PulseRest 隐私政策
最后更新:2026-09-06。服务:昇丽科技有限公司(SunnyCreate)旗下 PulseRest。联系:contact@striketl.com。
本机测量
PulseRest 使用手机运动传感器记录胸部机械运动,估计心率和呼吸频率。原始多轴运动、完整回放、测量结果和聊天记录默认保存在本机。不使用相机、麦克风、位置、广告标识或 HealthKit,不展示广告、不进行跨 App 跟踪。准备倒计时不采集;实际测量为 30 秒。
App 将本机数据库和波形存储目录标记为排除系统备份。该设置不控制您自行导出的文件、由您或其他工具制作的副本,也不保证供应商或服务器的备份会随本机删除而消失。设备保护与您管理的副本仍取决于您的系统和存储设置。
AI 仅在明确同意并主动发送后使用
进入分析页面只在本机附加上下文,不发送健康正文。您同意新版数据共享并点击发送或主动选择发起问题后,本次最终心率/呼吸估计及可用状态与单位、30 秒时长、固定胸部运动测量方法、随机记录 ID、语言、您的提问及当前会话中预算内的最近完整消息轮次会用于生成一般健康生活参考。
每段新关联测量对话的首个主动请求,若本机存在可信回放,会另附本次胸部运动的处理、抽样波形,最多 1200 点,包含相对秒数、g 单位、40 Hz 抽样信息与缺口标记。它不是原始多轴 IMU 数据或心电图。首轮成功回复保存后,追问只携带结果及预算内聊天,不重复附带波形数组;重新打开已有对话不会重置首轮。首轮失败、取消后的重试或已同意路线的容灾尝试可能再次传输同一首轮上下文。缺失或不可信波形不伪造,只分享结果;旧会话升级不会为了补传波形自动发起请求。
不上传全部多轴原始传感器采样点、设备与姿态信息、信号质量、其他测量历史、姓名或精确绝对测量时间。抽样波形不能让 AI 重新测量、核验准确性、诊断或估算血压。后续请求不附波形不代表供应商删除了之前接收的数据,本机删除或升级也无法撤回已分享内容。请勿在聊天中填写身份号码、联系方式或他人的健康资料。若您自愿提供过敏、饮食限制或用药信息,这些文字属于聊天内容,会随该请求及预算内的相关聊天一并发给已同意的数据接收方;无需提供这些信息也可继续本机测量。
数据接收方和路线
首选直连 DeepSeek(模型 deepseek-v4-flash),后备直连 PoYo(模型 gpt-5.4)。模型名称是供应商标称;PoYo 是转发平台,其下游模型处理方及处理地区受供应商实际服务安排影响。直连失败后,已同意的相同数据可能经我们运营的中国大陆 ECS 依次转发至 DeepSeek 或 PoYo。所有路线均通过 HTTPS。
供应商会依其条款处理、保留数据;我们不承诺供应商零存储、不用于训练或仅在某个国家处理。使用前可查阅 DeepSeek 隐私政策和 PoYo 网站中的现行隐私条款。您可以拒绝 AI 共享并继续本机测量。
身份、额度和安全
AI 不要求注册账号。我们使用 Apple App Attest、安装专用公钥、短期令牌和防重放签名验证安装;Apple 按其设备完整性服务规则处理证明信息。服务器记录安装标识、公钥、完整性证明及计数、任务和会话随机标识、摘要哈希、路由、时间和结算状态,以控制每天 30 条完整有效 AI 回复及并发。追问也计次;获得完整有效回复后,即使本机保存失败也计次。次数按安装身份计算,不是跨设备的每个自然人限制;UTC 00:00 重置,App 显示相应本地时间。
这些安全记录不是“完全匿名、无法关联”的数据,也不能识别同一自然人在所有设备上的身份。网络连接和限流会使用 IP 地址。所有 AI 发送,包括客户端直连路线,均先向 ECS 申请统一额度;ECS 不可用时 AI 暂停,本机测量仍可使用。
服务器保留与清理
ECS 不持久化健康正文或回复正文,不记录授权头或供应商密钥。转发时正文在内存中处理;供应商自己的保留不受本机删除控制。
任务及关联尝试、结算元数据的保留窗口为额度日 D 结束后七个完整 UTC 日,到 D+8 日 00:00 UTC 截止。例如,2026-09-05 额度日对应的窗口在 2026-09-13 00:00 UTC 截止。对于不再有活跃 ECS 工作进程、且不存在工作进程状态无法确认情形的任务,该截止点结束旧日任务对账;符合清理条件的记录在有界维护批次中删除。不再被任务引用的旧日额度记录也按该窗口清理。这个截止点不是承诺文件、日志或备份在精确同一秒被彻底擦除。
仍有活跃或状态无法确认的 ECS 工作进程时,相关任务、执行占用和旧日额度属于保留例外,不能仅凭超时假定处理失败或退还次数。维持安装凭证有效及防止重放、滥用所必需的最小身份安全记录也不随任务窗口一同自动删除。短期令牌、验证挑战、防重放随机数和限流窗口在到期后进入有界维护清理;批次清理可能不是即时完成。
若您要求删除服务器身份,请联系支持;为了防止滥用,当日额度及必要安全记录可能保留到对应目的完成。删除本机内容不会同时删除供应商持有的数据、您导出的副本或服务器备份,也不会重置当日额度。
您的选择
设置中可撤回未来 AI 发送授权;撤回不删除本机测量。您可在本机删除单条或全部记录及关联会话,或导出到您选择的位置。本机删除不能撤回已交给供应商的数据;对于导出文件及其他位置的副本,请在相应位置管理和删除。导出文件包含健康信息,请自行选择安全接收方。AI 为可选功能,不使用 AI 不影响测量。
年龄、安全及变更
本产品面向成年人,不面向儿童,不是医疗器械、心电图、血压计或急救监护服务。不要据此诊断、治疗或更改药物。休息、活动、情绪和饮食建议是可选的一般生活参考;具体食物需核对过敏原、个人饮食限制及食物与药物相互作用,不保证已排除全部禁忌。不确定时请咨询医生、药师或营养专业人员。若出现胸痛、呼吸困难、晕厥等不适,请及时寻求专业帮助,不要等待 App 或 AI。数据接收方、用途或范围发生实质变化时,我们会更新说明并再次请求同意。
PulseRest Privacy Policy
Last updated: September 6, 2026. Service: PulseRest, operated by SunnyCreate / 昇丽科技有限公司. Contact: contact@striketl.com.
On-device measurement
PulseRest uses your phone's motion sensors to record mechanical chest movement and estimate pulse and breathing rates. Raw multi-axis motion recordings, full replay, measurement results and chat history are stored on your iPhone by default. The app does not use the camera, microphone, location, advertising identifier or HealthKit. It does not display advertising or track you across apps. No motion is collected during the preparation countdown; the measurement itself lasts 30 seconds.
The app marks its on-device database and waveform storage directories as excluded from system backups. This setting does not control files you export or copies made by you or other tools. It also does not guarantee that provider or server backups disappear when you delete content locally. Device protection and copies you manage remain subject to your system and storage settings.
AI only after explicit consent and an active send action
Opening Analysis attaches context on your device only; it does not send health-related content. After you consent to the updated sharing scope and tap Send or actively choose a question starter, the selected measurement's final pulse and breathing estimates, availability and units, 30-second duration, fixed chest-motion measurement method, random record ID, language, your question and recent complete conversation turns selected within a size budget are used to generate general healthy-lifestyle information.
The first active request in a new measurement-linked conversation additionally includes the recording's processed, sampled chest-motion waveform when trusted replay is available locally: at most 1200 points, relative seconds, g units, 40 Hz sampling information and gap markers. This is not raw multi-axis IMU data or an ECG. After the first successful reply is saved, follow-ups include results and budgeted chat without repeating waveform arrays. Reopening a conversation does not reset its first-send state. Retrying an unsuccessful or cancelled initial request, or failing over among consented routes, may transmit the same initial context again. Missing or untrusted waveform is not invented; only results are shared. Upgrading an old conversation does not automatically send a waveform to fill in prior context.
Full raw multi-axis sensor samples, device or posture details, signal quality, other measurement records, your name and precise absolute measurement time are not uploaded. The sampled waveform does not enable AI to re-measure you, verify accuracy, diagnose or estimate blood pressure. Omitting it from a follow-up does not mean providers have deleted previously received data. Local deletion or an app upgrade cannot retract shared content. Do not enter identity document numbers, contact details or another person's health information. If you voluntarily provide allergy, dietary-restriction or medication information, that text is chat content shared with the consented recipients in the request and relevant budgeted conversation history. You can continue on-device measurement without providing it.
Data recipients and routes
The first route connects directly to DeepSeek (model deepseek-v4-flash), followed by a direct connection to PoYo (model gpt-5.4) if needed. Model names are the suppliers' designations. PoYo is a routing platform; its downstream model processors and processing locations depend on its actual service arrangements. If direct routes fail, the same data covered by your consent may be forwarded through our mainland-China ECS server to DeepSeek and then PoYo if needed. All routes use HTTPS.
Providers process and retain data under their own terms. We do not promise that providers retain no data, exclude it from training or process it only in a particular country. Before use, consult the DeepSeek Privacy Policy and the current privacy terms on the PoYo website. You may decline AI sharing and continue using on-device measurement.
Identity, allowance and security
AI does not require an account. We verify installations using Apple App Attest, an installation-specific public key, short-lived tokens and signed requests that prevent replay. Apple processes attestation information under its device-integrity service rules. The server records installation identifiers, public keys, integrity evidence and counters, random task and conversation identifiers, digest hashes, routes, times and settlement status to control concurrency and the allowance of thirty complete, usable AI replies per day. Follow-up replies also count. Once a complete, usable reply is obtained, it counts even if saving it on your device fails. The allowance applies per installation, not per person across devices. It resets at 00:00 UTC, with the corresponding local time shown in the app.
These security records are not completely anonymous or impossible to link. They also do not identify the same individual across all devices. Network connections and rate limiting use IP addresses. Every AI send, including a direct client route, first reserves the shared allowance through ECS. If ECS is unavailable, AI is paused; on-device measurement remains available.
Server retention and cleanup
ECS does not persist health-related request or reply content and does not log authorization headers or provider keys. During forwarding, content is processed in memory. Providers' own retention is not controlled by deletion on your device.
The retention window for tasks and their associated attempts and settlement metadata lasts for seven complete UTC days after allowance day D ends. It closes at 00:00 UTC on day D+8. For example, the window for the allowance day September 5, 2026 closes on September 13, 2026 at 00:00 UTC. For a task with no active ECS worker and no ECS worker whose status remains unverified, that cutoff closes reconciliation for the old-day task. Eligible records are deleted in bounded maintenance batches. Old-day allowance records no longer referenced by tasks are also cleaned up according to this window. The cutoff is not a promise that files, logs or backups are fully erased at exactly that second.
If an ECS worker is still active or its status cannot be confirmed, the related task, execution occupancy and old-day allowance are retention exceptions. A timeout alone is not treated as proof of failure or grounds to refund a reply. The minimum identity and security records necessary to keep installation credentials valid and prevent replay or abuse are not automatically deleted with the task window. Short-lived tokens, verification challenges, replay-prevention nonces and rate-limit windows enter bounded maintenance cleanup after expiry; batch cleanup may not be immediate.
Contact support if you request deletion of your server-side identity. To prevent abuse, the current day's allowance and necessary security records may remain until their corresponding purpose is complete. Deleting local content does not simultaneously delete data held by providers, copies you exported or server backups, and it does not reset the current day's allowance.
Your choices
You can withdraw authorization for future AI sends in Settings; doing so does not delete local measurements. You can delete individual or all local records and their associated conversations, or export them to a location you choose. Local deletion cannot retract data already sent to providers. Manage and delete exported files and other copies in their respective locations. Exported files contain health information, so choose recipients carefully. AI is optional; choosing not to use it does not affect measurement.
Age, safety and changes
The product is intended for adults, not children. It is not a medical device, ECG, blood-pressure monitor or emergency-monitoring service. Do not use it to diagnose, treat a condition or change medication. Rest, activity, emotional-well-being and food suggestions are optional general lifestyle information. Check specific foods against allergens, personal dietary restrictions and food/medicine interactions; the app does not guarantee that every contraindication has been excluded. Consult an appropriate clinician, pharmacist or nutrition professional when uncertain. If you experience chest pain, difficulty breathing, fainting or other symptoms, seek professional help promptly and do not wait for the app or AI. If data recipients, purposes or scope change materially, we will update the information and request consent again.