Pulse Protocol Open terminal

Private test version. Pulse Protocol is not open to the public yet: access is for testing and early access, by invitation only, and nothing is sold. It is operated by a company currently being incorporated in the Seychelles; its registration details will be published before any public commercial launch. The legal documents on this site are drafts that are not in force.

This document is a draft and is not yet in force. It describes Pulse Protocol during its private test and early-access phase: the company that operates it is currently being incorporated in the Seychelles, nothing is sold, and access is by invitation. Still to come: a review by a qualified lawyer. Everything else describes how Pulse actually works today.

Privacy Policy

Last updated: 24 September 2026.

This policy covers the website pulseprotocol.co and the trading terminal app.pulseprotocol.co. It says what we collect, why, who else sees it and how long it is kept. It is written to be read, not to be skimmed past.

Who is responsible

The controller of your personal data is a company currently being incorporated in the Seychelles, whose registered name, address and registration number will be published here before any public commercial launch. For any question about this policy or your data, write to stephan@pulseprotocol.co with "privacy" in the subject.

This website

This website sets no cookies, contains no forms, and uses no analytics or advertising tools. Its only script, on the Contact page, copies our email address to your clipboard when you ask; it sends nothing anywhere. It is hosted by Vercel, which, like any web host, processes the technical data of each request (IP address, time, page requested, browser type) to deliver the pages and protect its network, under its own privacy policy. We do not receive a copy of that data.

What the terminal collects, and why

DataWhy we need it
Account: username, password (stored only as a salted hash), two-factor secret (encrypted), creation dateTo let you sign in, and to protect the account.
Exchange API keys (encrypted) and the account label you give themTo place the orders you ask for and to read your balances and positions.
Your trades, bots, presets, webhooks, settings and their activity historyBecause they are the service: without them Pulse cannot manage your trades.
Notification settings you choose to add (your own email server or Telegram bot details, stored encrypted)To send you the alerts you asked for.
Sign-in attempts and webhook calls: time, IP address, resultTo detect and block attempts to break into your account or to fire your webhooks.
Web server logs: IP address, time, address requested, browser type. Webhook tokens are masked before they are written.Security, abuse prevention and diagnosing faults.
Your emails to us, and your email addressTo answer you, and to give you access.

We use this data only to provide the service you asked for, to keep it secure, to answer you, and where the law requires it. We do not use it for advertising or profiling, we make no automated decisions about you, and we do not sell or rent personal data to anyone.

Cookies and browser storage

The terminal sets two cookies, both strictly necessary: one keeps you signed in and expires after 12 hours or when you sign out; the other remembers the language you chose, for one year. It also keeps two display preferences in your browser's local storage: the unit in which order sizes are shown, and whether a chart guide is displayed. There are no tracking or advertising cookies, so there is nothing to consent to.

How long it is kept

DataKept
Account, API keys, trades, bots, presets, settings, sign-in and webhook historyWhile your account exists. Deleted when the account is deleted.
Web server logs14 days.
System logs of the server7 days.
BackupsThe 14 most recent daily backups on the server, and the 30 most recent on a separate copy kept by the operator.
EmailsIn our mailbox, until you ask us to delete them.

When an account is deleted, its data disappears from the backups as they rotate: from the server's within 14 days, from the separate copy within 30 days, plus the time the storage provider keeps deleted files in its recycle bin.

Who else sees it

Some of these providers (Vercel, Cloudflare, jsDelivr and, if you use it, Telegram) may process data outside the European Economic Area.

How it is protected

API keys, two-factor secrets and notification credentials are encrypted at rest; the master key is kept outside the application's data directory and is never included in backups. Passwords are stored only as salted hashes. Details, including what we do not claim, are on the Security page.

Your rights

You can ask for a copy of your data, its correction, its deletion, or that we stop processing it, by writing to stephan@pulseprotocol.co with "privacy" in the subject. There is no self-service deletion yet: on request, we delete the account together with its exchange keys, trades and settings, and confirm it by email. You can also complain to the Information Commission of Seychelles, which enforces the Data Protection Act 2023.

Changes

If this policy changes in a way that affects you, we will say so by email and on this page before the change takes effect.