cat.moe Privacy Policy
Version: 2026-09-08-2. The announcement and effective dates appear on the document page. The version date is not its effective date.
Minwoo Jeong (정민우), known as p1nkjelly, operates cat.moe as an individual and serves as its privacy officer. This policy covers members, anonymous creators, short-link visitors and people making inquiries or reports. Contact admin@cat.moe for privacy questions and rights requests.
1. Purposes, information and grounds
We process information you enter and information your browser sends with requests within the following scope.
| Purpose | Main information | Legal ground |
|---|---|---|
| Accounts and authentication | Email, display name, password hash, account ID, status and permissions, email verification, time of the age-14 declaration, creation/update times, session/verification/reset information, user agent | Forming or performing a contract under Article 15(1)(4) of Korea's Personal Information Protection Act (PIPA) |
| Creating, redirecting and managing links | Original and comparison destination URLs, short address, owner account, status, creation/update/age-declaration times, alias, expiration/access settings and password hash | Article 15(1)(4) |
| Session history, protected access and duplicate-request prevention | Random session ID, related links, access grants and expiry, request key, comparison value and result | Article 15(1)(4) |
| Agreements, assent and required email | Terms version, agreement time/source and related account/link, notice recipient and handling state, recipient address, authentication or notice content and delivery results | Article 15(1)(4), and Article 15(1)(2) for applicable legal duties |
| Support and rights requests | Reply address, necessary request contents and target, minimum identity/authority verification method and result, receipt, response and decision | Article 15(1)(4) for requested support; Article 15(1)(2) for statutory rights |
| Rate limits, security and report review | Request IP, secret-key-derived limit value, member/temporary-session ID, operation/count/time, reported target/reason/details/account and handling records | Legitimate interests under Article 15(1)(6) |
| Major actions and security audit | Member/administrator ID or anonymous/system classification, action, internal target ID and necessary short address, time, reason, route type, response status and minimum context | Article 15(1)(6) |
| Visitor analytics | Visit time, link ID, temporary raw IP/user agent, sanitized referrer URL/domain, estimated country/device/browser/OS, per-link visitor values and counts | Within the conditions of Article 15(1)(6) |
A feature may be unavailable without information necessary to provide it. Display names may be nicknames; registration does not require a legal name, resident registration number, phone number, birth date or payment information. Passwords are used for authentication and stored as hashes. Do not send passwords, authentication links or unnecessary identity-document copies in inquiries.
Security and analytics support service stability, abuse response and understanding link use. Processing based on legitimate interests is limited by its connection to the purpose, necessity and whether the interest clearly outweighs the individual's rights. A contract with a member or granting extended permissions does not by itself authorize processing of nonmember visitors' information. Where separate consent is required, we explain purposes, information, periods, refusal rights and effects and obtain that consent.
We currently use no social login, payments, targeted advertising, external advertising analytics or CDN. Agreement to the terms or a visit is not blanket consent to all personal-information processing.
2. URLs, visitor analytics and anonymous audit
- Paths, query parameters, tokens and fragments can be stored as part of a submitted URL. Do not enter destinations containing personal or secret information. Unprotected short addresses and their destinations may become visible to anyone who knows the address.
- Raw IP and user agent in pending clicks are deleted after processing; unprocessed records expire one hour after the visit. Country estimates use a server-side database without sending IPs to an external country lookup service. User agents in login sessions follow the separate session period.
- Visitor values are generated per link and are not provided to link owners together with raw IPs or emails. Referrers have credentials, query parameters and fragments removed; the retained domain and path may still contain personal information.
- Recent individual visits and small groups may identify someone when combined with other information; we do not treat all analytics as anonymous. We do not use them for advertising tracking across sites or precise location tracking.
- Audit scope includes anonymous link creation, reports, successful protected-link access, major authentication requests and security events such as access denials and rate limits. New anonymous audit records exclude raw IPs, email, passwords, authentication tokens and session identifiers. This is not an audit of every page view or redirect click; repeated request/security events may be subject to storage limits. Audits of authenticated users may be associated with their account ID.
3. Retention and the 365-day period
Retention periods are limits or ending conditions for processing and storage, not a promise to preserve and supply information for that entire time. We erase information without delay when its purpose ends or its period expires, using event-based deletion and scheduled cleanup. Expired sessions, credentials and access grants are unusable before cleanup. If an outage delays erasure, we address the cause and resume cleanup without returning expired information to ordinary service use.
| Information | Period or ending condition |
|---|---|
| Account profile, password and authentication methods | While the account exists; removed on withdrawal. See below for termination and internal references |
| Destination, owner association and link password | For link provision and management. Individual link deletion stops redirects; personal details are erased on withdrawal or a verified erasure request |
| Deleted address reservation | During service operation to prevent reissue pointing to someone else. Erasure removes destination, password and owner association |
| Login sessions | Seven days from issue/renewal; invalidated on logout, revocation or withdrawal |
| Email verification and password reset information | Valid for one hour; invalidated on completion as applicable, with expired records deleted |
| Browser session history and protected access | Within 24 hours of session creation |
| Duplicate-request results | 24 hours from creation |
| Pending clicks containing raw IP and user agent | Deleted after processing; unprocessed records expire one hour after the visit |
| Individual clicks, including per-link visitor values | Up to 90 days from each visit, regardless of extended permissions. Another visit does not renew older records |
| Time-bucket click counts | Up to 90 days from the time bucket, or up to 365 days under the extension conditions below; only the link, time bucket and number of clicks |
| Rate-limit counters | 60-second windows; anonymous daily creation counters cleaned up after the relevant UTC date |
| Our pending email payloads | Authentication email: 59 minutes; revision notices: seven days. Contents removed on SMTP acceptance, final failure or expiry |
| Our email-result metadata | Status, times and attempts without recipient/body, for seven days after the final change |
| Support, reports, rights requests and appeals | During handling and 90 days after resolution |
| Major-action, administrative and security audit | One year from creation |
| Our backups | Seven days from backup creation, full-server images on the operator's NAS in South Korea |
| Terms agreement records | Account version/time/source until withdrawal; link declaration until that link's personal details are erased |
| Revision-notice evidence | Version, account, delivery state and times for one year after the final state change or withdrawal, whichever is earlier |
| Recovery erasure inventory | Erased internal account/link IDs and erasure times for eight days after erasure; excludes email, destinations and message contents |
Extended analytics conditions
- Eligibility: After this revision takes effect, links whose owners have active accounts with extended retention permissions. Anonymous links and links owned by accounts without that permission use the standard period.
- Purpose and scope: Only time-bucket click counts used to understand longer-term link use and traffic changes. Extended aggregates contain no individual visit times, visitor values, countries, device profiles or referrers. They remain associated with the link and are not automatically anonymous. Visitor estimates and detailed breakdowns are calculated from retained individual clicks within the 90-day limit; the interface identifies the shorter detail period.
- Starting point: The visit time for individual click records and their visitor values; the relevant time bucket for aggregate counts. Another visit, granting permissions, downloading CSV or restoring a link does not restart old records' retention. There is no separate visitor registry whose retention renews on a return visit. Counts outside the detail period use complete hours because deleted individual visits cannot reconstruct partial hours.
- Ending: Revoking the permission or suspending the account restores the standard period for click counts. Older counts are excluded from queries and erased by the next cleanup. Withdrawal and verified erasure follow section 4. Raw IP/user-agent queue, support, audit, email and backup periods do not increase. A separate historical copy is not retained for restoration.
- Available history: Limited to retained records and the period shown in the interface, which may be shorter. Material operational reductions for normal users receive advance notice. Regranting permissions does not recover erased analytics. Reaching 365 days does not permit indefinite extension.
A support matter ends when necessary action, a reply, resolution, dismissal or lawful refusal is recorded; where individual notice is required, that notice must also be completed. Ordinary reports or duplicate inquiries that do not receive a separate reply can close on a recorded handling decision. Unresolved matters remain only as necessary for handling and are not left open to avoid erasure. Request contents, verification and response notes follow the 90-day period after resolution. Separate audits may retain the actor, operation, minimum target and reason for one year; request contacts or full contents are not copied into audits to extend their life. Operator-controlled mailbox copies follow section 6.
If another law or a lawful preservation order requires retention, only the relevant information is retained separately for that ground and period with restricted use. A hypothetical dispute or operational convenience does not justify keeping all personal information indefinitely.
4. Erasure, withdrawal and backups
Members can withdraw at My links → Account. Withdrawal terminates all short links owned by the account. The primary database removes profile, email, password, sessions, age and terms agreement records, owned-link destinations, owner associations, passwords and related analytics, duplicate-request results and pending email.
Individual link deletion stops redirects; withdrawal and verified erasure remove the relevant personal information. A verified request for a specific link can be handled without closing unrelated links. Internal IDs, times and termination status needed to prevent address reissue and reference remaining audits/reports may remain and are not assumed to be fully anonymous. Separate records follow their respective periods.
Electronic records are erased through deletion, overwriting or other appropriate means; retired media are securely erased or destroyed, and paper records, if any, are shredded.
Full-server images are automatically backed up to the operator's NAS in South Korea and rotated with a seven-day retention period from backup creation. Access is restricted and the images are used for incident recovery. They may include account, link, analytics, support, audit and pending-processing records, as well as settings and logs stored on the server at backup time. Copies of information erased or expired in the live service may remain until that image's seven-day retention ends; they are not reused for ordinary service or analytics delivery.
Before reopening public access after restoration, completed erasures are reapplied and expired records cleaned up. Restoration does not restart retention. Erasure in the live database does not immediately update existing server images or processor copies; each is handled under its period and applicable erasure duties.
Routine erasure at the end of a retention period does not receive a separate individual notice. We do not provide additional preservation or reconstruction of expired material merely on a user's request. Backups serve incident recovery and are not individual storage accounts. Statutory notice, disclosure and preservation duties remain applicable.
5. Owner access and third-party disclosure
The member owning a link can access the following retained information to understand its use. Authorized administrators may inspect it as necessary for operations and report review.
| Category | Information provided |
|---|---|
| Overall and time-based analytics | Clicks and clicks by time bucket, within the applicable 90/365-day limit |
| Estimated unique visitors | An estimate from retained visits within the 90-day detail limit |
| Breakdowns | Counts by country, device, browser, OS, sanitized referrer URL and domain |
| Recent individual visits | Visit time, estimated country, device, browser, OS and sanitized referrer URL |
| Values not provided | Raw IP, visitor value and the visitor's account email |
CSV exports for advanced permissions contain only time buckets and click counts, excluding destinations, referrers, individual visits, raw IPs and visitor values. Recipients control downloaded copies; service cleanup does not erase them automatically. Their use of personal information remains subject to the disclosed purpose, period and applicable law. We do not provide remote erasure of every copy.
Disclosure within the collection purpose based on legitimate interests is subject to Article 17(1)(2) of PIPA. An owner viewing information from abroad may constitute an overseas transfer; this clause does not authorize transfers requiring separate consent or a ground under Article 28-8. Send access, erasure, restriction or recipient-information requests to admin@cat.moe.
We do not sell personal information or disclose it to advertising businesses. Official requests are checked for legal basis and scope, and only necessary information is provided. Following a redirect may cause your browser to send IP and other connection information directly to the destination, whose privacy practices also apply.
6. Processors and overseas processing
The application and database run on a personally operated server in South Korea; full-server image backups are on the operator's NAS in South Korea. There is no CDN. Email is managed through one Google Workspace Business Plus account, which also receives inquiries sent to admin@cat.moe. Processing follows contractual purpose limitations, safeguards, subprocessing, oversight and deletion conditions.
| Item | Email processing and transfers |
|---|---|
| Processor/recipient | Google Asia Pacific Pte. Ltd., the Workspace contracting entity for a South Korean billing address. Google Workspace privacy team; operator contact admin@cat.moe |
| Work and purpose | Email transmission/storage necessary for verification, password recovery, required contractual notices and support, reports and rights requests |
| Information | Sender/recipient addresses, authentication/reset links, notice and correspondence bodies/attachments, transmission records |
| Timing/method | Network transmission when sending, receiving and processing email |
| Countries | No data-region restriction configured. Google's disclosed data-center processing countries: United States, Singapore, Taiwan, Japan, Belgium, Canada, Chile, Denmark, Finland, Ireland, Mexico and Netherlands |
| Operator-controlled copies | Support, reports, rights requests and appeals: deletion 90 days after resolution; authentication and contractual-notice copies: seven days after sending |
| Google deletion | Generally a system deletion period of up to 180 days after an unrecoverable customer deletion instruction, subject to contractual exceptions including applicable legal preservation, explained below |
| Ground | PIPA Article 28-8(1)(3) with this disclosure, limited to outsourcing/storage necessary to form or perform the requested service contract |
| Refusal/effects | Decline email-based features or request restriction at admin@cat.moe. Registration, verification, recovery and email replies may be unavailable; anonymous creation and public reporting remain available |
The countries are possible data-center locations, not a statement that every message goes to every country. Storage is not guaranteed to remain in Korea or a particular country. Countries and subprocessors for support, maintenance and other activities are available in Google's published list.
The deletion period in Google's Cloud Data Processing Addendum is not measured from sending email and is not our seven-day backup period. Applicable Google Vault rules/holds require checking their scope and lawful preservation grounds; mailbox deletion does not mean instant deletion of every Google copy. This does not authorize indefinite retention without a ground. Delivered email is under its recipient's control.
7. Cookies and browser storage
We use no advertising or external analytics cookies.
| Cookie | Purpose and period |
|---|---|
better-auth.session_token (possibly prefixed __Secure- on HTTPS) | Login, seven days from issue/renewal, removed on logout |
cat-moe-history | Same-browser link history and protected access; browser-session cookie, with server records within 24 hours of session creation |
Authentication cookies cannot be read by JavaScript, and production uses HTTPS. Block or erase cookies in browser privacy/cookie settings; login, session history and protected access may be restricted or require authentication again. Browser session restoration may restore session cookies.
Blocking cookies alone does not stop server-side click analytics. Analytics rights requests use the channel below.
8. Rights and request handling
You or a lawful representative may request access, correction, erasure, restriction and withdrawal of consent-based processing at admin@cat.moe. No prescribed form is required. Identify the information, requested action and reply address. You do not need an account to request these rights.
We may request minimum additional information to verify identity/authority and locate records safely. For visits, provide a known short address and approximate time. Knowing an address does not authorize disclosure of another person's information. Rights handling does not include reconstructing unheld or erased records, introducing new visitor tracking or creating unrelated information. Custom analysis, certificates and format conversion outside statutory disclosure requirements are not separately provided. If records cannot safely be identified, we explain the limit and available verification options.
Requests are handled without delay within statutory action and notice periods, independently of ordinary support policy. Lawful deferral, restriction or refusal is explained with reasons and appeal methods within the applicable deadline. An additional-information request does not arbitrarily restart that deadline. Consent withdrawal does not extinguish separate lawful preservation duties; restricting necessary processing may end or limit the relevant feature.
Privacy infringement advice/reports: KISA Privacy Center, 118. Dispute mediation: Personal Information Dispute Mediation Committee, 1833-6972.
9. Children and safeguards
Registration and anonymous creation are for people aged 14 or older. We have no parental consent procedure for registration under 14 and take necessary protective measures, including restriction or erasure, when a related issue is established. This age limit does not mean we verify every short-link visitor's age.
We protect information through access and ownership checks, HTTPS, password hashing, restricted authentication information, rate limits, audits and backup management. Statutory safeguards and incident notice/reporting requirements apply, including legally specified indications of possible leakage under the law in force at the time. Required notices include statutory information and available remedies.
10. Responsible contact and changes
The privacy officer is Minwoo Jeong (정민우), cat.moe's individual operator known as p1nkjelly. The operator personally handles privacy protection and complaints at admin@cat.moe.
We disclose revisions, reasons and effective dates on the site. Minor corrections that do not disadvantage individuals or materially change processing or rights do not generate separate emails; material changes receive advance notice and any legally required individual notice or separate consent. The previous effective version applies before the displayed date, and announced Korean/English documents remain available by version. Publishing a policy does not itself supply the necessary ground for processing, disclosure or overseas transfer.