Privacy Policy
Last updated: August 17, 2026
This Privacy Policy explains how PulseBooks ("we", "us") collects, uses, stores, and shares information when you use our websites and applications (collectively, the "Service"). By using the Service, you agree to this Policy together with our Terms of Service.
1. Who we are
The data controller for the Service is the entity operating PulseBooks as identified in your agreement or checkout. For EU/UK users, you may contact us regarding privacy using the details provided in the product or on our website.
2. Information we collect
- Account data: name, email, profile image (if you use a provider such as Google), password or auth tokens, and organisation membership.
- Financial and business data: transactions, invoices, clients, products, uploads (for example receipts), and content you enter into the Service.
- Payment data: subscriptions and billing are processed by our payment partner (for example Polar). We receive limited billing metadata (plan, status, customer identifiers) but not your full card details, which are handled by the payment provider.
- Technical data: IP address, device and browser type, logs, cookies, and similar technologies as described in our Cookie Policy.
- Support: information you provide when you contact support.
- Connected-assistant data: OAuth connection details, permissions you approve, and requests made through the Model Context Protocol (MCP).
3. How we use information
We use personal data to:
- Provide, operate, and improve the Service.
- Authenticate users, manage organisations, and enforce security.
- Process subscriptions, invoices, and communicate about billing.
- Send service-related messages (for example security alerts); marketing only where permitted and with consent where required.
- Comply with law, respond to lawful requests, and protect rights and safety.
- Analyse usage in aggregate or de-identified form to improve the product.
- Process receipts and bank statements with an AI model when you choose an OCR or statement import feature, so we can extract transaction details for your review.
4. Legal bases (EEA/UK)
Where GDPR applies, we rely on:
- Performance of a contract (providing the Service you signed up for).
- Legitimate interests (security, product improvement, billing), balanced against your rights.
- Consent where required (for example certain cookies or marketing).
- Legal obligation where we must retain or disclose data.
5. Sharing and subprocessors
We share data with:
- Service providers who host infrastructure, send email, process payments, provide analytics, or support customer service, under contractual safeguards.
- AI processing provider: when you use receipt OCR or PDF bank-statement import, PulseBooks sends the uploaded receipt or statement content to Anthropic for extraction. Review the extracted information before saving it to your books.
- Connected assistants: an assistant you connect through MCP can read or change organisation data only within the permissions granted to that connection. This can include transactions, invoices, clients and contacts, agreements, reports, and files. Connections can be reviewed or revoked in Settings.
- Organisation admins for data belonging to your organisation, as designed in the product.
- Authorities when required by law or to protect rights.
- Business transfers in connection with a merger, acquisition, or asset sale, with notice where required.
6. International transfers
We may process data in countries other than where you live. Where we transfer personal data from the EEA, UK, or Switzerland, we use appropriate safeguards such as standard contractual clauses where required.
7. Retention
We retain data for as long as your account is active and as needed to provide the Service, comply with law, resolve disputes, and enforce agreements. You may request deletion subject to legal retention requirements.
8. Security
We implement technical and organisational measures designed to protect personal data. No method of transmission or storage is completely secure; we encourage strong passwords and safeguarding your account.
9. Your rights
Depending on your location, you may have rights to:
- Access, correct, or delete your personal data.
- Object to or restrict certain processing, or request portability.
- Withdraw consent where processing is consent-based.
- Lodge a complaint with a supervisory authority.
Contact us to exercise these rights. We will respond within the timeframes required by law.
10. Children
The Service is not directed at children under 16 (or the age required in your jurisdiction). We do not knowingly collect personal data from children.
11. Changes
We may update this Policy and will revise the "Last updated" date. Material changes may be notified by email or in-product notice.
12. Contact
For privacy requests or questions, use our support page.