GDPR Notice
CLOVERA GDPR NOTICE
Last updated: July 26, 2026
Contact: kitteniverseclovera@gmail.com
1. Applicability
This section is intended to support Clovera's privacy disclosures for users in the European Economic Area and similar jurisdictions.
2. Controller
For purposes of applicable data protection law, Clovera acts as the controller of personal data processed in connection with the service.
3. Lawful Bases
Clovera may rely on contract necessity, legitimate interests, consent, and legal obligations, depending on the processing involved.
3a. Account Data Collected
Registration requires a username and a password only. Clovera does not ask for and does not hold an email address or telephone number for any account; an internal, non-deliverable placeholder address is generated so that the account record has a unique identifier. Two consequences follow and are stated here because they affect data subject rights: service communications reach users only inside the service (on-screen notices, the policy re-acceptance screen, and push notifications where enabled), and identity verification for a rights request is performed through the account itself rather than through a registered contact address. Clovera does not collect a date of birth and cannot verify a user's age.
4. Login and Connection Logging — Processing Details (GDPR Article 13/14 Notice)
Each successful login event causes Clovera to record a one-way keyed cryptographic digest (HMAC-SHA-256) of the connecting IP address together with the associated user account identifier and the login timestamp.
The following information is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR):
(a) Data processed: A one-way keyed cryptographic digest of the user's IP address, a digest of the surrounding network range, the network operator's autonomous system number, a network category (such as fixed-line, mobile, or datacenter), the User-Agent string, the associated user account identifier, and the date and time of the login. The raw IP address is not stored. The network operator and category are derived from an offline database held on Clovera's own servers; no address is transmitted to a third party for this purpose, and no geographic location is derived from the address.
(b) Related records created by the same mechanism: (i) a digest of the IP address used at registration, stored on the account record, to limit the number of accounts that can be created from one address; (ii) a digest of the IP address and the User-Agent string on every active session record, which is what allows a user to review and revoke their sessions in settings — this is created for every session, independently of the optional feature in Section 6; and (iii) a record of each failed login attempt, consisting of a digest of the IP address, the username attempted, the reason for the failure, and the User-Agent string, kept to detect password-guessing and account-takeover attempts. Failed login records carry no account identifier, because the username attempted need not belong to an existing user.
(c) Purpose and legal basis: The purpose of this processing is to support account security, detection of unauthorized or suspicious access, abuse prevention, and enforcement of platform rules. The legal basis is legitimate interests (Article 6(1)(f) GDPR). Clovera has assessed that users have a reasonable expectation that login activity is monitored for security, and that this processing does not override users' fundamental rights given the pseudonymous nature of the data (hashed IP, no raw address).
(d) Retention: Login records and session records are retained for as long as reasonably necessary for the security and enforcement purposes described above; they are not deleted on a fixed schedule, and those tied to an account are deleted when the account is erased under Section 9. Failed login records are retained independently of any account, since they are not linked to one.
(e) No automated profiling: This processing does not involve automated decision-making or profiling within the meaning of Article 22 GDPR.
(f) No third-party disclosure: Login records are not shared with, disclosed to, or accessible by any third party except where required by law or necessary to investigate a serious safety or legal matter. This is separate from the disclosure of the IP address itself to a bot-protection provider on the login and registration pages, which is described in Section 8(b).
(g) Security: The digest is derived using a keyed one-way function (HMAC-SHA-256) with a secret key held only by Clovera. The key is required because the space of possible IPv4 addresses is small enough that an unkeyed digest could be reversed by exhaustive search; keying the digest removes that possibility for anyone who does not hold the key.
(h) Right to object: Users have the right to object to processing based on legitimate interests under Article 21 GDPR. Objection requests may be sent to kitteniverseclovera@gmail.com. Clovera may decline to cease processing where it can demonstrate compelling legitimate grounds, such as ongoing security investigations.
5. Browser Security Identifier — Processing Details (GDPR Article 13/14 Notice)
When a user signs in or creates an account, Clovera stores a randomly generated identifier in a cookie on that browser and retains a one-way digest of that identifier alongside the login record.
The following information is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR):
(a) Data processed: A randomly generated identifier stored in the browser, and a one-way digest of that identifier held on Clovera's servers together with the associated user account identifier and login timestamp. The identifier contains no personal data and is not derived from any characteristic of the user, the device, or the browser.
(b) Purpose and legal basis: The identifier allows Clovera to recognise that two sign-ins originated from the same browser, for the purposes of investigating unauthorised account access, evasion of enforcement actions through replacement accounts, and coordinated abuse involving multiple accounts. The legal basis is legitimate interests (Article 6(1)(f) GDPR). In assessing that basis, Clovera has taken into account that an IP address alone is an unreliable indicator, because carrier-grade network address translation places large numbers of unrelated subscribers behind a single address; processing this identifier materially reduces the risk of incorrect security conclusions being drawn about ordinary users, which serves the interests of those users as well as Clovera's.
(c) Storage on the device: Clovera treats the storing of this identifier as strictly necessary for the security of the authenticated service the user has requested, and does not present a consent dialogue for it; the identifier is stored on every sign-in. Users who do not accept that assessment can prevent it from being stored using their browser's cookie controls, with no loss of access or functionality, and can object under paragraph (g). This position is stated plainly because whether a fraud- and abuse-prevention cookie falls within the "strictly necessary" exemption is a contested question on which regulators have not been uniform.
(d) Retention: The cookie expires no later than twelve months after it is set. The server-side digest is deleted together with the login record it belongs to, including when the account is erased under Section 9.
(e) No automated profiling: This processing does not involve automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR. The identifier informs human review; enforcement decisions are not taken automatically on the basis of it.
(f) No third-party disclosure and no tracking: The identifier is not shared with third parties, is not used for advertising, audience measurement, personalisation, or profiling, and is not capable of tracking users across other websites or services.
(g) Security, user control and right to object: The cookie is set with the HttpOnly attribute, and with the Secure attribute over secure connections, so it cannot be read by scripts running in the browser. The identifier is deliberately retained across logout, because an identifier removed at logout could not serve its security purpose. Users may delete the cookie at any time through their browser settings without any effect on access to their account or the availability of any feature. Users also have the right to object to this processing under Article 21 GDPR; objections may be sent to kitteniverseclovera@gmail.com.
6. IP-Based Persistent Session — Processing Details (GDPR Article 13/14 Notice)
Clovera offers users an optional "Keep me signed in on this network" feature. When a user explicitly opts in to this feature at the time of login, Clovera processes a one-way keyed cryptographic digest (HMAC-SHA-256) of the user's IP address, together with a digest of a random device token placed in a cookie on that browser, for the purpose of restoring the authenticated session on subsequent visits from the same network and device, without requiring the user to re-enter credentials.
The following information is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR):
(a) Data processed: A one-way keyed cryptographic digest of the user's IP address, a digest of the device token, and the associated user account identifier. The raw IP address is not stored.
(b) Purpose and legal basis: The sole purpose of this processing is session continuity at the user's explicit request. The legal basis is consent (Article 6(1)(a) GDPR), expressed through the voluntary selection of the "Keep me signed in on this network" option. Users who do not select this option have no persistent IP-bound token stored for them. This is a distinct record from the session address digest described in Section 4(b)(ii), which is created for every session regardless of this choice.
(c) Retention: The persistent token is retained for as long as the user account exists and the user has not explicitly logged out from that network; it is not deleted on a fixed schedule. Upon logout, the token bound to that IP address and device is immediately and permanently deleted. The accompanying device cookie expires five years after it is set. Tokens are also removed when the account is erased under Section 9.
(d) Right to withdraw consent: Users may withdraw consent at any time by logging out. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
(e) No automated profiling: This processing does not involve automated decision-making or profiling within the meaning of Article 22 GDPR.
(f) No third-party disclosure: The hashed IP address and session token are not shared with, disclosed to, or accessible by any third party.
(g) Security: The digest is derived using a keyed one-way function (HMAC-SHA-256) with a secret key held only by Clovera, so the original address cannot be recovered by exhaustive search.
7. KittenAI Features and Automated Moderation — Processing Details (GDPR Article 13/14 Notice)
Clovera's built-in AI features ("KittenAI") — conversation summaries, message translation, Live Translation, reply suggestions, Catch-Up digests, the KittenAI chat assistant, writing assistance, and automated content moderation — are powered by Google's Gemini models, accessed through the Google Gemini API.
The following information is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR):
(a) Data processed: The content submitted to or covered by the relevant feature. Depending on the feature, this may include the text of direct messages, group messages, and channel messages together with participants' display names; posts, post comments, and blog articles; usernames and profile text; messages sent to the KittenAI chat assistant; and images (profile photos, banners, server icons, and post attachments) submitted for automated moderation; together with limited context such as the target language. No account identifier is transmitted; the user identifier is used only within Clovera to apply per-user rate limits.
(b) Recipient and processor: Google (Google LLC and/or its regional affiliates, such as Google Ireland Limited), acting as a processor on Clovera's behalf via the Google Gemini API. Content is decrypted on Clovera's servers before transmission to Google and is processed by Google subject to Google's applicable API and data processing terms. Clovera uses a Gemini API service tier under which content submitted through the API is not used to train or improve Google's models and is not subject to human review for that purpose.
(c) Purpose and legal basis: For user-initiated features and Live Translation (an opt-in setting, off by default), the purpose is to provide the assistance the user has requested; the legal basis is the user's consent (Article 6(1)(a) GDPR) and, where the feature forms part of the requested service, performance of a contract (Article 6(1)(b) GDPR). For automated content moderation, the purpose is protection of users, prevention of abuse and illegal content, and enforcement of platform rules; the legal basis is legitimate interests (Article 6(1)(f) GDPR) and compliance with legal obligations (Article 6(1)(c) GDPR).
(d) Scope of automated moderation: Moderation runs without being requested on feed posts and post comments — including posts that are not public — blog articles, usernames chosen at registration or changed later, profile photos, banners, server icons, messages sent by creator bots, and messages and forum posts in the channels of communities that have enabled moderation. A user's own private messages and group messages are not subject to automated moderation; they are transmitted under this Section only where a conversation participant uses one of the user-initiated features or Live Translation on the conversation.
(e) Third-party processing note: Content a user sends to others may be processed under this section when another conversation participant uses a KittenAI feature on the conversation, or when the content is subject to automated safety moderation.
(f) International transfers: Google may process this content on servers located outside the EEA, including in the United States. Transfers rely on the safeguards provided under Google's data processing terms, such as adequacy mechanisms (including the EU–U.S. Data Privacy Framework, where applicable) and/or standard contractual clauses.
(g) Retention: Clovera caches translation results in encrypted form to reduce repeat processing and retains AI-related records only as long as reasonably necessary. Google's retention of API request data is governed by Google's applicable API terms.
(h) Automated decision-making: Automated moderation may result in content being blocked, removed, or restricted without prior human review. Users may contest a moderation decision and request human review by contacting kitteniverseclovera@gmail.com.
(i) Right to object and withdraw consent: Users may withdraw consent for user-initiated features by not using them, and for Live Translation by disabling it in settings at any time. Users may object to processing based on legitimate interests under Article 21 GDPR by contacting kitteniverseclovera@gmail.com; Clovera may continue processing where it can demonstrate compelling legitimate grounds, such as safety and abuse prevention.
8. Other Recipients — Processing Details (GDPR Article 13/14 Notice)
Beyond Google's role under Section 7, the following recipients receive personal data when Clovera is used.
(a) Hosting and infrastructure. Clovera's application and database run on a third-party hosting platform, which processes all data stored or transmitted by the service in order to operate it, as a processor acting on Clovera's instructions.
(b) Bot protection — Cloudflare, Inc. (Turnstile) and Intuition Machines, Inc. (hCaptcha). Where the operator has enabled bot protection, the login and registration pages load the provider's challenge script, and Clovera transmits the challenge token together with the visitor's IP address to the provider in order to verify the result. The address is transmitted in full for this check, even though Clovera stores only a digest of it. The provider may set its own cookies or browser storage and collect browser signals in order to distinguish automated traffic. Purpose: prevention of automated account creation and credential-guessing. Legal basis: legitimate interests (Article 6(1)(f) GDPR). This applies only to the login and registration pages and only while the protection is enabled.
(c) Google Fonts (Google LLC / Google Ireland Limited). Clovera's pages load two typefaces from Google's font servers. Because the browser fetches them directly, Google receives the visitor's IP address, User-Agent string, and the fact that a Clovera page was loaded. This occurs on every page view, including for visitors who are not signed in and have no account, and constitutes a transfer outside the EEA. Purpose: consistent presentation of the service. Legal basis: legitimate interests (Article 6(1)(f) GDPR). Users who prefer to avoid this transfer can block requests to Google's font domains in their browser; the service remains fully usable with fallback typefaces.
(d) Push notification delivery. If a user enables push notifications, their browser registers with the push service operated by the browser's vendor (for example Google, Mozilla, Apple, or Microsoft). Clovera stores the resulting subscription endpoint and encryption keys and sends notifications through that service, which therefore learns that a notification was sent to that subscription and when; the content is encrypted in transit to the browser. Purpose: delivery of the notifications the user has asked for. Legal basis: consent (Article 6(1)(a) GDPR), given by enabling push notifications, which are off by default and can be turned off at any time in settings.
Clovera does not use analytics, advertising, tag-management, or audience-measurement services, and embeds no third-party content other than what is listed in this Section and Section 7.
9. Erasure and How to Exercise It
Clovera does not currently provide a self-service control that deletes an account. A request under Article 17 GDPR is carried out manually by the controller. A user who wants their account and data erased should write to kitteniverseclovera@gmail.com from, or while signed in to, the account concerned; because no email address is held for any account, the request must contain enough information for the controller to be satisfied that it comes from the account holder.
When such a request is carried out, Clovera erases the account record, its login and session records, browser identifier digests, persistent-session tokens, the account's messages, posts, comments, blog articles, and uploaded files, and the registration IP digest. Content other recipients have received may remain in their own conversation history, and records Clovera must keep to comply with a legal obligation, to defend a legal claim, or to prevent the recurrence of serious abuse may be retained for as long as that purpose requires.
Several rights can be exercised directly in the service: profile details and the username can be corrected in settings, individual messages, posts, comments, and blog articles can be deleted by their author, active sessions on other devices can be revoked, Live Translation can be disabled, and push notifications can be turned off. Note that deleting a message hides it from the participants but does not destroy the stored encrypted copy immediately; that copy is retained so that reports about content deleted moments after it was sent remain capable of assessment, and is destroyed as part of an erasure carried out under this Section.
10. Rights
Subject to applicable law, users may request access, correction, deletion, restriction, objection, or portability. Users may also lodge a complaint with a competent supervisory authority.
11. Contact
Data protection requests may be sent to kitteniverseclovera@gmail.com.
12. Limits
Some rights are subject to exceptions, including where retention is necessary for security, fraud prevention, legal compliance, defense of legal claims, or protection of other users.