Security

Designed so there’s nothing to leak.

The strongest privacy guarantee is data you never collect. PulseKit AI's security model starts at the schema; the fields that would identify a person simply don't exist.

No cookies, no fingerprints

The tracker stores nothing on the visitor's device. There is no cookie to consent to, no localStorage token, no fingerprint composed from fonts or canvas. A consent banner is not 'disabled'; there is nothing it would need to cover.

Identity that expires nightly

A visitor is recognised by an HMAC of the site id, a daily salt, the request IP and a coarse user-agent class. The salt rotates every UTC midnight, so yesterday's identifier cannot be linked to today's. The raw IP is an argument and a local variable; it is never stored, logged or queued.

Honoured signals

Do Not Track and Global Privacy Control are enforced at the collector, before anything is queued. A browser that asks not to be counted is not counted, rather than filtered later in the dashboard.

Separated planes

Control-plane data (accounts, sites, keys) lives in Postgres. Analytics events live in ClickHouse. The only process that reads ClickHouse is the query gateway, and it answers signed query envelopes; the public API cannot reach the event store directly.

Scoped, hashable keys

Tracking keys are public-write-only by construction; they can enqueue an event and nothing else. Management keys are prefixed, revocable and stored hashed. Secrets never reach a log line, an error message or a response body.

Self-hostable end to end

The same codebase runs on your hardware: Postgres, ClickHouse, Valkey and the services, from one compose file with generated secrets. For the strictest data-residency answer, the honest one is 'it never leaves your machines'.

Minimal collection by default

The tracker sends the URL, referrer, coarse timing and device class, and that's the list. City-level geolocation is opt-in per site and resolved against a GeoIP database on local disk, never a third-party API.

Deletable, exportable

Site deletion is a real deletion: an erasure job removes events, sessions and rollups, not a flag on a row. Exports ship the same data the dashboard reads.

Architecture

Where the data lives

Ingest

Collector validates, rate-limits and queues; events land in ClickHouse via the worker, never the request path

Storage

Postgres 17 for the control plane, ClickHouse for events and rollups, Valkey for the durable queue and realtime cache

Read path

Query gateway validates Ed25519-signed envelopes; the API never talks to the event store

Edge

Caddy terminates TLS; security headers are set per-route, including frame-ancestors for embeds

Responsible disclosure

Found something? Tell us.

We take every report seriously and respond quickly. Please use the private contact channel below so we can investigate and fix an issue before it is disclosed.

Report a vulnerability

The fine print, honestly

  • · Hosted at pulsekitai.com and self-hosted installs run the same code; the privacy model above is the codebase’s, not a policy that can drift from it.
  • · We keep the product deliberately small, document the data boundaries, and make the important controls easy to inspect.
  • · Compliance details for the hosted service live in the privacy policy; self-hosted operators are their own data controller.