English
LimitPulse Privacy Policy
1. Scope and identity
This policy describes the Android app LimitPulse, published by YongTech. LimitPulse does not create a LimitPulse service account. Connecting OpenAI in the app connects an account the user already controls at OpenAI; it does not create or administer that account.
2. Data handled by the app
OpenAI authentication and account identifier.
Sign-in takes place in the system browser. LimitPulse never asks for or receives an OpenAI password. Device authorization results, access tokens, refresh tokens, ID tokens, and the ChatGPT account identifier are handled on the Android device so the app can make read-only usage requests directly to OpenAI over HTTPS.
Authentication material is encrypted with AES-GCM. The encryption key is generated in Android Keystore. Authentication material is not sent to the LimitPulse public-signal service.
Usage and local history.
The app receives quota, reset-time, plan, and Token Activity values from OpenAI. It normalizes and stores the minimum values needed for current status and history in the app-private Room database. LimitPulse does not read or store conversations, prompts, source code, profile photos, or email addresses.
Usage and history are processed on the device and are not uploaded to the LimitPulse public-signal service, Firebase, an analytics provider, or a crash-reporting provider.
Firebase Cloud Messaging.
When a release is configured for Firebase Cloud Messaging (FCM), Google/Firebase processes data required to deliver reset-verification signals. This may include a Firebase installation ID, app version, Firebase user agent, and messaging registration data. LimitPulse uses FCM only for the fixed public reset-signal topic.
FCM messages contain only a bounded public event type, public event identifier, public source category, and publication time. OpenAI tokens, cookies, account identifiers, usage, prompts, conversations, and source code are never put in an FCM message.
The app does not enable Google Analytics, Crashlytics, Firebase Performance Monitoring, advertising, or BigQuery delivery-metrics export.
Public reset-signal service.
The LimitPulse public-signal service reads public reset announcements, classifies explicit completed-reset evidence, deduplicates public events, and sends the fixed FCM topic signal. It does not expose a client upload endpoint and does not receive OpenAI account data from the app.
3. Purposes
Data is used only to:
- connect to OpenAI at the user's request;
- retrieve and display read-only usage information;
- retain local usage and reset history;
- schedule account verification near expected resets;
- prompt the device to verify the user's actual account after a public signal; and
- show safe local status and failure information.
LimitPulse does not sell personal or sensitive data, use it for advertising, build advertising profiles, run Codex tasks, consume reset credits, or read or modify conversations.
4. Storage, retention, and backup
Encrypted authentication material and the Room database stay in app-private Android storage. All LimitPulse files are excluded from Android cloud backup and device-to-device transfer. Authentication material remains until disconnect, unrecoverable encryption failure, app-data clear, or uninstall. Local history follows the in-app retention behavior and can be deleted at any time.
Google/Firebase applies its own retention rules to Firebase installation and messaging data. Disconnect disables FCM auto-initialization, requests topic unsubscription and FCM unregistration, and requests deletion of the Firebase installation ID.
5. User controls and deletion
- Disconnect OpenAI deletes the encrypted authentication file and Android Keystore key, clears transient Cloudflare state, disables FCM auto-initialization, requests FCM cleanup, and cancels scheduled account checks.
- Delete local history deletes usage snapshots, quota windows, Token Activity history, reset evidence, sync state, and stored public signals from the Room database.
These controls delete LimitPulse data on the Android phone. They do not delete the user's OpenAI account. OpenAI account deletion must be performed through OpenAI.
LimitPulse has no developer-operated user account or account-data backend, so there is no separate LimitPulse cloud account to delete.
6. Permissions
- Internet: required for OpenAI requests and Firebase messaging.
- Notifications: requested only from a user action so verified reset alerts can be shown.
Other network, wake, boot, and foreground-service permissions are contributed by FCM and WorkManager for delivery and scheduled work. The app does not request contacts, location, camera, microphone, phone, SMS, storage, advertising ID, or exact-alarm permissions.
7. Security and limitations
Network traffic uses HTTPS and cleartext traffic is disabled. Release builds
contain no network body logger, analytics SDK, or developer-operated crash
reporter. WebView is restricted to a Cloudflare fallback at the exact
https://chatgpt.com origin and WebView debugging is disabled.
OpenAI usage endpoints used by LimitPulse are internal and may change. The app preserves the last successful value and displays an explicit state when a request fails. Android may delay background work, and force-stopping the app blocks background checks and alerts until the user opens it again.
8. International processing
OpenAI and Google/Firebase may process data in countries other than the user's country under their respective terms and privacy policies. Applicable jurisdiction-specific rights and disclosures may vary by launch country.
9. Children
LimitPulse is not designed or directed to children. Its intended audience is adults who already control an eligible OpenAI account.
10. Changes and contact
Material changes will be reflected by updating this policy and its effective date.
Developer/operator: YongTech
Privacy contact: pyhppyyhh0307@daum.net