Privacy Policy
Last updated:
Draft. This document was written in-house and is pending review by a lawyer. It describes what the service actually does today, and we will publish a reviewed version before general availability.
Titus Pulse is operated by Titus Hub Inc. (“we”, “us”). This policy explains what we collect, why, who we share it with, how long we keep it, and how to have it deleted. It covers the Titus Pulse web application at tituspulse.com and the emails it sends.
Who this policy is about
Titus Pulse is used by people who report on websites for their clients. Two groups of people appear in it:
- Account holders: the people who hold an account, sign in, connect a Google account and approve reports.
- Report recipients: the people an account holder nominates to receive a site's report by email. They have no account and we hold only what is needed to send and to stop sending.
For the data an account holder brings into the service about the sites they manage, the account holder is the controller and we act on their instructions as a processor. For account data, we are the controller.
What we store
- Account: your email address, display name, a hashed password (held by Firebase Authentication; we never see the password), whether your email is verified, and sign-in timestamps.
- Account settings: the account name, time zone and reporting settings.
- Sites: the site names and web addresses you enter, and which Google Ads account, Google Analytics 4 property and Search Console property each one is mapped to.
- Report recipients: the name (optional) and email address of each person you choose to send a site's report to, plus their delivery state: sent, bounced, complained or unsubscribed.
- Report data: the weekly and monthly metrics read from the Google account you connect, the generated reports, the note you write, and a record of who approved each report and when.
- Google credentials: the identifier and email address of the connected Google account, the scopes it granted, and the OAuth refresh token. Refresh tokens are encrypted at rest with AES-256-GCM under a key held in Google Secret Manager, are never displayed in the interface, and are never sent to your browser.
- Operational logs: request and error logs used to keep the service running. We do not log report note text, and we avoid logging email addresses and tokens.
We do not ask for, and have no use for, special-category data. Please do not put personal information into free-text fields such as a site name or a report note beyond what your client would expect to read.
Data from your Google account (Limited Use)
When you connect a Google account, we ask Google for permission to read reporting data on your behalf. The scopes we request are:
https://www.googleapis.com/auth/webmasters.readonly: Google Search Console, read-only. Your verified properties, and clicks, impressions, click-through rate, average position, queries and pages for the report period.https://www.googleapis.com/auth/analytics.readonly: Google Analytics 4, read-only. Your properties, and aggregate metrics such as sessions, users, engaged sessions and key events for the report period.https://www.googleapis.com/auth/adwords: Google Ads. Google does not publish a read-only variant of this scope, so it is the one we must request; we only ever issue read (search) requests with it, for account and campaign performance figures such as cost, clicks, impressions and conversions. We do not create, edit, pause or delete anything in your Google Ads account.openidandemail: so we can show you which Google account is connected and keep a reconnection attached to the same account.
Titus Pulse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms, data read from a connected Google account is:
- used only to build and deliver that account's reports, and to show you the state of the connection;
- never sold or licensed to anyone;
- never used for advertising, ad targeting, profiling or market research;
- never used to train machine-learning or artificial intelligence models, ours or anyone else's;
- not read by humans, except where you have asked us to look at something, where it is necessary to investigate a security incident or abuse, or where the law requires it;
- not transferred to third parties except to the infrastructure providers listed below that we need in order to run the service, or where the law requires it.
You can revoke our access at any time from the connections screen in the app, or from your Google account permissions page. When you disconnect, we revoke and delete the stored tokens and delete the data we derived from that account, other than reports you have already sent, which stay in the record until the retention period below expires or you ask us to remove them.
Emails we send
Two kinds of email leave the service: account email to account holders (address verification, password reset, notifications that reports are ready) and report email to the recipients an account holder nominates.
Both are delivered through Brevo, our email provider, acting as a processor on our instructions. Brevo receives the recipient address and the message content in order to deliver it and to report back delivery outcomes such as bounces and complaints. See Brevo's privacy policy.
Every report email carries an unsubscribe link. Unsubscribes, bounces and complaints are recorded against that recipient and are honoured across the account: we will not send to a suppressed address again, and an account holder cannot switch it back on.
Cookies and local storage
We use no advertising or analytics cookies, and no third-party trackers. The only browser storage we rely on is what Firebase Authentication needs to keep you signed in: a session token in your browser's local storage. Clearing it signs you out; nothing else about you is kept there.
Where the service runs, and who else processes data
- Google Cloud / Firebase: Firebase Authentication, Cloud Firestore and Firebase App Hosting. This is where the application runs and where the data described above is stored. The application backend runs in Google's
us-east4region in the United States. - Brevo: transactional email delivery, as described above.
- Google Ads, Google Analytics and Google Search Console: the sources we read from, on your instruction and with your permission.
We will update this list before adding any other processor that handles personal data.
How long we keep things
- Reports, report versions and delivery records: 25 months, so that a report can always be compared with the same period a year earlier, then deleted automatically.
- Google refresh tokens: until you disconnect that Google account or the account is deleted, whichever comes first.
- Account, site and recipient records: until you delete them or the account is deleted.
- Suppression records (unsubscribes, bounces, complaints): kept for as long as the account exists, because deleting them would let a suppressed address be emailed again.
- Operational logs: up to 30 days.
Your choices, and how to have data deleted
Inside the app you can edit or remove sites and recipients, and once a Google account is connected you can disconnect it. To ask for a copy of your data, a correction, or deletion of everything we hold about you, email support@tituspulse.com from the address on the account. We will confirm and complete the request within 30 days.
If you are a report recipient and want to stop receiving a report or be removed entirely, use the unsubscribe link in any report email, or email us at the address above and we will remove you and tell the account holder that sent it.
Depending on where you live you may have rights to access, correct, delete, export or object to our use of your personal data, and to complain to your data protection authority. Email us and we will help.
Security
The browser never writes to our database directly: every change goes through a server route that checks who you are and which account you belong to. Accounts are isolated from each other by server-side checks and by database rules that deny access by default. Google refresh tokens are encrypted at rest as described above. No service can promise perfect security, but if a breach affects your data we will tell you and the relevant authority without undue delay.
Children
Titus Pulse is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes to this policy
We will change this page when the service changes. The date at the top always reflects the current version, and we will email account holders before a change that materially affects them.
Contact
Titus Hub Inc.
support@tituspulse.com
See also our Terms of Service.