cat.moe Privacy Policy
Effective: September 6, 2026 · Version: 2026-09-06
p1nkjelly operates cat.moe as an individual and personally handles privacy matters. This policy covers account holders, anonymous link creators, people visiting short links, and people making inquiries or reports. Send privacy requests to admin@cat.moe.
1. Information, purposes and legal grounds
We process information you enter and information your browser sends when requesting the service. Processing necessary for registration, authentication, links and requested support below relies on forming or performing a contract under Article 15(1)(4) of Korea's Personal Information Protection Act (PIPA). Without information necessary for a feature, that feature may be unavailable; features that do not require an account remain available.
| Purpose | Information processed |
|---|---|
| Registration and accounts | Email, display name, password hash, account identifier, email verification status, time of the age-14-or-older declaration, creation and update times, account status and permissions |
| Login and account recovery | Session identifiers, creation, renewal and expiry times, browser user agent, email verification and password reset credentials |
| Creating, redirecting and managing links | Original and comparison destination URLs, short address, member owner's identifier, status, creation, update and age declaration times, alias, expiration and password protection settings, password hash |
| Browser session link history and protected access | Random session identifier, links created or authorized for access, expiry |
| Preventing duplicate requests | Request key, request comparison value, result and expiry |
| Authentication email | Recipient email, message containing a verification or reset link, delivery identifier, times, status and attempt count |
| Support and privacy requests | Reply address, request contents, minimum identity or representative verification information, receipt and handling records |
You may use a nickname as your display name. Registration does not request your legal name, resident registration number, phone number, birth date or payment details. Passwords are processed during authentication and stored as one-way hashes. Do not include passwords or authentication links in support messages.
Security and abuse prevention, report review, accountability for administrative actions and understanding link usage rely on legitimate interests under Article 15(1)(6), within a necessary scope. A contract with a member is not treated as the basis for all analytics about visitors who are not members. We consider the purpose and necessity, visitors' reasonable expectations, reidentification risks and potential effects on their rights.
| Purpose | Information processed |
|---|---|
| Preventing excessive requests and misuse | Request IP, a secret-key-derived rate-limit value, member or temporary session identifier, operation, counts and times |
| Reviewing harmful links and infringements | Reported link, reason and details, account identifier if reporting while logged in, receipt and review times, outcome, reviewer and review note |
| Administrative audit | Acting administrator, target account or link identifiers, action, time and necessary context such as the reason |
| Click analytics | Visit time, link identifier, temporary IP and user agent, sanitized referrer URL, estimated country, device, browser, operating system, referring domain and per-link visitor value |
Where separate consent is required, we explain the purpose, information, retention, right to refuse and consequences before obtaining it. Agreement to the terms or a visit is not blanket consent to personal information processing. We currently use no social login, payments, targeted advertising, external advertising analytics or CDN.
2. URLs and visitor analytics
- Personal or secret information in a destination URL can be stored as part of that URL. Check paths, query parameters, tokens and fragments after
#. Do not enter passwords, resident registration numbers, health information or access links to confidential documents. - Anyone who knows an unprotected short address can open it, and the destination can become visible. Do not use short addresses as secret storage.
- Raw IP addresses and user agents are stored temporarily while analytics await processing. Country estimates use a database installed on our server; we do not send visitor IPs to an external country lookup service.
- Visitor values differ by link and are not names, emails or exact personal identities. Hashing does not make every click record anonymous.
- If the browser sends a referrer, we remove credentials, query parameters and fragments, retaining the domain and path. A path can itself contain personal information.
- We do not use these records for advertising tracking across websites or precise location tracking. Owners do not see raw IP addresses or visitor values. Section 5 describes the current analytics, including recent individual clicks.
3. Retention
We erase information through scheduled cleanup and privacy request procedures when its purpose ends or retention expires. Expired authentication credentials cannot be used even before cleanup runs.
| Information | Retention or ending condition |
|---|---|
| Account profile, password and authentication methods | While the account exists; removed on withdrawal. Internal identifiers and termination status used to reference existing administrative records remain separately |
| Destination, owner association and link password | For link provision and management. Individual link deletion initially stops redirects; erasure of its URL and related details is handled through account withdrawal or a verified erasure request |
| Deleted address reservation | Kept while the service operates to prevent reissuing an address that could point to someone else's destination. Withdrawal removes the destination, password and owner association |
| Login session | Seven days from issue or renewal; may renew during use and is invalidated on logout, revocation or withdrawal |
| Email verification and password reset credentials | Valid for one hour; invalidated on completion as applicable to the method, with expired server records deleted |
| Browser session history and protected access | Within 24 hours of session creation, separately from the link's own retention |
| Duplicate request results | 24 hours from creation |
| Pending clicks containing raw IP and user agent | Deleted after processing; unprocessed records expire one hour after the visit and are removed by cleanup |
| Individual clicks and time-based aggregates | 90 days from the visit or aggregation time |
| Per-link visitor values | 90 days from that link's last visit for the value; a return visit updates the last-seen time |
| Rate-limit counters | 60-second windows; anonymous daily creation counts are cleaned up after the relevant UTC date ends |
| Our pending email payloads | Removed on delivery, final failure or expiry; pending lifetime is 59 minutes |
| Our email result metadata | Status, times and attempts without recipient or body, for seven days after the final change |
| Support, reports and appeals | While being handled and 90 days after resolution, meaning completion of the response or a report's resolution or dismissal |
| Administrative and security action audit | One year from creation; action facts and reasons may be included separately from the original report |
| Our backups | Seven days from creation, on equipment owned by the operator in South Korea |
An unresolved report is not deleted merely because 90 days have passed since submission. Audit records cannot be changed or deleted through normal functionality; only expired records are purged. Support retention also covers copies in the separate mailbox. Section 6 explains Google's processing and deletion.
If a law or lawful preservation order requires specific records, we retain only the relevant information for the required purpose and period, separately. The possibility of a future dispute alone does not justify indefinite retention of everything.
4. Erasure and account withdrawal
Electronic information is deleted to prevent recovery or reproduction. Any paper records are shredded or otherwise destroyed. Legally retained records have restricted access and use.
Members can withdraw at My links → Account by confirming their current password and intention. Every short link owned by the account stops redirecting. We remove the name, email, profile image, password, sessions and age declaration time, and the owned links' destinations, passwords, associated analytics, request results and pending emails. Internal identifiers, times and termination status remain for address reservation and existing audit or report references; we do not describe these as necessarily anonymous.
Individual link deletion, account withdrawal, expiry of support or audit records, and mailbox deletion are separate procedures. Privacy requests are reviewed across related records and processor-held copies. Backups rotate over seven days; previously completed erasures must be reapplied after restoration before service resumes.
5. What link owners see and disclosure
The member owning a visited link can inspect the following information to understand its use. Authorized administrators can access it for report review and operations.
| Category | Visible information |
|---|---|
| Overall and time-based activity | Click count, clicks over time, estimated unique visitors |
| Breakdowns | Counts by country, device, browser, operating system, referrer URL and referring domain |
| Recent individual visits | Visit time, estimated country, device, browser, operating system and sanitized referrer URL |
| Not displayed | Raw IP, visitor value and the visitor's account email |
Service access is limited to the 90-day retention window. Under the terms, owners must not reidentify or track visitors, or retain or redistribute personal visit details without a lawful basis. Small groups or individual visits may identify someone when combined with other information, so we do not describe all analytics as anonymous.
Disclosure within the stated purpose based on legitimate interests must also meet Article 17(1)(2). That ground is not extended by itself to disclosures requiring separate consent or overseas transfers. An owner abroad may access analytics from abroad. To request access, erasure, restriction or information about recipients, contact admin@cat.moe. We may need minimal information, such as the short address and approximate visit time, to locate the relevant record safely.
We do not sell personal information or disclose it to advertising businesses. We check the legal basis and scope of official requests and provide only necessary information. Following a redirect can cause your browser to send your IP and other connection information directly to the external destination, whose privacy policy also applies.
6. Outsourcing and overseas processing
The application and database run on a personally operated server in South Korea, and our backups are on the operator's equipment in South Korea. We use no CDN. Email is separately entrusted to Google Workspace Business Plus, under contractual purpose restrictions, safeguards, subprocessing, oversight and deletion conditions.
| Item | Email processing |
|---|---|
| Processor and recipient | Google Asia Pacific Pte. Ltd., the Workspace contracting entity for a South Korean billing address. Contact: Google Workspace privacy team; contact the operator at admin@cat.moe |
| Work and purpose | Email transmission and storage necessary for verification, password recovery, support, reports and privacy requests |
| Information | Sender and recipient addresses, messages and attachments containing authentication links or correspondence, transmission records |
| Timing and method | Network transmission and processing when messages are sent, received or processed by the service |
| Countries | No data-region restriction is configured. Google's published Workspace data-center processing countries are the United States, Singapore, Taiwan, Japan, Belgium, Canada, Chile, Denmark, Finland, Ireland, Mexico and the Netherlands. We do not guarantee an individual message stays in Korea or a particular country |
| Retention and deletion | Operator-controlled mailbox copies of support and reports are subject to deletion 90 days after resolution, and authentication copies seven days after sending. Deletion from Google's systems follows a separate process described below |
| Ground | Article 28-8(1)(3) and this policy's disclosures apply only to outsourcing or storage necessary to perform the requested email authentication, recovery or support service |
| Refusal and effects | You may avoid registration or email features, or request restriction at admin@cat.moe. Email verification, recovery and replies may be unavailable; anonymous creation and the public report form remain available |
These are published possible processing locations, not a statement that every message goes to every country. Maintenance and support access may involve additional countries. The Workspace subprocessor list identifies country-specific activities and entities. We restrict the scope of Google support access where necessary.
The Google Cloud Data Processing Addendum generally provides a maximum 180-day system deletion period following an instruction triggered by deletion that the customer can no longer recover. This is not 180 days from sending and is separate from our seven-day backups. Applicable legal preservation requirements and any Google Vault retention rules or holds must also be checked. Deleting a mailbox copy is not confirmation that every Google copy has immediately disappeared.
7. Cookies and browser storage
We use no advertising or external analytics cookies. The following cookies support service functions.
| Cookie | Purpose and lifetime |
|---|---|
better-auth.session_token (may use the __Secure- prefix over HTTPS) | Maintains login for seven days from issue or renewal; removed on logout |
cat-moe-history | Maintains links created in the same browser and protected-link access. A browser session cookie, with server records lasting no more than 24 hours from creation |
Authentication cookies are inaccessible to page JavaScript, and production uses HTTPS. You can block or delete cookies through browser settings. Login, browser link history and protected-link access may be unavailable or require authentication again. A browser's session restore feature may also restore session cookies.
Analytics are processed on the server without advertising cookies. Blocking cookies alone does not stop server-side click analytics. See the next section to exercise your rights concerning analytics.
8. Your rights and requests
You or a lawful representative may request access, correction, erasure, restriction, or withdrawal of consent for consent-based processing. Email admin@cat.moe with the information concerned and the requested action. We use the minimum information necessary to verify identity or authority and do not request passwords or unnecessary identity document copies.
Members may withdraw through the account screen. Anonymous creators and visitors may also make requests. We do not reject all analytics requests merely because those records lack names; we explain how to locate the relevant information safely. We respond without undue delay and observe statutory deadlines for access and other rights. If there is a lawful limitation or refusal, we explain the reason and how to challenge it. Restricting processing essential to a feature can make that feature unavailable.
For complaints and advice in Korea: Personal Information Infringement Report Center, 118. For mediation: Personal Information Dispute Mediation Committee, 1833-6972.
9. Children
Registration and anonymous creation are available to people aged 14 or older. We do not operate parental consent registration for children under 14. If an underage account or a problem involving a child's information is identified, we assess restrictions, erasure and other necessary measures. This does not mean we have verified every redirect visitor's age; duties to protect child visitors remain applicable.
10. Safeguards
We protect information through restricted permissions, account and link ownership checks, HTTPS, password hashing, limits on authentication data exposure, rate limits, administrative records and backup management. Raw click IPs and user agents have a limited pending lifetime. Authentication secrets and unnecessary personal information are excluded from general operational logs. Confirmed breaches are handled, notified and reported as required by applicable law.
11. Privacy contact
p1nkjelly, the individual operating cat.moe, personally handles privacy and complaints. Contact admin@cat.moe for service questions, reports, access, erasure, restriction or questions about this policy.
12. Effective date and changes
This policy applies from September 6, 2026. We maintain matching contents, dates and versions in Korean and English. Changes state their substance and effective date. Material changes, including purposes or disclosure scope, are announced beforehand, with any separately required consent or procedure completed. Translation differences do not limit statutory rights.