Privacy Policy
Last updated: April 14, 2026
PulsaFit ("we", "us", "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, store, and share data when you use PulsaFit in connection with your Garmin wearable device.
1. Data We Collect from Garmin
When you connect your Garmin account, we receive the following data types via the Garmin Health API:
- Daily Summaries (steps, distance, calories, active minutes)
- Activity Files (workouts, GPS data, performance metrics)
- Sleep Data (sleep stages, duration, sleep score)
- Heart Rate (resting HR, HR zones, all-day HR)
- Body Composition (weight, BMI, body fat percentage)
- Stress Level (all-day stress tracking)
- Respiration (breathing rate data)
- Body Battery (energy level data)
2. How We Store Your Data
All health data is encrypted using AES-256 encryption at rest and transmitted over TLS 1.3 in transit. Access tokens from Garmin OAuth 1.0a are stored encrypted and never include your Garmin credentials. Data is hosted on secure servers within the European Union.
3. Data Retention
We retain your health data for as long as your account is active. If you delete your account or request data deletion, all associated data is permanently removed within 24 hours.
4. Your Rights
Access & Export
You may request a full export of your data at any time through your account settings or by contacting us.
Deletion
You may request complete deletion of your data at any time. Upon request, all personal and health data will be permanently deleted from our systems within 24 hours.
Revoke Access
You may disconnect your Garmin account at any time, which immediately stops all data syncing.
5. Third-Party Sharing
We never sell your personal health data. We do not share your data with third parties for marketing purposes. Data may only be shared with infrastructure providers strictly necessary for service operation, and only in anonymized or encrypted form.
6. GDPR Compliance
For users in the European Economic Area (EEA), we comply with the General Data Protection Regulation (GDPR). You have the right to access, rectify, erase, restrict processing, and port your data. Our legal basis for processing is your explicit consent when connecting your Garmin account.
7. CCPA Compliance
For California residents, we comply with the California Consumer Privacy Act (CCPA). You have the right to know what data we collect, request deletion, and opt-out of data sale (we do not sell data). We do not discriminate against users who exercise their privacy rights.
8. Contact
For privacy inquiries, data requests, or concerns, contact us at:
privacy@pulsafit.com