Legal
Privacy Policy
Who we are
EchoPulse is developed and operated by Khurram Ayubi Butt, an individual based in Canada. When this policy says "we," "us," or "our," it means Khurram Ayubi Butt personally.
If you have any questions about this policy or your data, email khurram.ayubi@yahoo.com.
What we collect
EchoPulse collects only what it needs to work. Nothing is collected for advertising or sold to third parties.
- Account information. When you sign in, we receive either an email address (email/password sign-in), an Apple-issued user identifier (Sign in with Apple), or a Google account identifier (Sign in with Google). Apple may provide a private relay email address rather than your real one — that is Apple's privacy feature, not ours.
- Your avatar photo. If you choose to upload a profile photo, both the cropped version and the full original are stored on our servers. Your partner can see your avatar.
- Your timezone. We record your device's timezone identifier so that period keys and countdowns work correctly in your local time. This is updated each time you open the app.
- Your approximate location. If you enable weather or distance context, we store your last known latitude and longitude. This is used to fetch your local weather (via Apple WeatherKit) and to calculate the distance between you and your partner in kilometres. Your raw coordinates are never shown to your partner — only the computed distance and weather summary are.
- Your pulses. Each pulse you send includes: a moment type, a mood, and optionally a note (text), a photo, a location name (text you choose), and a song title (text you choose). At send time, we also snapshot your weather condition, temperature, local time, and distance to your partner. All of this is shared with your partner.
- Pulse photos are stored on our servers and accessible to your partner.
- Previous versions of a pulse (your mood trail) are kept permanently. Nothing is erased.
- Your ripples. A ripple records only that you tapped, and when. No content, no mood, no text. Your partner sees "rippled · [time]."
- The name you give your partner. The name you choose for your partner (what you call them) is stored privately and is never visible to your partner. They choose their own name for you, separately.
- Partnership metadata. Your thread's start date, state (active, archived), pulse and ripple counts, and activity timestamps.
- Device token. If you grant notification permission, we store an Apple Push Notification token for your device so we can notify you when your partner sends a pulse or ripple. This token is stored on our servers and used only for that purpose.
How we use it
- To provide the app. Your data is what makes EchoPulse work — storing your pulses, connecting you with your partner, showing you their pulse, keeping the thread alive.
- To show ambient context. Location is used to calculate distance and to fetch local weather via Apple WeatherKit. Both are optional and can be disabled in the app's Context settings.
- To send you notifications. When your partner sends a pulse or ripple, we send a push notification to your device. We do not send reminder or engagement notifications — the app never says "you haven't sent today."
- To maintain your account. Timezone and session data keep the app accurate across time zones.
We do not use your data for advertising. We do not build profiles. We do not analyse behaviour in aggregate. We run no analytics SDKs.
Who we share it with
Your data is shared with three parties: your partner, our infrastructure provider, and the sign-in provider you chose.
- Your partner. They see your pulse content (mood, moment type, note, photo, location name, song title), your avatar, your ambient context (weather, local time, distance), and whether you sent a ripple. They do not see your raw location coordinates, your email address, or the name you chose for them.
- Supabase. All data is stored and processed on Supabase infrastructure (Supabase Inc., USA). This includes your account, pulses, ripples, photos, and device tokens. Supabase processes data on our behalf and does not use it for their own purposes. See supabase.com/privacy.
- Apple. If you use Sign in with Apple, Apple processes your authentication. Your location is used with Apple WeatherKit to fetch weather data — Apple receives location data for this request. See apple.com/legal/privacy.
- Google. If you use Sign in with Google, Google processes your authentication. See policies.google.com/privacy.
We do not sell your data. We do not share your data with advertisers, data brokers, or any other party not listed above.
Data retention
EchoPulse is built on the principle that nothing is ever deleted. Every pulse, every ripple, every version of a pulse — the full record of a thread is kept, even after a thread archives. This is a deliberate design choice, and you should know it before you use the app.
Your data is kept for as long as your account exists. If you close your account, your pulse and ripple records remain tied to the thread record, but your personal account data (email, avatar, device token) can be deleted on request.
Your rights
Under Canadian privacy law (PIPEDA) and applicable provincial legislation, you have the right to:
- Access your data. Request a copy of the personal information we hold about you.
- Correct your data. Ask us to correct inaccurate information. Most data is editable directly in the app (avatar, context settings).
- Delete your account. Request deletion of your account and personal information. Because pulses and ripples are part of a shared thread, pulse content may remain associated with the thread record after account deletion, but it will be disassociated from your identity.
- Withdraw consent. You can disable location access at any time in iOS Settings. You can disable notifications in iOS Settings. You can disable individual context features (weather, local time, distance) within the app.
To exercise any of these rights, email khurram.ayubi@yahoo.com. We will respond within 30 days.
Children
EchoPulse is not intended for children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account, please email us and we will delete it.
Security
All data is transmitted over HTTPS. Authentication is handled by Supabase, which uses industry-standard practices for credential storage. Photos are stored in Supabase Storage and accessed via authenticated requests.
No method of transmission or storage is completely secure. We take reasonable precautions but cannot guarantee absolute security.
Changes to this policy
If we make material changes, we will update the "last updated" date at the top of this page. For significant changes, we may notify you through the app. Continued use after changes constitutes acceptance.
Contact
For privacy questions, data requests, or anything else:
Khurram Ayubi Butt
khurram.ayubi@yahoo.com
Canada