1. Overview
- Message keys remain on client devices in sealed production modes.
- Identity, authentication, and payment confirmation run on our EU origin.
- Managed routing processes sealed payloads and the metadata needed for delivery.
- Marketing-site providers are documented separately in the Privacy Notice.
2. Separation of responsibilities
Account, directory, authentication, and payment-confirmation records are held on the EU origin operated for OpenPulse. Application data remains with the integrator unless a separate managed service expressly stores it.
Relays route traffic. They are not intended to become a second identity or payment-trust system.
3. Encryption
Production traffic is sealed end to end when configured. Operators see opaque bodies and routing metadata, not message plaintext. Demo and staging environments may use plaintext modes for debugging; those modes are not production privacy claims.
Messaging targets established protocols for one-to-one and group sessions. Transitional modes remain labelled until production ratchets are complete.
4. Authentication and payment confirmation
Passkeys and sign-in terminate on the OpenPulse Auth service. Payment confirmation asks Auth to verify the required factor. Authenticator secrets and signing secrets do not move into the checkout application.
5. Subprocessors
Current managed product-data-path providers:
| Processor | Purpose | Data processed | Region | Required |
|---|---|---|---|---|
| Hetzner | EU origin, identity, auth, payment confirmation, durable records | Identity, account bindings, Checkout UX, sealed routing metadata | EU | Yes |
Register updated 2026-08-20. Website delivery and optional bot protection are documented in the Privacy Notice.
6. Data categories
OpenPulse processes handles and account bindings, claim and verification email, session bindings, public identity and encryption material, sealed traffic, routing metadata, security events, and payment step-up session metadata.
The legal bases, retention criteria, recipients, international-transfer safeguards, and data-subject rights are set out in the Privacy Notice.
7. Customer controls
Integrators can self-host relays, restrict traffic with realm keys, revoke credentials, and require sealed production modes. Public performance and capacity statements apply only where the corresponding published validation gate has passed.
8. Security contact
Report vulnerabilities privately to security@openpulse.org. Include the affected service, a concise reproduction, and the likely impact. Do not include unnecessary personal data or publish an active exploit before remediation.
This disclosure channel covers the OpenPulse wire, Auth, Pay Checkout, and official managed relays. OpenPulse does not currently claim a public bug-bounty programme.