Privacy Policy

DRAFT — pending legal review. Not yet legally binding. This document is a draft and has not been reviewed by counsel. It must be reviewed by a qualified lawyer (in particular for Korean PIPA sensitive/biometric data and cross-border transfer, and for GDPR/CCPA) before it is published or relied upon.

Pulse Privacy Policy (Draft)

[Effective date: ____]

This Privacy Policy explains how Hai Inc. (주식회사 하이, "we," "us," or "the Company") collects, uses, shares, and protects your personal information when you use Pulse, our mobile dating service (the "Service").

We operate Pulse in the United States, Canada, Australia, and Korea. We aim to follow strong privacy practices everywhere, including the principles of Korea's Personal Information Protection Act (PIPA), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act as amended (CCPA/CPRA). If you live in a region with specific privacy laws, the sections on your rights below explain what applies to you.

By using Pulse, you agree to this Privacy Policy. Where the law requires consent — especially for sensitive/biometric information (Section 4) — we ask for your separate, explicit consent before processing.


1. Information We Collect

We collect the following categories of personal information. Sensitive/biometric information is described separately in Section 4 because it requires your separate, explicit consent.

CategoryWhat it includesBasis
Account / identity (required)Mobile phone number (verified by one-time passcode), display name, date of birthContract · identity & age verification
Account / identity (optional)Email address (if you provide it)Consent
ProfileGender, sexual orientation (stored encrypted), dating intent, who you want to meet, age-range and maximum-distance preferences, appearance preference, bio, job, school, prompt answers, interests, photosConsent
Location — coarse onlyAn on-device geohash cell of roughly 1 km, plus a city "bucket," with a per-user random "ghost offset." We never store or transmit your precise GPS coordinates.Consent
Sensitive / biometricOn-device heart-rate and heart-rate variability (HRV) estimated from face video (rPPG); a face selfie for liveness and identity verification (face-match). See Section 4.Separate, explicit consent
CommunicationsMessages (stored encrypted), reactions, and your participation in "Glance" live video/voice callsContract
Contacts (optional)To hide people you already know, your device phone numbers are hashed on your device (SHA-256) before they are sent; our server then adds a secret HMAC "pepper" and matches on that value. Your raw phone numbers never leave your device, and we do not store your raw contacts.Consent
Usage / deviceLogin activity, dormancy, in-app interaction events, push notification token, notification preferences, app/OS/device informationContract · legitimate interests
CommerceIn-app purchases and entitlements, in-app token wallet/credits, premium status. Payment is processed by Apple; we do not receive your card data.Contract
SafetyBlocks, reports, moderation outcomes, consent recordsLegal obligation · legitimate interests

How we collect it. We collect information you provide directly (during sign-up, profile creation, and use of the Service); information generated automatically as you use the Service (login activity, in-app events, device/OS information, push token); and information collected only when you grant a device permission (camera, photos, location, contacts, notifications). If you decline location permission, you can still use the Service by selecting your city manually.


2. How We Use Your Information

We use your information to:

  1. Create and manage your account — verify you by phone one-time passcode, confirm you meet the minimum sign-up age (18, or 19 in Korea), maintain your membership, and prevent misuse.
  2. Provide the dating service (matching) — build and show your profile, recommend people based on distance/age and other preferences, and power likes, matches, messages, and "Glance" live video/voice calls.
  3. Verify identity (anti-catfish / safety) — confirm you are a real, live person and that your face matches your profile photos (see Section 4).
  4. Keep the community safe — handle blocks and reports, moderate harmful content and photos, prevent romance scams, harassment, and use by minors, and keep consent records.
  5. Provide paid features — manage in-app purchases, subscriptions, tokens/credits, and premium entitlements (payment is handled by Apple; we do not receive card data).
  6. Improve the Service — analyze usage, develop features, and diagnose errors (analytics tooling is planned and not yet enabled).
  7. Support you and meet legal obligations — respond to inquiries, resolve disputes, and comply with applicable law.

We do not use your information for purposes incompatible with those above without an additional legal basis or your consent.


3. How We Share Your Information (Service Providers / Sub-processors)

We do not sell your personal information. We share it only with service providers ("sub-processors") who process it on our behalf to run the Service, under contracts that require appropriate safeguards, and as otherwise required by law (e.g., legal process, safety enforcement).

Most of these providers are based in the United States, so using Pulse involves an international transfer of your data (see Section 5 for Korean users).

Sub-processorWhat they doLocationNotes
ClerkAuthentication / loginUnited States
Amazon Web Services (AWS)Face-match verification (Rekognition) — used when identity verification is enabledUnited StatesHandles biometric data (face selfie / face geometry)
Cloudflare R2Media (photo/video) storageUS / global
NeonDatabaseUnited States
Fly.ioServer hostingUnited States
SentryError diagnostics (error logging)United StatesNo PII in logs
Google Firebase / FCMPush notificationsUS / global
LiveKit"Glance" live video/voice callsUnited States
RevenueCat · AppleIn-app purchases & entitlements (payment by Apple)United StatesUsed when in-app purchases are enabled
OpenAIMessage content moderationUnited States
SightenginePhoto content moderationUS / global
VercelWeb hosting (marketing site) and waitlist email storageUS / global
VultusHeart-rate estimation (rPPG) — processed on-device. No biometric data leaves your device for this processing.On-deviceSee Section 4

If our sub-processors change, we will update this Policy.


4. Sensitive / Biometric Information (Separate Consent)

We process the following sensitive/biometric information only with your separate, explicit, unbundled consent. This consent is not bundled with any other consent, and declining it does not block core features (browsing profiles, matching, messaging) — though some safety features that depend on verification may be limited.

BiometricHow it's processedPurpose
Heart-rate & heart-rate variability (HRV) — rPPGEstimated from face video on your device (Vultus); the resulting heart-rate signal (an encrypted per-capture time-series) is sent to our servers. No raw biometric video is processed off-device.Liveness / identity verification (confirming you are a real, live person); the in-product heart-rate you choose to share; and matching — your heart-rate reactions (e.g., changes relative to your own baseline) help infer likely interest/affinity and rank and match candidates.
Face selfie (face geometry)Liveness check and face-match against your profile photos (AWS Rekognition)Identity verification / anti-catfish (preventing photo theft and impersonation) / safety

Purpose limits (our commitments). We use this biometric information for the purposes described above — liveness and identity verification (anti-catfish), the in-product heart-rate you choose to share, and matching (using your heart-rate reactions, such as changes relative to your own baseline, to infer likely interest/affinity and to rank and match candidates) — always under your separate, revocable biometric consent. We do not build emotion or psychological profiles of you beyond this matching use; we never sell your biometric information; we never share it with other users beyond what you choose to reveal; we never use it for advertising or targeting; and raw camera video is processed on your device and never leaves it. Heart-rate information is not medical advice or diagnosis and Pulse is not a medical device.

Korean users. Consent is split into (a) collection/use of biometric information and (b) provision/entrustment to processors. Illinois (BIPA), Washington (MHMDA), and EU/EEA (GDPR special category) users are covered by the applicable jurisdiction-specific consent in addition to our universal biometric consent.

Withdrawing consent. You can withdraw biometric consent at any time in the app (Withdraw Consent) or via the contact in Section 9; we will stop further processing. We retain the record that consent was given/withdrawn for the legal-hold period described in Section 6, as proof of consent.


5. International Data Transfers

To provide the Service, we transfer personal information to the sub-processors listed in Section 3, many of which are located in the United States. The recipients, countries, data items, and purposes are as set out in Section 3.

  • Recipients / countries: the sub-processors in Section 3 (predominantly United States).
  • Items transferred: the items in Sections 1 and 4 needed for each provider's task (e.g., authentication data, face selfie/face geometry to AWS, media, database records, messages, push token).
  • Purpose: each provider's processing task (Section 3).
  • Method & timing: transmitted over the network on an ongoing basis as you use the Service.
  • Retention: as described in Section 6, or until the processing purpose is met.

Transferee contact information (PIPA Art. 28-8). The privacy contact for each overseas transferee is:

For Korean users, this constitutes a cross-border transfer (국외이전) under PIPA; you may decline, though declining may limit your use of the Service. We apply the safeguards required by applicable law to these transfers.


6. How Long We Keep Your Information

We keep personal information only as long as needed for the purposes above or as required by law.

  • While your account is active — we keep your data to provide the Service.
  • When you delete your account — there is a 7-day cooldown, after which your data is permanently deleted (hard-deleted). You can restore your account during the cooldown.
  • Consent records (including biometric/regulatory) — kept for the life of your account plus 7 years (to meet BIPA/MHMDA/GDPR-type legal-hold obligations), including records of any withdrawal. This retention exists to meet safety and legal obligations.
  • Safety and legally required records — blocks, reports, bans, and logs that the law requires us to keep are retained for the period required by applicable law (for example, certain commerce and access-log records under Korean law).

Under applicable law, the following records may be retained for the periods below (illustrative, where the relevant law applies):

RecordLegal basisRetention
Records on contracts or withdrawal of subscriptionAct on Consumer Protection in Electronic Commerce5 years
Records on payment and the supply of goodsAct on Consumer Protection in Electronic Commerce5 years
Records on consumer complaints or dispute resolutionAct on Consumer Protection in Electronic Commerce3 years
Records on labeling / advertisingAct on Consumer Protection in Electronic Commerce6 months
Service access (log) recordsProtection of Communications Secrets Act3 months

7. Destruction Procedure and Method

When personal information becomes unnecessary — because its retention period has elapsed or the processing purpose has been achieved — we destroy it without undue delay.

  • Destruction procedure. After the 7-day cooldown described in Section 6 following account deletion, we identify the personal information for which a ground for destruction has arisen and destroy it. Information we are required by law to retain (consent records; safety, commerce, and access-log records) is stored in a separate area and destroyed when its retention period expires.
  • Destruction method. Information held in electronic files is permanently deleted by a method that prevents recovery or reconstruction; paper documents are shredded or incinerated.

8. Your Privacy Rights and How to Exercise Them

Subject to applicable law, you have the right to:

  1. Access the personal information we hold about you;
  2. Correct inaccurate information;
  3. Delete your information;
  4. Withdraw consent and object to / restrict processing;
  5. Port / export your data — Pulse includes an in-app data export so you can download your information;
  6. (California residents) Opt out of "sale" or "sharing" of your personal information — Pulse honors a "Do Not Sell or Share My Personal Information" choice (we do not sell your data; this setting also limits cross-context sharing). You also have the right not to be discriminated against for exercising your rights.

How to exercise these rights.

  • In the app: edit your profile, delete your account, withdraw consent, set "Do Not Sell or Share," and export your data directly in Settings.
  • By contacting us: email [privacy contact email] or the Privacy Officer in Section 9. We will verify that you are the account holder (or an authorized agent) before acting, and respond within the time the law requires.

You may also lodge a complaint with your local data protection authority. Korean users may contact the Personal Information Dispute Mediation Committee (1833-6972), the Privacy Infringement Report Center (118), the Supreme Prosecutors' Office (1301), or the National Police Agency (182). EU/EEA users may contact their national supervisory authority.


9. Privacy Officer and Contact

  • Privacy Officer (개인정보 보호책임자): [개인정보보호책임자 성명·직책]
  • Contact (email): [privacy contact email]
  • Company: Hai Inc. (주식회사 하이)
  • Address: [회사 주소]
  • Representative: [대표자]
  • Business registration number: [사업자등록번호]

You can contact the Privacy Officer with any privacy question, complaint, or request, and we will respond promptly.


10. How We Protect Your Information

  • Encryption in transit: all traffic is encrypted with TLS.
  • Encryption at rest: sensitive items — photos/media, messages, heart-rate/HRV data, and sexual orientation — are encrypted at rest.
  • On-device processing & data minimization: location is processed only as coarse (~1 km) data with precise GPS never stored or transmitted; contacts are hashed on-device with no raw contacts stored; rPPG heart-rate estimation runs on-device.
  • No PII in logs: we do not record personally identifying information in diagnostic logs.
  • Access controls: access to systems that process personal information is minimized and managed.
  • Content moderation: photos pass content moderation before they are visible, and we screen messages and images for harmful content.
  • Data breach notification: if a data breach affects your personal information, we notify you without undue delay in accordance with applicable law. For Korean users, we notify affected users and report to the Personal Information Protection Commission (PIPC) and the Korea Internet & Security Agency (KISA) where statutory thresholds apply, within the timeframe the law requires; in other markets we follow a 72-hour notification posture.

11. Children

Pulse is a dating service. The minimum age to use Pulse is 18, or 19 in Korea — and higher where applicable local law requires. We verify age from your date of birth at sign-up, and we promptly restrict and delete accounts found or reported to belong to someone below the applicable minimum age. We do not knowingly collect personal information from minors.


12. Changes to This Policy

We may update this Policy as the Service or the law changes. We will post material changes in the app or on this page at least 7 days before they take effect (30 days for changes that are materially adverse to you).

  • Posted: [Effective date: ____]
  • Effective: [Effective date: ____]

This document is not legal advice. It is a draft that must be reviewed by qualified counsel — in particular for Korean PIPA sensitive/biometric data and cross-border transfer, and for GDPR/CCPA — before publication.