1. Introduction & scope
PulseFlow is operated by Ariel Tolome Technologies, using the PulseFlow Systems name (Ariel Tolome Technologies / PulseFlow Systems), in New York, NY, United States. In this policy, “PulseFlow,” “we,” “us,” and “our” refer to that operator. We determine how personal information submitted through this website is used and are the controller of that information where data protection law uses that term. This policy explains our current website practices separately from the requirements that will apply before an authorized connected publishing service launches.
This policy applies to our public pages, contact and access requests, and interactive scheduling preview. It does not govern the independent practices of a social platform, your employer, or a website reached through an external link. Connecting to a future service would require a separate, affirmative authorization through the relevant platform. Merely visiting this website, selecting a demo channel, or reading this policy provides no such authorization.
We do not represent that a platform has approved, verified, certified, or endorsed PulseFlow. Demonstration accounts, statistics, and publishing outcomes are illustrative. We will make the applicable privacy notice, requested permissions, operational providers, and material processing details available before collecting connected-service data. A launch commitment in this document is a condition for that future operation, not a statement that the described infrastructure is currently deployed.
2. Information this website collects today
Contact and access requests
If you submit our contact form, we collect the name, email address, company, topic, and message you choose to provide, together with the consent and submission record needed to administer your request. Company information is optional where indicated. We ask for explicit consent before saving the request. The website endpoint writes accepted requests to private local files on the operator’s server; submitting the form is not an email-delivery service and does not create a publishing account, paid subscription, or social-platform connection.
We use these records to consider access requests, answer questions, and maintain the correspondence necessary to resolve the inquiry. Access is limited to people authorized by the operator for these purposes. Please do not include passwords, access tokens, confidential client material, payment details, government identifiers, or sensitive personal information in the message. If you contact us directly by email, your email provider and our email provider also process the message under their own applicable terms and privacy practices.
Browser-only demonstration information
The interactive preview holds selections, captions, demo connections, and queued demo posts in browser memory. Media selected with the file picker remains local to your browser and is used only for its local preview; it is not uploaded to PulseFlow or a social platform. There is no server-side demo account to erase. Reloading or resetting the preview clears the session’s custom demo state and restores the initial sample experience. Closing the page ends that in-memory session. The original media file remains on your own device until you delete it yourself.
Cookies, tracking, and technical requests
This website does not set analytics, advertising, or tracking cookies and does not use tracking pixels, cross-site advertising identifiers, or browser storage to persist the demo. It does not sell visitor data or build advertising audiences. Ordinary page and form requests necessarily transmit technical information such as an IP address and browser request headers to the server delivering the website. Hosting infrastructure may process operational logs to deliver and protect the site; this is distinct from behavioral tracking. We do not use those requests to profile visitors across other websites.
We do not currently obtain social account identifiers, profile caches, follower information, private messages, Google user data, OAuth access tokens, or refresh tokens. Entering a caption or choosing a sample account in the preview does not cause a platform API request. There is no hidden authorization implied by any demo control.
3. Future authorized connected-service information
Before any connected publishing service becomes available, PulseFlow will restrict collection to information necessary for the features a user deliberately enables. This may include an account email, workspace membership, a platform-provided account or page identifier and display name, authorization scopes, OAuth access and refresh tokens, selected media and captions, scheduled publishing instructions, and delivery status or error information. Specific fields will depend on the platform and granted permissions. We will not request a permission merely because it is available.
OAuth credentials would allow the service to carry out authorized actions without receiving your social-platform password. The authorization screen must identify the platform, permission purposes, and access being requested. Tokens will not be collected through contact messages, embedded in public pages, sent to analytics systems, or exposed to browser application code. Users will be able to decline a connection or revoke it later; a feature that genuinely requires a refused permission may be unavailable without affecting unrelated choices.
Media and associated metadata will be processed only to prepare, queue, transmit, and report on the publishing action requested by the user. We will not collect private messages, contacts, or unrelated browsing information for publishing. If a later optional feature requires additional information, it must have an appropriate notice, a valid legal basis, and any platform-required consent before collection. We will not quietly repurpose a publishing permission for a new product.
4. How information is used & legal bases
For this website, the principal purpose is to respond to the inquiry or access request you send us. Where the GDPR or UK GDPR applies, we rely on your consent to collect and store the form submission as explained beside the form. You may withdraw consent at any time by contacting our privacy address. Withdrawal does not affect the lawfulness of processing before withdrawal, but we may be unable to continue an inquiry without the information needed to respond.
Where applicable, we may process limited information to take steps you request before entering a contract, comply with a specific legal obligation, or pursue legitimate interests in protecting the website, preventing abuse, and establishing or defending legal claims. We assess those interests against your rights and do not treat a general interest in running a business as permission to collect unrelated data. Legal obligations apply only where an actual law requires processing; they are not a blanket exception to deletion.
For a future connected service, processing necessary to execute your publishing instructions and administer your account would ordinarily support performance of the service contract. Additional consent will be requested where required by law or platform policy. Security and narrowly necessary fraud prevention may rely on legitimate interests, subject to applicable safeguards. We will not make legally or similarly significant decisions about you solely through automated processing, sell or rent personal information, conduct unauthorized profiling, or use user content or platform data to train general-purpose artificial intelligence or large language models.
5. Third-party platform disclosures
The following are requirements for future authorized integrations. None of these disclosures means this preview has access to the named platform. Each provider separately controls information held in its own systems, and its rules continue to apply even after you disconnect from PulseFlow.
TikTok
TikTok user data will be used exclusively for the user-requested integration, including identifying the authorized creator and submitting content with the creator’s chosen privacy and disclosure settings. We will not sell TikTok data, create unauthorized profiles, scrape unrelated information, or circumvent visibility and consent requirements. A creator must review the content and applicable controls before authorizing publication. Temporary transit media will be purged within 30 days. See the TikTok Developer Terms of Service, TikTok Privacy Policy, and TikTok Community Guidelines.
Meta: Facebook, Instagram, and Threads
Meta Platform Data will be restricted to the authorized publishing purpose and the accounts or pages a user is entitled to manage. Permissions such as pages_manage_posts, instagram_content_publish, and threads_content_publish will only be requested when necessary for the corresponding user-enabled publishing feature. We will not use these permissions to sell Platform Data, enrich unrelated profiles, or access other accounts. Deletion and permission revocation must be respected. Consult the Meta Platform Terms, Meta Developer Policies, and Meta Privacy Policy.
Google and YouTube
PulseFlow's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
No Google or YouTube API data is collected by this website today. A future YouTube integration will access only information and permissions necessary to provide the user-facing publishing features you authorize. Google user data will not be used for advertising, sold, or transferred for unrelated purposes; human access will be limited to circumstances allowed by the Limited Use requirements, such as your affirmative agreement for a specific support need, necessary security investigation, or legal compliance. We will not use Google data to develop, improve, or train generalized AI or machine-learning models.
Review the Google API Services User Data Policy, YouTube API Services Terms of Service, and Google Privacy Policy. You can review or revoke third-party access in Google Account connections. Revocation prevents further authorized access but is not itself a request to remove a video already published on YouTube.
X and LinkedIn
Any future X or LinkedIn authorization will be limited to the publishing capability a user selects, and the actual authorization interface must accurately explain requested scopes. We will not bypass API restrictions, resell platform data, conduct unauthorized surveillance, or imply access beyond an approved permission. Relevant rules include the X Developer Agreement and Policy, X Privacy Policy, LinkedIn API Terms of Use, and LinkedIn Privacy Policy.
7. Security & encryption requirements
Current contact records are saved outside the public website assets as private local files. They are not intended to be served through a public route, and access must be limited to authorized operational personnel. The demo avoids server-side media and credentials entirely. These facts should not be confused with an audited token vault, a security certification, or a guarantee that every deployment configuration is secure.
Before production connected-service operation, our requirements are an isolated credential vault using AES-256-GCM authenticated encryption at rest, unique nonces, controlled key access, and TLS 1.3 for supported production transport. Tokens must remain server-side and must never enter browser bundles, plaintext logs, or LLM prompts. Access controls, deletion workflows, and platform-specific permissions must be verified before live credentials are accepted. These are launch commitments described further in our security architecture, not presently exercised capabilities of this preview.
No system can promise absolute security. If a personal-data breach occurs, we will investigate, contain it, and provide notifications to affected people and regulators when required by applicable law. We will not ask you to send a social account password or raw token to investigate a privacy request. If you believe you have found an exposure, contact us with the minimum details necessary and avoid copying or distributing other people’s information.
8. Retention & automatic deletion
For present website inquiries, the operator removes contact-request records from private local storage within 90 days after the inquiry is resolved. We do not describe that operator-managed process as an automated email or CRM deletion feature. You may request earlier removal at any time. Unresolved correspondence is retained only while reasonably necessary to handle the active inquiry; it must not be kept indefinitely simply because a request was never formally closed.
A minimal record may be retained longer only when needed to meet a legal obligation or establish, exercise, or defend a legal claim. In that case, retention is restricted to the necessary information and applicable period, access is limited, and the record is not reused for marketing. A record documenting compliance with a deletion request should not preserve the original message or media merely for convenience. We will explain a lawful limitation when we cannot honor a request in full, unless law prohibits that explanation.
Browser demo information is not a server record: reset, reload, or closing the page clears the active in-memory session; sample data can reappear when the preview starts again. For the future service, temporary media transit files must be automatically purged within 30 days of receipt, or sooner when no longer necessary. On a verified deletion request, encrypted OAuth tokens and cached profile data must be permanently erased from PulseFlow-controlled storage within 48 hours. This 48-hour service SLA is a launch commitment, not an existing token-processing feature.
The future deletion design must include credential invalidation, queued-job cancellation, derivative caches, and recoverable copies so that a restore cannot reactivate a deleted connection. We will not claim the SLA is met while usable tokens remain in backups. Posts already delivered to a platform and the original files on your device are not automatically deleted by removing a PulseFlow record. See our data deletion instructions for current demo steps and platform revocation options.
9. Your GDPR, UK GDPR & California privacy rights
Depending on your location and applicable law, you may request access to personal information and details about its processing; correct inaccurate or incomplete records; request deletion; restrict certain processing; object to processing based on legitimate interests; and receive eligible information in a structured, commonly used, machine-readable format for portability. Consent may be withdrawn without penalty. Portability and other rights have legal conditions and are not promises that every internal record or another person’s information will be disclosed.
California residents may have rights under the CCPA, as amended by the CPRA, to know the categories and specific pieces of personal information collected, its sources and purposes, and categories of recipients; to correct inaccuracies; and to request deletion, subject to lawful exceptions. You may also have rights to opt out of sale or sharing and limit specified uses of sensitive personal information. We do not sell or share information for cross-context behavioral advertising, and do not collect sensitive information for the uses that trigger a limitation right. There is therefore no advertising sale or sharing to enable or opt back into on this website.
We will not discriminate against you for exercising a privacy right. You may use an authorized agent where permitted; we may ask for evidence of authorization and verify the request with you. We honor applicable browser-based opt-out signals where legally required; because the site does not sell or share data for targeted advertising, such a signal does not change the browser-only demo experience. We do not require a paid account or an account signup to submit a privacy request.
Send requests to [email protected], preferably from the address used for your inquiry. We normally verify control of that address and match the smallest amount of information necessary to locate the record. We will not routinely request a government ID, full birth date, password, or access token. If additional verification is genuinely needed to prevent disclosure to an impostor, we will explain why and use a proportionate method. Verification information is not retained for an unrelated purpose.
We respond within applicable statutory periods—ordinarily one month under the GDPR and 45 days for eligible California requests—and explain any lawful extension. The future 48-hour token-and-cache deletion commitment is a separate operational deadline after verification, not an extension of your legal rights. If we refuse all or part of a request, we will give the reason and any available review or appeal route. You may complain to the data protection authority where you live, work, or believe an infringement occurred, including your relevant EEA authority or the UK Information Commissioner. You may also contact the California Privacy Protection Agency where applicable.
10. Children & sensitive information
PulseFlow is intended for adult creators and authorized business users, not children under 18. We do not knowingly collect personal information from children or solicit sensitive personal information through the preview. If you believe a child has provided information, contact the privacy address so we can investigate and remove it as appropriate. Do not submit someone else’s personal information unless you have an appropriate basis and authority to do so, particularly when describing a support issue or proposed publishing workflow.
11. Changes to this policy
We may update this policy as the website, legal obligations, or proposed service changes. The date at the top identifies the current version. Material changes will be highlighted on the website, and we will provide direct notice when required and when we have a suitable contact method. We will seek fresh consent where a change requires it; continued browsing alone will not be treated as authorization for a new social connection or a materially different use of previously collected data.
12. Privacy contact & operator details
The responsible operator is Ariel Tolome Technologies / PulseFlow Systems, New York, NY, United States. Send privacy questions, access requests, objections, or deletion requests to [email protected]. For general product support, use [email protected] or the contact page.
Our privacy contact handles data protection inquiries. We do not claim to have appointed a statutory Data Protection Officer, named representative, or independent privacy certification. If an appointment becomes legally required, the relevant contact details will be published. This notice describes our practices and commitments; it does not waive any non-excludable right or remedy available to you under applicable privacy law.