Nekotree Logo

Privacy Policy

1. Who We Are

Nekotree is operated by NEKO CRAFT LIMITED, a company registered in the United Kingdom (Company No. 16912694).

Tax No: BRCT00003623627
Date of Registration: 15th December
Date First Trading: 01.02.2026
Website: nekotr.ee

For data protection inquiries, contact us at: nekocraftlimited@gmail.com

2. What Data We Collect

2.1 Data You Provide

  • Account Information: Email address, username, display name (collected via Clerk authentication)
  • Profile Content: Images, links, social media profiles, contact information, event details, cosplay information
  • Location Data: Event locations and addresses (if you choose to add them)

2.2 Data Collected Automatically

  • Technical Data: IP address (for security and rate limiting), browser type, device information
  • Usage Data: Pages visited, time spent, interactions with the service
  • Authentication Data: Login timestamps, session information (managed by Clerk)

3. How We Use Your Data

We process your personal data under the following legal bases:

  • Contract Performance: To provide the Nekotree service, display your profile, and manage your account
  • Legitimate Interest: To prevent fraud, abuse, and ensure security (e.g., IP-based rate limiting)
  • Consent: For any optional features you choose to enable

4. Third-Party Services

We use the following third-party services that may process your data:

5. International Data Transfers

Some of our service providers (including Clerk, Convex, and UploadThing) are based outside the United Kingdom and European Economic Area (EEA). When we transfer your data to these providers, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO) or participation in the UK-US Data Bridge (formerly EU-US Privacy Shield).

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide our services. When you delete your account (see our Data Deletion Guide), we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal compliance (e.g., tax records) or legitimate business purposes (e.g., preventing fraud).

7. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data (see our Data Deletion Guide)
  • Right to Restrict Processing: Request we limit how we use your data
  • Right to Data Portability: Request your data in a machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent where processing is based on consent

To exercise these rights, contact us at nekocraftlimited@gmail.com. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

8. Cookies and Local Storage

We use essential cookies and local storage to make Nekotree function properly:

  • Authentication Cookies: Set by Clerk to maintain your login session (essential)
  • Theme Preferences: Stored locally to remember your dark/light mode preference
  • Third-Party Cookies: Clerk and Convex may set cookies necessary for authentication and service functionality

We do not currently use analytics cookies or advertising cookies. If we introduce these in the future, we will update this policy and request your consent before using them.

9. Children's Privacy

Nekotree is not intended for users under the age of 13. We do not knowingly collect personal data from children under 13. If you believe we have collected data from a child under 13, please contact us immediately at nekocraftlimited@gmail.com.

10. Image Protection & Security

Watermark Protection

Nekotree provides optional watermark protection for your cosplay images. When enabled, a Nekotree watermark is automatically applied to your images to help protect them from unauthorized use and scraping. You can enable or disable watermarking for each cosplay page in your settings.

  • Watermarks are applied server-side and preserve your original image quality and file format
  • Watermarks appear in the bottom-right corner of images
  • You have full control over watermark settings for each cosplay
  • Original images are never modified - watermarks are applied on-the-fly when serving images

Image Proxy & Anti-Scraping

To protect your content from unauthorized scraping, Nekotree uses an image proxy system. This means:

  • Images are served through secure proxy endpoints
  • Direct access to original image URLs is restricted
  • Rate limiting prevents automated scraping attempts
  • Content Security Policy (CSP) headers protect against cross-site attacks

Benefits of Image Proxy

  • Protection: Prevents direct image URL access and hotlinking
  • Control: Allows watermark application based on your preferences
  • Performance: Images are cached for faster loading
  • Security: Validates image sources and prevents malicious content

Considerations

While our image proxy system provides significant protection, please note:

  • No protection method is 100% foolproof - determined scrapers may still access content
  • Watermarks can be removed with image editing software, though this requires effort
  • Proxy endpoints add a small processing overhead, but images are cached for performance
  • For maximum protection, consider combining watermarking with other measures like copyright notices

Content Security Policy

Nekotree implements Content Security Policy (CSP) headers to protect against cross-site scripting (XSS) attacks and other security vulnerabilities. These policies restrict which resources can be loaded and executed on our pages, providing an additional layer of security for both you and your visitors.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last Updated" date. Your continued use of Nekotree after changes become effective constitutes acceptance of the updated policy.

Last Updated: 2 January 2026