1. Scope
This policy applies to Pudding for desktop and the public website and OAuth exchange service hosted at https://teatak.com. Pudding does not require a website account.
2. Information Pudding handles
Information on your device
Pudding stores app settings, conversations, project references, and connection credentials in its local application data on your computer. You decide which projects and services to connect.
Google account information
If you choose to connect Gmail, Pudding requests your basic Google profile (name, email address, and profile information) and the gmail.readonly permission. This permits Pudding to search and read Gmail messages. It does not permit Pudding to send, modify, or delete email.
Service metadata
Our hosting and security providers may process standard request metadata such as IP address, timestamp, user agent, and requested URL to deliver and protect the service. We do not use advertising cookies or third-party analytics on this website.
3. How information is used
Google user data is used only to provide user-requested Gmail features, such as finding, reading, organizing, or summarizing messages inside Pudding. Basic profile information identifies the account you connected.
Pudding does not sell Google user data, use it for advertising, or use Gmail content to train a general-purpose AI model. Pudding's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
4. OAuth and credential handling
During a GitHub connection, GitHub returns an authorization code to teatak.com. The service exchanges that code for tokens and keeps the result only during a short device-handoff window. Pudding receives a single-use ticket, redeems it over HTTPS, and the handoff record is then deleted. The legacy Gmail flow sends an authorization code to oauth.x-t.top solely to exchange it for tokens.
Connection credentials are stored locally by Pudding on your device. Treat access to your operating-system account as sensitive and keep your device secured.
6. Retention and deletion
GitHub OAuth handoff records expire within minutes and are deleted immediately after successful redemption. The legacy exchange service does not retain Google tokens or Gmail content. Locally stored credentials remain until you remove the connection, delete Pudding's local data, or revoke access from the connected service.
See the data deletion guide for step-by-step options.
7. Security
We use HTTPS for network requests, fixed allowlisted application return schemes, random state values, client-bound challenges, short-lived single-use tickets, and no persistent server-side token database. No security measure is perfect; please report suspected issues to yangglive@gmail.com.
8. Your choices
Connecting Gmail is optional. You can decline a requested permission, remove the Gmail connection in Pudding, revoke access in Google, or stop using the feature at any time.
9. Children
Pudding is not directed to children under 13, and we do not knowingly collect personal information from children through this website.
10. Changes and contact
We may update this policy as the product changes. The date at the top identifies the latest revision. Questions or privacy requests can be sent to yangglive@gmail.com.