there is
no copy of ours for us to find.
If you believe we hold personal information about you despite the above, write to
privacy@pulselist.io and we will respond within the period the applicable law allows. You
may also complain to your state's Attorney General.
If you are in the UK or the EU, the GDPR may apply to us because we offer the app to
you, and it gives you further rights — access, rectification, erasure, restriction,
portability and objection — together with the right to complain to your national
supervisory authority. The same answer applies: we hold nothing, and the app is where you
exercise them.
No sub-processors. No analytics provider, no crash reporter, no advertising network, no
cloud service. Apple is involved as the platform and as the payment processor, on its own
terms.
PulseList is not directed at children under 13 and we do not knowingly process their data.
None are engaged, because no personal data is transferred anywhere.
If a future version of PulseList can reach the internet, this policy changes before that
version ships, and anything that widens what is accessed will ask you again rather than
relying on a permission you granted for something narrower.