Privacy

Privacy

Allycat has no accounts, advertising trackers, or non-essential browser cookies.

What the server receives

Like any website, the server receives the requested address and normal connection information needed to return a response. Allycat does not configure product analytics or an error-reporting vendor in this project.

Operational request logs are disabled by default. A deployment may enable a restricted log containing a request reference, deployment, route path, response status, duration, coarse error class, and media cache result. It excludes query values, IP addresses, raw headers, provider responses, and stack traces. Retention defaults to 14 days and is configuration-bounded to 90 days.

Cat images

The application server obtains cat metadata and images from CATAAS. Browser-facing pages use Allycat URLs rather than contacting CATAAS directly.

Validated images may be held in a bounded in-memory rendition cache for up to seven days or until eviction or process restart. Cookies received by the server from CATAAS are not forwarded to visitors. Following a visible CATAAS source link leaves Allycat and makes a request to that service under its own policies.

Sharing and local browser features

The Share action uses the browser's share sheet when available or copies the canonical page address to the clipboard. Allycat does not receive the destination or people you choose to share with.

Retention and changes

No account or behavioral profile is stored. This notice must be updated before telemetry, persistent storage, or additional third-party browser requests are enabled.