LimitPulse

Privacy, without surprises.

This policy explains how the LimitPulse Android app handles authentication, usage information, local history, notifications, and public reset signals.

Effective: July 30, 2026 Developer: YongTech Android app: com.limitpulse.app
LimitPulse is an independent third-party usage companion. It is not affiliated with or endorsed by OpenAI.

English

LimitPulse Privacy Policy

1. Scope and identity

This policy describes the Android app LimitPulse, published by YongTech. LimitPulse does not create a LimitPulse service account. Connecting OpenAI in the app connects an account the user already controls at OpenAI; it does not create or administer that account.

2. Data handled by the app

OpenAI authentication and account identifier.

Sign-in takes place in the system browser. LimitPulse never asks for or receives an OpenAI password. Device authorization results, access tokens, refresh tokens, ID tokens, and the ChatGPT account identifier are handled on the Android device so the app can make read-only usage requests directly to OpenAI over HTTPS.

Authentication material is encrypted with AES-GCM. The encryption key is generated in Android Keystore. Authentication material is not sent to the LimitPulse public-signal service.

Usage and local history.

The app receives quota, reset-time, plan, and Token Activity values from OpenAI. It normalizes and stores the minimum values needed for current status and history in the app-private Room database. LimitPulse does not read or store conversations, prompts, source code, profile photos, or email addresses.

Usage and history are processed on the device and are not uploaded to the LimitPulse public-signal service, Firebase, an analytics provider, or a crash-reporting provider.

Firebase Cloud Messaging.

When a release is configured for Firebase Cloud Messaging (FCM), Google/Firebase processes data required to deliver reset-verification signals. This may include a Firebase installation ID, app version, Firebase user agent, and messaging registration data. LimitPulse uses FCM only for the fixed public reset-signal topic.

FCM messages contain only a bounded public event type, public event identifier, public source category, and publication time. OpenAI tokens, cookies, account identifiers, usage, prompts, conversations, and source code are never put in an FCM message.

The app does not enable Google Analytics, Crashlytics, Firebase Performance Monitoring, advertising, or BigQuery delivery-metrics export.

Public reset-signal service.

The LimitPulse public-signal service reads public reset announcements, classifies explicit completed-reset evidence, deduplicates public events, and sends the fixed FCM topic signal. It does not expose a client upload endpoint and does not receive OpenAI account data from the app.

3. Purposes

Data is used only to:

LimitPulse does not sell personal or sensitive data, use it for advertising, build advertising profiles, run Codex tasks, consume reset credits, or read or modify conversations.

4. Storage, retention, and backup

Encrypted authentication material and the Room database stay in app-private Android storage. All LimitPulse files are excluded from Android cloud backup and device-to-device transfer. Authentication material remains until disconnect, unrecoverable encryption failure, app-data clear, or uninstall. Local history follows the in-app retention behavior and can be deleted at any time.

Google/Firebase applies its own retention rules to Firebase installation and messaging data. Disconnect disables FCM auto-initialization, requests topic unsubscription and FCM unregistration, and requests deletion of the Firebase installation ID.

5. User controls and deletion

  1. Disconnect OpenAI deletes the encrypted authentication file and Android Keystore key, clears transient Cloudflare state, disables FCM auto-initialization, requests FCM cleanup, and cancels scheduled account checks.
  2. Delete local history deletes usage snapshots, quota windows, Token Activity history, reset evidence, sync state, and stored public signals from the Room database.

These controls delete LimitPulse data on the Android phone. They do not delete the user's OpenAI account. OpenAI account deletion must be performed through OpenAI.

LimitPulse has no developer-operated user account or account-data backend, so there is no separate LimitPulse cloud account to delete.

6. Permissions

Other network, wake, boot, and foreground-service permissions are contributed by FCM and WorkManager for delivery and scheduled work. The app does not request contacts, location, camera, microphone, phone, SMS, storage, advertising ID, or exact-alarm permissions.

7. Security and limitations

Network traffic uses HTTPS and cleartext traffic is disabled. Release builds contain no network body logger, analytics SDK, or developer-operated crash reporter. WebView is restricted to a Cloudflare fallback at the exact https://chatgpt.com origin and WebView debugging is disabled.

OpenAI usage endpoints used by LimitPulse are internal and may change. The app preserves the last successful value and displays an explicit state when a request fails. Android may delay background work, and force-stopping the app blocks background checks and alerts until the user opens it again.

8. International processing

OpenAI and Google/Firebase may process data in countries other than the user's country under their respective terms and privacy policies. Applicable jurisdiction-specific rights and disclosures may vary by launch country.

9. Children

LimitPulse is not designed or directed to children. Its intended audience is adults who already control an eligible OpenAI account.

10. Changes and contact

Material changes will be reflected by updating this policy and its effective date.

Developer/operator: YongTech

Privacy contact: pyhppyyhh0307@daum.net

한국어

LimitPulse 개인정보처리방침

1. 적용 범위 및 운영자

본 방침은 YongTech가 제공하는 Android 앱 LimitPulse에 적용됩니다. LimitPulse는 OpenAI와 제휴하거나 OpenAI의 보증을 받은 서비스가 아닌 독립적인 서드파티 사용량 확인 앱입니다.

LimitPulse는 별도의 LimitPulse 서비스 계정을 만들지 않습니다. 앱에서 OpenAI를 연결하면 사용자가 이미 관리하는 OpenAI 계정이 연결되며, LimitPulse가 해당 계정을 생성하거나 관리하지 않습니다.

2. 앱이 처리하는 데이터

OpenAI 인증 정보 및 계정 식별자.

로그인은 시스템 브라우저에서 진행됩니다. LimitPulse는 OpenAI 비밀번호를 요청하거나 전달받지 않습니다. 기기 인증 결과, 액세스 토큰, 리프레시 토큰, ID 토큰 및 ChatGPT 계정 식별자는 앱이 HTTPS를 통해 OpenAI에 읽기 전용 사용량 요청을 보내기 위해 Android 기기 안에서 처리됩니다.

인증 정보는 AES-GCM으로 암호화되며, 암호화 키는 Android Keystore에서 생성됩니다. 인증 정보는 LimitPulse 공개 신호 서비스로 전송되지 않습니다.

사용량 및 로컬 기록.

앱은 OpenAI에서 할당량, 리셋 시각, 요금제 및 Token Activity 값을 받아 현재 상태와 기록에 필요한 최소 정보만 정규화하여 앱 전용 Room 데이터베이스에 저장합니다. LimitPulse는 대화, 프롬프트, 소스코드, 프로필 사진 또는 이메일 주소를 읽거나 저장하지 않습니다.

사용량과 기록은 기기에서 처리되며 LimitPulse 공개 신호 서비스, Firebase, 분석 서비스 또는 오류 보고 서비스로 업로드되지 않습니다.

Firebase Cloud Messaging.

Firebase Cloud Messaging(FCM)이 구성된 릴리스에서는 Google/Firebase가 리셋 검증 신호 전달에 필요한 데이터를 처리합니다. 여기에는 Firebase 설치 ID, 앱 버전, Firebase 사용자 에이전트 및 메시징 등록 데이터가 포함될 수 있습니다. LimitPulse는 고정된 공개 리셋 신호 토픽에만 FCM을 사용합니다.

FCM 메시지에는 제한된 공개 이벤트 유형, 공개 이벤트 식별자, 공개 출처 분류와 게시 시각만 포함됩니다. OpenAI 토큰, 쿠키, 계정 식별자, 사용량, 프롬프트, 대화 및 소스코드는 FCM 메시지에 포함되지 않습니다.

앱은 Google Analytics, Crashlytics, Firebase Performance Monitoring, 광고 또는 BigQuery 전송 측정항목 내보내기를 사용하지 않습니다.

공개 리셋 신호 서비스.

LimitPulse 공개 신호 서비스는 공개 리셋 공지를 읽고, 명시적인 리셋 완료 근거를 분류하고, 공개 이벤트를 중복 제거한 뒤 고정 FCM 토픽 신호를 보냅니다. 이 서비스는 앱 데이터 업로드 엔드포인트를 제공하지 않으며 앱에서 OpenAI 계정 데이터를 받지 않습니다.

3. 이용 목적

데이터는 다음 목적으로만 사용됩니다.

LimitPulse는 개인정보 또는 민감정보를 판매하거나 광고에 이용하지 않고, 광고 프로필을 만들지 않으며, Codex 작업을 실행하거나 리셋 크레딧을 소비하지 않고, 대화를 읽거나 수정하지 않습니다.

4. 저장, 보유 및 백업

암호화된 인증 정보와 Room 데이터베이스는 Android 앱 전용 저장소에 보관됩니다. 모든 LimitPulse 파일은 Android 클라우드 백업 및 기기 간 전송에서 제외됩니다. 인증 정보는 연결 해제, 복구 불가능한 암호화 오류, 앱 데이터 삭제 또는 앱 제거 시까지 보관됩니다. 로컬 기록은 앱 내 보유 동작을 따르며 언제든 삭제할 수 있습니다.

Firebase 설치 및 메시징 데이터에는 Google/Firebase의 보유 정책이 적용됩니다. 연결 해제 시 FCM 자동 초기화를 비활성화하고, 토픽 구독 해제, FCM 등록 해제 및 Firebase 설치 ID 삭제를 요청합니다.

5. 사용자 제어 및 삭제

  1. OpenAI 연결 해제는 암호화된 인증 파일과 Android Keystore 키를 삭제하고, 임시 Cloudflare 상태를 지우고, FCM 자동 초기화를 끄고, FCM 정리를 요청하며, 예약된 계정 확인 작업을 취소합니다.
  2. 로컬 기록 삭제는 Room 데이터베이스에서 사용량 스냅샷, 할당량 구간, Token Activity 기록, 리셋 근거, 동기화 상태 및 저장된 공개 신호를 삭제합니다.

위 제어 기능은 Android 휴대전화의 LimitPulse 데이터를 삭제합니다. 사용자의 OpenAI 계정은 삭제하지 않으며, OpenAI 계정 삭제는 OpenAI에서 직접 진행해야 합니다.

LimitPulse는 개발자가 운영하는 사용자 계정 또는 계정 데이터 백엔드가 없으므로 별도로 삭제할 LimitPulse 클라우드 계정이 없습니다.

6. 권한

기타 네트워크, 절전 해제, 부팅 및 포그라운드 서비스 권한은 메시지 전달과 예약 작업을 위해 FCM 및 WorkManager가 제공합니다. 앱은 연락처, 위치, 카메라, 마이크, 전화, SMS, 저장공간, 광고 ID 또는 정확한 알람 권한을 요청하지 않습니다.

7. 보안 및 제한사항

네트워크 통신은 HTTPS를 사용하며 평문 통신은 차단됩니다. 릴리스 빌드에는 네트워크 본문 로거, 분석 SDK 또는 개발자 운영 오류 보고기가 없습니다. WebView는 정확히 https://chatgpt.com origin의 Cloudflare fallback으로 제한되고 WebView 디버깅은 비활성화됩니다.

LimitPulse가 사용하는 OpenAI 사용량 엔드포인트는 내부 API이므로 변경될 수 있습니다. 요청 실패 시 앱은 마지막 성공값을 보존하고 명시적인 상태를 표시합니다. Android는 백그라운드 작업을 지연할 수 있으며, 앱을 강제 종료하면 다시 열 때까지 백그라운드 확인과 알림이 차단됩니다.

8. 국외 처리

OpenAI와 Google/Firebase는 각자의 약관 및 개인정보처리방침에 따라 사용자의 국가가 아닌 곳에서 데이터를 처리할 수 있습니다. 적용되는 지역별 권리와 고지사항은 출시 국가에 따라 달라질 수 있습니다.

9. 아동

LimitPulse는 아동을 대상으로 설계되거나 제공되지 않습니다. 이미 적격한 OpenAI 계정을 관리하는 성인을 대상으로 합니다.

10. 변경 및 문의

중요한 변경사항은 본 방침과 시행일을 업데이트하여 반영합니다.

개발자/운영자: YongTech

개인정보 문의: pyhppyyhh0307@daum.net