PulseList
Current as of 19 August 2026, and under legal review. If anything here changes, that date changes with it.

PulseList — Privacy Policy

Controller: David Sedacca, sole proprietor, United States

Contact: privacy@pulselist.io

Applies to: PulseList for iPhone, version 1.0

Offered in: the United States first, then further markets

The controller is established in the United States, and the app is sold in the United States first. Which privacy law governs is decided by where the controller is and where the people using it are — not by which storefront the download came from. §7 sets out the rights that follow.

Last updated: 19 August 2026


1. The short version

PulseList reads things on your iPhone — the screenshots and photos you choose, the

Reminders lists you tick, the calendars you tick — and turns them into one short list of

what needs you. All of that happens on your iPhone.

This version of PulseList contains no code that can reach the internet. There is no

account, no server, no sync and no analytics. Nothing you photograph, type, say or connect

is sent anywhere, because there is nowhere for it to be sent.

That is not a promise about our intentions. It is a property of the app, and it is checked

on every build: scripts/check-no-network.sh fails the build if any part of the shipped

app so much as references a networking symbol, and scripts/proof-egress.sh watches the

running app and reports every network socket it holds. It holds none.

2. Are you a "controller", and what do you hold?

We are the controller for the limited purposes described here. **In practice, in this

version, we hold nothing about you at all.** We have no account for you, no email address,

no identifier and no copy of anything you capture. If you deleted the app right now, there

would be nothing anywhere for us to delete, because nothing ever left your phone.

3. What PulseList accesses on your device, and why

Each of these is a separate decision you make, and PulseList works without any of them.

WhatWhenWhy
A photo you hand overYou tap and pick oneRead the text on it. Uses Apple's picker, which runs outside PulseList and returns only the picture you chose. No photo-library permission is involved.
Your photo libraryOnly if you connect itFind recent screenshots and photos so you do not have to hand each one over. Read-only in use; iPhone offers no read-only setting for photos, so the permission you grant is wider than what PulseList does with it.
Apple RemindersOnly the lists you tickShow reminders you already keep alongside everything else. PulseList never writes to Reminders.
Apple CalendarOnly the calendars you tickShow the few events that ask something of you before they happen. PulseList never adds, changes or deletes an event.

For Reminders and Calendar, iPhone's permission is wider than our use of it. We enforce

read-only in our own code and prove it on every build by inspecting the shipped binary for

write calls, rather than asking you to take our word for it.

4. Where processing happens

On your iPhone, using text recognition built into iOS. No text, image, reminder or event is

sent off the device for processing, and no artificial-intelligence service is contacted,

because the app cannot contact anything.

5. What is stored, and for how long

Stored on your iPhone only, in a container shared between PulseList and its widget:

account numbers and similar are detected and covered before anything is analysed or

saved;

Photos;

It stays until you delete it or delete the app. There is an in-app control that erases

everything and tells you what it erased.

Detection is automated and not perfect, so PulseList masks more than it needs to rather

than less. We do not claim that all sensitive data is removed.

6. Payments

PulseList Plus is sold through Apple's In-App Purchase. **Apple processes the payment; we never

see your card, your address or your Apple Account.** Apple tells us only whether a

subscription is active, and that check happens on your device. Apple's own privacy policy

governs what Apple collects.

7. Your rights

Under the CCPA/CPRA in California, and under the comparable state privacy laws now in

force elsewhere in the United States, you have rights to know, to delete, to correct, and

to opt out of the sale or sharing of your personal information. **We sell and share

nothing, and we have nothing to disclose, because we hold nothing.** We do not process

your information for targeted advertising, and we do not profile you.

You can exercise the substance of these rights on the device rather than by asking us:

export everything PulseList holds as a file, or erase all of it, from within the app.

Because it never leaves your iPhone, that export and that deletion are complete — there is

no copy of ours for us to find.

If you believe we hold personal information about you despite the above, write to

privacy@pulselist.io and we will respond within the period the applicable law allows. You

may also complain to your state's Attorney General.

If you are in the UK or the EU, the GDPR may apply to us because we offer the app to

you, and it gives you further rights — access, rectification, erasure, restriction,

portability and objection — together with the right to complain to your national

supervisory authority. The same answer applies: we hold nothing, and the app is where you

exercise them.

8. Who else is involved

No sub-processors. No analytics provider, no crash reporter, no advertising network, no

cloud service. Apple is involved as the platform and as the payment processor, on its own

terms.

9. Children

PulseList is not directed at children under 13 and we do not knowingly process their data.

10. International transfers

None are engaged, because no personal data is transferred anywhere.

11. Changes

If a future version of PulseList can reach the internet, this policy changes before that

version ships, and anything that widens what is accessed will ask you again rather than

relying on a permission you granted for something narrower.