We believe you should know exactly what we keep about you. This policy lists everything the Kitty Kingdom website, Discord server and bots store, why, who can see it, and how long it is kept.
The short version
- We never sell your data and there are no ads or third-party trackers.
- Passwords are hashed, two-factor secrets are encrypted, and staff can't see your password.
- Your stats count your activity (channels, hours, who you chat with) but never store your message text.
- Staff can review moderation records, logs and ticket transcripts to keep the community safe.
- Administrators can see account details such as your email and your sign-in devices and IP addresses, for security.
- You can delete your account from My Account, and ask us for a copy of your data or to delete more.
Part 1 What we collect
1. Who we are and what this covers
Kitty Kingdom ("Kitty Kingdom", "we", "us" or "our") is an online community operated by its owner and administration team. This Privacy Policy explains what personal information we collect, why we collect it, how it is used, stored and shared, how long it is kept, and the choices and rights you have.
It applies to (together, the "Services"):
- the website at kittykingdom.net and its subdomains (the "Site"), including accounts, the Store, leaderboards, news, the staff page and My Account;
- the Kitty Kingdom Discord server (the "Server"); and
- the Discord bots we operate in the Server, including the main bot, the moderation bot, the ticket system and the economy bot (the "Bots"). Dating profiles made with our former dating bot moved to Social on the Site.
Discord itself is operated by Discord Inc. under its own Privacy Policy. We do not control what Discord collects. This policy only covers what Kitty Kingdom collects and does with information.
2. Information you give us on the Site
When you create and use a Site account we store:
- Account details: your email address, username, optional display name, the date you accepted these policies, when the account was created, last logged in and last active, and whether your email is verified.
- Password: never stored in readable form. We keep a salted one-way hash (scrypt). Staff cannot see your password.
- Optional phone number: if you add one on My Account. It is only visible to you and to Site administrators. (Social links you add to your Social profile are covered under Social below.)
- Two-factor authentication: if you turn it on, the authenticator secret (encrypted with AES-256-GCM), your backup codes (stored only as hashes) and when each was used.
- Security tokens: email verification links (valid 72 hours), password reset links (valid 1 hour) and Discord link codes (valid 10 minutes). These are stored as hashes or expire automatically.
- Purchases and gifts you make in the Store, including any gift message ("love letter") you write, which is delivered to the recipient.
3. Information from Discord and the Server
The Site and the Bots work together. When you link your Discord account (with /link) or take part in the Server, we process:
- Discord profile data: your Discord user ID, username, display name, server nickname, avatar, account creation date, the date you joined the Server, your roles and whether you are boosting or in the Server.
- Join application: the answers you give when applying to join, which can include your age and date of birth. Your age and birthday on My Account are read from this application.
- Verification records: for age-restricted (18+) areas, the fact that you were verified, when and by which staff member. We record the result, not copies of identity documents, unless you choose to share images in a verification ticket (see Tickets below).
- Community and economy data: level, XP, Leaf balance, total messages sent, voice time, server bumps, daily streaks, inventory, purchases, gifts, game results (for example slots and Wordle), and Question of the Day answers.
- Activity statistics (My stats): counts of how many messages you send in each channel and at what hours and days, how many words, emojis, images, links and stickers you post, how often you reply to, mention, chat back-and-forth with or react to other members, and how long you spend in each voice channel and with whom, and which topics your messages touch. Topics are worked out by a small AI model that runs on our own bot (no outside service): it reads each message as it arrives, notes which of our topics it relates to (including 18+ topics) and any topic keywords from a fixed list (such as "minecraft" or "pizza"), and then discards the message. We do not store the text of your messages for these statistics, only counts. For the topic map's message viewer the bot also keeps the ids (not the text) of your 25 newest messages for each topic and topic keyword; when you open the viewer, the website fetches those messages and a few around them directly from Discord, only from channels you can currently see, and does not save them. Deleted messages no longer appear. Voice statistics also use the server's voice-channel logs (joins, leaves, camera and mute changes) and the VC reward messages the bot posts (session length, rewards and who was in the call). They power your My stats page (including your "server bestie", friendship map and topic map), which only you can open.
- Badges: the badges worked out from your statistics, which ones you pin or use as a title, and when you earned or changed tier on each (saved when you open My stats). Your pinned badges and title are shown on your profile card and your Social profile; the rest only you can see. Deleting your Site account deletes these dates.
- Social (dating and friends) profiles: if you use Social on the Site (including a profile you made with our former dating bot), the profile you create (which can include sensitive details such as gender, sexuality and relationship preferences), any photos or art you upload, your prompts and display choices, and your likes, passes, matches, friends and blocks. Photos have location and other hidden metadata removed when you upload them. To match people by meaning, our main bot turns the interests, dislikes, bio and location in your profile into numbers ("vectors") with a small model that runs on our own bot host; nothing is sent to an outside AI service. Your age there is worked out from the date of birth on your join application (or account) so it stays current; your birthday itself is never shown. If you link a partner, the link only appears on profiles after they confirm it, and either of you can remove it. We record who viewed a profile and when, so members can see who viewed theirs; you can browse anonymously in Social settings. You control your profile and settings and can edit, pause or delete it at any time on the Social page.
- Social messages and notifications: private messages you send or receive in Social, message requests, whether a conversation has been read, and notifications (the bell on the Site) about likes, matches, messages, friend and partner requests and profile views.
4. Moderation, tickets and logs
To keep the community safe, the following is recorded and can be reviewed by staff:
- Moderation records: warnings, mutes, kicks and bans, with the reason, the staff member or automated system that issued them and, where relevant, the message that caused them.
- AutoMod: our bot automatically checks messages, edits and server nicknames for blocked words, scam or phishing links, invites to other servers and spam. When it acts, it records what it caught (the rule, the matched word or link, and the start of the message) for 90 days so staff can review it and handle appeals. It may remove the message, give a warning or a temporary mute, reset a nickname, or DM you about it; it never kicks or bans anyone.
- Server logs: our staff log channels record events such as edited and deleted messages (including their content), member and role changes, and joining, leaving and moving between voice channels. These logs are mirrored to our database so staff can search them on the Site.
- Live chat mirror: messages sent in the Server (text, attachments and author) are copied to our database so administrators can moderate from the Site. These copies are deleted automatically after 72 hours.
- Support tickets: ticket conversations are recorded. When a ticket is closed, a transcript is created containing every message, attachment, image, video, sticker and reaction, the participants' names and avatars, and any messages that were edited, deleted or had attachments removed while the ticket was open. The staff copy is stored in a private staff-only channel. The member who opened the ticket can read their own copy on the Site (My Account → Transcripts, which needs a Site account with that Discord account linked). That copy has images, videos, files and stickers removed, and only they and staff can open it.
- Punishment appeals: if you appeal a punishment at kittykingdom.net/appeals, you sign in with Discord (we only ask Discord for your user ID, username and avatar) so we know the appeal is really from you. We store your appeal message, the punishment it is about, the optional email address you give for the decision, and a history of the review (who decided, when, and their reply). Only administrators can see appeals, and they do not see your email address; it is only used to email you about that appeal.
- Audit log: actions administrators take on Site accounts (for example resetting a password or changing roles) are logged with who did it and when.
5. Information collected automatically
- Sign-in sessions and devices: each time you log in we record a session with your IP address, browser and operating system (from your user agent), your approximate city, region and country (from our hosting provider, based on your IP address), and when the session was first and last used. This lets us keep you signed in, lets administrators sign out a device, and helps detect suspicious logins. Administrators can see this information and may use a third-party IP lookup service when investigating account security.
- Site statistics: we count page views with our own first-party statistics, with no third-party analytics or advertising trackers. For each page view we record the page, time, time spent, referring website, campaign tags, approximate country and region, device type, browser, operating system, screen size and whether you were signed in. Visitors are identified only by a random ID stored in your browser, which is hashed before it is saved. We do not store IP addresses for statistics. If your browser sends Do Not Track or Global Privacy Control, no statistics are recorded for you.
- Online count: a short-lived record (deleted after 5 minutes) that a browser has the Site open and which page of the Site it is on, used for the "on the website" counter. While you are signed in and online, administrators can see which page you have open (for example "Browsing the Store") to help with support and keep the Site running smoothly.
- Abuse prevention: attempts to log in, sign up, reset passwords and similar actions are counted per IP address and per account for a short window to stop brute-force attacks. These records expire automatically.
- Server logs of our providers: our hosting provider may keep standard technical logs (such as request times and IP addresses) for security and reliability, under its own policies.
Part 2 How it's used & shared
7. How we use information and our legal bases
We use personal information to:
- create, secure and run your account and the Services you ask for (performance of our agreement with you);
- link your Site account to Discord, sync roles, levels, Leaves and purchases, and show your stats (performance of our agreement);
- verify ages for 18+ areas, moderate the community, handle tickets and reports, and investigate rule-breaking, fraud and abuse (our legitimate interest in a safe community, and to protect members);
- keep the Services secure, prevent spam and brute-force attacks, and fix problems (legitimate interests);
- understand how the Site is used so we can improve it, using privacy-friendly statistics (legitimate interests);
- send account emails such as verification, password resets and security notices (performance of our agreement). We do not send marketing emails;
- comply with legal obligations and respond to lawful requests (legal obligation); and
- anything else you have clearly agreed to (consent), which you can withdraw at any time.
Some information, such as sexuality or preferences in dating profiles or 18+ role choices, may be considered sensitive. We only process it because you chose to provide it for that feature, and you can remove it at any time.
8. Who can see your information
- Other members can see what Discord and the Server normally show, plus your name, avatar and ranks on leaderboards, and your public staff profile if you are on the staff team. Your My stats page is only visible to you.
- Staff (moderators and helpers) can see moderation records, server logs, join applications and the Staff Panel.
- Dating profiles and photos are only shown to signed-in members who hold the 18+ Verified role. You can hide your age and last-active time, pause your profile, and block anyone. Social messages are not visible to other members or to moderators. If you report a message, moderators see only that message and up to two messages before and after it; if you report a profile or photo, staff see that profile as it was when reported. Administrators can read Social conversations when needed for safety, to investigate reports, harassment or scams, or to enforce the rules; every conversation an administrator opens is recorded in an audit log. Staff may review uploaded photos to keep Dating safe for work.
- Administrators can additionally see Site account details (email, phone, birthday, linked Discord, sign-in sessions and devices), ticket transcripts, the live chat mirror, inventories and purchase history, and can manage accounts, roles and inventories. To help with support and fix problems, an administrator can also view the Site as a member who has linked Discord and verified their email, seeing the pages exactly as that member does. This view is read only (nothing can be changed or bought), ends after an hour, and each use is recorded in the audit log. Administrator actions are logged.
- We do not publish your email, phone number, IP address or date of birth.
10. How long we keep information
| Information | Kept for |
|---|---|
| Site account, contact details, 2FA | Until you delete your account |
| Sign-in sessions and devices | Until you delete your account (you can ask us to clear old ones) |
| Site statistics | About 13 months, then deleted automatically |
| Live chat mirror | 72 hours, then deleted automatically |
| Dating profile, photos, likes and matches | Until you delete your dating profile (deleting it removes your photos, likes and matches) |
| Dating messages | While both members keep the conversation. A message you unsend (delete for everyone) disappears for both of you, and one you delete for yourself disappears only for you, but site admins can still see both for safety and moderation. Reports keep a copy of what was reported for as long as needed for safety |
| Notifications | 60 days, then deleted automatically |
| Online count, rate limits, link codes | Minutes to hours, deleted automatically |
| Ticket activity (while a ticket is open) | Until the ticket is closed and its transcript saved (at most 21 days if it is never closed) |
| Ticket transcripts, moderation records, punishment appeals, server logs, join applications, verification records | As long as needed for community safety and to handle appeals, disputes and repeat rule-breaking |
| Levels, Leaves, inventory, purchases, activity statistics | While you are part of the community, or until you ask us to delete them |
11. How we protect information
We use industry-standard safeguards, including encrypted connections (HTTPS with HSTS), salted password hashing, encrypted two-factor secrets, signed session cookies that can be revoked, rate limiting, strict browser security headers, role-based access for staff and administrators, and sandboxed viewing of ticket transcripts. Secrets such as bot tokens are kept out of our code.
No system is completely secure. Please use a strong, unique password and turn on two-factor authentication. If we become aware of a breach that affects your personal information, we will notify affected members and authorities where the law requires.
Part 3 Your rights
12. Your choices and rights
You can:
- view and update your account details, contact details and display name on My Account;
- unlink Discord at any time (Discord-only features stop working until you link again);
- delete your Site account from My Account. This deletes your account and sign-in sessions. Staff accounts must first have their staff role removed;
- turn off Site statistics for yourself by enabling Do Not Track or Global Privacy Control in your browser; and
- edit, pause or delete your dating profile, hide your age or activity, unsend your messages or delete them for yourself (admins can still see them for safety), and block members on the Social page.
Depending on where you live (for example under the EU or UK GDPR, or California and other US state privacy laws), you may also have the right to access a copy of your personal information, correct it, have it deleted, restrict or object to certain processing, receive it in a portable format, and withdraw consent. To make a request, open a support ticket in the Server or contact an administrator. We may need to verify your identity, and we will respond within the time the law requires (usually 30 days). Some information, such as moderation records, may be kept where we have a legitimate need, for example to prevent banned members from returning, and we will tell you if so. We will not treat you differently for using your rights. If you are unhappy with our answer you can complain to your local data protection authority.
13. Age requirements
The Services are only for people 18 years of age or older. We do not knowingly collect information from anyone under 18. If we learn that someone under 18 has an account or has joined the Server, we will remove their access and delete their information, except for any record we need to keep them from rejoining. If you believe someone under 18 is using the Services, please tell a staff member.
14. International transfers
Our providers store and process information in the United States and other countries whose data protection laws may differ from yours. Where the law requires, we rely on appropriate safeguards (such as our providers' standard contractual clauses) for these transfers. By using the Services, you understand that your information will be transferred to and processed in these countries.
15. Changes to this policy
We may update this policy as the Services change. We will change the "Last updated" date above, and for significant changes we will give notice on the Site or in the Server. Continuing to use the Services after a change takes effect means you accept the updated policy.
16. Contact us
Questions, requests or concerns about privacy? Open a support ticket in the Kitty Kingdom Discord server or message an administrator. You can find the team on the Staff page.