CTR Pulse Privacy and Cookie Notice
Last updated: 8 September 2026.
Who is responsible
CTR Pulse is operated by AB Testing Ltd, EIK 206916137, 12 Nikolay Liliev Street, Floor 1, Office 2, Lozenets District, Sofia 1421, Bulgaria. We are the controller of personal data processed to operate CTR Pulse.
For privacy questions or requests, contact privacy@ctrpulse.com or write to the address above.
Information we use
Accounts. We use your email address, authentication records and account identifier to provide your account and send essential account messages. Supabase handles password authentication and stores password hashes. Please do not send your password to us. The legal basis for providing requested account services is performance of our contract with you.
Google sign-in. If you choose Google sign-in, Google provides your account identifier, email address and basic profile information, such as your name and profile image, to Supabase to authenticate you and maintain your CTR Pulse account. We use this information for your requested sign-in and account services, under the same account retention and deletion rules described below. Google also processes the sign-in under its own privacy policy.
Tests and voting. We process the titles, links, descriptions, thumbnail images, favourites and ratings you submit. Test pages, images and results are public: do not upload confidential information or personal information you do not have the right to share. We use this content to provide the testing service you request.
Network identifiers and security. Our application derives a salted hash from your IP address to associate votes with a network connection, reduce duplicate voting and support management of tests created without an account. This is a pseudonymous identifier, not anonymous data or a reliable identifier of one person. People sharing a network may share an identifier. Hosting and infrastructure providers also process connection information, including IP addresses, to deliver and protect the service. Our legal basis for security and abuse prevention is our legitimate interest in operating a reliable service.
Recovery. If you delete your account and choose to keep tests temporarily, we retain the tests and a hashed recovery credential for the recovery period. Your saved recovery code and a browser credential allow access to those tests. Anyone holding the code may manage or claim them, so keep it private. This processing provides the temporary retention you requested.
Content reports. We process the reported test, your reason and explanation, any contact details you provide, and a network-derived identifier used to limit duplicate reports and abuse. Reports and review decisions are restricted to administrators. We use them to address legal notices and protect users and the service. Contact privacy@ctrpulse.com to follow up or challenge a restriction.
Contact requests. We process your email address, message and information needed to answer you or verify a request. Privacy requests are handled to comply with our legal obligations; ordinary support is handled to provide the service or in our legitimate interest in responding to questions. Please send only information needed for your request.
Cookies and browser storage
We do not use advertising cookies or optional audience-tracking cookies in this release.
| Feature | Purpose | Duration and control |
|---|---|---|
| Standard login | Keeps you authenticated while using the site | Session cookies. Signing out clears the login. Some browsers restore sessions after reopening, so use Sign out on shared devices. |
| Keep me signed in for 30 days | Remembers your login across browser sessions when you choose it | Optional, unchecked by default. The maximum period is measured from your choice and is not restarted by routine refreshes. Sign out to clear it. |
| Temporary test recovery | Maintains access after you request recovery or choose temporary retention | Session credential, with access ending at the original test deadline. A saved recovery code lets you restore access during that period. |
You can remove cookies through your browser settings, but this may sign you out or remove access to retained tests from that browser. Save your recovery code first if you need to return before the deadline. Essential login and requested recovery storage support the service you ask for; the separate persistent-login choice controls optional persistence. We do not use an Accept all cookies banner for these features.
How long information remains
Account-owned tests remain until you delete them or choose an account-deletion option. Deleting a test removes its associated database records and stored thumbnails through our deletion process.
When deleting your account, you can choose to delete your tests too or keep them temporarily. With temporary retention, access expires 48 hours after account deletion. You may edit or delete the tests during that window. To keep them, create and confirm an account and claim them before the deadline; saving a recovery code alone does not extend the deadline or claim the tests.
Tests created without an account normally have a 48-hour access window. Expired tests are removed by a scheduled deletion process after access ends. Removal from underlying storage is not necessarily instantaneous, and directly linked images may remain accessible until removed. Provider logs, backups and third-party cached copies may have separate lifecycles. We do not promise that deleting a public test erases copies others have made.
Deleting your account does not automatically identify votes you made on other people's tests: voting uses a network-derived identifier rather than your account. Contact us if you need help with a wider data request. We may need additional information to locate relevant records without collecting unnecessary identifying data.
We keep support correspondence only as long as needed to resolve the matter and handle applicable legal obligations or claims. Infrastructure and email providers retain operational information under their service retention rules. Resend currently retains email and log data for 30 days on its standard plans. Any information retained for a legal obligation or dispute is restricted to that purpose.
Providers and international processing
We use Supabase for authentication, database and image storage, Vercel for hosting, and Resend for account email delivery. Google provides optional Google sign-in. Privacy email is forwarded through ImprovMX to our designated Gmail inbox. These providers receive the information needed for their role. We may also disclose information where legally required or necessary to establish or defend legal claims.
Our production Supabase project is hosted in London, United Kingdom. A separate test project is hosted in Ireland. The selected hosting or sending region does not mean all provider processing stays there: for example, Resend states that customer message content and delivery logs are stored in the United States. Providers may process information in other countries through their operations and subprocessors.
Where required, international transfers must be covered by an applicable adequacy decision or appropriate safeguards such as the European Commission's standard contractual clauses. Contact us for information about the safeguards applicable to your data.
Your rights
Depending on the circumstances, you can request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it for future processing without affecting prior lawfulness. We do not make decisions producing legal or similarly significant effects about you solely through automated processing.
We normally respond within one month. Where the law permits an extension for a complex or numerous request, we will explain the reason within that month. We may ask for proportionate information to verify the request. Some rights have legal exceptions.
You may complain to Bulgaria's Commission for Personal Data Protection or the supervisory authority where you live, work or believe an infringement occurred.
Age and changes
CTR Pulse is for people aged 16 and over. Contact us if you believe a child below that age has provided personal information. We will update this notice as the service changes and provide appropriate notice of material changes; an update is not itself a request for consent.