Legal

Privacy Policy

What we collect, why, and what you can do about it.

Effective 14 August 2026. Operated by Socialocca LLC, Pennsylvania, United States.

Plain-English note. This document is written to be readable, and it is not legal advice. It describes how Socialocca LLC actually operates Pudding today. If anything here is unclear or looks wrong, tell us at hello@pudding.social and we will fix it.

1. Who we are

Pudding is operated by Socialocca LLC, Pennsylvania, United States. For data protection purposes Socialocca is the controller of the personal data described here. Contact us any time at hello@pudding.social.

2. The short version

  • Fingerprints are computed in your browser. Your files do not leave your device unless you tick the box asking us to keep a copy.
  • Your profile, verified channels and Proof Records are public on purpose. That is the product.
  • We do not sell your data, and we never have.
  • Analytics only runs if you say yes. Decline and the script is never loaded.
  • You can delete your account yourself. Your identity goes; your Proof Records stay public but anonymous, so anyone who relied on one can still check it. Ask us and we will erase those too.

3. What we collect

Account information

Your email address, username, display name, bio, and any avatar or cover image you upload. If you sign in with Google, we receive your email address and basic profile details from them, not your password.

Verified channels

The handles, domains and email addresses you verify, the method used, and when it was verified. When you verify by signing in to a platform, we use the access token once to read which account it is and then discard it. We never post on your behalf and we do not read your content.

Proof Records

The SHA-256 fingerprint, the source URL or file name, any title and note you add, the timestamp, and the verified channel it came from. The fingerprint is computed in your browser before anything is sent.

Files, only if you ask

Registration keeps no copy of your file by default. There is an unticked box offering to store one privately so you can re-verify later without hunting for the original. If you tick it, we hold that file in private storage that only you can read.

Payment information

Paid plans are processed by Stripe. We receive a customer identifier, the plan, and its status. We never receive or store your card number.

Technical data

Our hosting provider processes standard request data such as IP address and user agent to serve pages and protect against abuse. We also keep error reports when something breaks.

4. What is public by design

Your profile page, your username and display name, your bio, your avatar and cover image, your verified channel handles, and every Proof Record you register are public. Search engines can index them. Do not register anything you need to keep private.

Your email address is not published unless you verify it as a channel yourself, which deliberately puts it on your profile. Files you asked us to keep are private and are never published.

5. Why we process it

Where the UK and EU GDPR apply, our legal bases are:

  • Performance of a contract. Running your account, verifying channels, creating and displaying Proof Records, and taking payment.
  • Legitimate interests. Keeping the Service secure, preventing abuse and fraud, and fixing faults. We have weighed these against your rights and kept the processing to what the job needs.
  • Consent. Analytics cookies. You can give or withdraw this at any time, and withdrawing is as easy as giving it.
  • Legal obligation. Keeping tax and accounting records, and responding to lawful requests.

6. Cookies and analytics

We use a small number of cookies and similar storage. They fall into two groups.

Strictly necessary

Your sign-in session, and local storage remembering that you dismissed a notice or answered the analytics question. The Service cannot work without these, so they are not optional and they do not track you across other sites.

Analytics, only with consent

We use Google Analytics to understand which pages people find useful. It sets its own cookies and processes a truncated IP address. It runs only if you accept when asked. If you decline, the Google Analytics script is never requested and no analytics cookie is ever created. Declining costs you nothing: every feature works the same.

To change your mind later, clear this site's data in your browser and the question will be asked again on your next visit.

7. Who else handles your data

We keep this list short on purpose. Each of these processes data on our instructions under a data processing agreement.

  • Lovable Cloud (Supabase). Database, authentication and file storage.
  • Cloudflare. Hosting, content delivery and protection against attacks.
  • Stripe. Payment processing for paid plans.
  • Google Analytics. Usage analytics, only if you consented.
  • Our email provider. Sending verification, account and notification emails.
  • OpenTimestamps calendars and the Bitcoin network. Anchoring. Only a combined cryptographic value is published, never your content or your identity.

We do not sell personal data, and we do not share it with advertisers. We may disclose data if legally required, and where we are permitted to tell you, we will.

8. International transfers

We operate from the United States, and our providers may process data in the United States and elsewhere. Where data moves out of the UK or EEA, our providers rely on recognised safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision.

9. How long we keep it

  • Account data and verified channels: while your account exists.
  • Proof Records: indefinitely. They stay public after you delete your account, stripped of everything that identifies you. See section 10.
  • Files you asked us to keep: until you delete the record or your account.
  • Payment records: as long as tax and accounting law requires, typically seven years.
  • Error and security logs: a short period, normally under 90 days.
One thing we cannot delete. Anchoring publishes a single combined value for a batch of records to the Bitcoin blockchain. Nobody can withdraw it, including us. It is a hash derived from other hashes: it does not contain your content, your name or anything identifying you, and it cannot be reversed to reveal them. We would rather state this plainly than imply an erasure we cannot deliver.

10. Deleting your account

Go to settings and use "Delete my account". You will be asked to type your username to confirm. It removes your profile, your verified channels, any files we held for you, and every link between you and what you registered. It cancels an active subscription. It is immediate and cannot be undone.

Proof Records are anonymized, not deleted. The title, note, source link, handle and the connection to your account are all removed. What remains is the fingerprint, the timestamp and the proof of anchoring, which is what lets someone who was pointed at a record still check it.

A bare fingerprint is a one-way hash. It cannot be reversed and it identifies nobody. Keeping it also means a record cannot be made to vanish once it becomes inconvenient, which is part of what makes the public record worth anything.

If you want the anonymized remainder erased as well, email hello@pudding.social and we will do it within 30 days. The same address works if you would rather we handled the whole deletion for you.

The blockchain anchor described above survives either way, for the reason given there.

11. Your rights

Depending on where you live, you have some or all of these rights. Exercise any of them by emailing hello@pudding.social. We respond within 30 days and we do not charge for it.

  • Access. Get a copy of the personal data we hold about you.
  • Rectification. Correct anything inaccurate. Most of it you can edit yourself in settings.
  • Erasure. Delete your data, which you can do yourself at any time. Deletion anonymizes your Proof Records rather than removing them; email us and we will erase those too.
  • Restriction. Ask us to pause processing while a dispute is resolved.
  • Portability. Receive your data in a machine-readable format.
  • Objection. Object to processing based on legitimate interests.
  • Withdraw consent. Turn off analytics at any time, without affecting anything done before.

If you are in the UK or EEA and think we have got something wrong, you have the right to lodge a complaint with your national data protection authority, known in the legislation as a supervisory authority. We would appreciate the chance to fix it first.

12. California rights

Under the CCPA and CPRA, California residents may request the categories and specific pieces of personal information we have collected, the purposes, and the categories of third parties it was disclosed to; may request deletion; and may request correction.

We do not sell or share personal information as those terms are defined by California law, and we have not done so in the preceding twelve months. We do not process personal information for cross-context behavioural advertising.

We will not discriminate against you for exercising these rights. An authorized agent may act for you with written permission.

13. Security

Traffic is encrypted in transit. Database access is protected by row-level security so users can only reach their own private records, and private files are scoped to their owner. Payment details never touch our servers. Access to production data is limited to those who need it.

No service is perfectly secure. If a breach affects your personal data and creates a real risk to you, we will notify you and the relevant regulator within the time the law requires.

14. Children

Pudding is not for children under 13, and we do not knowingly collect their personal data. If you believe a child under 13 has given us data, email hello@pudding.social and we will delete the account.

15. Changes

We will update this policy when our practices change. If a change is material we will give notice through the Service or by email before it takes effect, and where the change relies on consent we will ask again rather than assume the old answer still applies.

16. Contact

Socialocca LLC, Pennsylvania, United States. Privacy questions and data requests go to hello@pudding.social.