Team Pulse is a lightweight reflection tool for teams. This page explains what personal data is processed, why it is processed, and what rights you have.
Team Pulse is pseudonymous, not fully anonymous.
We know that you answered. We do not store what you answered together with who you are.
Who provides Team Pulse?
Team Pulse is provided by Snowdrop AB.
- Company: Snowdrop AB
- Company registration number: 559450-1867
- Visiting address: Vegagatan 14, 113 29 Stockholm, Sweden
- Postal address: Smultronvägen 9, 178 38 Ekerö, Sweden
- Support: support@snowdrop.se
- Privacy questions and rights requests: privacy@snowdrop.se
Snowdrop is controller for account management, direct service operations, security, support, legal pages, and core product decisions controlled by Snowdrop.
If Team Pulse is used by your employer, customer organization, or another organization, that organization is normally controller for the decision to use Team Pulse in the team or workplace, who is invited, which legal basis applies, and what information is provided to employees.
When Snowdrop processes team content and reflection data on behalf of a customer organization, Snowdrop is normally processor for that processing.
What personal data is processed?
Team Pulse processes the data needed for the service to work:
- account and sign-in data, such as email address, Supabase Auth user id, sessions, and password credentials handled by Supabase Auth
- profile data, such as first name, last name, display name, and preferred language
- team data, such as team name, description, membership, role, status, reflection cadence, and settings
- invitations, such as email address, team, status, token, and expiry time
- reflection periods, such as start, end, status, and cadence
- reflection answers, such as numeric score, written impact answer, and written improvement answer
- participation records showing that a specific user answered for a specific period
- team insights, such as aggregate values, trends, response count, and written follow-up answers shown without names when the team's minimum response threshold is met
- AI insights, such as team-level summaries, model/prompt version, generation time, and technical fingerprints used to avoid unnecessary regeneration
- email and reminder data, such as recipient, template, delivery status, links, and technical delivery information
- technical information, logs, diagnostics, and error information needed for operations, security, and debugging
- necessary cookies and local storage for sign-in, language, and interface state
- demo and test-related data if the production environment includes the Research Lab demo, see "Demo data" below
How does reflection answer privacy work?
Reflection answers are saved without your identity on the answer itself.
Team Pulse stores two things separately:
- what the team answered
- that a specific user has answered
This lets the system prevent duplicate answers, show participation counts, and send reminders without storing who wrote which answer.
Team Admins and team members should not be able to see who answered, who has not answered, or who wrote a specific answer.
This is not the same as full anonymity. The system still needs to know who belongs to a team, who may answer, and who has already answered.
A team can also invite people as Observers. An Observer is a read-only team viewer who does not take part in reflections. Observers can see aggregate team results, stored AI insights when the team uses them, the team roster with names, email addresses and roles, and pending invitations with email address, intended role, status and expiry. Observers cannot see original reflection answers, who answered, or who has not answered. When a team has at least one active Observer, everyone in the team is told so in the app.
Why is data processed?
We process personal data to:
- create and manage accounts
- sign users in with magic links and, when chosen by the user, passwords
- create and manage teams, memberships, and roles
- invite team members
- manage recurring reflection periods and reflection cadence
- receive reflection answers
- prevent duplicate answers
- show team development, trends, and insights when enough responses exist
- create team-level AI insights when the feature is used and the threshold is met
- transcribe audio into editable text when the user chooses speech-to-text
- send necessary sign-in emails, password emails, invitations, and reflection reminders
- protect the service against errors, misuse, and unauthorized access
- debug, provide support, and handle rights requests
- meet legal and contractual obligations
Team Pulse is for team reflection. It is not a tool for individual performance evaluation, employee surveillance, or automated decisions about people.
Legal basis
The legal basis depends on how Team Pulse is used and which agreement applies.
In normal direct use, processing may be necessary to provide the service, perform agreements, protect the service, and support the team's legitimate need for reflection and improvement.
If your employer or organization uses Team Pulse, that organization is responsible for having a legal basis for inviting you and using the tool in its operations.
The first-version lawful basis is:
| Purpose | Lawful basis |
|---|---|
| Account, sign-in, and direct service operation | Contract or legitimate interest |
| Security, diagnostics, and abuse prevention | Legitimate interest |
| Transactional emails and necessary service messages | Contract or legitimate interest |
| Team membership, invitations, and reflection flows in an organization | The customer organization using Team Pulse is responsible for its lawful basis |
| Team-level insights and AI insights | Legitimate interest for team-level conversation support, not individual decisions |
| Speech-to-text | Only when you choose to use the feature |
| Support and rights requests | Contract, legitimate interest, and legal obligation where applicable |
Sensitive data and names in free text
Do not write sensitive personal data in free-text answers.
For example, avoid information about:
- health
- union membership
- political opinions
- religion
- sexual orientation
- ethnic origin
- personnel cases
- conflicts where individual people can be identified
Also avoid names and details that make a person identifiable.
Write about patterns and situations, not individual people.
When are team insights shown?
Team insights are shown only when the team's configured minimum number of responses exists for the period.
Teams can choose a low value, such as 1-4 responses. This can be useful for personal tracking, pairs, or very small teams, but it is a low-privacy setting. In small teams, people may be able to infer individual responses from context.
Do not use Team Pulse as if low thresholds create anonymity. Team Pulse should be described as pseudonymous, not anonymous.
AI insights
Team Pulse may create AI insights for Team Overview.
AI insights are team-level summaries and conversation support. They are not decisions, scores, diagnoses, HR advice, or performance evaluations.
AI insights must not be used to:
- score individual people
- try to identify who answered
- analyze the emotions of individual people
- create manager-only monitoring
- replace the team's own discussion
- make automated decisions about people
When AI insights are generated, Team Pulse may send written reflection answers and limited period information to an external AI provider through Lovable AI Gateway or the equivalent production configuration.
The data sent is intended to be identity-free:
- written answers for the current period
- written answers from up to four recent periods that meet the team's minimum response threshold
- response count, average score, language, reflection cadence, and period label
The data that should not be sent to the AI provider:
- names
- email addresses
- user ids
- profile ids
- membership ids
- participation record ids
- answer ids
- submission time
- order showing who answered when
- mapping between answer and person
AI insights may be stored so that the same dashboard does not need to be regenerated on every page load.
The AI model openai/gpt-5.5 is served by OpenAI.
Team Pulse uses Lovable AI Gateway for AI insights. Lovable's DPA states that customer personal data is not used to train, retrain, fine-tune, or develop AI or machine-learning models. Lovable's security page also states that customer prompts, code, and workspace data are not used to train Lovable models and that third-party AI provider contracts restrict training and retention.
OpenAI is listed as a Lovable subprocessor. If Team Pulse traffic is routed through Lovable AI Gateway, no separate Snowdrop-OpenAI DPA is required for that traffic.
AI insights are kept for up to 18 months and not longer than the underlying reflection answers.
Speech-to-text and transcription
Speech-to-text is optional.
If you use the microphone feature, the browser records audio while you dictate. Team Pulse does not store the audio as its own audio file.
The audio may be sent to an external speech-to-text provider through Lovable AI Gateway or the equivalent production configuration to create text. The text is returned to the form.
You can read and edit the text before submitting the reflection.
Only the written reflection answer that you submit is stored in Team Pulse. If you cancel or edit the text, the removed audio is not stored as a Team Pulse answer.
Team Pulse uses Lovable AI Gateway for speech-to-text. The direct transcription path uses the OpenAI models openai/gpt-4o-mini-transcribe and openai/gpt-4o-transcribe. OpenAI is listed as a Lovable subprocessor. Lovable's DPA states that customer personal data is not used to train, retrain, fine-tune, or develop AI or machine-learning models.
Team Pulse does not store speech-to-text audio as its own audio file. Provider-side transient processing, logging, and retention depend on the production configuration and provider terms.
Email and reminders
Team Pulse may send service and transactional emails, such as:
- magic sign-in links
- set or reset password links
- team invitations
- reflection reminders
- necessary operational or security messages
Emails are not used for marketing in the current version.
Reflection reminders may use system information about who has already answered for a period. That information is used to choose recipients, but it should not be shown to Team Admins or team members.
Manual reminders may be sent by Team Admins. Scheduled reminders may run automatically if enabled in the environment. Answers and participation records remain separated.
Team Pulse may process email logs, delivery status, suppression lists, and unsubscribe records to send, debug, and respect delivery settings.
Lovable Email is used for transactional emails. The downstream email provider is Mailgun. Mailgun is listed as a Lovable subprocessor for transactional email and email domain management. Email logs and suppression records are partly stored in Team Pulse's own Lovable Cloud database in the Europe region.
Sign-in emails, password emails, invitations, security messages, and necessary operational messages are service messages. They are not used for marketing.
Reflection reminders are service reminders connected to team participation. You can turn off reflection reminder emails for a specific team from that team's page in the app. This setting affects reflection reminders only. It does not affect magic sign-in links, invitation emails, security or authentication emails, or other service-critical messages. Team Admins can also disable scheduled reminders for the whole team. You can still contact support@snowdrop.se or privacy@snowdrop.se for help where practical.
Opting out of reminders does not remove your team membership and does not prevent reflection submission. Team Admins must not be able to see who asked not to receive reminders.
Transactional email logs are normally kept for 90 days. Email queue payloads are normally kept for 14 days and DLQ or failed email payloads for 30 days. Unsubscribe and suppression records are kept as long as needed to respect delivery preferences or legal and safety obligations.
Cookies and local storage
Team Pulse uses necessary cookies and local storage for the service to work.
Examples:
- sign-in session in the browser
- selected language
- interface preferences, such as sidebar state
Team Pulse does not use analytics or marketing cookies in the current version.
If analytics, marketing, or other non-essential cookies are added later, they should be described here and, where required, used only after consent.
Providers and processors
Team Pulse uses external providers to provide the service.
Examples of providers that may process data:
- Supabase for authentication, database, and access control
- Lovable for application hosting, email, AI Gateway, speech-to-text flows, and error reporting
- Mailgun for transactional emails
- OpenAI for AI insights using the
openai/gpt-5.5model - OpenAI transcription models for speech-to-text through Lovable AI Gateway
- GitHub for source code and development work
Lovable publishes a Data Processing Agreement, Privacy Policy, subprocessor page, and Trust Center. Lovable's DPA states that Lovable is processor for EU customer personal data and that Lovable may process service data, log data, and aggregated or de-identified data as an independent controller for purposes such as analytics, security, billing, and product development. Lovable states that the Trust Center is the authoritative subprocessor list, that the list is updated at least annually, and that customers may object to new subprocessors within 20 business days by contacting privacy@lovable.dev.
International transfers
Personal data may be processed in countries outside Sweden or the EU/EEA depending on chosen providers and production configuration.
If data is transferred outside the EU/EEA, Team Pulse should use appropriate safeguards, such as EU Standard Contractual Clauses or other valid transfer mechanisms. Lovable's DPA identifies EU Standard Contractual Clauses as the safeguard for transfers of EU personal data outside the EU/EEA, with UK SCCs or the UK Addendum where relevant.
Backend region: EU Central (Frankfurt) — eu-central-1 (AWS).
The Lovable Cloud database is configured in the Europe region. Lovable's Trust Center lists several relevant subprocessors with region US, including Mailgun, OpenAI, OpenRouter, Grafana, PostHog, and Rudderstack.
How long is data kept?
We keep personal data for as long as needed to provide Team Pulse, meet contractual and legal obligations, handle support, protect the service, and respect user rights.
First-version retention periods:
| Category | Retention |
|---|---|
| Profiles and account data | While the account is active, then deletion or anonymisation within 30 days after verified deletion request unless needed for legal/security reasons |
| Teams and memberships | While the team exists; archived teams are reviewed after 24 months; deleted teams are removed or anonymised within 30 days where technically feasible, subject to backup expiry |
| Invitations | 90 days after expiry, revocation, or acceptance |
| Reflection answers, including free text | 18 months |
| Participation records | 18 months |
| Aggregated period stats and team trends | 36 months or until team deletion |
| AI insights | 18 months and not longer than the underlying reflection answers |
| Speech-to-text audio | Not stored by Team Pulse; provider-side transient processing depends on configuration and terms |
| Transactional email logs | 90 days |
| Email queue payloads | 14 days |
| DLQ and failed email payloads | 30 days |
| Diagnostic and application logs | 30 days; up to 90 days for security investigations |
| Unsubscribe and suppression records | As long as needed to respect delivery preferences or legal and safety obligations |
| Notification and reminder preferences | Until changed by the user, team deletion, account deletion or anonymisation, or no longer needed to provide the service. Used only to decide whether to send reflection reminder emails for that team. Not visible to Team Admins or other members. |
| Backups | Subject to platform backup handling; Lovable Cloud documentation currently indicates daily database backups with approximately 14 days retention |
Team Pulse's long-term product value should come from aggregate trends, not permanent storage of raw free-text answers.
Demo data
Research Lab demo data is synthetic Snowdrop-controlled demo content. It is not customer data and must be kept separate from real team and customer data at all times.
If demo data temporarily exists in production, it must be Snowdrop-controlled, synthetic, clearly not customer data, isolated from customer teams, free from sensitive data, and use .invalid email addresses except for any Snowdrop-controlled demo inbox.
Scheduled reminders must be disabled for demo data unless they are explicitly being tested.
Your rights
You may have the right to:
- receive information about how your personal data is processed
- receive a copy of your personal data
- correct inaccurate data
- delete data where possible
- restrict certain processing
- object to certain processing
- receive data in a portable format where applicable
- withdraw consent where processing is based on consent
Contact us at privacy@snowdrop.se.
Because reflection answers are stored separately from identity, Team Pulse normally cannot identify which specific reflection answers were written by a specific person. This protects team privacy, but it also affects how export and deletion can be handled.
Snowdrop handles rights requests manually in the first version. We verify your identity before disclosure, export, correction, deletion, or restriction. We normally respond within one month. For workplace or customer-controlled use, Snowdrop may need to coordinate the request with the customer organization.
Export may include account data, profile data, email address, team memberships and roles, invitations involving you, participation records showing which periods you answered, transactional email records where available, and team-level insights you are allowed to see.
Export normally does not include specific reflection answers as "your answers", because Team Pulse intentionally does not store reflection answers together with identity.
Deletion or anonymisation may include profile and account data where possible, active memberships where appropriate, pending invitations involving you, email logs where reasonable, and participation records where feasible.
Pseudonymous reflection answers and team-level history may remain where they are no longer linkable to you, unless the whole team or customer requests deletion.
Complaints to a supervisory authority
You have the right to complain to the Swedish Authority for Privacy Protection or another competent supervisory authority.
Swedish Authority for Privacy Protection: https://www.imy.se/
Changes
We may update this privacy policy as Team Pulse develops or as legal, technical, or operational conditions change.
For major changes, we will update the date and inform users in a reasonable way.