1. Scope and company
This Privacy Policy describes how ReliaPulse LLC ("ReliaPulse," "we," "us," or "our") handles personal information through the ReliaPulse websites, application, beta program, device services, integrations, notifications, support, bug-reporting features, and related services (collectively, the "Service"). It applies to United States users of the current beta and free-service build.
This Policy does not govern third-party services you connect or visit. Their privacy policies apply to their processing.
2. Information we collect
Account and membership information
Name, email address, password hash, account role, plan and status, login and account timestamps, location memberships, member roles, and assignments.
Locations, assets, tasks, and records
Location names and addresses, time zone, asset name and type, manufacturer, model, serial number, purchase and warranty dates, status, notes, chores, maintenance plans, schedules, priorities, completion or dismissal status, assignments, resolution notes, service provider, service date, cost, and service history.
Files you choose to provide
When supported, manuals, warranties, receipts, photos, screenshots, service records, filenames, file type and size, notes, and upload time.
Devices and telemetry
Device identifiers and pair status, firmware and board information, network address, online or offline status, timestamps, Wi-Fi signal strength, uptime, memory status, point and state values, event payloads, rule configuration, alarms, errors, and update status.
Home Assistant integration
Server name and URL, encrypted access token, selected entity identifiers and friendly names, current state and attributes, device class, unit, rule settings, synchronization status, errors, and timestamps. ReliaPulse may use Home Assistant history to evaluate rules but does not intentionally retain raw Home Assistant history.
MQTT settings
Broker host and port, username, encrypted password, enabled status, connection state, errors, and timestamps.
Notifications
Push endpoint and subscription keys, browser and platform details, user-agent information, notification preferences and quiet hours, notification title, body and link, delivery status, errors, and timestamps.
Technical and security information
IP address, browser and device information, user-agent information, session cookie, request and error data, anti-abuse challenge information, login time, connection information, and administrative audit records.
Bug reports, support, and feedback
When you submit a bug report, support request, survey, or other feedback, we may collect:
- The description, comments, troubleshooting details, screenshots, files, or other information you choose to provide.
- Your optional contact information.
- When you are signed in, your ReliaPulse user ID, name, and account email address.
- The website or application from which the report was submitted.
- The current page URL, path, page title, and active application view. URLs may include information contained in query strings or page fragments.
- The date and time of submission and your reported time zone.
- Your IP address and browser user-agent information.
- Browser language and platform information.
- Whether the browser reports a mobile device.
- Browser viewport, screen dimensions, available screen area, color depth, and device pixel ratio.
- Internet connectivity status, application display mode, referring page, and supported touch-point count.
- Administrative status, internal notes, resolution information, and the date and administrator associated with resolving or closing the report.
The bug-report form is not intended for passwords, authentication tokens, payment-card information, financial account information, Social Security numbers, private encryption keys, medical information, or other sensitive information. Do not include this information in a report.
3. Sources of information
- Directly from you when you register, configure the Service, enter records, submit a bug report, contact us, or provide feedback.
- From other authorized members or administrators of a shared location or organization.
- Automatically from your browser, device, network, and use of the Service.
- From devices, MQTT brokers, Home Assistant, and other integrations you choose to connect and authorize.
- From security and infrastructure providers used to operate and protect the Service.
4. How we use information
- Provide accounts, shared locations, assets, tasks, records, notifications, device functions, integrations, and support.
- Authenticate users, enforce roles and limits, maintain sessions, prevent abuse, secure systems, investigate incidents, and keep administrative audit records.
- Generate schedules, tasks, alerts, state summaries, and other requested outputs.
- Receive, review, reproduce, prioritize, investigate, track, and resolve reported bugs and technical issues.
- Associate reports with the correct account, page, application view, browser, device environment, or Service component.
- Contact you about a report when you provide contact information or submit the report through a signed-in account.
- Identify duplicate, recurring, fraudulent, automated, or abusive submissions.
- Verify fixes, monitor whether issues recur, and maintain an internal history of reported problems and resolutions.
- Operate, troubleshoot, test, analyze, and improve beta and production features, including using feedback and aggregated or de-identified information where practical.
- Communicate about the Service, requested support, security, legal notices, beta activities, and material changes.
- Comply with law, respond to lawful process, enforce agreements, protect rights and safety, and complete business transactions.
5. How we disclose information
We do not sell or rent personal information, and the current beta build does not use personal information for cross-context behavioral or targeted advertising.
- Authorized ReliaPulse personnel: Bug reports, support requests, diagnostic details, and administrative records may be accessed by authorized personnel responsible for operating, securing, supporting, and improving the Service.
- Shared locations and organizations: Authorized location owners, administrators, members, and viewers can access information according to their role. An organization may control its workspace, members, and organization content. Bug reports submitted directly to ReliaPulse are not ordinarily shared with other users unless necessary to address an issue affecting a shared location or organization.
- Service providers: We may disclose information to hosting, database, security, email, support, backup, and infrastructure providers that process it for us under appropriate restrictions.
- Cloudflare: The Service uses Cloudflare Turnstile for login and registration anti-abuse checks and may use Cloudflare security and access services. Challenge data, IP address, and technical information may be processed by Cloudflare.
- User-directed integrations: When you connect Home Assistant, MQTT, browser push services, or devices, information is exchanged with those systems as needed to perform your instructions. Browser and operating-system providers may process push subscription and delivery data.
- Legal and safety: We may disclose information when reasonably necessary to comply with law or legal process, enforce agreements, investigate fraud or security issues, or protect rights, property, and safety.
- Business transfers: Information may be transferred as part of a financing, merger, acquisition, reorganization, bankruptcy, or sale of all or part of the business, subject to applicable law.
- With consent: We may disclose information in other ways you authorize.
6. Cookies, browser storage, and similar technology
ReliaPulse uses a first-party RELIAPULSE_SESSION cookie to keep you signed in and secure account access. The current configuration allows a session lifetime of up to 60 days. The cookie is configured as HttpOnly, SameSite=Lax, and Secure when the request is detected as HTTPS.
The progressive web app uses a service worker and browser cache for the application shell, static resources, offline behavior, and push notifications. The current service worker excludes API responses from caching but may cache same-origin non-API pages and resources. You can clear site data or remove the installed web app through browser settings.
Cloudflare Turnstile may use necessary browser storage or related technology to distinguish legitimate users from automated abuse. The current build does not contain Google Analytics, advertising pixels, localStorage, sessionStorage, IndexedDB, or geolocation calls. We will update this Policy before materially changing those practices.
Submitting a bug report causes the browser to transmit the report and associated technical details described in this Policy. Public reports may be subject to connection-based submission limits designed to prevent spam and abuse.
7. Retention
We retain information for as long as reasonably necessary to provide, support, improve, and secure the Service, maintain legitimate records, comply with law, resolve disputes, and enforce agreements. Retention varies by data type and configuration.
- Current free-beta settings generally schedule operational device point history, selected device events, completed notification queue records, and notification delivery logs for deletion after 90 days.
- Meaningful administrative action-audit records are generally scheduled for deletion after 365 days; routine administrative page-view records are intended to be removed sooner.
- Bug reports and associated diagnostic details may be retained while the issue is open and for a reasonable period afterward to document the resolution, verify fixes, identify recurring issues, prevent abuse, and improve the Service.
- Resolved or closed reports may remain in an internal issue history. We may delete, anonymize, or reduce identifying and diagnostic details when they are no longer reasonably needed.
- Core account, location, asset, task, service, membership, and configuration records may remain while the account or shared location is active and until deletion is requested or otherwise scheduled. Archiving or removing a location or member may not immediately delete all related history.
- Disabled push subscriptions, security records, legal-acceptance records, legal records, and backup copies may remain for a limited period until routine deletion, backup rotation, or a legitimate retention need ends.
Because the current build does not provide self-service account deletion, deletion requests are handled manually. We may retain limited records when required or permitted by law and will explain material exceptions when reasonably possible.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information. The current build includes password hashing, role-based access checks, secure-session settings, restricted administration, encrypted storage for supported Home Assistant and MQTT secrets, encrypted web-push delivery, origin restrictions, anti-spam controls, and rate limits for public bug reports.
No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.
Protect your email and ReliaPulse password, device and integration tokens, MQTT credentials, and network access. Do not place passwords, access tokens, payment information, or other secrets in bug reports or support messages. Promptly disconnect integrations and contact us if you suspect compromise.
9. Your choices and requests
- Account and content: Update information through available app features or contact us to request access, correction, export where reasonably available, closure, or deletion.
- Bug reports: Providing a contact email on the public bug-report form is optional. Signed-in reports are automatically associated with the submitting account. You may contact us to request access to, correction of, or deletion of a report, subject to identity verification and legitimate retention needs. Providing the report number may help us locate it.
- Shared locations: Location owners and administrators control membership and roles. Contact the relevant owner or administrator if organization-managed information is inaccurate or access should be removed.
- Push notifications: Change preferences in ReliaPulse and in your browser or device. Disabling push may not delete all prior delivery logs immediately.
- Integrations and devices: Disconnect Home Assistant, MQTT, push subscriptions, or devices through available controls, then rotate third-party credentials when appropriate.
- Communications: You may opt out of non-essential promotional messages if any are later offered. We may still send service, security, account, support, and legal notices.
We may verify identity and authority before acting, including authority to act for another person or organization. Rights vary by location, and we will respond as required by applicable law.
10. Children
The Service is not directed to children, and users must be at least 18 years old during beta. Do not create an account for a child or submit a child's personal information. If you believe a child's information was provided, contact us so we can review and delete it as appropriate.
11. United States processing
The current beta is offered only in the United States. Information is processed in the United States and may be subject to United States law. Do not invite or enroll users outside the United States until ReliaPulse has reviewed applicable international privacy, consumer, tax, and data-transfer requirements and updated this Policy.
12. Changes to this Policy
We may update this Policy as the Service and legal requirements change. We will post the updated version and effective date and provide additional notice for material changes when appropriate. If a change requires consent, we will request it before applying the change as required by law.
13. Contact
Privacy questions and requests: [email protected].