Skip to content

Privacy Policy

Last updated: 29 May 2026

Client Pulse (the "Service") is operated by Matrix One. This Privacy Policy explains what personal information we collect when you use the Service, how we use it, and the choices you have. By using the Service you agree to the terms below.

If you have questions about anything here, email ragool@matrixreq.com.

What we collect

We collect the minimum data needed to operate the Service.

Account data

When you sign in we receive, from Supabase Auth:

  • Your email address
  • A unique user ID generated by Supabase
  • The Google profile (name, picture, locale) if you sign in via Google OAuth
  • A session token used to keep you signed in

Your organisation is derived from the domain part of your email (e.g. matrixreq.com). Users with the same email domain share access to the same organisation's data. We refuse personal-email accounts (Gmail, Yahoo, Outlook, etc.) for organisational data isolation.

Data you upload or generate

  • Companies you import (name, LinkedIn URL, industry, country, owner name, notes, etc.)
  • Signal-type definitions and descriptions you write
  • Custom feed URLs you add
  • Slack workspace metadata (team name, channel names, user names visible to the bot)
  • Microsoft Teams webhook URLs you connect

Data the Service collects on your behalf

When you run a sync we fetch publicly available content about your target companies from:

  • LinkedIn (via the linkdapi API)
  • Google News RSS
  • The companies' own websites (RSS / Atom feeds)
  • openFDA (510(k) clearances)
  • Crunchbase (funding rounds, when you supply a Crunchbase API key)
  • URLs you add as custom feeds

Fetched content is classified by Anthropic Claude (Haiku 4.5) and stored as "signals" linked to the companies on your tracked list.

Operational logs

We log:

  • Per-API-call usage (provider, endpoint, units consumed, cost) for billing visibility — no payload content is stored in these rows
  • Slack delivery records (which signal was posted, to which channel or user, when, by whom) — used to show "Sent" badges and prevent duplicate sends
  • Errors and stack traces for debugging — never include passwords or secrets

We do not use cookies for advertising. We do not run third-party analytics scripts.

Where the data lives

  • Database: Supabase Postgres, region eu-west-1 (Ireland). Encrypted at rest by Supabase.
  • Backend: Fly.io machine in region lhr (London). Code is the open-source contents of the repo this site is built from.
  • Frontend: Cloudflare Pages CDN.
  • Auth: Supabase Auth + Google OAuth (Google sign-in flows through Google's servers).

Third-party services we send data to

We use the following processors. Each has its own privacy practices.

ServiceWhat we sendWhy
SupabaseAccount data + all app dataDatabase + auth
AnthropicFetched article text, company descriptions, your signal-type descriptions, chat questionsClaude classification + chat
LinkdAPICompany LinkedIn slugsFetching LinkedIn posts
SlackSignal content you choose to send + bot tokenMessage delivery
CloudflareHTTP request metadataCDN / Pages hosting
Fly.ioHTTP request metadata, runtime logsBackend hosting
GoogleOAuth profile when signing in via GoogleSingle sign-on

We do not sell or rent your data to anyone. We do not share it with advertisers.

How long we keep it

  • Account + organisation data: as long as your account is active.
  • Signals + companies: until you delete them or close your account.
  • Slack OAuth tokens: until you disconnect via Settings → Slack, or remove our app from your Slack workspace.
  • API usage logs: rolling 13 months for cost reporting.
  • Backend logs: rolling 30 days, then automatically discarded.

When you delete a company, its signals are also deleted. When you close your account, your row in users plus everything keyed by your email is removed within 30 days. Email ragool@matrixreq.com to request closure.

Your rights

Under the GDPR (and equivalent laws in many other jurisdictions) you can:

  • Access the data we hold about you — request via email.
  • Correct inaccurate data — edit it in the app, or email us.
  • Delete your account and all associated data — email us.
  • Export your data in a machine-readable format — email us.
  • Object to or restrict specific processing — email us.
  • Lodge a complaint with a supervisory authority (e.g. the CNIL in France).

We respond to requests within 30 days.

Children

The Service is intended for sales professionals at organisations. It is not directed at children under 16. We do not knowingly collect personal data from anyone under 16.

Security

  • All traffic is HTTPS (TLS 1.2+)
  • Auth tokens are short-lived JWTs signed by Supabase
  • Slack OAuth state is signed with a server-side secret to prevent CSRF
  • The Supabase service-role key is held only on the backend; the frontend uses the anon key
  • Backend runs as a non-root user inside a minimal Debian container
  • Secrets (Anthropic / LinkdAPI / Supabase / Slack credentials) live in Fly's encrypted secrets store

No system is perfectly secure. If you believe you've found a vulnerability, please email ragool@matrixreq.com before public disclosure so we can fix it.

International transfers

The primary data store is in the EU (Ireland). Some processors (Anthropic, Slack, Cloudflare, Fly.io) may process your data in the United States or other regions. We rely on the Standard Contractual Clauses approved by the European Commission for transfers outside the EEA.

Changes to this policy

We may update this policy from time to time. Material changes will be announced in the app and via email. The "Last updated" date at the top is authoritative.

Contact

Client Pulse — buying signals for your target accounts. Privacy · Terms · Open app ↗