Privacy Policy
Last updated October 9, 2026
This policy covers the people who visit pult.sh and use the Pult console. Pult is operated by Lantharos, which is the controller of the personal information described here. You can reach us at privacy@pult.sh.
The data that organizations' apps send to Pult works differently. It might be about an organization's own customers, such as a support request or a report about a user. For that data, the organization decides what is collected and why, and we process it on their behalf under the Data Processing Agreement. If you're one of their customers, the organization's own privacy policy applies, and they're the right people to ask.
What we collect
Account information. Your name and email address. Pult has no passwords: sign-in codes are stored only as hashes and expire after 10 minutes, and passkeys are stored as public keys.
Organizations and roles. The organizations you belong to, the roles you hold in each project, and the invitations you send or receive.
Activity. What you do in the console is recorded so your team can see who did what. This includes notes, replies, state changes, actions you run, flag changes and values you reveal. It appears in item timelines and in the audit log, with your name. We also record which months you used the console, because that's how monthly plans are billed.
Sessions. The IP address and browser for each sign-in, so you can stay signed in safely and so we can spot abuse.
Billing. If your organization buys a plan, Polar Software, Inc. ("Polar") processes the payment as our merchant of record. Polar collects your payment and billing details under its own privacy policy. We receive the plan, the subscription status, the number of seats and the email address used, never your card details.
Messages. What you send to our support, and records of the emails Pult sends you.
Service logs. Records of requests and errors that keep Pult running and help us fix problems.
We don't use analytics, advertising trackers or tracking pixels, and we don't sell personal information.
How we use it
- To run Pult: sign you in, show your team's work, deliver your notifications and carry out what you do in the console.
- To keep Pult secure: prevent abuse, limit automated traffic and investigate problems.
- To bill organizations: count the people who used the console each month, and keep plans and limits in sync with Polar.
- To contact you: notifications your team has set up, security alerts, billing notices and changes to our terms.
- To meet legal obligations.
Under the GDPR, we rely on our contract with you, our legitimate interest in keeping Pult secure and reliable, and our legal obligations.
Who else sees it
People in your organizations can see your name, your email address, your role and your activity in their projects.
We use these providers to run Pult:
- Cloudflare, Inc. hosts Pult, its databases and files, and delivers its email.
- Polar Software, Inc. handles subscriptions and payments.
Both process data under data processing agreements, or as an independent controller in Polar's case for the payment itself. Data may be processed outside your country, including in the United States. Where that requires protection, transfers are covered by the European Commission's Standard Contractual Clauses.
We share personal information with authorities only when the law requires it. Where we're allowed to, we tell the people affected.
Cookies and storage
pult.sh doesn't set cookies. The console uses one cookie that keeps you signed in. It also keeps your appearance settings (theme, list density, sidebar and pane sizes) in your browser's local storage, which never leaves your device.
How long we keep it
- Your account is kept until you delete it from your account settings. Your personal information goes with it straight away, along with organizations where you were the only member.
- Notes and actions stay in your organizations' timelines under your name, so the history stays readable. They're removed when the organization deletes them or when they pass its plan's history period.
- Sessions expire after a week without use.
- Service logs and backups are kept for up to 30 days.
- Billing records are kept for as long as tax law requires.
Your rights
You can change your name and delete your account in your account settings. You can also ask us for a copy of your personal information, ask us to correct it, or object to how we use it. Write to privacy@pult.sh and we'll answer within 30 days. You can also complain to your local data protection authority.
Children
Pult isn't meant for children under 16. If you think a child has created an account, write to privacy@pult.sh and we'll remove it.
Changes
If we make a material change to this policy, we'll tell you by email before it takes effect.