Privacy Policy

Last updated: 2026-05-05

This Privacy Policy explains how heaty-eaty ("we", "us", "the app") handles information about you when you use the mobile application. Read it together with our Terms of Service.

This is a provisional policy. It covers our current practices and is written to meet the baseline expectations of the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA / CPRA). It will be updated as the product grows.


1. Who is responsible for your data

Controller: heaty-eaty Contact: clair@puduhub.com

If you are in the EU/UK and need to exercise a data-subject right, or if you are in California and need to submit a CCPA request, please email the address above.


2. What information we collect

You provide to us directly:

Collected automatically:

We do not collect: precise GPS location, contacts, SMS, or advertising identifiers.


3. Why we use your data and the legal basis (GDPR Art. 6)

PurposeLegal basis
Operating your account and delivering the app's core functionality (saving recipes, running the voice pipeline, showing your library)Performance of a contract — Art. 6(1)(b)
Keeping the service secure, preventing abuse, diagnosing bugsLegitimate interests — Art. 6(1)(f)
Recording your consent to this policy and the Terms of ServiceLegal obligation / our legitimate interest — Art. 6(1)(c) / (f)
Optional features we may add in the future (e.g. sharing recipes publicly, marketing emails)Your consent — Art. 6(1)(a); you can withdraw at any time

We do not sell your personal information and we do not share it for cross-context behavioural advertising.


4. Who we share data with

We use the following third-party processors. They act on our instructions and only receive the minimum data needed for their function.

We do not sell data, and we do not provide data to advertising networks or data brokers.

We may disclose data when required by law (e.g., a valid court order) or to protect the safety of our users or the public.


5. What becomes public when you publish a recipe

Most of what you put into heaty-eaty stays private to your account. Marking a recipe as "public" deliberately changes that. When you publish a recipe, the following becomes visible to every other authenticated user of the app:

Once content is public, it can be viewed, copied, screenshotted, or otherwise saved by other users, and we cannot retract copies that have already left our service. Treat public recipes the same way you would a public social-media post — only publish content you would be comfortable seeing on a public archive indefinitely.

To protect children and bystanders, please do not publish recipes that contain photos or videos of children (under 18), or images and audio of people who have not consented to being shared. Our Terms of Service also prohibit sexual content, violence or graphic harm, and profanity in public recipes; we may remove public content that we believe in good faith violates those rules.

You can unpublish a recipe at any time from the recipe screen, which removes it from public listings going forward. Audio recordings, transcripts, and any drafts you keep private are never made public unless you explicitly publish a recipe derived from them.


6. International transfers

Our data infrastructure is hosted with Supabase. Depending on the region your project is deployed in, data may be stored in the United States or another country outside your own. Where EU/UK personal data is transferred, we rely on Standard Contractual Clauses (SCCs) with our processors.


7. How long we keep data

If you delete your account, we delete associated data within 30 days, subject to legal-retention obligations.


8. Your rights

If you are in the EU/UK (GDPR): you have the right to access, rectify, erase, restrict, or object to processing, and the right to data portability. You also have the right to withdraw consent for any consent-based processing, and the right to lodge a complaint with your local supervisory authority.

If you are in California (CCPA/CPRA): you have the right to know what we've collected, the right to delete, the right to correct, the right to opt out of "sale" or "sharing" (we do neither), the right to limit use of sensitive personal information, and the right not to be discriminated against for exercising these rights.

To exercise any right, email clair@puduhub.com. We will respond within the timeframes required by applicable law (generally 30 days under GDPR; 45 days under CCPA).


9. Security

We protect your data in transit with TLS and at rest with the safeguards provided by our hosting partners. Session tokens are stored in your device's secure enclave (iOS Keychain / Android Keystore). No system is perfect — if we ever experience a breach that is likely to affect you, we will notify you within the timeframes required by law.


10. Children

heaty-eaty is not directed at children under 13 (or under 16 in the EU, where that is the applicable threshold). We do not knowingly collect personal information from children. If you believe a child has created an account, email us and we will delete it.


11. Changes to this policy

When we materially change this policy, we will update the "Last updated" date at the top and notify you inside the app before the change takes effect. If the change requires new consent under applicable law, we will ask for it.


12. Contact

Questions, complaints, or requests: clair@puduhub.com