This describes Pulse's default tracker. It is not legal advice. Your notice, lawful basis, and consent rules depend on your site, audience, and which optional features you enable.
Default tracker
No analytics cookies. No localStorage or sessionStorage used to count visits. If Global Privacy Control is set or Do Not Track equals "1", the script sends nothing. Paths are stored without query strings. Referrers are origin-only. Unique visitors are a daily HMAC of site, UTC day, truncated IP, and a coarse user agent, keyed by a secret that rotates at midnight UTC. The hash cannot be reversed and is not reused the next day. Raw IP addresses are never written to Postgres.
Opt out
Open the site with #pulse-ignore or ?pulse_ignore=1, or use Settings → Tracking. That sets localStorage.pulse_ignore in this browser. That flag is a local preference, not an identifier.
Revenue attribution (opt-in)
When enabled, the script stores a UUID in sessionStorage for the current tab only and sends it with events. Pulse stores a hash of that UUID, never the raw value. Stripe customer emails are not copied into analytics. Enable this only after you check the rules that apply to your checkout.
What we do not do
No canvas or WebGL fingerprinting, no cross-day profiles, no session replay. See the DPA.
Optional experience measurements
Tracker extras can record click coordinates for aggregated heatmaps and Web Vitals measurements. Heatmaps do not record input values, page screenshots or session-replay video. These features require the full tracker to be enabled in site settings.