Privacy Policy
Last updated: 6 October 2026
Pulse Extractor is a software product operated by Muhammad Awais Muhammad Saeed, an individual based in the United Arab Emirates. The operator may also use the professional name Awais BinSaeed. This Policy describes how the operator handles information through the website, browser extension, and related service.
1. What the extension reads
Pulse accesses the active tab only after you invoke Extract Page. It may read the page URL, title, visible text, headings, links, tables, structured metadata, and similar page elements needed to create the requested result. It does not request permission to view your browsing history, monitor other tabs, read Chrome passwords, or crawl sites in the background.
2. Extract Page (deterministic extraction)
Extract Page is performed by the extension on your device. Results remain in the extension unless you copy or download them. Pulse does not automatically upload an ordinary Extract Page result merely because you extracted a page. On the Free plan, a lightweight request containing only metadata (an operation identifier only, never page content) authorizes each Extract Page run against your monthly allowance; paid plans are recognized as unlimited by the same check. Full-Page Capture and Professional Export are authorized the same way: the request carries only an operation identifier, the kind of action, the file format and where in Pulse it started, never page content or the file itself. See Section 8.
3. Research
Research is an authenticated feature, billed in Investigations, that looks for relevant public evidence beyond the page you're viewing: the relevant website and other useful public sources. It runs on Pulse's backend, not on your device: the backend fetches and processes publicly accessible pages to find additional information (such as related pages, contacts, projects, or procurement routes), guided by a preset or a custom objective you choose. Research does not access private pages or pages that require signing in, and only processes sources that are otherwise publicly reachable.
Research is built on deterministic page analysis and public-source search. Pulse may also use AI-assisted synthesis to help organize what Research finds; when it does, that assistance is grounded in the evidence Research actually collects and is checked against it before being included; where Research cannot verify enough reliable information, it returns an honest Insufficient evidence result rather than an AI-generated guess, and that Research is not charged. See Section 10 for the providers involved.
4. Smart Snip
When you choose Smart Snip, Pulse processes the webpage region you selected to identify useful table, text, image, or mixed content. It prefers page structure where available and may use built-in on-device text recognition when needed. The selected content is not uploaded merely to create the local Smart Snip result. A server request authorizes the plan allowance but does not carry the selected webpage content.
Smart Snip can copy the selected image to your clipboard, and it keeps your recent snips from the current browser session in the extension's local storage on your device so you can reopen, edit or export them. They are never uploaded, you can delete them at any time, and they are deleted when the browser starts again. Image edits such as blur or redaction change the image only; text Pulse recognized from the original selection is unaffected, and Pulse points this out when it applies.
5. Smart Enrichment and Google Gemini
Smart Enrichment is a separate, optional, AI-assisted capability that would require an authenticated account, a usage allowance, and your explicit, revocable consent before ever running. It is not reachable from the current version of the extension: no interface exists to grant that consent, so this capability does not currently process any data. This section is retained so its behavior is documented accurately if it is ever enabled: when active, Pulse would send a bounded evidence packet derived from the selected page to the Pulse backend, which may send that packet to Google Gemini to generate the requested enrichment; Pulse would validate and ground returned fields before presenting them, but AI output can still be incomplete or wrong.
The current database intentionally stores request and outcome metadata rather than raw webpage evidence. Raw evidence, when processed at all, is handled in memory for the request and is not intentionally written to Pulse database tables. Network and AI providers may process transient data under their own service terms and technical logs.
6. Account and authentication data
Supabase provides authentication and stores account identifiers such as email address, user ID, confirmation state, and timestamps. The extension stores the authenticated session in Chrome extension storage so it can make authorized requests; it does not store your account password. Confirmation and recovery emails are sent through Supabase using the configured email-delivery provider.
7. Billing and Investigation data
Pulse stores payment provider customer, subscription, transaction, purchase session, plan, entitlement, and Investigation ledger identifiers needed to fulfill and reconcile purchases. Where a third-party payment provider or Merchant of Record is used, that provider handles payment card data; Pulse does not receive or store full card details. Server records, not the website or extension display, control entitlement and balance.
8. Service metadata
Pulse may process an extraction identifier, operation type (Extract Page, Free plan authorization, Smart Snip, Full-Page Capture, Professional Export, or Research), evidence size, latency, acceptance outcome, credit or quota event, a rate-limit key derived from your IP address (a keyed hash of the address that changes every day and is deleted within about a day, not the address itself), and limited error information for fulfillment, ledger integrity, reliability, fraud prevention, and abuse control. This includes Free plan usage counts (how many of your monthly Page Extractions, Smart Snips, Full-Page Captures and Professional Exports you've used) so the allowances can be enforced and displayed to you. Usage tables are designed to avoid raw page content, extracted facts, and personal data found on a page.
Pulse installation identifier and your devices. Versions of the extension that include device management create a random Pulse installation identifier the first time it needs one and keeps it in the extension's own storage on your device. It is random: it is not derived from your hardware, your browser, your network or anything about you, and it is not a device fingerprint. The extension sends it only with requests to Pulse's own servers, never to the websites you visit or to any third party. Pulse stores a keyed hash of it, not the identifier itself, together with a name you can edit, a coarse label such as “Windows · Chrome”, the Pulse version, and when the device was first and last used. We use it only for device and security management and to keep plan allowances fair: to count the devices on an individual plan and show them to you under Your devices, so you can rename or remove them; to make sure free allowances are not claimed again by switching accounts on the same installation; to notice unusually rapid device changes; and to prevent fraud and abuse. For the same reason, free allowances are shared by different spellings of one email mailbox (for example “name+1@gmail.com” and “n.ame@gmail.com”): Pulse stores a keyed hash of the mailbox for this, never the address in that record. It is not used for advertising, analytics, profiling or tracking you across websites. Signing out does not change it, because it identifies the Pulse installation rather than you; uninstalling Pulse deletes it. When unusually rapid device changes, or many new accounts from one network on the same day, need a security check, Pulse may ask you to complete one on pulseextractor.com, where Cloudflare Turnstile processes the check under Cloudflare's Turnstile Privacy Addendum.
Page view counting. On pulseextractor.com we count page views as daily totals per page and traffic source, including the referring website’s hostname and campaign tags in the link. Pulse analytics uses no cookies, device storage or persistent visitor identifiers, and does not store IP addresses for this measurement or use it to identify visitors. We do not record the analytics event when your browser sends Global Privacy Control or Do Not Track.
Feedback you send us. If you use a feedback form on our website or in the extension, we keep your message, the topic you chose, the website domain (never the page address or its content), your plan and extension version if you are signed in, and, only if you provide it, an email address so we can reply. Diagnostics are attached only if you explicitly choose to include them. We use feedback only to improve Pulse and to reply to you. We do not sell feedback data or use it for advertising.
9. Referrals, campaign attribution, and the partner program
Pulse records how some visitors first reach pulseextractor.com, so that a partner who referred you can be credited, so that referral fraud can be prevented, and so that we can see which channels bring customers. A visit is recorded only when you arrive through a partner's referral link or referral code, a link carrying campaign labels (for example “utm_source”), or a recognised external website such as a search engine, social network, or AI assistant. An ordinary direct visit is not recorded. For a recorded visit, your browser's local storage holds a random identifier, any referral code, and a note of the last recorded visit so that reloading a page is not counted twice. Pulse receives the referral code, the campaign labels, the page you landed on (without its query string), and the name of the website that linked to you, never the full address of that page. We do not store your IP address, user agent, or a device fingerprint with referral records. As for every Pulse request, a short-lived rate-limit key derived from your IP address may be used to prevent abuse (see Section 8).
Your choice. If you are in the European Union, the European Economic Area, the United Kingdom, or Switzerland, Pulse asks for your permission before storing or sending anything for referral attribution. Your browser works out whether to ask from your device's time-zone setting; the time zone is not sent to Pulse, and if it cannot be read, Pulse asks. You are asked only when you arrive through a referral or campaign link. If you choose “Don't allow”, nothing is stored on your device for referrals except that choice, no visit is sent to Pulse, and a later sign-up is not credited to anyone. Visitors elsewhere can turn referral tracking off in the same way. If your browser sends a Global Privacy Control or Do Not Track signal, no visit is sent to Pulse; outside the regions above, a referral code you arrived with is kept only on your device so the partner who referred you can still be credited if you sign up, and inside those regions nothing is stored at all. Pulse, including sign-in, the extension, and every paid feature, works exactly the same whether or not you allow referral tracking.
Withdrawing deletes the referral identifier and code from that browser and stops further referral tracking there. It does not undo a referral that was already linked to an account; you can ask us to delete that as described in Section 12.
The 90-day window. A referral is credited only if the account is created within 90 days of the referred visit. When you create an account or first sign in, the referral is linked to your account once. An account that already existed is not assigned to a partner through a later click, you cannot be credited to yourself, and Pulse's own staff and test accounts are not credited. After that, Pulse links later events on your account to the referral, such as your first use of Pulse, subscription starts, renewals, plan changes, cancellations, payment amounts, refunds, and chargebacks, so that commission can be calculated on revenue Pulse actually collects and reversed when a payment is refunded or charged back. To prevent self-referral and abuse, Pulse compares your account email with the referring partner's email and checks whether the same browser identifier appears on several accounts. If you have the Pulse Chrome extension installed and referral tracking is allowed, the website may pass the same random identifier and referral code to the extension on your own device, so that signing in inside the extension can be credited in the same way.
Partners see totals only (clicks, sign-ups, activations, conversions, and commission amounts) and never see your name, email address, or account. If you are a Pulse partner, we process your name, email, referral codes, aggregated performance, commission records, and payout references to run the program. Referral and attribution records are retained while reasonably needed for crediting partners, fraud prevention, and dispute handling. Where a referral leads to a payment, the related conversion, commission, and accounting records may be kept separately for as long as contractual, accounting, tax, fraud-prevention, or other legal obligations require, including after consent is withdrawn or an account is closed (see Section 12).
10. Service providers
- Supabase: authentication, database, and backend functions.
- Cloudflare: HTTPS website hosting and network delivery.
- YouTube (Google): plays the video tutorials on this website, in privacy-enhanced mode. Video previews do not contact YouTube until you press play. When you play a video, YouTube receives the normal information required to deliver the video.
- Public search providers: used by Research to locate relevant public sources beyond the page you're viewing; not used by Extract Page.
- AI language model providers: may be used by Research to help organize verified public evidence into a structured result, and by Smart Enrichment only if it is enabled in the future (see Section 5); not used by Extract Page, Smart Snip, or Full-Page Capture.
- Payment provider: checkout, billing, applicable tax handling, receipts, refunds, and customer account or portal functions where available.
- Authentication email provider: delivery of confirmation and recovery email.
Providers process information only as needed to supply these functions, under their applicable terms and privacy practices. We may also disclose information where legally required or reasonably necessary to protect users, the service, or legal rights.
11. Limited use and no sale of data
Pulse uses active-page data only to provide the user-requested Extract Page or Research result, protect the service, provide support with your consent, or comply with law. Pulse does not sell personal data, use extracted page content for personalized advertising, or share it with data brokers. Humans do not routinely read page content; the current server does not intentionally retain raw page evidence for later human review.
12. Retention and deletion
Pulse currently has no automated self-service account deletion flow and no single fixed retention period for every record. Account, billing, subscription, purchase session, entitlement, ledger, webhook idempotency, and usage metadata are retained while reasonably needed to operate accounts, prevent duplicate grants, handle disputes, investigate abuse, and meet legal, tax, or accounting obligations. Some financial records and records kept for fraud prevention may have to remain after account closure. Raw page evidence is not intentionally persisted in Pulse database tables. Device records are kept while the device is on your account and deleted about 180 days after it is removed; a device that has not used Pulse for 45 days is removed from your account automatically. Device and security event records are kept for about 180 days. The link between a free-plan action and the installation it came from is kept for about 60 days, except the record that an installation or mailbox has used its one free lifetime Research, which is kept for as long as that rule applies. The daily network key used for rate limits changes every day and is deleted within about a day.
You may request access, correction, or deletion by email. We will verify the request and delete or de-identify information that is no longer needed, subject to legal and operational retention requirements. Local extension data can also be removed by signing out, clearing extension data, or uninstalling Pulse.
13. Security
Pulse uses HTTPS, authenticated endpoints, row-level access controls, signed payment webhooks, rate limits, and server-authoritative ledgers. No internet service can promise absolute security, and Pulse does not claim certifications it has not obtained.
14. Choices, rights, children, and international processing
You may use Extract Page without Research, sign out, cancel through the payment provider's customer portal where available, or contact us about your information. Privacy rights vary by location and may require identity verification. Pulse is not directed to children under 16. Providers may process data in countries other than yours, subject to their applicable safeguards and legal obligations.
15. Changes and contact
We will update this page and its date when this Policy materially changes. Privacy and support requests may be sent to support@pulseextractor.com.