Privacy policy
Who operates CatDance, how we process data, and how to request deletion.
Last updated: 2026-10-08
Operator and contact
CatDance is operated by Nong Bao Yi, an individual developer based in China. Contact hello@catdance.app for privacy questions, access requests or deletion requests.
Information we process
Google sign-in provides account information such as your name, email, profile image and account identifier. We use account records and session cookies to authenticate you, associate your videos with your account and administer credits and free-trial limits.
Selecting a photo displays a local browser preview. Submitting it sends the image to our server and image moderation service. Approved images are stored and sent for video generation. Generation records include your account identifier, task status, input and output addresses, and credit activity; we do not store the full base64 image in the task database. Only upload pet or plush photos you have permission to use, not photos of people or sensitive personal information.
When purchases are available, we keep order, payment-status and credit records to deliver purchases, handle refunds and prevent duplicate charges. We do not store full payment card numbers. Support emails contain the information you choose to provide.
Storage and protection
Account, order and task records are stored in Neon PostgreSQL in AWS US East (Ohio), region us-east-2, United States. Uploaded images and generated videos are stored in Cloudflare R2. CatDance uses HTTPS for media transfer and authenticated database connections; R2 encrypts stored objects at rest. Administrative access and write operations are restricted using credentials and access controls.
Media are served through HTTPS URLs on our media domain for processing, playback and download. Anyone who obtains a media URL may access that file while it remains available; these URLs are not private, account-authenticated storage. Avoid sharing links you do not want others to access. No security measure guarantees absolute protection.
Service providers
- Google: sign-in and identity information.
- Neon: PostgreSQL hosting for account, order and task records.
- EvoLink / Alibaba Wan 3.0: EvoLink receives submitted media for moderation and video generation; Alibaba Wan 3.0 is the video generation model accessed through EvoLink.
- Waffo: payment processing as Merchant of Record (MoR) when checkout is available, including transaction and refund handling.
- Cloudflare: website hosting, delivery, security and R2 media storage.
These services process data needed for their functions under their own applicable terms and privacy policies. Because the operator is in China and infrastructure includes the United States and global services, data may be processed outside your country. CatDance's R2 deletion schedule does not control independent copies retained by third-party processors.
Retention
- Uploaded source images: R2 lifecycle rules expire objects under
uploads/petbeat/after 1 day from upload. - Generated videos: R2 lifecycle rules expire objects under
uploads/petbeat-results/after 7 days from upload. Download videos you wish to keep. - Lifecycle expiration is processed asynchronously, so removal is not guaranteed at an exact hour. These rules cover user media, not the site's reusable template assets.
- Account data are retained while your account is active, until you request account deletion. Deleting a media object does not itself remove the associated task or account record. Limited order, refund or security records may be retained where needed for legal obligations, disputes or fraud prevention; we explain any applicable exception when handling your request.
Your requests
Email hello@catdance.app to request access, correction, account deletion or earlier media deletion. We may verify ownership before acting. Deletion requests are handled by the operator; sending an email does not immediately delete data. We will explain the scope of deletion and any records that must be retained. Provider backups and independent processor records follow their respective retention procedures.
Cookies and acquisition source
Session cookies support login. A source cookie lasting up to 30 days records broad channels such as ChatGPT, Perplexity, Gemini, other or unknown and may be associated with orders for revenue attribution. This source tracking does not record your AI prompts or full referring-page URL. You can clear cookies through your browser, which may sign you out.