Privacy Policy
Last updated 1 August 2026
This policy explains the personal information VulniPulse processes and the choices available to you.
Information we process
- Account information such as email address, display name, password hash, verification state, identity-provider account identifier, and an optional encrypted two-factor authentication secret.
- Monitoring configuration including vendor and platform alert rules, severity thresholds, alert preferences, comments, and optional linked-account state.
- Mobile installation information including a pseudonymous installation identifier, platform, app version, locale and locale-derived country, installer source, optional campaign referrer, first-open time, timezone, notification permission, quiet hours, and APNs, Live Activity, or Firebase registration tokens used to deliver requested notifications.
- Legacy records retained for existing accounts may include previously saved products and versions, webhook configuration, referral state, and Apple App Store, Google Play, or Stripe transaction identifiers, entitlement status, renewal state, and expiry. VulniPulse does not receive full card details.
- Security and operational records such as hashed signup network or device signals, coarse signup-risk reasons, CAPTCHA verification time, rate-limit keys, delivery status, login or session tokens stored as hashes, and service diagnostics. VulniPulse does not store raw CAPTCHA tokens.
How information is used
We use this information to authenticate accounts, match advisories to requested rules, deliver email or phone alerts, measure whether the Android app was opened after installation, attribute voluntary campaign referrers, maintain legacy transaction state, prevent abuse, provide support, and keep the service secure. The first-open measurement is an unverified, first-party adoption signal—not Google Play's official install count—and is reported separately from delayed Google Play statistics. Verified website accounts with product-release email enabled may receive a concise summary and update link when a new Android production release becomes available. Discord-only alert addresses are not used for those product notices. We do not sell personal information or use private alert configuration for advertising.
Advertising measurement and optional cookies
The website uses Google Ads measurement through Google's consent mode to understand visits from advertisements and campaign performance. By default it runs in a privacy-safe state: it sets no advertising cookies and shares no advertising or measurement identifiers, sending only anonymous, aggregated signals such as page URL, referrer, coarse browser or device information, and approximate location derived from the IP address. Only after you select Accept measurement does it store cookies and share advertising or measurement identifiers for more accurate attribution. VulniPulse does not send Google your password, private alert rules, legacy saved-product records, or full payment details.
After you accept measurement, Google may set cookies such as _gcl_au and, when Google Analytics is configured, _ga. The strictly necessary vp_google_consent preference cookie and matching local browser preference record your choice for up to 12 months. Google processes measurement data under its Privacy Policy.
Service providers
VulniPulse may use Fly.io for hosting, Cloudflare Turnstile for automated-abuse prevention, Apple and Google for sign-in and legacy store transaction handling, Firebase Cloud Messaging for iOS and Android delivery, Stripe for legacy web billing records, configured email providers for account and alert email, and—with your consent—Google Ads for advertising measurement. Each provider processes only the information needed for its role.
Optional server-side OpenAI GPT-5.6 Luna assistance may process public advisory and lifecycle-source material or a restricted set of technical product fields when a lifecycle selection needs help matching a record. VulniPulse does not send OpenAI passwords, authentication tokens, email addresses, hostnames, IP addresses, or private alert fields.
Retention and deletion
Account data is retained while the account is active. Successful delivery diagnostics are pruned on a rolling basis. A salted one-way hash may be retained after first open to deduplicate the anonymous aggregate; the raw installation identifier is not stored in that analytics record. If the device later signs in, the aggregate can be marked as converted; account deletion permanently clears that account linkage while retaining only the anonymous deduplication record. Revoked tokens, minimal deduplication records, and limited store transaction-ownership or revocation records may be retained where needed to prevent fraud and preserve delivery integrity. Existing saved-product, webhook, referral, and entitlement records remain attached to the account until deletion even though those features are no longer promoted. You can permanently delete your account and associated rules, legacy records, registered devices, comments, sessions, and entitlements from the iOS app, Android app, or website account settings.
Security
VulniPulse uses access controls, encryption in transit, hashed credentials and tokens, scoped notification identifiers, validation, rate limits, and operational monitoring. No service can guarantee absolute security.
Your choices
You can disable phone notifications or website email delivery, remove individual alert rules, revoke registered devices, change digest and quiet-hour preferences, or delete your account. Every product-release email includes a signed, no-login one-click opt-out that remains valid for more than 30 days. Product-release emails can also be changed on the account page without changing security alerts or essential account messages. Notification permission can be changed in iOS or Android system settings. Any legacy recurring charge must be managed through the provider that billed it.
The persistent Manage cookies control lets you accept or reject Google measurement at any time. Rejecting keeps measurement in the denied state, clears accessible Google measurement cookies, and does not limit VulniPulse features.
Contact
Privacy questions can be sent to support@vulnipulse.com.