Privacy Policy
Last updated: 29 May 2026
Client Pulse (the "Service") is operated by Matrix One. This Privacy Policy explains what personal information we collect when you use the Service, how we use it, and the choices you have. By using the Service you agree to the terms below.
If you have questions about anything here, email ragool@matrixreq.com.
What we collect
We collect the minimum data needed to operate the Service.
Account data
When you sign in we receive, from Supabase Auth:
- Your email address
- A unique user ID generated by Supabase
- The Google profile (name, picture, locale) if you sign in via Google OAuth
- A session token used to keep you signed in
Your organisation is derived from the domain part of your email (e.g. matrixreq.com). Users with the same email domain share access to the same organisation's data. We refuse personal-email accounts (Gmail, Yahoo, Outlook, etc.) for organisational data isolation.
Data you upload or generate
- Companies you import (name, LinkedIn URL, industry, country, owner name, notes, etc.)
- Signal-type definitions and descriptions you write
- Custom feed URLs you add
- Slack workspace metadata (team name, channel names, user names visible to the bot)
- Microsoft Teams webhook URLs you connect
Data the Service collects on your behalf
When you run a sync we fetch publicly available content about your target companies from:
- LinkedIn (via the linkdapi API)
- Google News RSS
- The companies' own websites (RSS / Atom feeds)
- openFDA (510(k) clearances)
- Crunchbase (funding rounds, when you supply a Crunchbase API key)
- URLs you add as custom feeds
Fetched content is classified by Anthropic Claude (Haiku 4.5) and stored as "signals" linked to the companies on your tracked list.
Operational logs
We log:
- Per-API-call usage (provider, endpoint, units consumed, cost) for billing visibility — no payload content is stored in these rows
- Slack delivery records (which signal was posted, to which channel or user, when, by whom) — used to show "Sent" badges and prevent duplicate sends
- Errors and stack traces for debugging — never include passwords or secrets
We do not use cookies for advertising. We do not run third-party analytics scripts.
Where the data lives
- Database: Supabase Postgres, region
eu-west-1(Ireland). Encrypted at rest by Supabase. - Backend: Fly.io machine in region
lhr(London). Code is the open-source contents of the repo this site is built from. - Frontend: Cloudflare Pages CDN.
- Auth: Supabase Auth + Google OAuth (Google sign-in flows through Google's servers).
Third-party services we send data to
We use the following processors. Each has its own privacy practices.
| Service | What we send | Why |
|---|---|---|
| Supabase | Account data + all app data | Database + auth |
| Anthropic | Fetched article text, company descriptions, your signal-type descriptions, chat questions | Claude classification + chat |
| LinkdAPI | Company LinkedIn slugs | Fetching LinkedIn posts |
| Slack | Signal content you choose to send + bot token | Message delivery |
| Cloudflare | HTTP request metadata | CDN / Pages hosting |
| Fly.io | HTTP request metadata, runtime logs | Backend hosting |
| OAuth profile when signing in via Google | Single sign-on |
We do not sell or rent your data to anyone. We do not share it with advertisers.
How long we keep it
- Account + organisation data: as long as your account is active.
- Signals + companies: until you delete them or close your account.
- Slack OAuth tokens: until you disconnect via Settings → Slack, or remove our app from your Slack workspace.
- API usage logs: rolling 13 months for cost reporting.
- Backend logs: rolling 30 days, then automatically discarded.
When you delete a company, its signals are also deleted. When you close your account, your row in users plus everything keyed by your email is removed within 30 days. Email ragool@matrixreq.com to request closure.
Your rights
Under the GDPR (and equivalent laws in many other jurisdictions) you can:
- Access the data we hold about you — request via email.
- Correct inaccurate data — edit it in the app, or email us.
- Delete your account and all associated data — email us.
- Export your data in a machine-readable format — email us.
- Object to or restrict specific processing — email us.
- Lodge a complaint with a supervisory authority (e.g. the CNIL in France).
We respond to requests within 30 days.
Children
The Service is intended for sales professionals at organisations. It is not directed at children under 16. We do not knowingly collect personal data from anyone under 16.
Security
- All traffic is HTTPS (TLS 1.2+)
- Auth tokens are short-lived JWTs signed by Supabase
- Slack OAuth
stateis signed with a server-side secret to prevent CSRF - The Supabase service-role key is held only on the backend; the frontend uses the anon key
- Backend runs as a non-root user inside a minimal Debian container
- Secrets (Anthropic / LinkdAPI / Supabase / Slack credentials) live in Fly's encrypted secrets store
No system is perfectly secure. If you believe you've found a vulnerability, please email ragool@matrixreq.com before public disclosure so we can fix it.
International transfers
The primary data store is in the EU (Ireland). Some processors (Anthropic, Slack, Cloudflare, Fly.io) may process your data in the United States or other regions. We rely on the Standard Contractual Clauses approved by the European Commission for transfers outside the EEA.
Changes to this policy
We may update this policy from time to time. Material changes will be announced in the app and via email. The "Last updated" date at the top is authoritative.
Contact
- Email: ragool@matrixreq.com
- Operator: Matrix One