Pulsa is built around one rule: everything you see was made by a verified human. That same premise shapes this policy — we collect the minimum needed to prove a human is behind an account and a photo, and we don't sell, advertise against, or algorithmically mine what you share.
1. Information we collect
1.1 Information you provide directly
- Phone number. Your phone number is how you sign in — Pulsa sends a one-time code by SMS instead of using a password. It's also how a friend can find you if they already have your number (see 1.4).
- Profile information. Display name (required), bio and avatar photo (both optional). Editable any time from your profile.
- Posts. Text (up to 2,000 characters) and photos you choose to share. Every post is linked to the account that made it — Pulsa has no anonymous or pseudonymous posting.
- Reports and blocks. If you report a post or account, we store the reason you selected, and any additional detail you write. If you block someone, we record that relationship.
1.2 Identity verification (liveness check)
Before you can post, Pulsa confirms there's a live person behind the account with an on-device liveness check: a short camera capture that on-device machine-learning models (bundled in the app, not run on our servers) analyze to confirm a real, live face is present — the kind of check that catches a photo held up to the camera or a pre-recorded video.
That capture never leaves your device. Pulsa's servers only ever receive the pass/fail result and a numeric confidence score — never the image or video itself. We do not build a face template, and we do not use this check to identify you against other people or other services.
If Pulsa later reintroduces a hosted identity-verification option — for example, government-ID checks through a third-party provider — that provider would process any submitted images under its own privacy commitments, including deleting raw biometric data within 24 hours, and this policy will be updated first. That path is not active today.1.3 Device attestation
When you take a photo to post, Pulsa asks your device to cryptographically prove the upload is coming from a genuine, untampered copy of the Pulsa app on genuine hardware — Apple's App Attest on iOS, Google's Play Integrity on Android. This produces a per-install cryptographic key and a signed assertion tied to that specific photo upload. It is a statement about the app and device, not about you personally, and it is not linked to any biometric data.
Separately, if your phone offers Face ID or fingerprint unlock, we use it only to gate your own device's keychain entry that holds your Pulsa session — that check happens entirely on your device, using your OS's own biometric system. Pulsa's servers never receive, store, or compare any biometric data.
1.4 Information from other users, and finding people you know
- If someone looks you up by your exact phone number to connect on Pulsa, we log that they searched (who, and when) so we can rate-limit and detect abuse — we do not log what number they searched. Lookups are capped at 20/hour per person and require the searcher to be a verified account.
- If someone invites you to Pulsa, that happens through your phone's own share sheet — Pulsa's servers are not involved and receive nothing from that invite.
- If another user reports you or your content, we retain that report (see 1.1) for moderation review, described in Section 4.
1.5 Information collected automatically
- Session data. A bearer token identifying your signed-in session, stored in your device's OS keychain, rotated periodically.
- Standard request data. Like most APIs, our servers process the technical data inherent in any request (IP address, timestamps) as part of normal operation and abuse prevention; we do not build advertising or tracking profiles from it.
2. How we use your information
We use the information above to:
- create and secure your account, and sign you in (phone number, session tokens);
- confirm you're a real, verified human before letting you post (liveness result, device attestation);
- show your posts, profile, and follow relationships to other Pulsa users;
- let you find people you already know (phone lookup) and be found the same way;
- respond to and act on reports, and keep the app safe (Section 4);
- operate, maintain, and secure the service generally.
We do not use your information for advertising, and we do not sell it. Pulsa has no ad business — the only revenue is an optional paid subscription. We also do not run any algorithmic ranking or recommendation system on your content or feed: the feed is strictly chronological, and there is currently no automated system that scores, flags, or analyzes your posts for content — reported content is reviewed by a human moderator (Section 4).
3. What's visible to other people on Pulsa
Pulsa is a social app, not a private messaging tool — some information is inherently shared with other users as part of using it:
- Your display name, avatar, bio, and posts (text and photos) are visible to other signed-in Pulsa users through your profile, unless you and they have blocked each other.
- Your follower and following counts and lists are visible the same way.
- The chronological feed shows your posts to accounts that follow you (and your own posts back to you); anyone signed in can also see your public profile and post history, subject to the block rule above.
Photo files themselves are never publicly hosted — they're served through short-lived signed links (15 minutes) rather than public URLs, so access can't be replayed indefinitely or scraped from outside the app.
4. Blocking, reporting, and moderation
- Blocking someone removes any follow relationship between you in both directions and prevents a new one; once blocked, you and the other account are invisible to each other everywhere in the app (profile, posts, search, phone lookup).
- Reporting a post or account sends it to a review queue handled by human moderators. Reports are rate-limited to prevent abuse of the report system itself. A report of illegal or violent content against a post hides that post immediately pending review; reporting an account does not automatically restrict it — only a moderator's decision does.
- Moderator actions (dismiss, remove content, warn, suspend, or ban) are recorded against the report. A suspension or ban immediately ends all of that account's active sessions.
6. Data retention and deletion
- You can edit your profile at any time, and delete individual posts you've authored (author-only, immediate).
- Deleting your account (available directly in the app, under Profile) is immediate and permanent. It removes your account and cascades to your sessions, posts, follows, device keys, phone-lookup logs, reports you filed, blocks, verification records, and your uploaded photo files. There is no undo, grace period, or recovery once you confirm deletion.
- Liveness capture (Section 1.2) is never stored by us in the first place — only the pass/fail outcome and confidence score persist, tied to your verification status.
- Photos that end up attached to no post (an abandoned upload, or the photos of a deleted post) are cleaned up automatically by a background process rather than kept indefinitely.
7. Your choices and rights
- Access and correction: your profile information is visible and editable to you at any time in the app.
- Deletion: delete your account at any time (Section 6).
- Blocking: block anyone unilaterally; it is immediate and does not notify the blocked person.
- Depending on where you live, you may have additional rights — for example, to obtain a copy of your data, or to object to certain processing — under laws like the GDPR (EEA/UK) or the CCPA (California). pending — applicable regimes and region-specific mechanics not yet confirmed To exercise these, contact us at privacy@humanly.one.
8. Children's privacy
Pulsa is not directed at children and is not intended for use by anyone under 13. We do not knowingly collect information from children under that age. pending — revisit if store age-rating review pushes Pulsa to 17+/Mature
9. International data transfers
Pulsa's API and database infrastructure (Section 5) run in São Paulo, Brazil for both staging and production. If you use Pulsa from outside Brazil, your information is transferred to and processed there. pending — production database region not yet provisioned; add transfer-mechanism language (e.g. SCCs) if Pulsa launches in the EEA/UK
10. Security
We use industry-standard measures to protect your information, including encryption in transit, keychain-backed session storage on your device, short-lived signed URLs for photo access rather than public hosting, and cryptographic device attestation before accepting photo uploads. No system is perfectly secure, and we can't guarantee absolute security.
11. Changes to this policy
We'll update this policy as Pulsa's features change — for example, before launching planned features like in-person event discovery or on-device screen-time insights, both of which are committed (per Pulsa's product principles) to minimal, on-device-first data handling and will be described here before they ship. We'll update the "Last updated" date above when we do, and for material changes we'll provide more prominent notice in the app.
12. Contact us
Questions about this policy or your information: privacy@humanly.one.
General support: support@humanly.one.
Pulsa is operated by Marani Informativo, Rua Dante Millarch, 175, sob. 03, Santa Felicidade, Curitiba - PR, 82015-670, Brazil.