Skip to content
cat.moe
My linksSign in
Terms of ServicePrivacy Policy한국어

Version 2026-09-06

Announced: September 6, 2026 at 12:00 AM (KST)

Effective: September 6, 2026 at 12:00 AM (KST)

cat.moe Privacy Policy

Effective: September 6, 2026 · Version: 2026-09-06

한국어 · Terms of Service

p1nkjelly operates cat.moe as an individual and personally handles privacy matters. This policy covers account holders, anonymous link creators, people visiting short links, and people making inquiries or reports. Send privacy requests to admin@cat.moe.

1. Information, purposes and legal grounds

We process information you enter and information your browser sends when requesting the service. Processing necessary for registration, authentication, links and requested support below relies on forming or performing a contract under Article 15(1)(4) of Korea's Personal Information Protection Act (PIPA). Without information necessary for a feature, that feature may be unavailable; features that do not require an account remain available.

PurposeInformation processed
Registration and accountsEmail, display name, password hash, account identifier, email verification status, time of the age-14-or-older declaration, creation and update times, account status and permissions
Login and account recoverySession identifiers, creation, renewal and expiry times, browser user agent, email verification and password reset credentials
Creating, redirecting and managing linksOriginal and comparison destination URLs, short address, member owner's identifier, status, creation, update and age declaration times, alias, expiration and password protection settings, password hash
Browser session link history and protected accessRandom session identifier, links created or authorized for access, expiry
Preventing duplicate requestsRequest key, request comparison value, result and expiry
Authentication emailRecipient email, message containing a verification or reset link, delivery identifier, times, status and attempt count
Support and privacy requestsReply address, request contents, minimum identity or representative verification information, receipt and handling records

You may use a nickname as your display name. Registration does not request your legal name, resident registration number, phone number, birth date or payment details. Passwords are processed during authentication and stored as one-way hashes. Do not include passwords or authentication links in support messages.

Security and abuse prevention, report review, accountability for administrative actions and understanding link usage rely on legitimate interests under Article 15(1)(6), within a necessary scope. A contract with a member is not treated as the basis for all analytics about visitors who are not members. We consider the purpose and necessity, visitors' reasonable expectations, reidentification risks and potential effects on their rights.

PurposeInformation processed
Preventing excessive requests and misuseRequest IP, a secret-key-derived rate-limit value, member or temporary session identifier, operation, counts and times
Reviewing harmful links and infringementsReported link, reason and details, account identifier if reporting while logged in, receipt and review times, outcome, reviewer and review note
Administrative auditActing administrator, target account or link identifiers, action, time and necessary context such as the reason
Click analyticsVisit time, link identifier, temporary IP and user agent, sanitized referrer URL, estimated country, device, browser, operating system, referring domain and per-link visitor value

Where separate consent is required, we explain the purpose, information, retention, right to refuse and consequences before obtaining it. Agreement to the terms or a visit is not blanket consent to personal information processing. We currently use no social login, payments, targeted advertising, external advertising analytics or CDN.

2. URLs and visitor analytics

  1. Personal or secret information in a destination URL can be stored as part of that URL. Check paths, query parameters, tokens and fragments after #. Do not enter passwords, resident registration numbers, health information or access links to confidential documents.
  2. Anyone who knows an unprotected short address can open it, and the destination can become visible. Do not use short addresses as secret storage.
  3. Raw IP addresses and user agents are stored temporarily while analytics await processing. Country estimates use a database installed on our server; we do not send visitor IPs to an external country lookup service.
  4. Visitor values differ by link and are not names, emails or exact personal identities. Hashing does not make every click record anonymous.
  5. If the browser sends a referrer, we remove credentials, query parameters and fragments, retaining the domain and path. A path can itself contain personal information.
  6. We do not use these records for advertising tracking across websites or precise location tracking. Owners do not see raw IP addresses or visitor values. Section 5 describes the current analytics, including recent individual clicks.

3. Retention

We erase information through scheduled cleanup and privacy request procedures when its purpose ends or retention expires. Expired authentication credentials cannot be used even before cleanup runs.

InformationRetention or ending condition
Account profile, password and authentication methodsWhile the account exists; removed on withdrawal. Internal identifiers and termination status used to reference existing administrative records remain separately
Destination, owner association and link passwordFor link provision and management. Individual link deletion initially stops redirects; erasure of its URL and related details is handled through account withdrawal or a verified erasure request
Deleted address reservationKept while the service operates to prevent reissuing an address that could point to someone else's destination. Withdrawal removes the destination, password and owner association
Login sessionSeven days from issue or renewal; may renew during use and is invalidated on logout, revocation or withdrawal
Email verification and password reset credentialsValid for one hour; invalidated on completion as applicable to the method, with expired server records deleted
Browser session history and protected accessWithin 24 hours of session creation, separately from the link's own retention
Duplicate request results24 hours from creation
Pending clicks containing raw IP and user agentDeleted after processing; unprocessed records expire one hour after the visit and are removed by cleanup
Individual clicks and time-based aggregates90 days from the visit or aggregation time
Per-link visitor values90 days from that link's last visit for the value; a return visit updates the last-seen time
Rate-limit counters60-second windows; anonymous daily creation counts are cleaned up after the relevant UTC date ends
Our pending email payloadsRemoved on delivery, final failure or expiry; pending lifetime is 59 minutes
Our email result metadataStatus, times and attempts without recipient or body, for seven days after the final change
Support, reports and appealsWhile being handled and 90 days after resolution, meaning completion of the response or a report's resolution or dismissal
Administrative and security action auditOne year from creation; action facts and reasons may be included separately from the original report
Our backupsSeven days from creation, on equipment owned by the operator in South Korea

An unresolved report is not deleted merely because 90 days have passed since submission. Audit records cannot be changed or deleted through normal functionality; only expired records are purged. Support retention also covers copies in the separate mailbox. Section 6 explains Google's processing and deletion.

If a law or lawful preservation order requires specific records, we retain only the relevant information for the required purpose and period, separately. The possibility of a future dispute alone does not justify indefinite retention of everything.

4. Erasure and account withdrawal

Electronic information is deleted to prevent recovery or reproduction. Any paper records are shredded or otherwise destroyed. Legally retained records have restricted access and use.

Members can withdraw at My links → Account by confirming their current password and intention. Every short link owned by the account stops redirecting. We remove the name, email, profile image, password, sessions and age declaration time, and the owned links' destinations, passwords, associated analytics, request results and pending emails. Internal identifiers, times and termination status remain for address reservation and existing audit or report references; we do not describe these as necessarily anonymous.

Individual link deletion, account withdrawal, expiry of support or audit records, and mailbox deletion are separate procedures. Privacy requests are reviewed across related records and processor-held copies. Backups rotate over seven days; previously completed erasures must be reapplied after restoration before service resumes.

5. What link owners see and disclosure

The member owning a visited link can inspect the following information to understand its use. Authorized administrators can access it for report review and operations.

CategoryVisible information
Overall and time-based activityClick count, clicks over time, estimated unique visitors
BreakdownsCounts by country, device, browser, operating system, referrer URL and referring domain
Recent individual visitsVisit time, estimated country, device, browser, operating system and sanitized referrer URL
Not displayedRaw IP, visitor value and the visitor's account email

Service access is limited to the 90-day retention window. Under the terms, owners must not reidentify or track visitors, or retain or redistribute personal visit details without a lawful basis. Small groups or individual visits may identify someone when combined with other information, so we do not describe all analytics as anonymous.

Disclosure within the stated purpose based on legitimate interests must also meet Article 17(1)(2). That ground is not extended by itself to disclosures requiring separate consent or overseas transfers. An owner abroad may access analytics from abroad. To request access, erasure, restriction or information about recipients, contact admin@cat.moe. We may need minimal information, such as the short address and approximate visit time, to locate the relevant record safely.

We do not sell personal information or disclose it to advertising businesses. We check the legal basis and scope of official requests and provide only necessary information. Following a redirect can cause your browser to send your IP and other connection information directly to the external destination, whose privacy policy also applies.

6. Outsourcing and overseas processing

The application and database run on a personally operated server in South Korea, and our backups are on the operator's equipment in South Korea. We use no CDN. Email is separately entrusted to Google Workspace Business Plus, under contractual purpose restrictions, safeguards, subprocessing, oversight and deletion conditions.

ItemEmail processing
Processor and recipientGoogle Asia Pacific Pte. Ltd., the Workspace contracting entity for a South Korean billing address. Contact: Google Workspace privacy team; contact the operator at admin@cat.moe
Work and purposeEmail transmission and storage necessary for verification, password recovery, support, reports and privacy requests
InformationSender and recipient addresses, messages and attachments containing authentication links or correspondence, transmission records
Timing and methodNetwork transmission and processing when messages are sent, received or processed by the service
CountriesNo data-region restriction is configured. Google's published Workspace data-center processing countries are the United States, Singapore, Taiwan, Japan, Belgium, Canada, Chile, Denmark, Finland, Ireland, Mexico and the Netherlands. We do not guarantee an individual message stays in Korea or a particular country
Retention and deletionOperator-controlled mailbox copies of support and reports are subject to deletion 90 days after resolution, and authentication copies seven days after sending. Deletion from Google's systems follows a separate process described below
GroundArticle 28-8(1)(3) and this policy's disclosures apply only to outsourcing or storage necessary to perform the requested email authentication, recovery or support service
Refusal and effectsYou may avoid registration or email features, or request restriction at admin@cat.moe. Email verification, recovery and replies may be unavailable; anonymous creation and the public report form remain available

These are published possible processing locations, not a statement that every message goes to every country. Maintenance and support access may involve additional countries. The Workspace subprocessor list identifies country-specific activities and entities. We restrict the scope of Google support access where necessary.

The Google Cloud Data Processing Addendum generally provides a maximum 180-day system deletion period following an instruction triggered by deletion that the customer can no longer recover. This is not 180 days from sending and is separate from our seven-day backups. Applicable legal preservation requirements and any Google Vault retention rules or holds must also be checked. Deleting a mailbox copy is not confirmation that every Google copy has immediately disappeared.

7. Cookies and browser storage

We use no advertising or external analytics cookies. The following cookies support service functions.

CookiePurpose and lifetime
better-auth.session_token (may use the __Secure- prefix over HTTPS)Maintains login for seven days from issue or renewal; removed on logout
cat-moe-historyMaintains links created in the same browser and protected-link access. A browser session cookie, with server records lasting no more than 24 hours from creation

Authentication cookies are inaccessible to page JavaScript, and production uses HTTPS. You can block or delete cookies through browser settings. Login, browser link history and protected-link access may be unavailable or require authentication again. A browser's session restore feature may also restore session cookies.

Analytics are processed on the server without advertising cookies. Blocking cookies alone does not stop server-side click analytics. See the next section to exercise your rights concerning analytics.

8. Your rights and requests

You or a lawful representative may request access, correction, erasure, restriction, or withdrawal of consent for consent-based processing. Email admin@cat.moe with the information concerned and the requested action. We use the minimum information necessary to verify identity or authority and do not request passwords or unnecessary identity document copies.

Members may withdraw through the account screen. Anonymous creators and visitors may also make requests. We do not reject all analytics requests merely because those records lack names; we explain how to locate the relevant information safely. We respond without undue delay and observe statutory deadlines for access and other rights. If there is a lawful limitation or refusal, we explain the reason and how to challenge it. Restricting processing essential to a feature can make that feature unavailable.

For complaints and advice in Korea: Personal Information Infringement Report Center, 118. For mediation: Personal Information Dispute Mediation Committee, 1833-6972.

9. Children

Registration and anonymous creation are available to people aged 14 or older. We do not operate parental consent registration for children under 14. If an underage account or a problem involving a child's information is identified, we assess restrictions, erasure and other necessary measures. This does not mean we have verified every redirect visitor's age; duties to protect child visitors remain applicable.

10. Safeguards

We protect information through restricted permissions, account and link ownership checks, HTTPS, password hashing, limits on authentication data exposure, rate limits, administrative records and backup management. Raw click IPs and user agents have a limited pending lifetime. Authentication secrets and unnecessary personal information are excluded from general operational logs. Confirmed breaches are handled, notified and reported as required by applicable law.

11. Privacy contact

p1nkjelly, the individual operating cat.moe, personally handles privacy and complaints. Contact admin@cat.moe for service questions, reports, access, erasure, restriction or questions about this policy.

12. Effective date and changes

This policy applies from September 6, 2026. We maintain matching contents, dates and versions in Korean and English. Changes state their substance and effective date. Material changes, including purposes or disclosure scope, are announced beforehand, with any separately required consent or procedure completed. Translation differences do not limit statutory rights.

cat.moeA little less URL.
© p1nkjellypinkjelly.catTerms of ServicePrivacy PolicyContact admin@cat.moeReport abuse