Effective: August 14, 2026. This beta privacy notice describes the current Pulse Stack product.
Activity metadata we collect
We process account details, API-key identifiers, timestamps, measured activity intervals, foreground application category, idle-state signals, supported source/provider and session identifiers, projects, task/session labels, supported file paths, languages, editors, operating systems, machines, activity states, coverage quality, and diagnostic delivery metadata.
Content the tracker excludes
The collector does not upload user prompts, assistant replies, encrypted reasoning, source-code contents, transcripts, window titles, keystrokes, mouse coordinates, screenshots, full command output, or patch contents. Foreground and idle signals are reduced locally to time/activity metadata. The ingest boundary uses allowlists and redacts sensitive or unknown fields before raw diagnostic metadata is stored.
Storage and access
Activity is private to the account by default. API keys are stored as hashes after creation. Transport uses HTTPS. Diagnostic raw metadata is restricted to staff audit tooling and remains subject to the same redaction boundary.
Product and acquisition analytics
When the operator configures Mixpanel, Pulse Stack sends explicit product-funnel events from the public site, account application, billing flow, installer delivery, and the first accepted tracker activity. The metadata is limited to the event name and time, an opaque account or browser-device identifier, utm_source, utm_medium, utm_campaign, referrer domain only, low-cardinality page/action, plan/trial/trial-eligibility/access/cancellation state, installer platform/version, and the first agent provider (codex or claude) when applicable.
Pulse Stack does not send Mixpanel email addresses, prompts, code, transcripts, patch contents, filenames, project/task/session/thread names, API keys, browser/OS/screen details, or full URLs with query parameters. Mixpanel autocapture, automatic page views and marketing-parameter collection, session replay, heatmaps, IP geolocation, full URL/referrer collection, and production debug logging are disabled. Signup, checkout, subscription, installer delivery, tracker connection, and first accepted agent activity are recorded authoritatively by the server. When no Mixpanel Project Token is configured, this integration is disabled.
Public reports
Reports are opt-in and use revocable links. Project and date scope controls are available. Additional safe-by-default hiding for sensitive task and file names remains a beta launch gate; do not share a report containing names you consider confidential.
Compatibility configuration
The tracker prefers ~/.pulse-stack/config.toml. It can import or fall back to ~/.wakatime.cfg without modifying the Waka-compatible file.
Questions and deletion requests
Contact the Pulse Stack operator through the support contact published on this site. Account deletion and configurable retention are not yet self-service beta features.