GDPR Notice
CLOVERA GDPR NOTICE
Last updated: September 14, 2026
Contact: kitteniversestudios@gmail.com
1. Applicability
This section is intended to support Clovera's privacy disclosures for users in the European Economic Area and similar jurisdictions.
2. Controller
For purposes of applicable data protection law, Clovera acts as the controller of personal data processed in connection with the service. Kitteniverse Studios is not a registered company; the controller is therefore the natural person who operates the project, from Türkiye, and is reached at the address in Section 11. There is no establishment in the Union and no establishment in the United Kingdom.
No representative has been designated under Article 27 GDPR or under the equivalent provision of the UK GDPR. That Article applies where a controller outside the Union processes the personal data of people in the Union in connection with offering goods or services to them or monitoring their behaviour. Clovera does not offer its services to any Member State in that sense and does not monitor behaviour there: the landing page, the descriptions offered to search engines and the rest of the promotional material are published in English only, no advertising is placed in any Member State, no national domain is used, no price is quoted in euro, and the service is not distributed through a national app store. The interface can be displayed in other languages at the choice of someone who has already found Clovera and created an account, which is a function of the service rather than an approach to a market. Section 1 of the DSA Information document sets the same assessment out at greater length. The position is kept under review as the service grows, and a representative is designated and named here if it changes. Nothing in this paragraph is a reason to delay an answer: a data subject in the Union or the United Kingdom may write to the address in Section 11 and will be answered.
3. Lawful Bases
Clovera may rely on contract necessity, legitimate interests, consent, and legal obligations, depending on the processing involved.
3a. Account Data Collected
Registration requires a username and a password only. Clovera does not ask for and does not hold an email address or telephone number for any account; an internal, non-deliverable placeholder address is generated so that the account record has a unique identifier. Beyond that, an account holds what its holder chooses to put in it: a display name, pronouns, a short biography, a custom status, an accent colour, a profile photo, a banner, a language preference, and, for the marker shown on a profile, the day and month of a birthday. Two consequences follow and are stated here because they affect data subject rights: service communications reach users only inside the service (on-screen notices, the policy re-acceptance screen, and push notifications where enabled), and identity verification for a rights request is performed through the account itself rather than through a registered contact address. The year of a birthday is never asked for and never stored, so Clovera holds no date of birth and cannot verify or derive a user's age.
4. Login Records and Address Digests — Processing Details (GDPR Article 13/14 Notice)
Each successful login event causes Clovera to record which account signed in, when, and the User-Agent string of the browser. Nothing derived from the IP address of the connection is written to that record.
The following information is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR):
(a) Data processed in the login record: The associated user account identifier, the date and time of the login, and the User-Agent string. The login record holds no IP address, no digest of one, no digest of the surrounding network range, no autonomous system number and no network category. Clovera formerly recorded those and no longer does, because behind proxies and carrier-grade network address translation the address reaching the server was frequently not the user's own and the record therefore associated unrelated accounts. No geographic location is derived from any address at any point.
(b) Address digests kept elsewhere: While a request is being handled the server necessarily sees the IP address, and uses it at that moment for rate limiting, for checking the address against a ban already in force, and, where bot protection is enabled, for the challenge verification described in Section 8(b). Afterwards the address is retained only as a one-way keyed cryptographic digest (HMAC-SHA-256), and only as follows: (i) a digest of the address used at registration, stored on the account record, to limit the number of accounts that can be created from one address; (ii) a digest of the address and the User-Agent string on every active session record, which is what allows a user to review and revoke their sessions in settings — created for every session, independently of the optional feature in Section 6; (iii) a record of each failed login attempt — and of a recovery key offered and refused — consisting of a digest of the address, the username attempted, the reason for the failure, and the User-Agent string, kept to detect password-guessing and account-takeover attempts, and carrying no account identifier because the username attempted need not belong to an existing user; (iv) a digest of the address stored with a persistent-session token under Section 6; (v) a digest recorded as a banned address when an account is banned, derived from the digests held under (iv), which may be retained after the account itself is erased; (vi) a digest of the address, with the User-Agent string, on a request to reset a password that is to be approved from a device still signed in to the account, compared with the digests held under (ii) so that the person deciding on the request is shown whether it came from an address the account has signed in from before, and deleted when the account is erased; and (vii) the counters that enforce rate limits, each holding a digest of the address, the name of the action limited, a count reset when the window passes, and the times the window opened and was last touched, carrying no account identifier. The raw address is not stored in any of these.
(c) Purpose and legal basis: The purpose of this processing is to support account security, detection of unauthorized or suspicious access, abuse prevention, and enforcement of platform rules. The legal basis is legitimate interests (Article 6(1)(f) GDPR). Clovera has assessed that users have a reasonable expectation that login activity is monitored for security, and that this processing does not override users' fundamental rights given the pseudonymous nature of the data (hashed IP, no raw address).
(d) Retention: Login records, session records, recovery requests and the registration digest are retained for as long as reasonably necessary for the security and enforcement purposes described above; they are not deleted on a fixed schedule, and those tied to an account are deleted when the account is erased under Section 9. Failed login records and rate-limit counters are retained independently of any account, since they are not linked to one. A digest recorded as a banned address may be retained after erasure, for as long as the enforcement purpose requires.
(e) No automated profiling: This processing does not involve automated decision-making or profiling within the meaning of Article 22 GDPR.
(f) No third-party disclosure: Login records are not shared with, disclosed to, or accessible by any third party except where required by law or necessary to investigate a serious safety or legal matter. This is separate from the disclosure of the IP address itself to a bot-protection provider on the login and registration pages, which is described in Section 8(b).
(g) Security: The digest is derived using a keyed one-way function (HMAC-SHA-256) with a secret key held only by Clovera. The key is required because the space of possible IPv4 addresses is small enough that an unkeyed digest could be reversed by exhaustive search; keying the digest removes that possibility for anyone who does not hold the key.
(h) Right to object: Users have the right to object to processing based on legitimate interests under Article 21 GDPR. Objection requests may be sent to kitteniversestudios@gmail.com. Clovera may decline to cease processing where it can demonstrate compelling legitimate grounds, such as ongoing security investigations.
5. Public Visibility of Content — Processing Details (GDPR Article 13/14 Notice)
Some personal data a user publishes on Clovera is made available to the public at large, and part of it is offered to search engines. Because that audience is wider than the service's signed-in users, it is described here as a separate processing operation.
(a) Data processed and recipients: Content a user marks public — a public feed post and the files attached to it, a published blog article, the front page of a community the owner has listed publicly — together with the author's username, display name, profile photo, banner, and the reactions and comments on the item, is served to any visitor without an account and is listed in Clovera's sitemap, so that search engines and AI crawlers may fetch and index it. The recipients are therefore the general public and the operators of those crawlers, and this constitutes a transfer to any country from which the pages are fetched.
(b) Readable but not indexed: In a community the owner has listed publicly and left open to guests, the text and announcement channels, the forum listing and the forum threads are readable by any visitor holding the link. Those pages are excluded from the sitemap and are served with a "noindex" instruction in the page and in the response headers, so that they are not placed in a search index unless the operator switches indexing on for the deployment. Voice, mission, counting and showcase channels are never readable in this way, and permissions that hide a channel from everyone hide it from visitors as well.
(c) Purpose and legal basis: To publish what the user has chosen to publish and to allow a community to be found. The legal basis is performance of the contract with the user for content the user has actively marked public (Article 6(1)(b) GDPR), and Clovera's legitimate interest in making publicly listed communities discoverable (Article 6(1)(f) GDPR) for the community pages, the owner having chosen to list the community publicly. Guest reading of a publicly listed community is on unless the owner turns it off in Community settings → Visibility.
(d) Limits of erasure: Once content has been fetched by another person, by a search engine or by a crawler, Clovera can stop serving it but cannot recall the copy already taken. Deleting an item or making it private removes it from Clovera and is what causes search engines to drop it in time. Users should treat anything marked public as published.
(e) Right to object: A user may make a post or a blog article private or delete it at any time, and a community owner may close guest reading, at which point the processing under this Section ceases for that content. Objections under Article 21 GDPR may be sent to kitteniversestudios@gmail.com.
6. Persistent Session — Processing Details (GDPR Article 13/14 Notice)
Clovera offers users an optional feature presented at login as "Keep me signed in on this network". When a user opts in, Clovera places a random device token in a cookie on that browser and stores a digest of that token, together with a one-way keyed cryptographic digest (HMAC-SHA-256) of the address the user was connecting from, against the user account, so that the session can be restored without the credentials being re-entered.
The following information is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR):
(a) Data processed: A digest of the device token, a one-way keyed cryptographic digest of the user's IP address, and the associated user account identifier. The raw IP address is not stored.
(b) How the session is actually restored: By the device cookie alone. A returning browser that presents the token has the session restored whatever address the request comes from; the stored address digest is not consulted for that purpose, despite the wording of the option. This is stated because it bears both on the security risk a user takes by enabling the feature and on the basis for keeping the address digest at all.
(c) Purposes and legal bases: Two purposes, with two different bases. Restoring the session at the user's request rests on consent (Article 6(1)(a) GDPR), expressed through the voluntary selection of the option at login and withdrawable at any time. Keeping the address digest rests on Clovera's legitimate interest in making an enforcement decision effective (Article 6(1)(f) GDPR): where the account is banned, the digests held with its persistent-session tokens are recorded as banned addresses so that the same address can be refused. That second purpose is not covered by the consent and is not ended by its withdrawal, though it cannot arise for a token that has already been deleted. Users who do not select this option have no persistent token and no digest stored under this Section. This is a distinct record from the session address digest described in Section 4(b)(ii), which is created for every session regardless of this choice.
(d) Retention: A token that is not revoked is retained for as long as the user account exists; it is not deleted on a fixed schedule. The accompanying device cookie expires five years after it is set. Tokens are removed when the account is erased under Section 9 and when the account is banned; a digest already recorded as a banned address is governed by Section 4(d).
(e) Right to withdraw consent, and to object: Consent may be withdrawn at any time by logging out, by signing out of all other devices, or by revoking an individual token in Settings → Sessions; each of these deletes the stored token and the digest held with it. Withdrawal does not affect the lawfulness of processing prior to withdrawal. The right to object under Article 21 GDPR applies to the legitimate-interests purpose in (c).
(f) No automated profiling: This processing does not involve automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR. A ban is imposed by a human administrator; the address digest only gives effect to that decision.
(g) No third-party disclosure: The hashed IP address and session token are not shared with, disclosed to, or accessible by any third party.
(h) Security: The digest is derived using a keyed one-way function (HMAC-SHA-256) with a secret key held only by Clovera, so the original address cannot be recovered by exhaustive search.
7. KittenAI Features and Automated Moderation — Processing Details (GDPR Article 13/14 Notice)
Clovera's built-in AI features ("KittenAI") — conversation summaries, message translation, Live Translation, reply suggestions, Catch-Up digests, the KittenAI chat assistant, writing assistance, and automated content moderation — are powered by Google's Gemini models, accessed through the Google Gemini API.
The following information is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR):
(a) Data processed: The content submitted to or covered by the relevant feature. Depending on the feature, this may include the text of direct messages, group messages, and channel messages together with participants' display names; posts, post comments, and blog articles; usernames and profile text; the name, description, welcome message, and channel names of a community and the name of a group chat; messages sent to the KittenAI chat assistant, together with the earlier messages of that assistant conversation and, where the user attaches one of their own direct or group conversations to it as context, the last forty messages of that conversation with the sender names; and images (profile photos, banners, server icons, and post attachments) submitted for automated moderation; together with limited context such as the target language. No account identifier is transmitted; the user identifier is used only within Clovera to apply per-user rate limits.
(b) Recipient and processor: Google (Google LLC and/or its regional affiliates, such as Google Ireland Limited), acting as a processor on Clovera's behalf via the Google Gemini API. Content is decrypted on Clovera's servers before transmission to Google and is processed by Google subject to Google's applicable API and data processing terms. Clovera uses a Gemini API service tier under which content submitted through the API is not used to train or improve Google's models and is not subject to human review for that purpose.
(c) Purpose and legal basis: For user-initiated features and Live Translation (an opt-in setting, off by default), the purpose is to provide the assistance the user has requested; the legal basis is the user's consent (Article 6(1)(a) GDPR) and, where the feature forms part of the requested service, performance of a contract (Article 6(1)(b) GDPR). For automated content moderation, the purpose is protection of users, prevention of abuse and illegal content, and enforcement of platform rules; the legal basis is legitimate interests (Article 6(1)(f) GDPR) and compliance with legal obligations (Article 6(1)(c) GDPR).
(d) Scope of automated moderation: Moderation runs without being requested on feed posts and post comments — including posts that are not public — blog articles, usernames chosen at registration or changed later, profile text, profile photos, banners, server icons, messages sent by creator bots, the name, description, welcome message, and channel names of a community, the name of a group chat, and messages and forum posts in the channels of communities that have enabled moderation. A user's own direct messages and group messages are not subject to that general moderation. They are read by one automated process only — the serious-crime screen described in (d-bis) below, and only where the operator has enabled it; apart from that screen, they are transmitted under this Section only where a conversation participant uses one of the user-initiated features or Live Translation on the conversation.
(d-bis) Serious-crime screen for messages: Clovera can be configured by its operator to put the text of each direct message and group message to KittenAI with a single question — whether the message is itself a step in organised or other grave crime. The screen is off by default; while it is off, no direct or group message is read by it. The categories are closed and are listed in Section 15(e) of the Privacy Policy: running a criminal organisation; trafficking or smuggling people, forced labour, and forced prostitution; terrorism; dealing in drugs, firearms, or explosives; the sexual abuse of children; arranging violence for another party; and laundering money, trading stolen payment or identity data, or producing counterfeit money or documents. It is not general moderation of private conversation: insults, threats made in anger, hate, harassment, sexual talk between adults, jokes, roleplay, fiction, personal drug use, and discussion of crime as a subject are outside it and are not flagged. Only the text of the single message is transmitted, with no username, display name, identifier, or other message from the conversation; messages carrying a file and messages already deleted are not read. Where no category is found, nothing is recorded and no trace of the reading is kept. Where one is found, a case is opened for a human administrator holding the date, the category, the sending account, the name of the group chat where applicable, and an encrypted excerpt of at most 200 characters. Nothing the screen reads is used for profiling, ranking, targeting, or any other purpose. Legal basis: legitimate interests in preventing the service from being used for serious crime and in protecting its users (Article 6(1)(f) GDPR), and compliance with legal obligations to act against illegal content and to cooperate with lawful orders (Article 6(1)(c) GDPR). The screen removes nothing and restricts nothing of its own motion; every consequence for a user follows from a human decision on the case.
Account, community, and group review: at intervals Clovera also reviews accounts, communities, and groups for spam, deception, and coordinated attacks. Beyond the texts listed above, this review relies on counts derived on Clovera's own servers from usage data — publishing frequency, the number of distinct direct-message recipients who never replied or who blocked the sender, group additions, friend requests, blocks, reports, earlier automated removals, community invite links and membership bursts, and a match between an account's address digest and a ban record — none of which is transmitted to Google and none of which involves reading a private or group message. Legal basis: legitimate interests (Article 6(1)(f) GDPR) in protecting users and the service from spam, fraud, and abuse.
(e) Third-party processing note: Content a user sends to others may be processed under this section when another conversation participant uses a KittenAI feature on the conversation, or when the content is subject to automated safety moderation.
(f) International transfers: Google may process this content on servers located outside the EEA, including in the United States. Transfers rely on the safeguards provided under Google's data processing terms, such as adequacy mechanisms (including the EU–U.S. Data Privacy Framework, where applicable) and/or standard contractual clauses.
(g) Retention: Clovera caches translation results in encrypted form to reduce repeat processing and retains AI-related records only as long as reasonably necessary. A conversation with the KittenAI chat assistant is an exception worth stating: it is kept in plain text on Clovera's servers so that it can be displayed again and sent back as context for the next question, until the user clears it on that page or the account is erased. Google's retention of API request data is governed by Google's applicable API terms.
(h) Automated decision-making: Automated moderation may result in content being blocked, removed, or restricted without prior human review, and may place a community on hold — hidden from discovery and closed to new members — pending human review; the hold is reversible. The account, community, and group review and the serious-crime screen for messages each produce a case for a human administrator and do not themselves suspend an account, close a community, dissolve a group, or remove a message; those decisions, which could have a significant effect on the person concerned, are taken by a human, so the review does not constitute a decision based solely on automated processing within the meaning of Article 22 GDPR. Users may contest a moderation decision and request human review by contacting kitteniversestudios@gmail.com.
(i) Right to object and withdraw consent: Users may withdraw consent for user-initiated features by not using them, and for Live Translation by disabling it in settings at any time. Users may object to processing based on legitimate interests under Article 21 GDPR by contacting kitteniversestudios@gmail.com; Clovera may continue processing where it can demonstrate compelling legitimate grounds, such as safety and abuse prevention.
8. Other Recipients — Processing Details (GDPR Article 13/14 Notice)
Beyond Google's role under Section 7, the following recipients receive personal data when Clovera is used.
(a) Hosting and infrastructure. Clovera's application and database run on a third-party hosting platform, which processes all data stored or transmitted by the service in order to operate it, as a processor acting on Clovera's instructions.
(b) Bot protection — Cloudflare, Inc. (Turnstile) and Intuition Machines, Inc. (hCaptcha). Where the operator has enabled bot protection, the login and registration pages load the provider's challenge script, and Clovera transmits the challenge token together with the visitor's IP address to the provider in order to verify the result. The address is transmitted in full for this check, even though Clovera stores only a digest of it. The provider may set its own cookies or browser storage and collect browser signals in order to distinguish automated traffic. Purpose: prevention of automated account creation and credential-guessing. Legal basis: legitimate interests (Article 6(1)(f) GDPR). This applies only to the login and registration pages and only while the protection is enabled.
(c) Google Fonts (Google LLC / Google Ireland Limited). Clovera's pages load two typefaces from Google's font servers. Because the browser fetches them directly, Google receives the visitor's IP address, User-Agent string, and the fact that a Clovera page was loaded. This occurs on every page view, including for visitors who are not signed in and have no account, and constitutes a transfer outside the EEA. Purpose: consistent presentation of the service. Legal basis: legitimate interests (Article 6(1)(f) GDPR). Users who prefer to avoid this transfer can block requests to Google's font domains in their browser; the service remains fully usable with fallback typefaces.
(d) Push notification delivery. If a user enables push notifications, their browser registers with the push service operated by the browser's vendor (for example Google, Mozilla, Apple, or Microsoft). Clovera stores the resulting subscription endpoint and encryption keys and sends notifications through that service, which therefore learns that a notification was sent to that subscription and when; the content is encrypted in transit to the browser. Purpose: delivery of the notifications the user has asked for. Legal basis: consent (Article 6(1)(a) GDPR), given by enabling push notifications, which are off by default and can be turned off at any time in settings.
Clovera does not use analytics, advertising, tag-management, or audience-measurement services, and embeds no third-party content other than what is listed in this Section and Section 7.
8a. Calls, Voice Channels and Screen Sharing — Processing Details (GDPR Article 13/14 Notice)
Clovera offers one-to-one calls, started from a direct message and carrying sound only, and voice channels inside a community, carrying sound and, where a member shares a screen, the picture of that screen or window with its sound where the sharer includes it.
(a) How the media travels: not between the participants and not through any third party. Each participant's stream travels over an encrypted connection to Clovera's own server, which forwards it to the other participants from memory. No STUN, TURN, or other relay operated by anyone else is used, and no recipient beyond the other participants receives it. Because it is forwarded by Clovera's server it is not end-to-end encrypted, and that server is technically in a position to read it while it passes.
(b) Data processed and retained: the sound and the shared picture are held only for the moment they are being forwarded. Nothing is recorded, nothing is written to disk, and no transcript is produced. What is retained is a record that a call took place, between which two accounts, whether it was answered, and when it began and ended; and, while a user is in a voice channel, that they are in it, together with whether they are muted, deafened, or sharing a screen, and by whom they were muted where a moderator muted them. Those records are deleted when the account is erased under Section 9.
(c) Purpose and legal basis: to provide the call the user has asked for, which is performance of the contract for the service (Article 6(1)(b) GDPR). The record of who is present in a voice channel exists so that the channel can show its participants and so that a moderator can act on what happens in it, which rests on the same basis and, for the moderation part, on legitimate interests (Article 6(1)(f) GDPR).
(d) No AI processing and no moderation: no KittenAI feature and no automated review is applied to a call, a voice channel, or a shared screen. Nothing spoken or shown is transmitted to Google or to any other processor, and Section 7 therefore does not apply to it.
(e) Consequence for a complaint: since nothing is retained, Clovera cannot produce what was said in a call. A complaint about conduct in one is assessed on what the person complaining can show.
9. Erasure and How to Exercise It
A data subject may exercise the right to erasure under Article 17 GDPR directly in the service: the account settings contain a "Delete account" control that erases the account at once. The erasure is irreversible and has no waiting period; confirming it requires the account password and the account's own username. Where the account owns a community that other members are still in, that community must first be handed to another member or closed, so that erasing one person's account does not destroy a group of other people's content. A user who cannot reach the control may instead write to kitteniversestudios@gmail.com from, or while signed in to, the account concerned, and the controller will carry the erasure out manually; because no email address is held for any account, such a request must contain enough information for the controller to be satisfied that it comes from the account holder.
Erasure removes the account record, its login records, session records, persistent-session tokens, any recovery request made for it, the account's direct, group, and channel messages, its posts, comments, blog articles, polls, reactions, and uploaded files, its conversation with the KittenAI assistant, the records of its calls and of its presence in voice channels, the recovery keys issued to it, any bots it created together with those bots' own accounts, and the registration IP digest. Failed login records and rate-limit counters are not removed, because they carry no account identifier; content other recipients have received may remain in their own conversation history; and records Clovera must keep to comply with a legal obligation, to defend a legal claim, or to prevent the recurrence of serious abuse may be retained for as long as that purpose requires, with any link to the erased account removed where the record can stand without it. Clovera keeps a record that an erasure occurred — its date, whether the account holder or the controller carried it out, and how much was removed — which identifies no account.
Several rights can be exercised directly in the service: the account and its data can be erased from settings as described above, profile details and the username can be corrected in settings, individual messages, posts, comments, and blog articles can be deleted by their author, active sessions on other devices can be revoked, Live Translation can be disabled, and push notifications can be turned off. Note that deleting a message hides it from the participants but does not destroy the stored copy immediately; that copy is retained so that reports about content deleted moments after it was sent remain capable of assessment, and is destroyed as part of an erasure carried out under this Section. Since 14 September 2026 that stored copy is encrypted only where the message is a direct message between two people; a group message or a community channel message is held in plain text, for the reasons Section 8 of the Privacy Policy gives. A file attached to a message is not encrypted in either case, and neither are the other items that Section lists.
9a. Personal Data Breaches
Where a breach of security leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data, Clovera assesses it as soon as it becomes aware of it, records it, and notifies the competent supervisory authority under Article 33 GDPR without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the people affected. Where the breach is likely to result in a high risk to them, Clovera also communicates it to them under Article 34 GDPR.
Clovera holds no email address or telephone number for any account, so such a communication cannot be sent out of band. It is given inside the service — an on-screen notice to every account, and a push notification where the user has enabled them — and on the public site, which is the route Article 34(3)(c) contemplates where individual communication would involve disproportionate effort. A person who has stopped using the service, or whose account has been erased, cannot be reached at all; this follows from Section 3a and is stated here rather than discovered during an incident.
10. Rights
Subject to applicable law, users may request access, correction, deletion, restriction, objection, or portability. Users may also lodge a complaint with a competent supervisory authority.
11. Contact
Data protection requests may be sent to kitteniversestudios@gmail.com.
12. Limits
Some rights are subject to exceptions, including where retention is necessary for security, fraud prevention, legal compliance, defense of legal claims, or protection of other users.