Last updated:
1. Who we are and what this Policy covers
Fastpulse is operated by Vatsal Sanghvi, trading as 1811 Labs, a sole proprietorship based in Bengaluru, India. This Policy explains our handling of personal information through the Fastpulse website, application, workspaces, customer support, billing relationship, and communications. It also covers personal information in public references and licensed materials that we select for Fastpulse. We refer to the website, application, creative tools, and related services together as the “Service.” Use of the Service is governed by our Terms of Service.
Contact hello@fastpulse.app for privacy questions, requests, complaints, or information about our providers. References to “we,” “our,” or “us” mean the operator identified above.
For our customer relationship, account administration, product security, marketing, and processing we determine for our own purposes, we act as the controller or equivalent responsible organization. When we handle personal information solely on a business customer's documented instructions, that customer generally acts as controller and we act as its processor or service provider. A separate data-processing agreement governs that processing where required. Contact us to arrange the applicable terms before using the Service for that processing.
UGC Pulse is another product operated by 1811 Labs. Section 8 explains our common marketing arrangements. A Fastpulse account does not automatically become a UGC Pulse account, and each product's own policy describes its other processing.
2. Information we collect and its sources
We collect information from you, authorized workspace users, the operation of the Service, payment and infrastructure providers, and the public or licensed sources described below. The information depends on the features you use.
Account and workspace information. This can include your name, email address, authentication identifiers and session information, organization or client name, workspace memberships and roles, invitations, preferences, account status, and information you provide about your business or project. An owner or administrator may provide information when inviting you. A sign-in provider may supply basic identity information if you choose that sign-in method.
Customer content and creations. We process uploaded video, audio, images, product demonstrations, brand materials, captions, scripts, prompts, instructions, project settings, selections, and finished outputs. Material you or authorized workspace users provide is referred to as “Customer Content.” We also process related metadata such as file type, duration, timestamps, processing status, and asset associations. These materials can contain personal information about you or other people, including their appearance or voice.
Subscription and credit records. We receive or maintain plan and entitlement details, free and purchased credit balances, generation charges and corrections, billing dates, transaction references, payment and refund status, and relevant invoice or tax details. Dodo Payments collects payment information at checkout. We do not directly store complete payment-card numbers or card security codes.
Support and communications. We retain correspondence, feedback, privacy and rights-holder requests, and the information needed to resolve them. Our email system also handles marketing choices, consent and unsubscribe records, and message delivery information. Where enabled and lawful, it may record message engagement such as link clicks or opens; any tracking that requires consent is subject to that consent.
Technical and product-use information. This may include IP address, approximate location inferred from IP rather than precise device location, browser and operating-system details, timestamps, referring pages, pages or features used, event and session identifiers, performance measurements, and error or security events. These are used for operation, diagnostics, abuse prevention, and permitted analytics. Section 7 explains tracking controls and the exclusion of customer content from routine telemetry.
Reference and catalogue information. Public or licensed media may contain creator names, handles, profile or post links, images, voices, captions, posting dates, and publicly available engagement or media metadata. Sources include TikTok, Instagram, other public pages, and rights holders or providers from whom we obtain material. People represented in this information may not have a Fastpulse account.
Do not submit passwords, complete payment details, government identifiers, health records, or other sensitive information that is unnecessary for your task. Ordinary images and voices can be personal information; that does not mean we use them for biometric identification. The current Service does not provide customer face or voice cloning or use uploaded media to identify people through biometric matching.
3. Why we process information
We use personal information to administer sign-in and workspaces; provide requested editing, captioning, rendering, storage, and downloads; operate subscriptions and credits; answer support and rights requests; and send essential account, billing, security, and service notices.
We also use limited information to understand feature usage, diagnose errors, improve usability and performance, and prevent fraud, unauthorized automation, raw-asset extraction, and security incidents. Legal and operational uses include enforcing agreements fairly, handling disputes, preserving required records, and responding to lawful requests.
Marketing about Fastpulse and UGC Pulse is a separate purpose described in Section 8. We do not treat the use of an AI feature as permission to train models, or a workspace upload as permission to publish it in our own marketing.
For reference material we select, the purpose is creative research and inspiration. Eligible catalogue assets support the creation of finished content. Reference-only videos are not supplied as reusable material for customer exports. We assess the relevant source, necessity, permissions, and individuals' interests before processing personal information from public sources. Public availability does not give us unrestricted permission to use that information.
4. Legal bases for processing
Where applicable law requires a legal basis, we match it to the purpose rather than relying on blanket consent to this Policy.
| Purpose | Basis we rely on where applicable |
|---|---|
| Providing an individual's requested account, paid access, creative processing, and support | Performance of our contract with that individual, or steps they request before entering it. |
| Administering business contacts and workspace membership | Our legitimate interest in delivering the service to the relevant organization, or another applicable basis. A business customer's processing instructions govern its own use of contributor data. |
| Security, fraud prevention, service diagnostics, and enforcement | Legitimate interests in protecting people and systems and operating a reliable service; legal obligations where a particular activity is required by law. |
| Product analytics and non-essential tracking | Consent where required for the relevant technology or purpose; otherwise a permitted legitimate interest, after considering privacy impact. |
| Marketing our products | Consent where required; otherwise the legal basis permitted for that communication, including legitimate interests where a valid existing-customer exception applies. Objections and opt-outs are respected. |
| Selecting and presenting lawful public reference material | Legitimate interests in providing creative research, subject to a balancing assessment, source and purpose limits, minimization, and applicable objection or removal rights. |
| Billing records, compliance, and legal claims | Legal obligations and, where appropriate, legitimate interests in establishing, exercising, or defending claims. |
We do not apply “legitimate interests” as a substitute for consent in a jurisdiction or situation where the law does not permit that basis. You may request information about a relevant balancing assessment and object where applicable.
Where we rely on consent, you can withdraw it without affecting processing that was lawful before withdrawal. Some information is necessary to provide the requested account, purchase, or feature; declining that information may prevent that function. Refusing optional marketing or optional analytics does not prevent access to the core Service.
5. AI processing and the no-training commitment
Some features may use AI providers to process the text and context needed for a requested task, such as generating captions or scripts. Depending on the feature enabled, this may involve OpenAI's business/API services or Anthropic's commercial services. We send the information needed for the feature, not an entire workspace merely because an AI option is selected.
We do not use Customer Content or customer-generated outputs to train or fine-tune Fastpulse or third-party AI models without a separate, informed opt-in. This commitment also applies when providers process Customer Content on our behalf. Delivering a requested feature, conducting content-safety checks, or investigating a processing error does not give us permission to use your content for model training.
We use tools such as Higgsfield and Replicate internally to produce or prepare our own catalogue assets. Customer uploads, prompts, and customer-specific generations are not routed to those tools in our current customer-generation workflow. If internal catalogue preparation involves an identifiable person's material, we process it only with an appropriate legal basis and any required permissions.
An AI provider may retain limited request information for service delivery, security, abuse prevention, or legal compliance under the applicable agreement and settings. A no-training commitment is not a claim of zero retention or zero authorized human access. We will assess materially different providers or uses before sending customer information to them, and update notices and permissions where required.
If an optional future customization feature requires customer-specific model training, we will explain that processing and seek the separate permission it requires before enabling it. It will not create general permission to train on unrelated workspace material.
6. Who can receive information
We disclose only information reasonably needed for the stated purpose. Where a provider acts for us, it is subject to appropriate contractual restrictions, security requirements, and confidentiality obligations. Some providers, particularly the merchant of record, determine their own purposes for transaction compliance and are responsible for those activities under their own notices.
| Recipient | Purpose and relevant information |
|---|---|
| Supabase | Authentication, database, and storage services for account information, workspace records, and stored media or outputs. |
| Vercel | Website and application hosting, request handling, and associated technical and security information. |
| Railway | Rendering and background-processing infrastructure, including the media and job information needed to carry out the requested work. |
| Dodo Payments | Merchant-of-record checkout, payment and tax administration, invoicing, fraud controls, refunds, and disputes. It receives the transaction and customer details necessary for those purposes. |
| AutoSend | Delivery of service and permitted marketing emails, using contact details, message content, delivery records, and communication preferences. |
| PostHog | Product-use analytics using limited identifiers, events, and technical information, subject to applicable tracking choices. Session replay is not enabled. |
| Sentry | Error and performance diagnostics using limited technical information. Session replay is not enabled, and customer content is excluded from routine diagnostic capture. |
| OpenAI and Anthropic, when enabled for a feature | Business/API processing of the prompts and relevant text or context needed for that feature, under the no-training arrangements in Section 5. |
Higgsfield and Replicate are internal catalogue-production tools as described in Section 5, not recipients of customer uploads or prompts in the current customer-generation workflow.
Workspace participants. Workspace owners and administrators can access and delete all content in their workspace. Other members can access information according to permissions. Your name, membership, and contributions may be visible to collaborators. Material contributed to a workspace remains there after you leave, unless the workspace controller removes it or applicable law requires otherwise.
Other recipients. We may disclose relevant information to advisers, auditors, insurers, authorities, or parties involved in a genuine sale or restructuring of the business where necessary and lawful, using confidentiality and other safeguards as appropriate. We may also disclose information to comply with law, address a security threat, or protect legal rights. A transfer of the business does not authorize an undisclosed incompatible use of personal information.
We do not make private workspace media publicly available merely because it has been uploaded or rendered. A user or client who independently exports and publishes a creation determines that publication. Future connected publishing is addressed separately in Section 12.
7. Cookies, analytics, diagnostics, and advertising choices
We use cookies, local storage, and similar technologies where needed for authentication, session continuity, security, and user-requested preferences. Blocking necessary technologies may prevent the relevant feature from working.
Optional product analytics helps us understand use and improve the experience. Our marketing site loads Google Analytics 4 on every visit when a measurement identifier is configured for an authorized environment. It does not display an analytics pop-up or consent prompt. GA4 sets the _ga and _ga_<measurement-id> cookies to measure site use. Advertising features are not enabled.
You can limit or block analytics cookies through your browser's cookie controls, the Google Analytics opt-out browser add-on, or other controls a vendor provides, or by contacting hello@fastpulse.app. Browser settings do not erase information already transmitted.
Neither PostHog nor Sentry records session replays in our current setup. We do not send the contents of uploads, prompts, captions, scripts, or generated files to routine analytics or error-reporting tools. We exclude or redact customer-content fields from routine telemetry. A support case you deliberately submit may contain information needed to investigate it, handled separately under the support purpose.
We do not sell personal information for money, sell customer content, or provide it to advertisers. The practices described here do not include advertising pixels or disclosures for cross-context behavioral advertising. If a future disclosure falls within a broader legal definition of “sale,” “sharing,” or targeted advertising, we will provide the required notice and controls before that disclosure. We honor legally applicable opt-out preference signals, including Global Privacy Control, and do not require a paid plan to exercise a privacy right.
8. Marketing for Fastpulse and UGC Pulse
Fastpulse and UGC Pulse are operated by the same business, 1811 Labs. We may manage a common marketing contact list containing contact details, the product through which the relationship began, relevant marketing preferences, consent records, and permitted delivery or engagement information. We use it to communicate about both products where lawful and consistent with those choices.
Where consent is required, we obtain it before sending marketing. Agreement to the Terms, acknowledgment of this Policy, or creating an account does not by itself constitute that consent. Where an existing-customer exception is available, we use it only when its conditions are met. Existing objections and restrictions on previously collected contact details continue to apply.
You may unsubscribe using the link in a marketing email or by contacting hello@fastpulse.app. A request to stop all 1811 Labs marketing will be respected across the shared Fastpulse and UGC Pulse list. Where separate brand preferences are offered, you may choose them instead. No login is required to request an unsubscribe. We retain a limited suppression record when needed to prevent further marketing.
Unsubscribing does not stop essential messages about a transaction, account security, requested support, service closure, or a legal notice. We do not use that exception to send unrelated promotions. The common marketing list does not merge account credentials or workspace content, or authorize us to use private customer creations in marketing without separate permission.
9. International processing
1811 Labs operates from India, and our hosting and service providers may process information in the United States and other countries where they operate. Primary service infrastructure may be US-hosted; account administration or support may involve access from India. We do not promise exclusive storage or access within any one country unless a separate agreement says so.
We transfer personal information internationally only as permitted by applicable law. Where additional safeguards are required, we use an applicable adequacy decision or appropriate contractual safeguards, together with any required assessments and supplementary measures. For EEA or UK data, these safeguards may include European Commission standard contractual clauses and the applicable UK transfer terms. We do not rely solely on your acceptance of this Policy to authorize a transfer that requires additional safeguards.
You may contact us for information about the countries, providers, and safeguards relevant to your information, and for a copy or explanation of applicable safeguards, with necessary confidential details protected. We do not represent that every provider, country, or data flow has the same transfer arrangement.
10. Retention and deletion
We retain personal information for its stated purpose, taking account of customer instructions, service needs, the sensitivity of the information, applicable law, and proportionate requirements for security and legal claims. We do not keep all categories for the same period.
Uploads and generated outputs. We currently keep these while the owning account or workspace is maintained, unless deleted by an authorized user or removed for a stated lawful reason. There is no automatic 90-day expiry for generated outputs under the current policy. This is not permanent storage. A material future reduction in storage or retention will be announced at least 30 days before it affects stored content, with a reasonable export opportunity and protection for existing paid commitments. Urgent legal or security removal may require earlier action.
Workspace deletion. When we receive an authorized request to delete a workspace, we remove that workspace's content from active systems within 30 days, except where retention is required by law. Authorization is established through an authenticated request or proportionate verification. Once accepted, the workspace is closed to ordinary access while cleanup takes place. The deletion covers original uploads, generated outputs, and associated project content held in active systems.
Cancellation and individual accounts. Subscription cancellation or expiry does not start that deletion clock. Nor does a member leaving a workspace. A request to close your individual account covers your personal account data under applicable deletion rights, but does not automatically authorize deleting another organization's workspace or its business records. We will explain any owner instructions or legal exceptions that affect your request and will respect your individual privacy rights even where a workspace retains a contribution.
Inactive accounts and workspaces. We may delete an account or workspace after at least 12 months without meaningful activity if it has neither an active paid subscription nor unexpired purchased credits. We give a further warning at least 30 days before deletion and an opportunity to resume use or export material. Activity by an authorized member counts as activity for the workspace.
Backups. Deleted information may remain temporarily in restricted backups until the applicable backup reaches the end of its finite disaster-recovery rotation cycle and is overwritten or deleted. It is not available for ordinary product use or repurposed for analytics or marketing. If we restore a backup, we reapply deletion instructions before the affected information returns to ordinary use. A legally required preservation is handled separately. The 30-day active-system commitment is not a claim that every backup copy disappears on the same date.
Billing, tax, and legal records. We retain the information required for accounting, tax, disputes, and other legal obligations for the applicable statutory period or for the time reasonably necessary to resolve an identified claim. Such records do not justify keeping an entire deleted workspace. Dodo Payments may independently retain transaction records under its own obligations.
Security logs, support, and analytics. Security records are retained for the period needed to detect, investigate, and prevent abuse, or meet a statutory logging requirement. Support records are retained while needed to resolve the matter and a proportionate follow-up or claims period. Analytics follows the shortest configured retention suitable for its stated measurement purpose. We review these needs and delete or genuinely anonymize information when it is no longer needed; identifiable logs are not treated as anonymous merely because names have been removed.
Marketing and reference information. Marketing information is retained while there is a lawful basis to communicate, with limited consent or suppression records kept as needed to demonstrate and respect choices. Public or licensed reference material is retained only while useful and lawful for its purpose, taking account of source restrictions and valid correction or removal requests. A minimal identifier may be retained to prevent removed material from being reintroduced.
We instruct relevant processors to delete information as required by our agreements and applicable law. Copies independently held by customers, clients, publishing platforms, or legally independent controllers follow their own obligations. Contact us for category-specific retention information. Where a shorter deadline is mandatory, that deadline prevails.
11. Security, human access, and incidents
We use reasonable organizational and technical safeguards appropriate to the information and risks. These include access restrictions, workspace permissions, secure transmission, and limited access for personnel or providers with an operational need. No service can promise complete security or uninterrupted availability.
Authorized access to customer content may be needed for a support request, processing failure, security investigation, rights complaint, or legal obligation. We limit it to the purpose and do not treat routine staff access as permission to browse private projects. We do not promise end-to-end encryption or claim that Fastpulse holds a certification merely because a provider holds one.
If a personal-information incident occurs, we investigate and mitigate it and provide notices to affected customers, individuals, or authorities within the periods required by law and applicable agreements. Report a suspected security issue to hello@fastpulse.app.
12. Additional features and external platforms
Social-account publishing, customer face or voice cloning, and custom-avatar features are not currently available to customers. We do not collect information for these features simply because they are mentioned in our Terms.
If enabled later, a social integration may require account identifiers, permission scopes, authorization tokens, publishing instructions, and the media to be posted. We will explain the actual information collected, access requested, recipients, revocation route, and retention before the connection is used. We do not currently obtain social-account passwords, private messages, or private analytics through an unlaunched publishing feature.
A future likeness or voice feature will require a separate assessment of the media and any derived data it processes, appropriate permissions, and any legally required feature-specific notice or consent. We will not assume a general account acceptance is sufficient for sensitive or biometric processing.
Third-party websites, embedded content, and independently connected services have their own information practices. An embedded platform player, where used, may receive technical information when loaded. Google Analytics on our marketing site loads without a consent prompt, as described in Section 7. Deleting a workspace does not delete a copy you or a client has independently published elsewhere.
13. Your choices and privacy rights
Depending on the applicable law and our role, you may ask for access to your information, a copy, correction, deletion, restriction, portability, or an explanation of processing. You may also have rights to object to legitimate-interest processing, withdraw consent, opt out of particular disclosures or profiling, appeal a decision, or complain to a regulator. These rights apply to personal information, not an unrestricted download of the Fastpulse library or other people's confidential material.
Send requests to hello@fastpulse.app. Describe the request and the account, workspace, or reference material involved. We may ask for only the information reasonably needed to verify identity and authority. An authorized representative may act where the law permits. We will respond within the applicable legal deadline, generally within one month for EEA and UK rights requests, subject to lawful extensions or verification rules. We explain an extension, limitation, or refusal when required. We do not impose a fee or disadvantage for exercising a right unless a specific lawful exception permits a fee.
Where a business customer controls the information, we may refer the request to that customer and assist it under our agreement. You can still contact us; we will explain our role. Workspace permissions do not extinguish an individual's statutory rights.
EEA and UK. You may complain to the data-protection authority responsible for your location, including the UK Information Commissioner's Office where relevant. You need not complete our informal complaint process before exercising a legal right to complain. You have an unconditional right to object to processing for direct marketing, including related profiling.
United States. Where applicable state law covers the processing, rights may include knowing the categories and specific information collected, access, correction, deletion, portability, opt-outs from sale, sharing, targeted advertising or qualifying profiling, and appeal. The categories, sources, purposes, and recipients are described in Section 2, Section 3, and Section 6. We do not use sensitive personal information to infer characteristics or offer a financial incentive in exchange for personal data. An appeal may be sent to hello@fastpulse.app with “Privacy appeal” in the subject; we will explain the outcome and available further complaint routes.
India. We handle requests for access or information, correction, erasure, withdrawal of consent, and grievance redressal under the Indian privacy requirements that apply and are in force. Any additional statutory rights, including nomination rights where applicable, are not limited by this Policy. Address a grievance to Vatsal Sanghvi, 1811 Labs, at hello@fastpulse.app. We will provide information about further lawful complaint routes when relevant.
We do not use AI to make decisions about individuals that are intended to produce legal or similarly significant effects. Routine credit accounting, permissions, or abuse controls may be automated; contact us to request human review of a disputed restriction or billing event. Any materially different qualifying automated decision-making would require separate assessment and disclosures.
14. People appearing in reference material
You do not need a Fastpulse account to ask about information concerning you. If a reference, catalogue item, or public-source record identifies you, email hello@fastpulse.app with the relevant URL or identifying details. You may ask about its source, seek correction, object, request restriction or removal, or raise a likeness or copyright concern.
We assess requests against applicable law, the purpose and basis for processing, and relevant rights. We may keep a minimal suppression record to avoid re-collecting material validly removed. We do not assume a person's public profile amounts to consent to marketing or unrestricted reuse.
15. Children
Fastpulse is for users aged 18 or older and is not directed to children. We do not knowingly register children or solicit their account information. Do not create an account for a child or upload a child's personal information without a lawful and necessary basis and appropriate permissions. Report suspected inappropriate collection at hello@fastpulse.app so we can investigate and take required action.
16. Changes and contact
We will update this Policy when our processing changes and update its effective date. Material changes will be brought to users' attention through appropriate notice, and we will obtain fresh consent where required before a new use begins. Posting a revised Policy alone does not override a prior objection or supply a missing permission.
For privacy requests, marketing objections, appeals, complaints, retention or provider information, and questions about this Policy, contact hello@fastpulse.app.