PULSE PRIVACY POLICY
Pulse by Arch Labs | getarchlabs.xyz/privacy | Effective September 4, 2026
1. Who we are and who this covers
Pulse is made by Arch Labs LLC, a North Carolina company (“Arch Labs,” “we,” “us”). Pulse is a Discord bot (currently named Pip) and a dashboard that help the people who run a Discord community understand how it is doing.
This policy covers two groups of people. Operators are the server owners, administrators, and staff who sign in to the Pulse dashboard. Members are people in a Discord server where an operator has installed Pulse. If you are a member, the parts written for you are Sections 3 through 8 and Section 12. If you have questions about how a specific server uses Pulse, the server’s administrators decide which channels Pulse reads, and they are your first stop.
2. The short version
- Pulse reads messages in the text channels the bot can see. A server administrator can switch any channel off, and Pulse asks them to review the list during setup. It never reads direct messages.
- The server’s administrators are told to post a notice in the server before Pulse reads anything, and to honor any member who asks to be left out.
- We keep messages for the server’s retention window, ninety days by default, then delete them.
- We do not sell data, show ads, share data with data brokers, or use message content to train AI models.
- Pulse never sends a message to a member unless a person on the server’s team approves that specific message.
- You can ask any administrator of the server to exclude you. Reading stops within a minute and what we stored is deleted on the nightly cleanup.
3. What Pulse reads in a server
Messages. In the text channels the bot can see, Pulse reads the messages members post: the text, who posted it, when, and in which channel, along with reactions. Threads count as part of the channel they hang off. An administrator can switch any channel off, and Pulse asks them to review the channel list during setup. Channels that are switched off, channels Discord’s permissions do not let the bot see, and direct messages are never read.
Support requests. If an administrator connects a ticket category, a ticket panel, a transcript log, a support channel, or a forum channel as a request source, Pulse reads the conversations in those tickets and posts so the team can see which requests are waiting and which problems many members share. Nothing ticket-shaped is read until an administrator configures a source.
Who is in the server. Pulse keeps a list of members and their roles, their display names, the channels they are most active in, their join dates, and how many members the server has each day, so it can tell the team about activity against each member’s own normal and show the server’s growth.
Events and roles. Pulse reads the server’s scheduled events and its list of roles so the team can plan around them.
History import. If an administrator asks Arch Labs to import a server’s history, Pulse reads past messages once, going back no further than the server’s retention window, in the channels Pulse reads. This happens only after the server’s notice to members has been posted.
4. What Pulse does with it
Pulse uses what it reads to produce analysis for the server’s team: a daily read of the community’s mood and the topics behind it, early warnings when a conversation is heating up, members whose activity has dropped against their own baseline, requests and issues members raise and how many members share them, and, where the team turns those features on, moments when a member seems interested in a perk the server offers.
Some of this analysis is produced with the help of artificial intelligence models run by Anthropic, PBC. We send message content to Anthropic’s service for analysis under commercial terms that prohibit Anthropic from using it to train models. We do not use message content to train any machine learning or AI model ourselves, and Discord’s Developer Policy forbids it.
Pulse may also draft a message for the team to send to a member, such as a check-in with someone who has gone quiet. Nothing is sent unless a person on the team approves that specific message. Pulse does not contact members outside Discord, and we never use what Pulse reads to contact you ourselves.
We use aggregated or de-identified information, which cannot identify any individual, to understand how Pulse performs and to improve it.
5. How long we keep it
Messages are kept for the server’s retention window, which an administrator can set between 7 and 365 days. The default is 90 days. A nightly cleanup deletes messages older than the window and blanks any quote Pulse copied from them. Analysis derived from those messages, such as a day’s mood score or a member’s activity trend, is kept without the message text.
If an administrator switches a channel off, reading stops within about a minute and the messages Pulse stored from that channel are deleted, then deleted again on the nightly cleanup in case any slipped through.
If you delete or edit a message in Discord, Pulse deletes or updates its copy too, usually within a minute, along with any quote Pulse copied from it.
If Pulse is removed from a server, reading stops that day and stored data is deleted under the server’s retention window, or within thirty (30) days of the operator’s written request. Routine backups expire in the ordinary course.
6. Who can see it
The server’s team. Operators and the staff they invite can see Pulse’s analysis for their own server, including quoted messages as evidence for a finding. They cannot see any other server. This is enforced in the database itself, not just in the interface.
Arch Labs. Arch Labs staff can open a server’s dashboard to provide support or investigate a problem. Each time they do, the reason and the time are recorded, and the server’s operators can ask for that record. We do not browse servers for any other reason.
Our service providers. Pulse runs on services that process data on our behalf: Discord, Inc. (the platform and its API); Supabase, Inc. (database and sign-in, hosted in the United States); Railway Corp. (bot hosting, United States); Vercel, Inc. (dashboard hosting, United States); and Anthropic, PBC (AI analysis, United States, no training on your data). Each is bound by terms that limit what it can do with the data.
Nobody else, except where the law requires us to disclose information, to protect the safety of a person, or to enforce our terms, and except to a successor if Arch Labs is sold, in which case this policy continues to apply.
We do not sell personal information, show advertising, or share data with advertisers or data brokers.
7. Your choices as a member
Ask to be excluded. Ask any administrator of the server to add you to Pulse’s exclusion list. Reading stops within a minute, and everything stored from you is removed on the nightly cleanup. The administrator sees this promise in the confirmation before they exclude you, in these same words.
Ask about a server. The server’s administrators choose which channels Pulse reads and are responsible for telling you. If you cannot reach them, or you believe a server is using Pulse against Discord’s rules or this policy, write to us at the address in Section 12.
Your rights under the law. Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict its processing, or to complain to a supervisory authority. The server’s administrators are the controller of your data under laws like the EU and UK GDPR, and we process it for them. Ask them first; Pulse gives them the tools to act on your request. If they cannot or do not, contact us and we will help within thirty (30) days, and we may ask for information to confirm who you are. We will not treat you differently for exercising a right.
8. Children
Pulse is not directed at children under 13, or under the age of digital consent where you live, and operators may not connect a server or channel that is. Discord requires users to be at least 13. If we learn we have collected personal information from a child under 13 without a parent’s consent, we will delete it. Contact us at the address in Section 12.
9. Operators: your account
When you sign in with Discord, we receive your Discord user ID, username, avatar, and the list of servers you own or administer, so we can show you only the servers you are allowed to see. We do not store your Discord access token. If you sign in with an email link, we store your email address. We use cookies only to keep you signed in and to remember which server you were viewing. We do not use advertising or tracking cookies.
We keep your account for as long as you use Pulse, and delete it on request. If you invite staff, we record who invited whom and when.
If you are an operator whose members are protected by a data protection law, you are the controller and we are your processor. Our Data Processing Terms, written to meet Article 28 of the GDPR, are available on request and form part of our agreement with you.
10. Security
Data is encrypted in transit. Each operator’s access is limited to their own servers by row-level rules in the database. Credentials for third-party services are stored server-side and never reach a browser. We keep access logs, and we will notify affected operators without undue delay if we learn of a breach affecting their data, so they can meet their own obligations to their members. No system is perfectly secure, and we cannot guarantee that unauthorized access will never occur.
11. Where data is processed
Arch Labs is in the United States, and our service providers process data in the United States. If you are in the European Economic Area, the United Kingdom, or another place with data transfer rules, your data is transferred to the United States. For operators to whom those rules apply, our Data Processing Terms incorporate the European Commission’s Standard Contractual Clauses and the UK Addendum.
12. Contact and changes
Questions, requests, and complaints: pulse@getarchlabs.xyz. Mail: Arch Labs LLC, 5309 Hollow Branch Rd, Charlotte, NC 28278, United States, attention Lester Archambeau.
We may update this policy. If a change is material, we will give operators at least fourteen (14) days’ notice by email or in the dashboard, and we will update the effective date at the top. The version at getarchlabs.xyz/privacy is the current one.