Pulse logoPulse by MMTC
Legal

Privacy Policy

Effective: 26 September 2026

This policy explains how personal data is processed when you use the Pulse by MMTC iPhone app (“App”), the website pulsebymmtc.com (“Website”) and our social media channels. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Controller

Manuel Eggers (Pulse by MMTC)
Kammerbotenstraße 1
83435 Bad Reichenhall, Germany
E-mail: [email protected]

We are not required to appoint a data protection officer. For all privacy questions, please contact us at the address above.

2. Website

The Website is hosted by Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA) via Cloudflare Pages. When you visit the Website, Cloudflare automatically processes technical data that your browser transmits (IP address, date and time, requested page, browser type, operating system, referrer). This is necessary to deliver the Website and to protect it against attacks (legal basis: Art. 6(1)(f) GDPR – our legitimate interest in a secure and working website). Cloudflare may process data in the USA; Cloudflare is certified under the EU-U.S. Data Privacy Framework and additionally uses EU Standard Contractual Clauses.

The Website does not use cookies, analytics, advertising tools, external fonts or embedded third-party content. If you contact us by e-mail, we use your e-mail address and message only to answer your request (Art. 6(1)(b) or (f) GDPR).

3. App

3.1 Using the App without an account

Many features (market data, heatmap, news, market regime) work without an account. The App loads this public market information from our backend and from public data sources (e.g. Binance, CoinGecko, alternative.me and news feeds). These requests contain your IP address and device information technically required for the connection, but no account data.

3.2 Account (Sign in with Apple)

If you create an account, we use Sign in with Apple. We receive a unique user identifier and – depending on your choice – your e-mail address or an Apple private relay address, and optionally your name. We store your profile: display name, optional profile picture, language, selected interests and notification preferences, plan/subscription status. Legal basis: Art. 6(1)(b) GDPR (providing the service you requested).

3.3 Content you enter

Data you enter yourself is stored in your account so that it is available on your devices and for alerts: watchlists, price alarms and alert rules, trades (symbol, side, entry, size, leverage, targets, stop loss, results) and your trade journal. Legal basis: Art. 6(1)(b) GDPR. We use this data only to provide the App’s functions (e.g. portfolio view, trade coach, risk alerts) and never sell it.

3.4 Face ID, widgets and Live Activities

The optional app lock uses Face ID / Touch ID. Biometric data is processed exclusively by iOS on your device; we never receive it. Widgets and Live Activities display data that is already in the App.

3.5 No tracking

The App contains no advertising, no third-party analytics or tracking SDKs and does not track you across apps or websites.

4. Exchange import (optional)

If you connect an exchange (Bybit, Binance or Phemex), you provide a read-only API key. The key secret is stored encrypted in our backend’s secure key vault and is used only to read your trade history and import it into your journal. We store the exchange name, a short hint of the key (e.g. the last characters), the sync status and the imported trades. We never place orders or withdraw funds. Please only use keys without trading or withdrawal permissions. You can disconnect at any time; the stored key is then deleted. Legal basis: Art. 6(1)(b) GDPR.

5. Notifications

If you allow notifications, we store a push token of your device (plus app version, device model and selected alert categories) to send price, liquidation, news and trade alerts via the Apple Push Notification service (APNs) operated by Apple. Legal basis: Art. 6(1)(a) GDPR (your consent via iOS). You can revoke this at any time in the iOS settings.

6. In-app purchases

Subscriptions and purchases are processed exclusively by Apple via the App Store. We do not receive your payment details. We receive and store information about the purchased plan, its status and expiry date in order to unlock features (Art. 6(1)(b) GDPR). Apple’s privacy policy applies to the payment process.

7. Social media

We operate accounts on Instagram (Meta Platforms Ireland Ltd.), YouTube (Google Ireland Ltd.), TikTok (TikTok Technology Ltd., Ireland) and Telegram. When you visit these profiles, the respective platform processes your data under its own privacy policy. For Instagram page insights, we are jointly responsible with Meta (Art. 26 GDPR); Meta provides the Page Insights Addendum.

Automated replies: We use the official Instagram API to publish our own posts and to reply to comments under our posts. When you comment, we process your username, the comment text and its ID to post a public reply. If you comment a keyword such as “HEATMAP” or “LINK”, we send you one private message with the requested link. We keep a short log of these actions (comment ID, username, action, time) for up to 90 days to avoid duplicate replies. Legal basis: Art. 6(1)(f) GDPR (our interest in answering our community) and, for the requested message, Art. 6(1)(b) GDPR. We also read aggregated post statistics (reach, likes, views).

We use the official YouTube and TikTok interfaces only to publish our own videos to our own channels; we do not access data of viewers through these interfaces.

8. Google / YouTube API data

Pulse uses the YouTube Data API solely to upload our own short videos to our own YouTube channel. The OAuth access is limited to that channel. Pulse’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. YouTube’s Terms of Service and the Google Privacy Policy apply. Access can be revoked at any time via the Google security settings.

9. Service providers and transfers

Where data is transferred to the USA, this is based on the EU-U.S. Data Privacy Framework and/or EU Standard Contractual Clauses (Art. 45, 46 GDPR). We do not sell personal data and do not share it with third parties for advertising.

10. Retention and deletion

We store account data and content for as long as your account exists. You can delete your account directly in the App (in your profile settings) or by e-mail; your profile, trades, alerts, push tokens and exchange keys are then deleted, unless statutory retention obligations apply. Server logs are deleted after a short period (usually within 30 days). Records of purchases may be kept as required by commercial and tax law.

11. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to withdraw consent at any time with effect for the future (Art. 7(3) GDPR).

Right to object (Art. 21 GDPR): Where we process data based on legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation, e.g. to automated replies to your comments. Just send us an e-mail.

You also have the right to lodge a complaint with a supervisory authority, e.g. the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

12. Other

We do not use automated decision-making within the meaning of Art. 22 GDPR. The App is not directed at children under 16. Providing data is voluntary; without an account, some features (sync, alerts, trades) are not available. We may update this policy when our services change; the current version is always available on this page.