This policy explains what Amarkal holds, what our servers hold, and what neither of us can see. It covers the Amarkal application for macOS and the pulso.tools website. The controller is Peretz Yam, trading as Pulso Tools, Israel — [email protected]. Amarkal is sold through the Mac App Store and is not offered for sale in the European Union or the United Kingdom. One sentence decides everything below: your vault is encrypted on your Mac before it goes anywhere, and we never hold the key.
An account is required to use Amarkal: it is what your recovery and your sharing belong to, rather than a single Mac. You sign in with an email address or with your Apple Account; if you use Apple, we receive the private relay address Apple gives us, not your real one. We hold:
We do not hold your account password: our authentication provider stores it only as a one-way hash it cannot reverse. Providing an address is necessary to have an account. Without one there is no recovery, no sharing and no purchase bound to you.
Everything in your vault — logins, keys, notes, documents, projects, services, amounts — is encrypted on your Mac with a key we never see. What reaches our servers depends entirely on where you keep it. If your vault lives on this Mac, in a folder, or on your own S3 or WebDAV server, none of it reaches us and we do not learn where it is. If you turn on Amarkal Sync, we store the encrypted records. Being honest about what that leaves visible matters more than sounding absolute, so here is the list:
We cannot see: the contents of any record, your recovery phrase, your account password, or any key that would open the above.
When you share a group with someone, their email address reaches us because that is how their access is granted; we hold it for as long as they are a member. If you were added to a group by someone else, that is how we came to hold your address, and everything in this policy applies to you too — including your rights in section 11.
Apple sells Amarkal. Apple does not tell us who bought it: we never see your name, address or payment details. To connect an active subscription to your account we store the transaction identifier Apple gives us, the product bought and the date it expires. If you have allowed your Mac to share diagnostics with developers, Apple may show us crash reports for the app. They come from Apple, contain no vault data, and are not collected by us.
Amarkal can read balances, spending, revenue, certificates and uptime from services you already use. The credentials for those services are stored in your vault, encrypted like everything else, and the requests go from your Mac straight to the service. We are not in that path and never receive those credentials or the data they return.
We send email only about your own account and only to your own address: to confirm it when you sign up, to send a sign-in link, to reset your password, and — when you change the address — to confirm the change to the old address and the new one. Those messages are sent through our own mailbox using the Gmail API, and the address is used for nothing else. We send no newsletters and no marketing. We never send mail to anyone on your behalf. When you invite someone to a group, Amarkal writes the invitation and hands it to your own mail program, so it leaves from your address, through your provider; we never see it and never learn who you invited. If you send us feedback or a bug report from inside the app, Amarkal prepares the message in your own mail program: it carries the app version, your macOS version and a short tail of the app's log, all of it visible and editable by you before you send it. We then hold that message as ordinary correspondence.
pulso.tools uses Umami Cloud for basic analytics: page views, referring site, country, browser and device type. It sets no cookies. A "unique visitor" is counted using a value derived from the visitor's IP address and browser that is regenerated daily and cannot be traced back to a person by us. The site sets no advertising or tracking cookies of any kind.
Three companies process data for us, and none of them can read your vault contents either: Supabase, which hosts our servers in the European Union (Ireland); Google, whose Gmail API sends the account emails above; and Apple, which sells the app and processes every payment. The website's analytics are processed by Umami Cloud in the European Union. We are in Israel, so we read the data on those servers from Israel. The European Commission recognises Israel as providing an adequate level of data protection, which is the basis for that transfer.
Nothing in your vault is ever destroyed automatically because time passed.
You may ask for a copy of what we hold, correct it, delete it, restrict how we process it, receive it in a portable form, object to processing based on our legitimate interest, or withdraw a consent you gave. Two of these you can do yourself, without asking anyone: export your entire vault to a file from within the app, and delete your account from Settings. For anything else, write to [email protected]; we answer within one month. You can complain to Israel's Privacy Protection Authority, or to the data protection authority of your country if it has one.
We process your account address, device names and device keys to provide the service you asked for — performance of a contract. We process sign-in records, and the sizes and timings of records, in our legitimate interest in keeping the service running and free of abuse. Password recovery, and any copy of your key we hold for it, are processed on your consent, given by switching the feature on, and withdrawn by switching it off. Website analytics are aggregate and cookie-free and rest on our legitimate interest in knowing whether the site works.
Your vault is encrypted on your device before it is stored or transmitted, and the key never leaves it. Our servers hold ciphertext, isolated per account by database-level rules so that one account cannot read another's rows. All traffic is over TLS. Access to production is limited to the developer named above and protected by two-factor authentication. If a breach ever affects your data in a way that puts you at risk, we will tell you and the regulator without undue delay, describing what happened and what to do.
We make no automated decisions about you and do no profiling. Amarkal is not directed at children and we do not knowingly collect data from anyone under 16; if we learn we have, we delete it.
Israel's Protection of Privacy Law, 5741-1981, as amended, applies to us directly, and Israel's Privacy Protection Authority supervises it. Where the law of your own country gives you further rights, those rights stand alongside this policy.
The current version always lives at pulso.tools/amarkal/privacy with the date it was last changed; material changes are noted in the app's release notes. Peretz Yam, trading as Pulso Tools, Israel — [email protected]