New · Launch pricingHome →
← Back to Home

Privacy Policy

Last updated: 26 June 2026 · Effective from user acceptance

📋

TL;DR — Plain English Summary

  • I collect only what I need: your email, name, YouTube channels you research, and reports you generate.
  • Your data is stored on Supabase servers in Mumbai, India (ap-south-1 region).
  • I never sell your data. I don't use Google Analytics, Facebook Pixel, or any third-party tracker.
  • I share only anonymous data (a random ID + YouTube channel data) with my AI providers to generate reports.
  • You can request deletion, correction, or export of your data anytime by emailing me.
  • We follow India's DPDP Act 2023 and IT Act 2000.

1. Who I am

PulseROI is an individual sole-operator service run by Aditya Kumar Ekka, an individual based in Balrampur, Chhattisgarh, India. PulseROI is not currently registered as a company, LLP, or partnership firm. All contracts are entered into with Aditya Kumar Ekka in individual capacity.

In this policy, "PulseROI", "I", "my", and "myself" refer to this individual sole operator. "You" and "your" refer to the person using my service.

I provide a YouTube creator intelligence platform for Indian D2C brands, agencies, and marketers. I am the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) with respect to my handling of your personal data.

2. Data we collect

We collect only the following categories of personal data:

2.1 Account data (from you directly)

  • Email address (from signup or Google OAuth)
  • Display name (from Google OAuth, if applicable)
  • Password (hashed, never stored in plain text; managed by Supabase Auth)

2.2 Usage data (generated as you use the platform)

  • YouTube channels you search or analyse
  • Reports you generate and their contents
  • Lists of creators you save
  • Brand profile information you voluntarily provide
  • PulseChat conversation history
  • Analytics events (page visits, feature usage) tied to your account ID
  • Usage counters (analyses/month, chats/month) for plan limit enforcement

2.3 Payment data (when you subscribe)

  • Payment reference numbers (UPI transaction ID, bank reference)
  • Amount, plan purchased, invoice details
  • GSTIN (only if you voluntarily provide it for GST-compliant invoices)
  • We never store your UPI PIN, credit card number, CVV, or bank passwords. Payments are processed by our payment gateway (Razorpay), which is PCI-DSS certified.

2.4 Technical data (automatically collected)

  • IP address (only for ambassador referral tracking, stored as an irreversible hash)
  • Browser user-agent string (for the same purpose)
  • Session cookies (essential for keeping you logged in)

We do NOT use Google Analytics, Facebook Pixel, Hotjar, Mixpanel, or any third-party behavioural tracking tool.

3. How we use your data

We use your personal data only for the following purposes:

  • Providing the service: Generating creator reports, saving lists, running comparisons, powering PulseChat.
  • Account management: Authenticating you, enforcing plan limits, sending transactional emails.
  • Billing: Processing subscriptions, issuing GST invoices, verifying payments.
  • Personalisation: Recommending creators based on your brand profile, remembering your preferences.
  • Communication: Sending trial expiry reminders, feature announcements, service updates. You may opt out of promotional emails anytime.
  • Fraud prevention: Detecting trial abuse, unauthorised access, and suspicious patterns.
  • Legal compliance: Responding to lawful requests from Indian authorities under the IT Act 2000, DPDP Act 2023, or Consumer Protection Act 2019.
  • Product improvement: Aggregated, anonymised analytics to identify bugs and popular features.

We do NOT use your personal data to train AI models. AI providers we use are third-party inference services only; we do not send them data for training.

Under DPDP Act 2023 Section 6, we process your personal data based on:

  • Your consent (Section 6(1)) — you consent by creating an account and using the service.
  • Contractual necessity — to deliver the service you paid for.
  • Legitimate uses (Section 7) — for fraud prevention and legal compliance.
  • Legal obligation — where required by Indian law.

5. Third parties we share data with

We share the minimum data necessary with the following service providers. Each has their own privacy policy governing how they handle data. We do not sell your personal data to anyone, ever.

Third PartyPurposeData Shared
Supabase (Singapore Ltd.)Database + authentication (Mumbai region)All account and usage data
Google (YouTube Data API)Fetching public YouTube channel dataOnly public channel identifiers you search for. No personal data.
Google (OAuth)Optional Google sign-inYour email + display name (only if you choose Google sign-in)
RazorpayPayment processing (subject to activation)Payment amount, email, transaction reference. PCI-DSS certified.
ResendSending transactional emailsYour email address + email content
AI Providers (Groq, Mistral, Cerebras, Cohere, HuggingFace, Google Gemini)Generating AI-powered reports and chat responsesOnly a random anonymous user ID (UUID) + public YouTube channel data. No email, no name, no personal identifiers.
Vercel (hosting)Serving the websiteStandard server logs (IP, browser, timestamp)
open.er-api.comCurrency exchange rates (USD-INR)None. No user data shared.

We may also disclose your data if legally compelled by an order from an Indian court, law enforcement agency, or regulatory body under IT Act 2000, DPDP Act 2023, CrPC, or other applicable law.

6. Where your data is stored

Your primary data is stored on Supabase infrastructure in the Mumbai region (ap-south-1), within Indian territory. This means your data enjoys the full protection of Indian law and does not require cross-border transfer disclosures under DPDP Act 2023 Section 16 for primary storage.

Certain third-party services (AI inference providers, email delivery, currency rates) may process transient data outside India. Where this happens, only minimal, non-identifying data is transferred (e.g., YouTube channel data + anonymous UUID for AI inference).

7. How long we keep your data

  • Account data: Retained while your account is active.
  • Reports and lists: Retained while your account is active. Soft-deleted for 30 days when you delete them, then permanently deleted.
  • Chat history: Retained for 90 days, then automatically purged.
  • Usage logs and analytics events: Retained for 90 days, then automatically purged (as per our 3-month retention manager).
  • Payment records: Retained for 7 years, as required by Indian tax law (Income Tax Act 1961 and CGST Act 2017).
  • After account deletion: All personal data is deleted within 30 days of your written request, except a hashed form of your email retained solely to prevent free trial abuse (see Section 8).

8. Your rights under DPDP Act 2023

As a Data Principal under DPDP Act 2023, you have the following rights:

  • Right to access (Section 11): Request a copy of all personal data we hold about you. Available directly via Dashboard → My Data → Export.
  • Right to correction (Section 12): Request correction of inaccurate data. Editable in Settings.
  • Right to erasure (Section 12): Request deletion of your account and all associated data. Contact us at pulseroi.officials@gmail.com.
  • Right to grievance redressal (Section 13): File a grievance with our Grievance Officer (see Section 13 below).
  • Right to nominate (Section 14): Nominate another individual to exercise your rights in the event of your death or incapacity. Contact us to register a nominee.
  • Right to withdraw consent (Section 6(4)): Withdraw consent at any time by deleting your account. Note: this will end your service access.

Account deletion process: On email request to pulseroi.officials@gmail.com, we permanently delete your account and all associated data (reports, lists, brand profile, chat history, usage records, payment metadata) within 30 days. We retain only your email address (in irreversible hashed form) indefinitely to prevent free trial abuse, as permitted under Section 8(7) of the DPDP Act 2023 (legitimate business interest — fraud prevention). No other personal data is retained. You may request full erasure of even the hashed email by providing valid reason, which will be reviewed case-by-case within 15 days.

9. Security measures

We implement the following technical and organisational security measures:

  • HTTPS/TLS encryption for all data in transit
  • Data encryption at rest (managed by Supabase)
  • Password hashing using industry-standard algorithms (bcrypt via Supabase Auth)
  • Row-Level Security (RLS) policies on all database tables
  • Access control: only the operator (Aditya Kumar Ekka) has administrative access
  • Regular software updates and dependency patching
  • Server logs monitored for suspicious activity
  • Chat filter to prevent abuse and off-topic misuse

No system is 100% secure. If a breach occurs, we will notify you as described in Section 10.

10. Data breach notification

In the event of a personal data breach affecting your information, we will:

  • Notify the Data Protection Board of India as required under DPDP Act 2023 Section 8(6)
  • Notify you via email within 72 hours of discovering the breach
  • Describe the nature of the breach, what data was affected, and what steps we are taking
  • Recommend actions you can take (e.g., password reset)

11. Cookies

We use only essential cookies to keep you logged in (Supabase authentication session cookies). We do not use advertising cookies, behavioural tracking cookies, or third-party analytics cookies. Because we use only essential cookies, no cookie consent banner is legally required under DPDP Act 2023 or IT Rules 2011.

12. Children's data

PulseROI is intended for use by adults aged 18 years or older. By creating an account, you confirm that you are at least 18 years old. We do not knowingly collect personal data from individuals under 18. If we become aware that we have collected data from a person under 18, we will delete it promptly.

If you are a parent or guardian and believe your child under 18 has provided us with personal data, please contact pulseroi.officials@gmail.com and we will delete it within 30 days.

13. Grievance Officer

In compliance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (Rule 3(2)) and Digital Personal Data Protection Act, 2023 (Section 8(9)), the Grievance Officer for PulseROI is:

Name: Aditya Kumar Ekka

Designation: Grievance Officer & Sole Operator

Email: pulseroi.officials@gmail.com

Address: Balrampur, Chhattisgarh, India

Response time: Within 1–2 business days for most grievances; maximum 15 days as required by IT Rules 2021.

If your grievance is not resolved satisfactorily, you may escalate to the Data Protection Board of India once established under the DPDP Act 2023.

14. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified to you via email at least 15 days before they take effect. Continued use of the service after changes take effect constitutes acceptance of the updated policy.

15. Contact us

For any questions, requests, or grievances regarding this Privacy Policy or your personal data:

Email: pulseroi.officials@gmail.com

Subject line for fastest response: "Privacy Request" or "Grievance"

Operator: Aditya Kumar Ekka, Balrampur, Chhattisgarh, India

This Privacy Policy is governed by the laws of India. Any disputes shall be subject to the exclusive jurisdiction of the courts at Balrampur, Chhattisgarh.