LAST UPDATED JULY 18, 2026
Privacy, in plain language.
This policy describes the data handled by Pudding's web and mobile shopping assistant, including account, memory, purchase, notification, and diagnostic data.
Data Pudding collects
- Account data such as name, email address, authentication provider, and session/security metadata.
- Shopping content such as briefs, constraints, conversations, product interactions, carts, collaboration activity, feedback, and memories you ask Pudding to save.
- Purchase and payment-reference data such as cart snapshots, explicit purchase authorizations, merchant order status, Stripe customer/payment-method references, card brand, and last four digits. Pudding servers do not receive full card numbers or security codes.
- Notification data such as preferences, Expo push token, device platform, delivery status, and price/restock watch configuration.
- Operational data such as IP address, user agent, request IDs, app errors, performance measurements, model/tool telemetry, and feature events used for security, reliability, and product improvement.
How the data is used
Pudding uses this data to authenticate you; maintain your shopping workspace; personalize recommendations you request; source, compare, and explain products; support collaboration; prepare authorized checkout; deliver alerts; prevent abuse; diagnose failures; and measure aggregate product quality and cost.
Service providers and sharing
Data is shared only as needed with infrastructure and database providers, authentication providers you choose, AI model providers used to process your shopping request, product and merchant-data providers, Stripe for payment vaulting, Expo for opted-in push notifications, transactional email providers, and observability or uptime providers. Merchant checkout receives the information needed for the transaction you explicitly authorize. Pudding may also disclose data when legally required or to protect users and the service.
Pudding does not sell personal data. It does not use shopping memories or purchase history for third-party behavioral advertising. Eligible merchant links may carry an affiliate identifier so a qualifying purchase can be attributed to Pudding.
Memory and sensitive information
Saved memories are visible in Settings and can be edited or permanently deleted, including their stored embedding. Pudding does not create cross-shopping memories about sensitive categories unless you explicitly ask it to remember that information. Avoid entering information that is not needed for shopping.
Retention and deletion
Account data is retained while the account is active and only as long as needed for the purposes above. You can permanently delete the account in web or mobile Settings. Deletion removes account records, sessions, owned shopping workspaces, conversations, memories and embeddings, carts, purchase records, alerts, invitation addresses, and saved payment references; live Stripe customers are deleted first. Security audit events that must remain for system integrity are de-identified. Encrypted backup copies age out under Pudding's backup retention schedule and are not restored for normal product use.
Visit Privacy choices or go directly to Delete account.
Security and international processing
Pudding uses encrypted network transport, secure session cookies or device secure storage, least-privilege service credentials, strict tool boundaries, and access controls. Providers may process data in the United States or other locations where they operate. No online service can guarantee absolute security.
Children
Pudding is not directed to children under 13, and we do not knowingly collect personal data from children under 13.
Contact and changes
Material policy changes will be posted here with a revised date. For a privacy request, use the privacy choices page.