GetSkipa Legal Center
GetSkipa Pulse
Terms, privacy disclosures, Google user data practices, and service information for the production Pulse service.
Agreement
GetSkipa Pulse Terms of Service
These Terms of Service govern access to and use of GetSkipa Pulse, a capture, organization, synchronization, and recall tool provided by GetSkipa LLC ("GetSkipa," "we," "us," or "our"). By using Pulse, you agree to these Terms. If you use Pulse for an organization, you represent that you have authority to accept these Terms for that organization.
1. Pulse and your Pulse Vault
A "Skip" is a captured item that may contain text, tags, dates, pin or Archive status, or an AIR transcript. Pulse keeps local browser or installed-PWA state and, when connected, synchronizes Pulse-managed Markdown and supporting files with a Pulse Vault folder in the Google Drive account you choose.
Pulse may create and update supporting files such as pulse_index.json and a vault map. These supporting files are indexes or derived artifacts. Individual Skip Markdown files are the canonical synchronized records.
2. Eligibility, authority, and accounts
You must have legal capacity to enter an agreement and must comply with laws that apply to you. You are responsible for the Google account connected to Pulse, the security of that account and your devices, and activity performed through them. If you act for an organization, you must have authority to connect and process that organization's information.
3. Your content and limited operating permission
You retain ownership of your Skip content. GetSkipa does not claim ownership of your Pulse Vault or its contents. You grant GetSkipa only the limited permission needed to transmit, process, format, synchronize, recover, and display your content to operate Pulse at your direction.
You are responsible for ensuring that you have the rights and lawful authority to capture, upload, record, transcribe, or otherwise process content with Pulse. The software, interface, documentation, and GetSkipa and Pulse branding remain the property of GetSkipa or its licensors. Google Drive, Gemini, and other third-party services are governed by their respective providers.
4. Google Drive dependency
Synchronized Pulse Vault functionality depends on a functioning Google account, Google Drive access, available Drive storage, and continued authorization. Google outages, API or policy changes, account restrictions, storage limits, or authorization revocation can interrupt Pulse. Google is a separate service provider and does not sponsor, endorse, or operate Pulse.
You control your Google Drive and are responsible for actions you take there, including manually deleting, moving, renaming, replacing, editing, trashing, permanently deleting, or otherwise altering the Pulse Vault or its files. Those actions can cause data loss, broken references, synchronization problems, incomplete recovery, or permanent deletion. Use Pulse itself for ordinary Skip organization, Archive, restore, and deletion, and do not manually modify or remove Pulse-managed supporting files such as the index or vault map. To the extent permitted by law, GetSkipa is not responsible for loss or disruption caused by manual Drive actions outside Pulse.
5. Local-first operation and synchronization
Pulse writes local state to browser storage and synchronizes with Drive asynchronously. A locally visible change may remain queued before Drive confirms it. Connectivity, browser suspension, authorization status, and third-party availability can delay synchronization. Allow pending synchronization to complete before clearing browser data, uninstalling the PWA, disconnecting devices, or relying on another device.
Local-only or pending information may be lost if device or browser storage is cleared before successful synchronization. Conflict handling and recovery reduce risk but do not guarantee that every transient state can be recovered.
6. Archive, Delete, and derived files
Archive is an organizational classification, not deletion or backup. It removes a Skip from ordinary active views while leaving the underlying Markdown in the Pulse Vault. Restoring removes the Archive classification.
For a synchronized Skip, Delete enters a pending state until Pulse confirms that the original Drive Markdown has been moved to Google Drive trash and the Pulse index has been updated. Normal Pulse deletion does not permanently erase a Drive file. Recovery and permanent deletion from trash follow Google's settings and behavior. Indexes and maps may update asynchronously after canonical deletion.
7. AI Context Export
Pulse may create an AI Context Export when you explicitly request one. Each export is a focused, user-owned Markdown snapshot saved in a dedicated folder within your Pulse Vault and is not updated automatically. GetSkipa does not maintain a separate hosted copy of the export. Exporting does not send its content to an AI provider or publish it publicly. Content reaches an AI provider only if you separately supply the exported file. Exports remain in Drive until you delete them, and Download copy creates an additional user-controlled copy.
8. Service availability and changes
We may maintain, improve, modify, suspend, or discontinue parts of Pulse. We use reasonable efforts to provide a reliable service but do not promise uninterrupted availability, perfect synchronization, error-free transcription, or compatibility with every device or third-party change. We may provide notices of material service changes through the product, website, or available contact information.
9. Your responsibility and backups
Your Drive-based Pulse Vault gives you direct control of synchronized files, but neither Pulse nor Drive should be treated as an infallible backup. You remain responsible for reviewing important records, monitoring pending synchronization, maintaining appropriate independent copies, and complying with retention duties that apply to you.
Before clearing browser storage, uninstalling Pulse, or changing Google Drive files directly, confirm that pending changes and pending AIR recordings stored on your device have completed or been intentionally discarded. Google account restrictions, Drive storage limits, third-party service interruptions, or manual alteration of Pulse files can prevent synchronization or recovery.
10. Suspension, disconnection, and termination
We may limit or suspend access when reasonably necessary to protect users or infrastructure, investigate misuse, comply with law, address nonpayment, or enforce these Terms. You may stop using Pulse and disconnect its browser session. Disconnection revokes the current Pulse session but does not delete local Pulse data on your device, the persistent Google connection record, the encrypted refresh token, the Pulse Vault, or Google Drive files. You may revoke Google's authorization through your Google Account.
Ending Pulse access ordinarily does not transfer ownership of or delete user-owned Drive files. Some local functionality may remain available, while synchronization and server-dependent features will not.
11. Disclaimer of warranties
To the extent permitted by law, Pulse is provided "as is" and "as available." GetSkipa disclaims implied warranties, including merchantability, fitness for a particular purpose, noninfringement, and warranties arising from course of dealing. We do not warrant uninterrupted service, perfect synchronization or transcription, preservation of every local state, or continued availability of third-party services.
12. Limitation of liability
To the maximum extent permitted by law, GetSkipa LLC and its members, personnel, and service providers will not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, opportunities, goodwill, or data, arising from Pulse. This includes loss or disruption caused by manual changes to Pulse Vault files, Google account or Drive storage limitations, interruption of third-party services, or clearing local storage before pending synchronization or AIR recovery completes. GetSkipa's aggregate liability for claims relating to Pulse will not exceed the amount you paid GetSkipa for Pulse during the twelve months before the event giving rise to the claim. These limits do not apply where applicable law prohibits them.
13. Indemnification
To the extent permitted by law, you will defend and indemnify GetSkipa LLC against third-party claims and reasonable costs arising from your unlawful content, infringement or violation of third-party rights, illegal recording or transcription, material misuse of Pulse, or material violation of these Terms. This provision does not require indemnification for GetSkipa's own unlawful conduct.
14. Governing law and changes
These Terms are governed by the laws of the State of Texas, without regard to conflict-of-law principles. If a provision is unenforceable, the remaining provisions remain effective. We may update these Terms to reflect service, legal, or security changes. The posted effective date identifies the applicable version. Material changes may be communicated through Pulse, the website, or available contact information, and continued use after an updated version becomes effective constitutes acceptance to the extent permitted by law.
Privacy
GetSkipa Pulse Privacy Policy
Your Skips belong to you. Pulse is designed so your saved content lives on your device and in your own Google Drive Pulse Vault, rather than in a GetSkipa-hosted content database. GetSkipa does not maintain a separate hosted copy of your ordinary Skip library or use your Skip content for advertising or profiling. GetSkipa and its service providers do temporarily process content when needed to operate synchronization, user-requested AIR transcription, or AI Context Export. GetSkipa also stores the limited account, connection, entitlement, billing, security, and operational records described below.
Information Pulse handles
Google account and connection information
Pulse receives the Google account's stable subject identifier (sub), email address, granted scopes, connection timestamps and status, associated Pulse Vault folder ID, and OAuth/session metadata. We use this information to associate the correct Google account with its Pulse connection, display connection context, maintain the session, and isolate vault access.
Google Drive information
Pulse works with its own Pulse Vault and the specific files you create or use with Pulse. It processes the Pulse Vault folder ID; Pulse file IDs, names, types, parent relationships, modified times, and trash status; Skip Markdown; the Pulse index; vault maps; and user-requested AI Context Export snapshots. Pulse uses this information to find or create the Pulse Vault, synchronize and hydrate Skips, update tags and organizational metadata, archive and restore records, trash deleted Skip Markdown, rebuild indexes, maintain the vault map, and create exports you request. Pulse does not scan or browse the rest of your Google Drive.
Local browser and device information
IndexedDB stores Skip bodies and metadata, previews for immediate display, Drive identity and modification information, content-completeness and hydration state, tags, pin and Archive state, synchronization operations, DELETE PENDING state, and pending AIR recordings awaiting recovery. Local settings may store connection display state, system-file IDs, mode preferences, deletion recovery markers, synchronization timestamps, and Pulse Pad draft state. The service worker caches the application shell; it does not perform Drive synchronization or store canonical Pulse Vault content. Clearing browser or device storage can remove this local state.
Server-side operational metadata
Cloudflare D1 stores the Google stable account identifier and email, connection ID and status, encrypted refresh-token material and key version, granted scope text, associated Pulse Vault folder ID, verification and update timestamps, hashed session identifiers and session timestamps, short-lived OAuth transaction records, Pulse plan and AIR balances, immutable AIR accounting records, Stripe customer/subscription references and status, and webhook-processing records. Normal Skip bodies and the ordinary Skip library are not stored in D1.
Tokens and sessions
Google refresh tokens are encrypted server-side using authenticated encryption. Short-lived Google access tokens are obtained only as needed, retained temporarily in Worker memory, are not returned to the browser, and are not persisted in D1. Pulse uses a Secure, HttpOnly, SameSite session cookie; D1 stores a cryptographic hash of the session token rather than the browser's token value. OAuth transaction state and PKCE verifier material are short-lived and protected server-side.
Pulse AIR
When you activate AIR, your browser records audio and uploads it to GetSkipa's Cloudflare-hosted transcription endpoint. The endpoint sends the audio inline to Google's Gemini API with an instruction to transcribe it. Pulse returns the transcript to the browser, then saves it as an ordinary Skip tagged AIR. Pulse does not maintain an AIR audio library or intentionally retain the recording after successful processing.
If you record offline or transcription cannot complete, Pulse durably stores each pending recording in IndexedDB on that device until transcription and saving succeed or you explicitly discard it. Pending recordings can survive closing or reopening Pulse. Clearing browser storage, removing the site or PWA data, or losing the device can delete pending recordings before recovery.
Google and Cloudflare necessarily process the audio and request metadata to provide transcription and transport. Their own handling is governed by their applicable service terms and policies. The Pulse code does not establish or control provider-side log or retention periods, so users should review the providers' current policies before submitting sensitive audio.
Telemetry and operational logs
The public Pulse marketing page sends limited funnel events to GetSkipa's Cloudflare-hosted metrics endpoint: product and page labels, page-view or selected navigation/CTA events, target label, referrer, UTM campaign values, anonymous session/event/page-load identifiers, broad device class, and timestamp. The Pulse PWA does not load that marketing telemetry module.
Cloudflare and GetSkipa systems may also process ordinary network information such as IP address, request headers, error status, timestamps, and security logs. Successful AIR operational telemetry may include an internal Pulse account identifier, recording duration, Gemini token counts, requested and returned model version, Gemini response identifier, retry count, AIR charged, entitlement category, and processing timestamps. Request/error logging may include an attempt identifier, media type and size, selected model, retry count, and response or error status. The implementation does not intentionally include AIR audio or transcript text in this telemetry. No code-defined retention period exists for marketing telemetry or infrastructure logs.
How we use information
- Authenticate and maintain the selected Google connection.
- Find, create, isolate, synchronize, hydrate, and recover the user's Pulse Vault.
- Operate Skip creation, updates, tags, pinning, Archive, restore, deletion, export, and generated vault files.
- Transcribe user-requested AIR recordings and save resulting transcripts as Skips.
- Maintain security, diagnose failures, prevent abuse, and support users.
- Understand limited marketing-page navigation and campaign performance.
- Comply with law and enforce applicable agreements.
Sharing, sale, and advertising
GetSkipa does not sell Google user data or Skip content, use it for advertising, transfer it to build advertising profiles, or share it with unrelated third parties. Information is disclosed only as needed to service providers acting for the purposes described here, at the user's direction, in a business transfer subject to appropriate protections, or when reasonably required by law, security, or enforcement needs.
Relevant service-provider processing includes Google for OAuth, Drive, and user-requested Gemini transcription; Cloudflare for site delivery, Workers, D1, network security, AIR request handling, and GetSkipa-hosted telemetry; and Stripe for checkout, billing, subscription management, and payment records. An AI service processes exported information only if the user separately provides the export to that service.
User choices
You can disconnect the current Pulse session, revoke Pulse through Google Account permissions, Archive or restore Skips, delete Skips to Drive trash, manage or permanently delete Drive files through Google Drive, clear browser storage, and contact GetSkipa about access, correction, deletion, or other privacy requests. See Retention and Deletion for the different effect of each control.
Google API Disclosure
Google User Data
Scopes Pulse requests
openid: provides the stable Google identity needed to associate the authenticated account with the correct Pulse connection.email/userinfo.email: provides the Google account email used for account display and connection context.https://www.googleapis.com/auth/drive.file: permits Pulse to create, access, update, and trash the specific Drive files the user creates or uses with Pulse.
Purpose and limits
Pulse uses Google data only to authenticate the connection; resolve or create the correct Pulse Vault; synchronize and hydrate user-created Skips; read Pulse-managed files; update tags, pin and Archive metadata; restore archived records; trash deleted Pulse Markdown; maintain the Pulse index and vault map; and create AI Context Export snapshots when requested by the user.
The drive.file permission lets Pulse work with the specific Drive files you create or use with Pulse. Drive requests are made by the Pulse API on behalf of the authenticated user and are restricted to the associated Pulse Vault and supported Pulse Markdown or JSON files. Pulse does not scan or browse the rest of Drive and does not expose a general-purpose Drive proxy to the browser.
Google Limited Use
GetSkipa Pulse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This statement describes Pulse's obligations; it does not imply Google certification, sponsorship, or endorsement.
Lifecycle
Retention and Deletion
Skip content
- Local: IndexedDB retains Skips and synchronization state until Pulse changes them or browser/device storage is cleared.
- Drive: synchronized Markdown and generated files remain in the user's Drive until changed, trashed, or permanently deleted under Google Drive controls.
- Archive: keeps the Markdown and classifies it as archived; it is not deletion.
- Delete: remains pending until Pulse confirms the original synchronized Markdown is in Drive trash and the index is cleaned up.
- Derived artifacts: the index and map may update after the canonical operation and can temporarily contain prior derived information. AI Context Export snapshots do not update automatically.
Disconnect and Google authorization
Disconnect revokes the current Pulse session cookie and leaves local Skips on the device. It does not delete the Google connection record, encrypted refresh token, Pulse Vault, or Drive files. Revoking Pulse in Google Account settings prevents future Google access; the next Drive operation will require reconnection. Direct Drive controls remain available to the Google account owner.
Connection records, tokens, and sessions
The server retains the Google connection record and encrypted refresh token to support reconnection and server-authorized Drive access. The current product does not provide a self-service "forget this Google connection" operation. Contact GetSkipa to request deletion of server-side connection information. Requests may require identity verification and may be limited by legitimate security, fraud-prevention, dispute, accounting, tax, or legal requirements.
Pulse session and authentication records are retained as needed to maintain the connection, provide security and recovery, and meet applicable operational or legal requirements. Disconnect revokes the current Pulse session. Expired, revoked, used, and abandoned authentication records are periodically removed through opportunistic cleanup during later authentication activity. Short-lived Google access tokens remain only temporarily in Worker memory and expire or are discarded without persistent storage.
AIR, telemetry, and logs
Pulse does not intentionally store AIR audio after successful transcription processing, subject to provider and infrastructure handling. Offline and failed recordings are stored in IndexedDB on the user's device until successful transcription and saving or explicit discard. The resulting transcript follows the ordinary Skip lifecycle. The service does not promise a fixed retention period for marketing telemetry, infrastructure logs, AIR operational telemetry, Stripe billing records, or provider-side processing records; retention may depend on operational, security, fraud-prevention, dispute, tax, accounting, and legal needs. Contact GetSkipa with a specific retention or deletion request.
Third Parties
Service Providers
Pulse currently relies on the following providers for production functions. GetSkipa does not list planned providers here.
- Google: Google OAuth supplies account identity and authorization; Google Drive stores the user-owned Pulse Vault and canonical synchronized files; and the Gemini API processes audio submitted through AIR for transcription. Google may process account information, Drive files and metadata, AIR audio, transcripts generated in response, and ordinary request metadata for those purposes. Google Drive—not GetSkipa D1—stores the canonical synchronized Skip library. See the Google Privacy Policy.
- Cloudflare: hosts and delivers GetSkipa pages and application assets, runs the Pulse API and AIR endpoint, stores connection/session metadata in D1, provides network and security services, and hosts GetSkipa's limited marketing telemetry endpoint. Cloudflare may process connection metadata, encrypted token material, session records, AIR audio in transit, telemetry payloads, IP addresses, request headers, and operational logs. D1 does not store normal Skip bodies. See the Cloudflare Privacy Policy.
- Stripe: provides hosted Checkout and Customer Portal pages and processes card and billing details, payment/customer identifiers, subscriptions and status, invoices, receipts, promotions, and related transaction records. Payment card details are entered on Stripe-hosted pages; Pulse does not receive or store complete payment-card credentials. See the Stripe Privacy Policy.
- User-selected AI services: do not receive Pulse data merely because Pulse creates an AI Context Export. A selected service processes the export only if the user separately provides it to that service.
Safeguards
Security and Data Handling
Pulse uses a server-managed OAuth authorization-code flow with PKCE. Refresh tokens are encrypted at rest, and short-lived access tokens are held only in server memory as needed. The browser receives a Secure, HttpOnly session cookie; D1 stores a hash of its token. Browser access is limited to approved GetSkipa origins.
The Pulse API exposes narrow Pulse Vault and supported-file operations rather than an arbitrary Drive proxy. It verifies the authenticated connection, associated Pulse Vault folder, file parent, and supported file type before access. Stable Google identity and the stored Pulse Vault association isolate accounts and vaults.
Canonical synchronized content remains in the user's Drive, with local hydrated copies in IndexedDB. The service worker caches application code and static assets but does not perform Drive synchronization. Delete uses durable pending state and waits for Drive trash confirmation before removing the local record.
No system is perfectly secure. Users should secure their Google accounts and devices, review connected-app access, keep browsers current, and report suspected security issues to admin@getskipa.com.
Voice Processing
Pulse AIR
AIR records audio only after the user activates the microphone. Current recordings are limited to five minutes and uploads to twenty megabytes. The browser sends the recording to a Cloudflare-hosted GetSkipa endpoint, which sends it to Google's Gemini API for transcription. A successful transcript is saved as a Skip with the automatic tag AIR.
Audio is used for the requested transcription and is not saved in a GetSkipa audio library. Offline or failed recordings are stored as separate pending items in IndexedDB on that device until successful transcription and saving or explicit discard. AIR processing can fail because of browser, network, Cloudflare, Google, format, duration, or service limits. Google and Cloudflare policies also apply to their processing.
Transcription may be inaccurate, incomplete, or affected by noise, accents, multiple speakers, or technical limitations. Review important transcripts. You are responsible for obtaining any consent required to record or transcribe other people and for complying with recording, privacy, employment, confidentiality, and communications laws.
Conduct
Acceptable Use
Do not use Pulse to:
- violate law or another person's intellectual-property, privacy, publicity, confidentiality, or contractual rights;
- record, transcribe, upload, or process content without required authority or consent;
- distribute malware, conduct phishing, probe or attack systems, or obtain unauthorized access;
- interfere with Pulse, Google, Cloudflare, other users, or service infrastructure;
- evade security, access controls, rate limits, purchase requirements, or AIR usage limits;
- use automated activity that imposes an unreasonable burden or creates security risk; or
- misrepresent identity or use another person's Google account without authorization.
Reasonable security research should be reported privately and must not access, retain, or disrupt other users' information.
Commercial Terms
Billing and Refunds
Pulse offers a Monthly subscription for $7 per month, an Annual subscription for $49 per year, and a one-time pack of 250 purchased AIR for $9.99. Prices are presented in U.S. dollars unless the checkout states otherwise. Applicable taxes may be added or collected as required by law. Stripe processes Pulse checkout, subscription management, and payment records under its own terms and policies.
AIR balances and subscription allowances
A Monthly subscription tops up the subscription AIR balance to 200 for each monthly billing period. An Annual subscription tops it up to 1,000 for each annual billing period. A top-up or reset sets the subscription balance to the applicable allowance; unused subscription AIR does not stack above that plan's ceiling. Plan changes, cancellation timing, and renewal take effect according to the authoritative Stripe subscription state and Pulse's displayed account status.
Purchased AIR is separate, remains available until used, and is consumed only after subscription AIR. Purchasing 250 AIR adds 250 to the purchased balance. Ending or changing a subscription does not remove purchased AIR. AIR usage, allowance resets, and purchases are protected by account binding and transaction idempotency, but users should contact GetSkipa if a displayed balance appears incorrect.
Renewal and cancellation
Subscriptions renew automatically for the displayed billing interval until canceled. Cancellation prevents the next renewal and the subscription remains active through the paid period shown in Pulse or Stripe. Cancellation does not delete Skips, the Pulse Vault, or purchased AIR. Except where applicable law requires otherwise, cancellation does not produce a prorated refund for the current billing period.
Refund policy
AIR purchases and subscription charges are non-refundable. Billing errors, duplicate charges, or exceptional circumstances may be reviewed individually. At GetSkipa's discretion, a review may result in an AIR adjustment, reversal of an erroneous charge, refund, or another appropriate resolution. This policy does not limit refund or cancellation rights that cannot lawfully be waived.
Questions and Requests
Contact
GetSkipa LLC uses the following established public contact for Pulse support, privacy requests, legal questions, and security reports:
Email: admin@getskipa.com
Do not send passwords, Google tokens, payment credentials, or unnecessary sensitive content by email. We may need to verify identity or account authority before acting on a data request.