Pudding Back to Pudding

Privacy Policy

Last updated: 21 September 2026

Pudding is a study app. This page says what it knows about you, where that goes, and how you stay in control of it.

Who runs Pudding?

Pudding, in full "Pudding for Study", lives at pudding4study.app. It is made and run by one independent developer in Adelaide, South Australia: [[OWNER: legal name]], ABN [[OWNER: ABN if registered]]. On this page "we" and "us" mean that developer.

We aim to handle your information in line with the Australian Privacy Principles. Those are the rules in the Privacy Act 1988 about how personal information is collected, used, stored, corrected and shared. [[OWNER: confirm whether the Privacy Act small business exemption applies to you. This page is written as if it does not.]]

What do you collect about me?

  • Your account. If you make an account, we keep your email address. Your password is stored only as a salted PBKDF2 hash, so we cannot read it.
  • Your plan. Which plan you are on and your payment status.
  • Your study data. Cards, review history, drafts and settings. Before you sign in, this lives only in your browser's storage on your device. From 21 September 2026, once you sign in, it is stored on our server so it follows you between devices.
  • Product analytics. Private events such as which screen you opened, which button you pressed, the build number and a random visitor id. Never the contents of a card, draft, note or recording.
  • Feedback. Messages you choose to send us.

You can use Pudding without an account. In that case your study data stays in your browser.

Do you see my card details?

No. Payments are taken by Stripe, and Stripe holds the card details. Pudding never sees or stores card numbers. We only keep your plan and payment status, plus the payment and invoice records that tax law requires.

What happens to my lecture recordings?

Lecture audio recordings stay in your browser. They are not uploaded for storage.

[[OWNER: confirm and describe how audio is handled when live transcription is on. That covers the plan-based transcription that runs through Pudding's server and the browser's built-in speech engine, which may use the browser maker's servers.]]

What is sent to OpenAI?

Some features use a language model: answers, marking, generation, speech and transcription. When you use one, the text you give that feature is sent to OpenAI for processing. It goes through Pudding's own server, not straight from your browser. If you do not use these features, nothing is sent to OpenAI.

Why do you use my information?

To run your account, keep your study data in step across your devices, take payment, run the features you ask for, fix problems, improve the app and answer your messages.

We do not sell personal information. Pudding has no advertising trackers and no third-party ad cookies.

Who else handles my information?

Pudding relies on these providers to work:

  • Vercel hosts the site.
  • Cloudflare Workers and D1 run the server and the database.
  • Supabase provides an optional way to sign in.
  • Stripe takes payments.
  • OpenAI processes text for the model features.
  • Google Fonts supplies the font files your browser loads.

Analytics events go to Pudding's own analytics service, not to an outside analytics company.

These providers may process your information outside Australia.

Does Pudding use cookies or trackers?

Pudding uses your browser's storage to hold your study data and settings on your device, and a random visitor id for the private analytics described above. There are no advertising trackers and no third-party ad cookies.

How do I see, export, correct or delete my data?

  • Export. Go to Settings, Your data, and export everything as a file.
  • Reset. In the same place you can reset the profile held in your browser.
  • Delete. In Settings, Your data, you can delete your account and its server data. If you have an active Weekly plan, cancel it first. We keep payment and invoice records for as long as tax law requires.
  • Access or correction. To ask what we hold about you, or to have it corrected, you can email __SZ_SUPPORT_EMAIL__.

How long do you keep it?

Data in your browser stays until you reset it or clear your browser. Server data is removed when you delete your account, apart from the payment and invoice records that tax law requires us to keep.

[[OWNER: state how long you keep server data for inactive accounts, analytics events and feedback messages.]]

How old do I have to be?

Accounts are for people aged 16 and over. If you are under 16, please do not make an account. If you are 16 or 17, tell a parent or guardian that you are using Pudding, and ask them to read this page with you. The email list on the phone screen is separate and is only for people aged 18 and over.

What if I have a complaint?

Tell us first, so we can fix it. To do that, you can email __SZ_SUPPORT_EMAIL__. We will reply within [[OWNER: reply time, for example 30 days]].

If we do not resolve it, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Will this policy change?

It may, as Pudding changes. When it does, we will update the date at the top of this page.

How do I contact you?

For anything about privacy, you can email __SZ_SUPPORT_EMAIL__.