Privacy Policy
Effective date: 9 August 2026 · Last updated: 9 August 2026
This Privacy Policy describes how catfu (https://catfu.app) collects, uses, and shares information when you use our research catalogue product, website, and related services (the “Service”). Contact us at [email protected].
1. Who we are
catfu is a multi-tenant SaaS research workbench for cataloguing and searching content metadata (for example YouTube channel and video metadata, notes, and tags). Our public organization / product home is https://catfu.app.
2. Information we collect
2.1 Account and authentication
- Email address — when you sign in with a magic link or when an OAuth provider shares it.
- OAuth identity data — when you use Google, X (Twitter), Facebook, or other configured providers (for example GitHub or Discord): provider name, stable provider user id, and any email or display name the provider returns for sign-in. We use this only to authenticate you, link multiple sign-in methods to one account, and operate your session. We do not post to your social accounts or use OAuth to scrape your private social graphs for marketing.
- Session data — a session cookie (HttpOnly, Secure when served over HTTPS, SameSite=Lax) so you stay signed in.
- Magic-link tokens — short-lived, single-use tokens stored hashed server-side to complete email sign-in.
- Profile fields you provide — for example first name and UI theme preferences.
- Security / bot checks — when Cloudflare Turnstile is enabled, challenge results may be verified server-side.
- Login context — limited previous sign-in timing may be stored to show a “last signed in” style notice; we do not expose raw IP addresses in the product UI.
2.2 Product research data
- Queries you save, gathering Workspaces and Canvases, notes, tags, and favourites you create.
- Catalogue metadata you track (channel identifiers, titles, descriptions, and related research fields) stored per tenant.
- API keys you create (secrets are stored hashed or equivalent; we show prefixes/metadata only in the UI).
- Usage and quota counters needed to enforce free and paid plan limits.
2.3 Billing
If you purchase a paid plan, our payment processor (for example Stripe, and PayPal when configured) processes payment details. We receive subscription status, customer identifiers, and related billing metadata; we do not store full card numbers on catfu servers.
2.4 Technical logs
Like most web services, our infrastructure and edge (for example Cloudflare) may process IP addresses, user-agent strings, request paths, and error logs for security, reliability, and abuse prevention.
3. How we use information
- Provide, secure, and improve the Service (authentication, catalogues, search, quotas, support).
- Send transactional email (magic links, essential account or billing messages).
- Process payments and prevent fraud.
- Comply with law and enforce our Terms of Service.
We do not sell your personal information. We do not use OAuth access solely granted for sign-in to run unrelated advertising campaigns.
4. OAuth providers (Google, X, Facebook, and others)
When you choose “Continue with Google”, “Continue with X”, “Continue with Facebook”, or another configured provider, you are redirected to that provider to authenticate. We request only the scopes needed for sign-in (typically basic profile identity and email, depending on provider configuration). After callback, we store the provider identity linkage so you can sign in again and optionally link multiple providers under Profile → OAuth Connections. You can disconnect a provider in the product when another sign-in method remains available.
Those providers process your data under their own privacy policies. Review Google, X, Facebook (and any other IdP you use) policies before connecting.
5. Sharing and processors
We share data only as needed to run the Service, including:
- Infrastructure / edge — e.g. Cloudflare (tunnel, security, optional email delivery).
- Authentication providers — Google, X, Facebook, and other OAuth IdPs you choose.
- Payments — Stripe and/or PayPal when you subscribe.
- Email delivery — SMTP or Cloudflare Email for magic links and essential messages.
- Optional research add-ons — e.g. Scout / search APIs when enabled for your account.
- Legal — if required by law, regulation, or valid legal process, or to protect rights and safety.
6. Cookies and similar technologies
We use essential cookies for sessions and security (including OAuth state/link flows and Turnstile where enabled). We do not rely on third-party advertising cookies for the core product.
7. Data retention
We retain account, catalogue, and billing metadata while your account is active and as needed for legal, security, and accounting purposes. Magic-link tokens expire quickly (on the order of minutes). You may request deletion of your account by contacting [email protected]; we will delete or anonymize personal data except where retention is required by law or legitimate operational needs (for example completed invoices).
8. Security
We use HTTPS in production, hashed magic tokens, HttpOnly session cookies, and tenant-separated catalogue storage. No method of transmission or storage is perfectly secure; please use strong email account security and protect API keys.
9. International processing
We may process data in the countries where we or our processors operate. If you access the Service from another region, you consent to transfer to those locations as needed to provide the Service, subject to applicable law.
10. Children
catfu is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided data, contact us to request deletion.
11. Your choices and rights
Depending on your location, you may have rights to access, correct, export, or delete personal data, or to object to certain processing. Contact [email protected]. You may disconnect OAuth providers in Profile when another sign-in method remains, and manage billing through the in-product billing portal when available.
12. Changes
We may update this Privacy Policy. We will post the revised policy on this page with a new effective date. Material changes may also be communicated by email or in-product notice when appropriate.
13. Contact
Privacy questions:
[email protected]
Organization / product:
https://catfu.app
Terms of Service:
https://catfu.app/terms
This policy is written for catfu’s current SaaS research product and OAuth consoles. It is not a substitute for formal counsel as the business scales into additional jurisdictions.