LEGAL

Privacy Policy

Effective 3 August 2026 · Publisher: Manuel Ferreira

At a glance. Pulse has no advertising or third-party analytics SDK. Optional anonymous product analytics are off by default. Most working data remains on your device. Pulse never asks for a Roblox password, security cookie, or Open Cloud API key.

About Pulse

This policy explains how Manuel Ferreira (the “Publisher”) handles information in Pulse: Experience Analytics. Pulse is an independent companion and is not affiliated with, sponsored by, or endorsed by Roblox Corporation.

Data stored on your device

Depending on the features you use, Pulse stores selected and followed public experiences and artwork; locally sampled CCU, visits, favourites, approval and metadata history; alert rules and history; release notes, goals, event schedules, feed subscriptions and reminder choices; display preferences; creator-entered or imported daily Robux revenue; and user-configured public earnings assumptions.

Creator revenue entries are private local data. Pulse does not verify them with Roblox, convert them to fiat currency, or transmit them to the Publisher. They leave the app only when you explicitly export a revenue CSV or Pulse backup.

Requests to Roblox and other publishers

When you search for an experience or refresh public metrics, the search term, public place or universe identifier, IP address and ordinary network request information are sent directly to Roblox-operated domains. Roblox handles those requests under its own privacy policy. Pulse does not proxy them through a Publisher server.

Player Discovery retains up to six recent search terms locally. They are not sent to the Publisher, are excluded from Pulse backups and can be cleared from Discovery.

If you choose to import or refresh an HTTPS event feed, Pulse contacts that publisher directly. The publisher can receive ordinary network information and governs it under its own policy. Pulse validates imported URLs and does not scrape Roblox event pages.

Optional cloud features

If a release offers Continuous updates and you explicitly enable it, the Pulse service may receive a random anonymous installation identifier and secret, selected public Roblox universe IDs, an Apple Push Notification service device token and locale, and a signed App Store transaction used to verify Pulse Pro. Apple and hosting providers also receive normal connection information such as an IP address. Recent searches, private revenue, notes, credentials and event-feed URLs are not sent to the Pulse service.

Installation-linked watchlists, push tokens and entitlement state remain until you disable Continuous updates and authenticated deletion succeeds, or the Publisher removes them. Shared public metric samples are not linked to an installation and may remain after deletion.

Optional Studio publishing

A Studio operator can submit a public Studio name, URL slug, tagline, optional HTTPS website, public Roblox owner type and owner ID, and one to 20 public universe IDs. Pulse issues a temporary 30-minute verification code. The operator places that code in the public description of one submitted Roblox experience; the service then checks the description, creator identity and submitted universes using Roblox public data. Pulse never asks for a Roblox password, security cookie or API key.

After successful verification, the profile and its experiences are intentionally public in the searchable, CCU-ranked Studios directory. A separate random management token is stored in the iPhone Keychain and used only to update or delete that profile. If access is lost, the operator can repeat the public-description proof to rotate the token.

Optional anonymous product analytics

Anonymous product analytics are off by default. If you enable them in Settings, Pulse sends a random app-specific installation identifier, platform, app version, abbreviated locale, event time, and only these interactions: app opened, Studios directory viewed or refreshed, Pulse Pro paywall viewed, and subscription purchase or restore started.

Pulse does not send your name, email, Roblox identifier, advertising identifier, exact location, search text, selected experience or studio, private revenue, notes, or feed URLs with these events. Aggregate counts are used only to understand reliability, adoption, and subscription-funnel steps. They are not sold, shared for advertising, or used to track you across other companies' apps or websites.

Turning analytics off sends an authenticated deletion request for that installation's consent and events. Events are otherwise kept for no more than 90 days. To guarantee remote deletion, turn analytics off while online before using Delete all local Pulse data.

Apple Watch and notifications

The optional Watch companion receives a bounded copy of the latest public portfolio snapshot through Apple WatchConnectivity. It can include aggregate CCU, public experience identifiers and names, movement, timestamps and small artwork thumbnails. It does not include creator revenue, notes, alert rules or Roblox credentials.

Pulse requests notification permission only when you enable an alert or reminder. Local notifications are generated on the device. If you separately enable Continuous updates, a device token may be sent to the Pulse service for opted-in alerts.

Exports, deletion and retention

Pulse exports data only after your action through the iOS file or share sheet. Exported backups can contain public analytics, schedules, settings, URLs and creator revenue, so you should treat them as private.

The confirmed Delete all local Pulse data control in Settings removes the local portfolio, revenue ledger, follows, events and feeds, goals, recent searches, preferences, Pulse notifications, widget snapshots, cached artwork, restore data and the local Studio management token. Removing only that local token does not remove an already-public Studio profile.

The authenticated Delete public Studio control in Studio management permanently removes the public profile, its listed experiences, upcoming Studio events and management token from the Pulse service. If the token was lost, the operator can first repeat the public-description verification to recover access and then delete the profile.

Pulse cannot delete files previously exported to another service, revoke iOS notification authorization, erase an App Store purchase record, or control an unpaired Watch. Local data remains until you delete it, uninstall Pulse or a stated retention limit removes older samples. Protected archive and recovery files use iOS file protection. No security measure can guarantee absolute protection.

Purchases

Pulse is free to download and offers optional auto-renewable Pulse Pro subscriptions through Apple. Apple processes payments, renewals, cancellations and refunds. Pulse does not receive payment-card or billing-address information. StoreKit supplies localized product information and signed entitlement status. Restoring purchases asks Apple to synchronize App Store transactions. Ending Pro does not delete local data.

Children, third parties and changes

Pulse is a developer and companion utility and is not directed to children. Public experience names, descriptions and artwork may be user-generated Roblox content. Apple, Roblox and feed publishers process information under their own policies. This policy may be updated when Pulse features, providers or legal obligations change; the effective date identifies the published version.

Contact

Questions or privacy requests can be sent to manuelferreira28ya@gmail.com.