← Back to Putpad

Privacy Policy

Version 1.1, 6 August 2026

Version: 1.1, 6 August 2026 Last updated: 6 August 2026 Applies to: the Putpad demo at putpad.com.au/app


Beta notice. Putpad is beta, pre-release evaluation software, offered free, as it is. There are no accounts, no sign-up, no subscription and no payment, and we do not ask you for personal information. Because it is a beta, it may change, and if what it does with information changes, this policy changes with it and you will be shown the new version at the gate.

1. Who we are

Putpad is operated by A Siriyar Interactive Pty Ltd, ABN 15 700 041 890, a company incorporated in Victoria, Australia ("we", "us", "our"), trading as Siriyar Interactive.

Contact for privacy questions, access requests and complaints:

The Privacy Officer, A Siriyar Interactive Pty Ltd chezhianmonish@gmail.com

We are a small, email-first business. Email is our contact channel for all privacy matters. We do not operate a public postal counter, and we will respond to every privacy enquiry by email within 30 days.

We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth). We do not rely on the small business exemption in s 6D of that Act. This policy is written, and we operate, on the basis that the Privacy Act obligations apply to us in full.


2. This product is for children, so read this part first

Putpad builds lessons for children aged three to ten. Children that age cannot understand a privacy policy or give valid consent to anything. The OAIC's guidance is that a person under 15 is presumed not to have the capacity to consent.

So we ask the adult. The person who accepts our terms and uses Putpad must be a parent, guardian, carer or teacher aged 18 or over. That adult:

We have no accounts, no sign-up, and we never ask for a name, an email address, a date of birth, an address or a school. There is no name field anywhere in the product.

There is no age check of any kind on this demo, and we cannot verify that an adult is present. We do not use age assurance, age estimation or identity checks. Anyone with the link can use the demo, including a child alone. We are telling you that plainly rather than implying a check exists. It is one of the reasons we ask for supervision, and one of the reasons we collect as little as we do.

Please do not type or say anything into Putpad that identifies your child. Do not use the child's real name, their school, their address or their birthday. Putpad does not need any of it to build a lesson, and what is typed or spoken is sent to third-party AI providers (section 5). Type the topic, not the child.

If you believe a child has given us personal information, email the Privacy Officer at chezhianmonish@gmail.com and we will delete whatever we hold. Because we hold very little, this is usually quick.


3. What we collect

3.1 What you type into Putpad

The topic or question entered, and any material pasted in alongside it. This is the core of the product: it is what the AI turns into a lesson.

We treat whatever is typed as potentially personal information, because we cannot control what is typed. "Explain fractions" is not personal information. "Explain fractions for Amelia who is 7 and has dyslexia" is, and it includes health information, which is sensitive information under s 6(1) of the Privacy Act 1988 (Cth). Please do not do that.

3.2 Voice input: please read this carefully

Putpad can listen. There are two ways this happens, and they behave differently.

(a) The microphone button. You press it, Putpad listens once, and stops.

(b) Conversation mode. This is a setting you turn on. When it is on, the microphone stays open for the whole time a lesson is playing, so a child can interrupt and ask a question out loud without pressing anything. It pauses while Putpad is speaking, and resumes afterwards. It is off unless you turn it on, and your browser will show its own microphone indicator whenever it is active.

Be clear about what conversation mode means: it is continuous listening while a lesson plays, not push-to-talk. If other people are in the room, they may be picked up too.

Where the audio goes. Putpad uses your browser's own built-in speech recognition (the Web Speech API). Putpad's servers never receive an audio recording.

However, your browser sends the audio to the browser vendor's own speech service. In Google Chrome that means the audio goes to Google. In Microsoft Edge it goes to Microsoft. This happens under their privacy policies, not ours. We have no contract with them about it, no visibility into it, and no control over how long they keep it. Safari and Firefox behave differently again.

If a child speaks into Putpad, the child's voice leaves the device, to the browser vendor, not to us. If you are not comfortable with that, leave conversation mode off and type instead. Everything works the same way.

We make these commitments about voice, and they are deliberate:

This matters legally as well as practically. Under s 6(1) of the Privacy Act 1988 (Cth), voice data becomes sensitive information only when it is "to be used for the purpose of automated biometric verification or biometric identification", or where a biometric template is created. The same purpose test applies under Articles 4(14) and 9 of the GDPR. Because we do none of those things, we do not collect biometric information. If that ever changes, this policy will change first, and a parent's express consent would be required.

What comes back is text, and that text is kept and re-sent. See 3.3, which is the part most people would not expect.

3.3 Your child's spoken questions are remembered and sent with later requests

When a child speaks a question during a lesson, the text of what they said is saved on your device in an interaction log, and is included in the information sent to the AI provider the next time a lesson is generated, so the AI has context about what the child has been asking.

This happens whether or not you have turned on the optional profiling setting.

The log holds the most recent 200 events and older ones drop off. Only a short extract of each question (roughly the first 60 characters) is put into the prompt.

We think this is the least obvious thing Putpad does with personal information, so we are stating it directly rather than burying it. A spoken question can contain anything a child says out loud. If that concerns you, leave conversation mode off, and use "Delete local child data" in Settings to clear the log (section 9).

3.4 The child profile in Settings, including health-related information

Putpad has a Settings screen where an adult can enter, to tailor lessons:

Information about ADHD or autism is health information, and health information is "sensitive information" under s 6(1) of the Privacy Act 1988 (Cth). It attracts a higher standard of protection than ordinary personal information.

Here is the important part: the age and the learning-needs flags never leave your device. They are stored in your browser only. They are not sent to us, and they are not sent to any AI provider.

The interests setting is different. It is sent to the AI provider, but only if you have turned on the optional profiling setting (section 3.5).

Entering any of this is entirely optional. Putpad works without it.

3.5 Optional profiling

There is a setting that lets Putpad build a picture of how the child is going: which skills they have practised, how often they needed prompting, and what they are interested in, so lessons can adapt.

It is off unless you turn it on. When it is on, a short summary (skill labels, counts of independent versus prompted answers, and the interest label) is included in the request to the AI provider. When it is off, none of that is sent.

Turning it off, or using "Delete local child data", stops it.

3.6 Information about your visit

Our server and our content delivery network receive the ordinary technical information every website receives: your IP address, your browser type and version, the resource requested, the time, and the response. Google Cloud and Cloudflare log this.

We also set a small number of strictly necessary cookies, including a random, meaningless identifier used only to apply fair-usage limits. Section 7 lists every cookie, what it contains and how long it lasts.

3.7 Your acceptance of our terms

When you tick the boxes and continue, we record that the Terms of Use and this Privacy Policy were accepted, the time, the version and a cryptographic hash of the exact text shown to you, a randomly generated acceptance identifier, and your IP address and browser user-agent string. We record those last two so we can show, if it is ever disputed, that a specific device accepted a specific version of these documents. We do not ask for your name or email. The same details are recorded where invited pre-release reviewers accept our confidentiality terms.

Acceptance records on our servers are kept for 30 days and then deleted. The cookie that records your acceptance on your own device lasts longer (180 days) so that you are not asked to accept again on every visit. Section 7 sets out every cookie. You can delete it at any time by clearing your browser's site data, which simply means you will see the acceptance screen again.

3.8 What we do not collect

To be explicit, because it is unusual and it is in your favour:


4. What stays on your own device

A lot of what Putpad remembers never leaves your device. It is kept in your browser's local storage, and we cannot see it.

Stored on your deviceWhat it holdsEver sent to us or a provider?
Child profileAge, ADHD/autism flags, sensory and wait-time settings, avatar, interestsAge and learning needs: never. Avatar and lesson caps: yes. Interests: only if profiling is on
Interaction log (last 200 events)Includes the text of questions the child spokeYes, sent with every generation (see 3.3)
Learning telemetrySkill counts, accuracy, completionsOnly a short summary, only if profiling is on
Profiling opt-inWhether you turned profiling onYes, as a yes/no
Saved lessons (last 50)The question, the material and the generated lessonNo
Local session idA random string generated on your deviceSent, but ignored by our server in production
Settings and preferencesVoice, display, projector settingsNo
Any API keys you enter yourselfProvider credentials you supply in SettingsAn AI provider key you enter is stripped by our server and not forwarded. An ElevenLabs key you enter is forwarded to ElevenLabs to make your voice request work

To delete it: Settings contains a "Delete local child data" control that removes the child profile, interaction log, saved lessons, session id, profiling opt-in and any unsent questions you had saved. (It deliberately leaves any provider API keys you entered alone.) You can also clear your browser's site data for putpad.com.au, or use a private window so nothing persists at all.

Because there is no account, we cannot delete this for you and we cannot see it.

On a shared or school device, the next person using the same browser profile may see saved lessons and the stored profile. Clear the data when you finish.


5. Who we send information to

This is the most important section.

Putpad cannot build a lesson by itself. It sends your topic or question, plus the recent interaction log described in 3.3, to third-party artificial intelligence providers, which generate the lesson. The narration is then turned into speech by a third-party text-to-speech provider.

Those providers may process the information outside Australia.

5.1 The AI that builds the lesson

What is sent: the typed or spoken topic; any pasted material; our own instructions to the model; your screen dimensions; the recent interaction log (including short extracts of questions the child spoke); the avatar and lesson settings; and, only if profiling is on, the learning summary and interest label.

What is not sent: the child's age, the ADHD/autism flags, your name (we do not have one), or any audio.

Who receives it. The live service runs an ensemble of two providers, and a single request may go to either or both:

ProviderModelRole
Anthropicclaude-sonnet-4-5Lesson generation
Googlegemini-2.5-flashLesson generation
Googlegemini-2.5-flash-liteFallback if gemini-2.5-flash is unavailable

These are the only lesson-generation providers in use. If we add, remove or change one, we will update this policy and the version at the top before the change goes live.

We use these providers' business and API tiers, under which inputs are not used to train their models. Each provider may retain inputs for a limited period for abuse monitoring, under its own published policies.

5.2 The AI that speaks the narration

What is sent: the narration text the lesson generator wrote. Never your voice. Never the child's voice. No audio of any kind is ever sent to a text-to-speech provider.

Who receives it: ElevenLabs, a United States company. If ElevenLabs is unavailable, or if you choose a browser voice in Settings, the narration is spoken by your browser's own speech synthesis instead. Browser speech synthesis is handled by your browser and, depending on the voice you or your browser selects, may be produced by the browser vendor's own online voice service under its privacy policy rather than on your device.

5.3 Speech recognition (your browser's vendor)

As described in 3.2, speech recognition is done by your browser, not by us. The audio goes to the browser vendor (Google in Chrome, Microsoft in Edge) under their privacy policies. We are not a party to that and receive no audio.

5.4 Emoji images

Putpad's lessons are built from emoji. These are served from our own servers. Occasionally, for an emoji we have not bundled, your browser fetches the image from the jsDelivr public CDN. That request reveals your IP address to jsDelivr but sets no cookies.

5.5 Hosting and delivery

5.6 Cross-border disclosure

By using Putpad you accept that information may be disclosed to and processed by these providers outside Australia.

Our own application and logs run in Australia (australia-southeast1). The AI providers are a different matter: Anthropic, Google and ElevenLabs may process requests on infrastructure outside Australia, and we cannot guarantee Australian data residency for the AI processing.

The countries in which those recipients are likely to be located are: Australia, the United States, and other countries in which Google, Anthropic, Cloudflare and ElevenLabs operate infrastructure, including countries in the European Union and the United Kingdom.

We take reasonable steps under Australian Privacy Principle 8 to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles, including using business/API tiers with contractual data-protection terms and no training on our inputs. We do not ask you to waive APP 8.1, and we remain accountable for what those recipients do with information we disclose to them.

5.7 Other disclosures

We may also disclose personal information to professional advisers bound to keep it confidential; where the law requires it or to a regulator or law enforcement body; where we reasonably believe it necessary to prevent a serious threat to someone's life, health or safety; or to a buyer or successor if the business is sold, on terms that continue to protect it.

We never sell personal information.


6. What we keep on our servers, and for how long

There is no user database. No accounts, no profiles, no saved lessons, nothing persistent about any individual. This is unusual and it is genuinely good for your privacy. It also means that if you ask us for a copy of your information, we have almost nothing to give you.

Our retention rule is simple: 30 days, then deletion. Every server-side record described below is deleted, or automatically expires, no later than 30 days after it is created. We do not keep children's prompts, spoken-question extracts or access logs indefinitely, and we do not keep anything for longer than we need it. This is our written retention policy, and it is published here deliberately.

WhatWhereHow long
Your question, in transitServer memoryFor the length of the request only. Retention by the AI provider is that provider's decision. See 5.1
Diagnostic record of a generated lesson, including the question textServer-side logs, australia-southeast130 days, then deleted
Server access logs (IP, browser, request)Google Cloud Logging, australia-southeast130 days, then deleted
Terms acceptance records (time, document versions and hashes, acceptance id, IP, user-agent)Google Cloud Logging, australia-southeast130 days, then deleted
Fair-usage counters (a one-way digest of the putpad_anon cookie value, and a count)Server memory / logs, australia-southeast1The length of the rate-limit window, and 30 days at the outside
Reviewer access audit events (IP, browser)Google Cloud Logging, australia-southeast130 days, then deleted
Cloudflare logsCloudflarePer Cloudflare's own retention, which for our plan is short-term operational logging only
Interaction log, profile, lessons, telemetryYour device onlyUntil you clear it
Voice audioNever reaches usNot applicable to us. Retention by the browser vendor is that vendor's decision. See 3.2

If you ask us to delete something we hold and we can identify it, we will delete it sooner. Email the Privacy Officer at chezhianmonish@gmail.com.


7. Cookies

We use no advertising cookies and no analytics cookies, and the application sets no cookies from JavaScript. The cookies below are set by our server, and each one is needed for the demo to work.

CookieSet byPurposeContentsLifetimeFlags
putpad_termsUsRecords that the Terms of Use and Privacy Policy were accepted, so you are not asked again on every visitA random acceptance identifier, the version and hash of the documents you accepted, and an expiry, all signed by us. No name, no email180 daysHttpOnly; Secure; SameSite=Lax; Path=/
putpad_anonUsFair-usage limits only. It gives your browser a stable bucket so the limit on how many lessons can be generated in an hour actually applies. Without it every request would look like a brand new visitor32 random hexadecimal characters (128 bits of randomness) and nothing else. No IP address, no browser details, no timestamp, no identifier supplied by you, no personal information. Our server stores only a one-way digest of the value, never the value itself30 daysHttpOnly; Secure; SameSite=Lax; Path=/
putpad_authUsOnly if you were given an invited pre-release reviewer link or a one-time access code. Identifies that session. Signed. No name, no emailA signed session tokenUp to 30 days (1 hour in the one-time-code mode)HttpOnly; Secure; SameSite=Lax; Path=/
putpad_reviewer_termsUsOnly for invited reviewers. Records that the reviewer accepted the confidentiality termsA signed acceptance marker30 daysHttpOnly; Secure; SameSite=Lax; Path=/
Cloudflare cookies (e.g. __cf_bm)CloudflareBot management and securitySet by CloudflareSet by CloudflareSet by Cloudflare

Every one of these is strictly necessary or functional. None of them is an analytics, advertising, tracking or cross-site cookie. We do not use cookies to build a profile of you, to follow you to other websites, or to identify who you are. putpad_anon in particular is random data that means nothing outside this service. We set no cookie that is not needed to run the demo.

You can block or delete cookies in your browser. Blocking them will make the acceptance gate appear on every visit, will make fair-usage limits apply more bluntly, and the demo may stop working.


8. Security

No system is completely secure. If we suffer a data breach likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.


9. Your rights

Delete everything. Settings has a "Delete local child data" control, which removes the child profile, the interaction log (including saved spoken questions), saved lessons, the session id and the profiling opt-in. Clearing your browser's site data for putpad.com.au removes everything else. Anything on our servers is deleted within 30 days in any event (section 6).

Turn things off. Conversation mode (continuous listening) and profiling are both off by default and can be turned off again at any time. Nothing in the child profile is required.

Access and correction (APP 12 and APP 13). You can ask us for a copy of the personal information we hold about you, and ask us to correct it. Email the Privacy Officer at chezhianmonish@gmail.com and we will respond within 30 days. In practice, because there are no accounts, we usually cannot identify which records relate to you, and most of what Putpad remembers is on your own device where we cannot reach it. We will tell you honestly what we can and cannot do.

Anonymity (APP 2). You can use the demo without telling us who you are. That is how it works by default.

Complaints. If you think we have mishandled information, email the Privacy Officer at chezhianmonish@gmail.com. We will acknowledge promptly and respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992.


10. If you are outside Australia

The demo is reachable worldwide, and it is built and operated to Australian standards. Your local law may give you rights this policy does not describe.

We are an Australian company operating a free pre-release demo. We have not established local representation in the United States, the United Kingdom or the European Union, and the demo is not directed at users in those places. If you are a parent, guardian or teacher outside Australia and you have a question or request about your local privacy law, email the Privacy Officer at chezhianmonish@gmail.com and we will deal with it on its merits, including deleting whatever we hold.

If you are in the United States, please note in particular that we do not obtain verifiable parental consent as that term is used in the US Children's Online Privacy Protection Rule, and the demo should not be used by a child under 13 in the United States.


11. Changes to this policy

We may update this policy. The version and date are at the top. Because we have no accounts and no email addresses, we cannot notify you individually. The current version will always be shown at the gate and linked from the demo.

If we make a change that materially affects how we handle children's information, we will ask you to accept it again before you continue.


12. The short version