HeartPulse Privacy Policy
Last updated: 2026-09-08 · 中文
HeartPulse keeps your music on your own device. Lyrics, the photos you pick, and the audio files themselves are never uploaded, and we cannot tell what titles are in your library. Only a song you actively resonate with is uploaded, with its title — so that other people can see it too.
1. You can use it without an account
Every feature works anonymously. Signing in with Apple is optional and does exactly one thing: it lets your growth and resonance records come back after you switch devices or reinstall.
2. What we collect
- A device identifier — an opaque random string generated on your device, used to attribute resonance records to the same device. It is not an advertising identifier and not a device serial number.
- Account identifiers — the opaque user ID Apple gives us when you sign in, plus an account ID we generate. Sign in with Apple asks you for your name and email; we do not store your email address and our database has no field for it.
- Usage data — a fingerprint of each song you resonate with (a digest that cannot be turned back into a title), the emotion tag you choose, events such as plays, favourites and shares (time, duration, completion — a play also carries a fingerprint of the song, one that cannot be turned back into a title, used for growth and the timeline), and a numeric summary of your Pulse growth together with your interface preferences. The growth summary covers your pulse value, current form and star level, the badges you have lit up and their grades, how many awakened forms you own, and counts of resonances and listening; every device with online features unlocked syncs this summary, so that your growth can be restored once you sign in and so that we can understand how the product is used and how people grow with it. We also keep one daily growth snapshot per device to follow long-term trends; that history is kept for 24 months and deleted automatically after that. On devices with online features unlocked, launching the app also records a "last used" time (a single timestamp that overwrites the previous one, used to tell whether the device is still in use).
- The title, artist and album of songs you resonate with — uploaded for that one song, only when you actively tap resonate. It is what lets displays such as "what others are resonating with right now" name a song at all. We do not upload your library: for a song you never resonated with, we cannot see its title.
- The avatar you upload — once you actively pick an image from your library on the avatar page and confirm it, that image is uploaded to our servers so that other people can see it on your profile page, on the living-room seats, in the member list and in friend lists — anyone who can reach your profile can see this image, which is exactly what it is for. We take only the one image you picked; we do not read your library, and we do not run face recognition or any image analysis on it. The same applies to the avatar you set for a companion. The image is kept until you act: replace it and the old one is deleted from the server at that moment; tap "Clear avatar" on the same page and it is deleted at that moment; delete your account and it goes with the account. We set no separate retention period for it.
- Technical information — device model, OS version, app version, and the IP address and connection port of your requests. They are used only for operating the service, security auditing and investigating abuse; never to locate you and never for advertising.
- Login log — each time you sign in we record the time, IP address, connection port and device identifier, for account security and abuse investigation (a legitimate interest in keeping the service safe). This log is kept for 12 months and deleted automatically after that.
- Crash and abnormal-exit diagnostics — when the app exits unexpectedly (a crash, a freeze, or the system ending it), your phone's operating system keeps a technical record of it. On devices with online features unlocked, the next launch of the app retrieves that record: when it happened, why the process ended, memory usage, and the call stack at the point of failure (which contains only our own function names and code library names). It is used solely to locate and fix faults. The record contains none of your content — no song titles, no lyrics, no file paths, nothing from your library. Diagnostics are kept for 90 days and deleted automatically after that; they are deleted immediately when you delete your account.
- Live voice (living room / bedroom) — the microphone is used only while you yourself have tapped the mic open in a room to talk; with the mic closed the app never touches the microphone, and the system permission prompt appears only the first time you open it. Your voice is relayed in real time through servers we operate ourselves to the people in the same room, and is never recorded or stored: the server handles it only for the instant it passes through — there is no recording and no archive, and the moment you close the mic the audio no longer exists anywhere. People in the room can see your Pulse number and nickname (they are shown on entering the room regardless of whether you talk). While you have the mic open, capture and relay continue even if the screen turns off or you switch to another app — otherwise the people in the room would stop hearing you the moment your screen locked. The mic switch is yours alone: closing the mic or leaving the room stops capture immediately. While your mic is open a notification stays in your status bar (“In a voice room · microphone on”) — that is the sign it is still working.
3. What we specifically do not collect
- Lyric text. When you mark "this line got me", what leaves your device is a digest of that line (a string that cannot be turned back into words), not the words. Someone else seeing that line is seeing the copy of the lyrics already on their own device, matched against that digest — a person who does not have the song cannot see the line.
- Your audio files, or the photos you choose from your library as cover art (cover photos never leave the app). The only photo from your library that leaves your device is the one you actively choose as an avatar — see the section above.
- Your library listing, playlists, or favourites (none of these go into the cloud backup). For a song you never resonated with, we cannot see its title (a play only carries a title-proof fingerprint, see above).
- Your voice recordings. Live voice exists only in transit; we neither record nor store it — see the section above.
- Email address, contacts, location, health data, or payment information
- Any advertising identifier
4. What other people can see
Resonance is by nature about other people: you get to see that someone else is in this song right now, and they get to see the traces you leave. Here is exactly what is exposed.
- Exposed: the emotion tag chosen on a song (always one of the app's twelve — there is no free-text field), the lyric lines people have resonated with, and the titles and artists of songs people have resonated with.
- Not exposed: anything that points back to you. No nickname, no avatar, no account, no device identifier, no "you were the Nth person" ordinal, and no precise timestamps — time is only ever "today / this week / earlier". What others see is "someone", never "who".
- Too few people, nothing shown: a song (or a single lyric line) has to have been resonated with by several distinct devices before it appears to anyone else. An obscure track only one or two people have will not be shown — otherwise "someone" would mean "that one person".
- Resonance displays reveal no counts: the ambient stream and the resonance charts are deduplicated by kind, not laid out one row per person, so counting the rows tells you nothing about how many people there are.
- Your own entry is never shown back to you.
- Pulse Summit (the one public count): the Pulse page shows the highest form anyone has currently reached and how many people stand at that level, settled once a day at midnight. It carries no identity whatsoever — it does not say who, it attributes no position, and there is nobody to tap through to. It publishes only the top level and not the distribution across levels, because adding those counts together would give the total number of people, and we do not intend to tell anyone how many people use this product. Your own ranking is visible only to you; nobody else can obtain it.
All of this is a read-only ambient layer: there is nothing to reply to, no direct messages, and no profile to tap through to — because there is no "someone" to tap.
5. Tracking and advertising
Neither exists here. The app contains no advertising SDK and no third-party analytics, shares nothing with data brokers, and performs no cross-app or cross-site correlation. That is why you are never shown an "Allow tracking" prompt.
6. Third parties
- Sign in with Apple — happens only when you choose to sign in. What we receive from Apple is an opaque user ID.
- Last.fm (optional, off by default) — only after you connect your own Last.fm account do the title, artist, album and duration of what you play get sent to Last.fm to record your listening. That connection goes from the app straight to Last.fm; the data does not pass through our servers. You can disconnect at any time in settings. While connected, Last.fm's own privacy policy also applies.
- Curated songs — downloading a track from our catalogue produces ordinary server access logs, recording the time, the file path requested and your IP address. They are used to count how many times each song is downloaded and to investigate abuse. These logs contain no account or device identifier and are deleted automatically after 30 days.
- Apple DeviceCheck (anti-abuse) — to detect malicious device resets, we may query Apple's DeviceCheck service when you sign in or register for the two yes/no flags associated with this device. Those two bits are all we ever receive from Apple — no hardware details, no serial number, no location, and nothing that can track you across apps. If an Android version is released, it will use Google Play Integrity for the same purpose.
7. Where data lives and how long we keep it
Data is held on servers we operate ourselves, and every transfer is encrypted with HTTPS. We keep it for as long as your account exists. When you delete your account it is all removed immediately, with no retention period; routine database backups are kept for at most 30 days, so any copy inside them disappears as those backups rotate.
Three kinds of record have fixed retention windows, after which entries are deleted automatically: the login log is kept for 12 months, the server-side audit log of resonance writes for 180 days, and the daily growth history for 24 months. When you delete your account, your entries in all three are removed immediately as well.
The avatar you upload is not kept for a number of days; it is kept until you act. Replacing it, tapping "Clear avatar", or deleting your account each deletes the image file from the server at that moment. Apart from those, we do not delete it on our own and we set no retention period for it.
8. Your rights
- Delete your account — in the app, under Profile → Settings → Account → Delete account. This cannot be undone: every record belonging to the account is deleted from the server straight away, this app's Sign in with Apple authorisation is revoked at the same time, and the growth, badges and resonance records on your device are cleared as well. Your own music files and playlists are kept.
- Sign out — ends the session on this device only. Your data stays in the cloud and returns the next time you sign in.
- Stay anonymous — every feature works without an account.
- You may also write to us to access, correct, or delete data relating to you.
9. Children
This app is not directed at children under 13, and we do not knowingly collect their personal data.
10. Changes to this policy
If it changes we update the "Last updated" date at the top of this page. Any change to what we collect will also be explained inside the app.
11. Contact
For anything privacy-related, write to aipo@ailenshow.com.