Pulsar Privacy Policy

How Pulsar collects, uses and shares information across Pulsar Studio, the Pulsar Figma plugin, the Pulsar live preview, the Pulsar mobile app and the Pulsar website.

Last updated: 7 September 2026

1. Who we are

Pulsar is built by Software Mansion S.A., a joint-stock company with its registered office at ul. Zabłocie 43B, 30-701 Kraków, Poland, entered in the register of entrepreneurs of the National Court Register kept by the District Court for Kraków-Śródmieście in Kraków, XI Commercial Division of the National Court Register, under KRS number 0000961952, NIP 6793131302, REGON 364909814, share capital PLN 1,081,081.90 paid up in full. For the purposes of the EU General Data Protection Regulation (GDPR), Software Mansion is the data controller for the information described here.

You can reach us about anything on this page - including to exercise any of the rights in section 20 - at projects@swmansion.com.

2. What Pulsar is

Pulsar has five surfaces, and they handle different data:

3. The short version

We store your account, the haptic patterns you design and the files you upload, because that is the product. From Figma we read only the layers you attached a preset to - never your images, text, styles or unbound layers. We use anonymous, cookieless analytics, so there is no cookie banner. We send error reports to Sentry to fix bugs, and you can switch that off. We do not sell your data, we do not advertise, and we do not train machine-learning models on your work. You can delete your account, and everything in it, yourself from Studio's Settings page.

4. Your account

When you create a Pulsar account we store your email address, your name if you give one, whether your email has been verified, and when the account was created. If you sign up with a password, we store a cryptographic hash of it, never the password itself. If you sign in with Google or GitHub instead, we store the identifier that provider gives us and the tokens needed to keep the connection working - we never receive your password.

One account covers Studio and the Figma plugin. Signing in creates a session record, which - as a standard part of the authentication library we use - holds the IP address and browser user-agent the session was created from.

You can use Studio without an account, as a guest. Guest work is held in your browser tab and never reaches our servers.

5. What you create

Haptic patterns you design in Studio, the projects and snippets that hold them, and any audio or animation files you upload to a project are stored on our servers so they are available across your devices. We store the file's original name, size, type and a checksum alongside the bytes themselves. Uploaded files are never served publicly - they can only be fetched through an authenticated request or a share link you created.

Files that exceed your account's storage quota stay in your browser instead and are never uploaded.

The Voice Sketch microphone recording never leaves your browser. When you sketch a pattern with your voice, Studio asks for microphone access, analyzes the audio locally, and keeps only the haptic pattern that analysis produces. The recording itself is not uploaded, not stored, and is discarded when you finish or cancel.

We do not use your content to train machine-learning models, and we do not use it for advertising.

6. Figma design data

The Figma plugin does not read your design file in general. Its query for what to upload is scoped to the layers you have attached a haptic preset to. Your images, text content, styles, comments, components' internals and unbound layers are never read or transmitted.

When you share a preview, pair a phone, or press Sync, it uploads, for the current page:

Nothing is uploaded until you share a preview, copy a share link, pair a phone, or press Sync. After a file has been shared or paired once, the plugin keeps that upload current in the background as you edit - it updates what already exists, but it never creates an upload for a file you have not shared or paired.

Three further things travel to us as part of running the plugin:

7. What we write into your Figma file

Attaching a preset stores it on that layer as Figma plugin data, adds a "Play haptic" relaunch button, and adds a Dev Mode annotation to the screen it belongs to so a developer reading the file can see it has haptics. Removing the preset removes them. The plugin also stores an opaque identifier for the file, and the file key you enter for the live preview, on the file's root node. Pulsar never changes your layers, styles or layout, but these writes do mark the file as edited and appear in its version history.

One copy of the binding is written as shared plugin data, on purpose, so that design-to-code tooling can read which haptic belongs to which layer. Shared plugin data is readable by anyone with access to the file, by other Figma plugins, and through Figma's REST API. Do not put anything confidential in a preset name you attach to a shared file.

You can turn the Dev Mode annotations off in the plugin, under Account → Privacy → Annotate screens for developers. Turning it off also removes the annotations already placed.

8. Sharing and pairing

A share link carries a 256-bit random token, and that token is the only thing protecting what it points at: anyone holding the link can read it, with no sign-in and no expiry. A Studio share link is readable from the moment you create it. A Figma live preview is created private and becomes readable only when you share it. Pairing a phone does not make anything public.

You can revoke a link at any time, which stops it working immediately; sharing again mints a fresh token, so the revoked link stays dead permanently.

Pairing a phone works through a relay on our server. The relay is a pass-through: it holds the pairing code and the connection in memory for as long as the connection lasts, forwards messages between your browser and your phone, and writes nothing to a database or to disk. Pairing codes expire after 15 minutes, and a code can only be claimed once. When you send a browser-only file to your phone, it is uploaded temporarily with a download token that expires after 10 minutes, and the bytes are deleted shortly after that.

The live preview embeds your prototype directly from Figma. Whether a recipient can see the design depends on that file's own sharing settings in Figma, not on Pulsar.

9. Subscriptions and payments

Payments are processed by Lemon Squeezy, which acts as merchant of record. You enter your card details on their hosted checkout - we never see or store them. We send Lemon Squeezy your email address and your Pulsar account identifier so the subscription can be matched to your account.

From them we receive, and store, the status of your subscription: the plan, the billing interval, the renewal or expiry date, the provider's subscription and customer identifiers, and the brand and last four digits of your card, so we can show you which card is on file. We also record when you start a free trial, so that it can only be started once.

10. Support, feedback and email

If you send feedback from Studio or the plugin, we store the category, your message, which account sent it and the email address on that account at the time, so we can follow up.

We send you transactional email - to verify your address, to reset your password, and to tell you when your password has been changed. These are sent through SendGrid. We do not send marketing email to Pulsar account holders unless you separately signed up for it.

11. The waitlist and marketing

If you fill in the Pulsar Studio waitlist form on our website, we pass your email address, name, company and role to MailerLite, which manages our mailing lists, and add you to the Pulsar Studio list. If you tick the optional box, we also add you to the Software Mansion newsletter. This is done on the basis of your consent, and every email we send you carries an unsubscribe link - using it withdraws that consent.

12. Diagnostics

Pulsar sends crash reports and performance data to Sentry, hosted in the EU (Germany), so we can find and fix bugs. A report contains an error message and stack trace, timings, the page or screen you were on, and basic browser or device and operating-system information. It does not contain your haptic patterns, your uploaded files, or your Figma design content. Share links, reset links, sign-in codes and pairing tokens are stripped out of the addresses in a report before it is sent.

Diagnostics are on by default, and you can turn them off on every surface that has a setting:

SurfaceWhere to turn it off
Figma plugin Account → Privacy → Send crash reports
Pulsar Studio Settings → Privacy → Send crash reports
Live preview The Send crash reports box in the header - no account needed, since you may have arrived from a share link without one
Mobile app No in-app switch at present

Your choice is remembered on that device and takes effect immediately, in both directions, with no reload. When it is off, nothing is sent.

We do this on the basis of our legitimate interest in a service that works. Where no switch is offered, you can still object to this processing under GDPR Art. 21 by writing to projects@swmansion.com.

13. Usage analytics

We measure which features are used, so we know what to improve. We use PostHog for this.

In Pulsar Studio and on our website, analytics are configured to be cookieless and anonymous: no cookie and no browser storage is used, no profile is built, we never identify you, page addresses are stripped of query strings and of project identifiers, and we do not record your session or capture clicks automatically. We send named events - which feature was used - and nothing about the content you were working on. Names of projects, patterns, devices and markers, and the text of your feedback, are explicitly never sent. Because nothing is stored on or read from your device, this needs no cookie banner.

In the mobile app, analytics record which screens you visit, which in-app actions you take, and app lifecycle events such as install, update and open. These are tied to a randomly generated identifier held on your device, not to your name or email - the app has no accounts.

On our website we also load Google Tag Manager. It is configured with consent for advertising, analytics, personalization and functional storage denied by default, so no tag it manages may store or read anything on your device unless and until you give consent.

14. Technical and security data

15. Stored on your own device

Your session, your settings and preferences, your favorites, your paired devices, and a local cache of your projects and media are kept on your device - in Figma's plugin storage inside the plugin, and in your browser's local storage and IndexedDB in Studio. This is not transmitted to us except as described elsewhere on this page, and Studio's Settings page has a "Clear local data" button that removes the cache.

16. Legal bases

WhatWhy we may do it (GDPR Art. 6)
Account, your content, sharing, pairing, subscriptions, support Performance of our contract with you - Art. 6(1)(b)
Diagnostics, anonymous usage analytics, rate limiting and abuse prevention, administration of the service Our legitimate interests in a working, secure product - Art. 6(1)(f). You may object under Art. 21.
Waitlist and marketing email Your consent - Art. 6(1)(a). Withdraw it at any time.
Keeping billing and tax records Compliance with a legal obligation - Art. 6(1)(c)

We do not process special categories of personal data, and we make no decisions about you by automated means that produce legal or similarly significant effects.

17. Who we share it with

These are our processors and partners. Each is bound to use the data only to provide its service to us.

ServiceWhat it receivesWhere
Lemon Squeezy Your email, account id and the payment details you enter at checkout United States
Sentry Error and performance reports EU (Germany) region
PostHog Anonymous, cookieless usage events United States
SendGrid (Twilio) Your email address and the transactional message we send you United States
MailerLite Waitlist sign-ups: email, name, company, role European Union
Google / GitHub Sign-in, if you choose to use them United States
Figma Your file key, when the live preview embeds your prototype United States
Supabase A request for a video file when the plugin shows a tutorial clip -

Pulsar's own servers and database are operated by Software Mansion. We may also disclose data where the law requires it, and to a successor if the business is sold - in which case we will tell you first.

We do not sell your data, we do not use it for advertising, and we do not use it to train machine-learning models.

18. International transfers

Some of the services above are in the United States. Where personal data reaches them, the transfer is covered by the European Commission's Standard Contractual Clauses, or by the recipient's certification under the EU-US Data Privacy Framework where it holds one. You can ask us for a copy of the safeguards that apply at projects@swmansion.com.

19. How long we keep it

20. Your rights

If you are in the EU, the EEA or the UK, you have the right to access your data, correct it, delete it, export it, restrict or object to how we use it, and to withdraw any consent you have given - withdrawal does not affect what we did before. In particular, you can object at any time to processing we do on the basis of legitimate interests, including diagnostics.

Two of these you can exercise yourself, immediately: delete your account from Studio's Settings page, which erases your projects, patterns, uploaded files, shares, feedback and subscription record in one go; and unsubscribe from any marketing email using the link in it.

For anything else, email projects@swmansion.com. We will answer within one month, as the GDPR requires.

You also have the right to complain to a supervisory authority. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl). You may also complain to the authority where you live or work.

21. Security

Traffic to Pulsar is encrypted in transit. Passwords are stored hashed. Share, preview and pairing tokens are generated from a cryptographically secure random source; share tokens are 256-bit and are rotated whenever a link is revoked and re-shared. Uploaded files are stored under random names, outside any publicly served directory, and can only be fetched through an authorized request. Repeated failed pairing and admin login attempts are rate-limited and locked out. Access to production data is limited to the people who need it to run the service.

No system is perfectly secure. If you find a vulnerability, please tell us at projects@swmansion.com before disclosing it, and we will fix it.

22. Children

Pulsar is a professional design tool and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.

23. Cookies and local storage

Pulsar sets only strictly necessary cookies - the cookie that keeps you signed in, short-lived cookies used during a Google or GitHub sign-in, and a cookie for the internal administrative panel. These are exempt from the consent requirement because the service you asked for cannot work without them, so Pulsar shows no cookie banner.

We set no advertising or tracking cookies, and our analytics are configured not to use cookies or browser storage at all (section 13).

Studio and the plugin do keep things in your browser's local storage and IndexedDB - your theme, editor preferences, paired devices and a cache of your work. That is storage on your device, and you can clear it from Studio's Settings page or through your browser. The live preview embeds Figma, and Figma may set its own cookies inside that embedded frame under its own privacy policy.

24. Changes

If we change this policy we will update the date at the top, and tell you in the product or by email if the change is significant.