KVKK Privacy Notice (Türkiye)
CLOVERA KVKK PRIVACY NOTICE (TÜRKİYE)
Last updated: August 13, 2026
Contact: kitteniverseclovera@gmail.com
This notice is provided in accordance with Article 10 of Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") and the Communiqué on the Procedures and Principles for Compliance with the Obligation to Inform. In case of any discrepancy between this English version and the Turkish version, the Turkish version prevails for users subject to Turkish law.
1. Data Controller
Clovera is an independent project run under the name "Kitteniverse Studios". Kitteniverse Studios is not currently a registered company. For the purposes of the KVKK, the data controller is therefore the natural person operating the project. The data controller can be reached at kitteniverseclovera@gmail.com. If the project is later registered as a company, this notice will be updated to show the registered name and contact details.
2. Personal Data Processed
The following categories of personal data may be processed within Clovera:
a) Account data: a username, a password (stored only as a hash), a language preference, and optional profile details such as a display name, pronouns, custom status, profile photo, and banner. Registration requires only a username and a password. Clovera does not ask for, and does not collect, an email address or a telephone number; an internal, non-deliverable placeholder address is generated so that the account record has a unique identifier;
b) Technical data: the IP address of each connection (only a one-way keyed digest is stored, never the address itself), a digest of the surrounding network range, the network operator's autonomous system number, a network category such as fixed-line, mobile, or datacenter, the browser's User-Agent string, and the browser security identifier described in Section 8. Clovera does not derive or store users' geographic location from their IP addresses;
c) Usage data: login times, failed login attempts, interactions, reports, blocks, community participation, and feature usage;
d) Content data: messages, posts, comments, blog articles, attachments, profile text, and other user-submitted content;
e) Safety and moderation data: report records, enforcement history, detection signals, and abuse-prevention logs.
3. Purposes of Processing
Your personal data is processed for the following purposes:
a) Creating and managing accounts;
b) Providing messaging, community, feed, moderation, and support functions;
c) Protecting users and the service from spam, fraud, abuse, illegal activity, and security threats;
d) Enforcing platform rules and legal obligations;
e) Improving reliability, performance, and user experience;
f) Communicating service notices, policy updates, and support responses. Because Clovera holds no email address, this communication takes place inside the service: as on-screen notices, as the acceptance screen shown when the policies are revised, and, where the user has enabled them, as push notifications. Clovera has no way to reach a user outside the service unless the user writes first.
4. Legal Grounds for Processing
Your personal data is processed on the following legal grounds under Article 5 of the KVKK and, where required, Article 6:
a) Processing of personal data of the parties to a contract being necessary, provided that it is directly related to the establishment or performance of that contract;
b) Processing being necessary for the data controller to comply with a legal obligation;
c) Processing being necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject;
d) The explicit consent of the data subject, where explicit consent is required.
5. Method of Collection
Your personal data is collected electronically, by automated and partly automated means, through registration forms, in-app interactions, messaging and content submission, automated logs, security systems, cookies, and similar technologies. The cookies Clovera places in your browser are: a session cookie necessary to keep you signed in, the browser security identifier described in Section 8, a device cookie for the "Keep me signed in on this network" feature where that option is selected, and preference values such as language and theme. Clovera has no cookies of its own for advertising, audience measurement, or cross-site tracking.
6. Recipients of Personal Data and the Purposes of Transfer
Within the framework of Articles 8 and 9 of the KVKK and the related legislation, your personal data may be transferred to the following recipients for the purposes stated:
a) Hosting and infrastructure provider: Clovera's application and database run on a third-party hosting platform, which necessarily processes all data stored or transmitted by the service in order to operate it. It acts as a processor on Clovera's instructions;
b) Google (Gemini API): to process the relevant content for the KittenAI features described in Section 7;
c) Google (hosted fonts): Clovera's pages load two typefaces from Google's servers. Because the browser makes that request directly, Google learns the visitor's IP address, User-Agent string, and the fact that a Clovera page was loaded. This happens on every page view, including for visitors with no account who are not signed in; its only purpose is to display the site's typography;
d) Bot-protection providers — Cloudflare, Inc. (Turnstile) and Intuition Machines, Inc. (hCaptcha): where bot protection is enabled, the login and registration pages load the provider's challenge script, and Clovera sends that provider the challenge token **together with the visitor's IP address** in order to verify the result. While Clovera itself stores only a digest of the address, the full address is transmitted to the provider for this check. The provider may also set its own cookies or browser storage in order to distinguish automated traffic. This transfer occurs only on the login and registration pages and only while the protection is enabled; its purpose is to prevent automated account creation and password-guessing;
e) Push notification delivery services: if a user enables push notifications, the browser registers with the notification service operated by its vendor (Google, Mozilla, Apple, or Microsoft, depending on the browser) and Clovera sends notifications through that service. The service learns that a notification was sent to that subscription and when; the notification content is encrypted in transit to the browser. Push notifications are off unless the user turns them on;
f) Competent authorities and institutions: to comply with lawful requests, investigate abuse, enforce platform rules, and fulfil obligations arising from legislation;
g) Third parties in connection with legal claims: to establish, exercise, or protect a right and to conduct legal proceedings.
Clovera does not sell personal data. Clovera does not use analytics, advertising, tag-management, or audience-measurement services, and embeds no third-party content other than what is listed above.
7. Cross-Border Data Transfer
Every recipient listed in Section 6 may process personal data on servers outside the user's country, including outside Türkiye. This constitutes a cross-border transfer of personal data within the meaning of Article 9 of the KVKK, and it covers not only the KittenAI features but also the hosting infrastructure, the IP address and User-Agent disclosed to Google when hosted fonts are loaded, the IP address and challenge token sent to a bot-protection provider, and push notification delivery.
Such transfers are carried out on the basis of an adequacy decision where one exists; where no adequacy decision exists, on the basis of appropriate safeguards; and/or, where required, on the basis of your explicit consent, which you give by activating or using the relevant KittenAI feature. Where appropriate safeguards are not available and the transfer is incidental in nature, the exceptional conditions set out in the KVKK and the related legislation are reserved.
Users who wish to avoid the transfer caused by the hosted fonts can block requests to Google's font domains in their browser; the service remains fully usable with fallback typefaces.
KittenAI Features
Clovera's built-in artificial intelligence features ("KittenAI") — conversation summaries, message translation, Live Translation, reply suggestions, Catch-Up digests, the KittenAI chat assistant, writing assistance, and automated content moderation — are powered by Google's Gemini models, accessed through the Google Gemini API. Google acts as a data processor on Clovera's behalf for these features.
When a KittenAI feature runs, the relevant content is decrypted on Clovera's servers and transmitted to Google for processing. Depending on the feature, this content may include:
a) The text of direct messages, group messages, and channel messages, together with the display names of the participants, where a summary, translation, reply suggestion, or Catch-Up digest is produced from a conversation;
b) Posts, post comments, blog articles, usernames, profile text, and messages sent to the KittenAI chat assistant;
c) Images such as profile photos, banners, server icons, and post attachments (for automated image moderation).
The features run as follows:
a) User-initiated features (summarize, translate, reply suggestion, community idea, Catch-Up, writing assistance, and the KittenAI chat) run only when the user actively requests them;
b) Live Translation runs only if the user has turned it on in settings, and can be turned off at any time; it is off by default;
c) Automated content moderation runs by itself, without being requested, on the following: feed posts and post comments — including posts that are not public — blog articles, usernames chosen at registration or changed later, profile photos, banners, server icons, and messages sent by creator bots. It also runs on messages and forum posts in the channels of communities that have enabled moderation. A user's own private messages and group messages are not subject to automated moderation; those are transmitted to Google only where a participant uses one of the features in (a) or (b) on the conversation.
Content you send to other users may be processed by KittenAI if another participant in the conversation uses an AI feature on that conversation (for example, translation, summarization, or Catch-Up), or if the content is subject to automated safety moderation.
Users who do not use KittenAI features and have not enabled Live Translation do not have their private message content sent to Google, except where the automated safety moderation described above applies.
Clovera transmits only the content reasonably needed for the requested feature, together with limited context such as the target language. No account identifier is transmitted; the user identifier is used only inside Clovera to apply per-user rate limits. Content transmitted to Google is processed subject to Google's applicable API and data processing terms. Clovera uses a Gemini API service tier under which content submitted through the API is not used to train or improve Google's models and is not subject to human review for that purpose, and Clovera does not permit its processors to use this content for their own advertising purposes. Translation results are cached in encrypted form on Clovera's servers to reduce repeat processing.
8. Browser Security Identifier
When a user signs in or creates an account, Clovera stores a randomly generated identifier as a cookie on that browser (the cookie named "clv_bid"). The identifier contains no personal data and is not derived from any characteristic of the user, the device, or the browser. Only a one-way digest of the identifier is retained on the server, alongside the related login record.
The identifier allows Clovera to recognise that two sign-ins came from the same browser. It is used solely for account security and abuse investigations: unauthorised access to an account, evasion of an enforcement action through a replacement account, and coordinated abuse involving multiple accounts. It is not used for advertising, audience measurement, personalisation, profiling, or tracking across other sites and services, and is not shared with third parties for such purposes.
Because an IP address alone is not a reliable indicator, and because carrier-grade address translation (CGNAT) can place large numbers of unrelated subscribers behind a single address, relying on IP addresses alone can lead to incorrect conclusions about ordinary users. This identifier reduces that risk by allowing security assessments to rest on more reliable evidence rather than on the coincidence of a shared network.
The identifier is issued only in connection with an authentication event — signing in or creating an account — and is not issued to visitors who are not signing in. The cookie is set with the HttpOnly attribute and, over secure connections, the Secure attribute, so it cannot be read by scripts running in the browser.
Legal ground: the legitimate interests of the data controller, provided that the fundamental rights and freedoms of the data subject are not harmed (KVKK Article 5/2-f). Clovera treats the storing of the identifier on the device as necessary for the security of the sign-in the user has requested. No separate consent dialogue is presented for it, and the identifier is stored on every sign-in. Users may object to this processing; objections may be sent to kitteniverseclovera@gmail.com. A user who objects can also prevent the identifier from being stored at all using their browser's cookie controls, without any effect on access to the account or the availability of any feature.
Retention: the cookie expires no later than twelve months after it is set. The server-side digest is deleted together with the login record it belongs to, including where the account is deleted under Section 10. Users may delete the cookie at any time through their browser settings. Deleting it does not affect access to the account or the availability of any feature.
9. Login and Connection Records
On each successful login, a one-way keyed digest of the connecting IP address is recorded together with the account identifier and the time of the login. The raw IP address is never stored by Clovera. Alongside the digest, limited technical context that does not identify the user is recorded: a digest of the surrounding network range, the network operator's autonomous system number, and a network category such as fixed-line, mobile, or datacenter. This information is derived from an offline database held on Clovera's own servers; no address is sent to any third party for this purpose, and no geographic location is derived.
The same mechanism creates three further records:
a) A digest of the IP address used at registration is kept on the account record, to prevent an unlimited number of accounts being created from a single address;
b) Every active session record stores a digest of the IP address and the User-Agent string of the device that created it. This is what allows a user to see their active sessions in settings and sign other devices out. This record is created for every session, whether or not the user has selected the optional "Keep me signed in on this network" feature;
c) A failed login attempt is recorded with a digest of the IP address, the username attempted, the reason for the failure, and the User-Agent string. These records exist to detect password-guessing and account-takeover attempts. They are not linked to any account, because the username attempted may not belong to an existing user.
The "Keep me signed in on this network" feature creates a separate record: when the user selects that option at login, a digest of the IP address and a digest of a random device token placed in the browser are stored in association with the account, so that the session can be restored automatically on later requests. The legal ground for this feature is the explicit consent the user gives by deliberately selecting the option at login. When the user logs out, the relevant token is permanently deleted; otherwise it remains valid for as long as the account exists and the user has not logged out from that network. The accompanying device cookie expires five years after it is set.
The legal ground for these records is the legitimate interest in protecting account security and the integrity of the platform (Section 4(c) above). They are not used for advertising, behavioural profiling, or cross-service tracking.
10. Retention and Destruction
Your personal data is retained for as long as necessary for the purposes described in this notice and in the Privacy Policy, subject to the maximum periods prescribed by the applicable legislation. Retention periods per category of data are determined taking into account the purpose of processing, legal obligations, limitation periods, dispute management, security needs, and technical requirements. Account content, login records, and failed login records are kept for as long as those purposes require and are not deleted on a fixed schedule.
Where the purpose of processing ceases, the legal ground ends, or the retention period expires, personal data is deleted, destroyed, or anonymised. Deletion, destruction, and anonymisation are carried out in accordance with the provisions of the applicable legislation, the technical and administrative measures in place, and the retention and destruction procedures. These operations are recorded, and the related records are kept for at least three years, save for legal obligations to the contrary.
Account deletion: the account settings contain a "Delete account" control that erases the account and its data in a single step. The erasure is immediate and irreversible; confirming it requires the account password and the account's own username. An account that owns a community with other members in it must first hand that community to another member or close it. A user who cannot reach the control may instead write to kitteniverseclovera@gmail.com from, or while signed in to, the account concerned, and the data controller will carry the erasure out manually. Because no email address is held for any account, such a request must contain enough information for the controller to be satisfied that it comes from the account holder (see Section 13). In line with the recording obligation described above, Clovera keeps a record of each erasure — its date, who carried it out, and how much was removed — containing nothing that identifies the erased account.
When such a request is carried out, the following are erased: the account record, the login and session records belonging to it, the browser identifier digests, the persistent-session tokens, the account's messages, posts, comments, blog articles, and uploaded files, and the registration IP digest. Content other users have received may remain visible to them insofar as it forms part of their own conversation history; records that must be kept to comply with a legal obligation, to defend a legal claim, or to prevent the recurrence of serious abuse may be retained for as long as that purpose requires. Destruction is carried out on the criteria of inaccessibility, irretrievability, and non-reusability.
Content can also be removed without erasing the account: a user may delete their own messages, posts, comments, and blog articles at any time, and may change or remove their profile photo and banner.
An important note on message deletion: when a user deletes one of their own messages, the message is marked as deleted and stops being shown to the participants, but the encrypted copy remains in Clovera's database rather than being destroyed immediately. This is deliberate: a message deleted seconds after it was sent is frequently the subject of a report, and destroying it on request would make such reports impossible to assess. Deletion in the sense of destruction follows the procedure described in this Section.
Report records and misuse measurement: user reports carry a category chosen by the reporter (for example fraud, threats, or content involving minors) and a free-text explanation; when a report is reviewed, the outcome is recorded with it. The free-text explanation of a settled report — upheld or dismissed — is erased 180 days after it is settled; the category, outcome, and dates are kept so that the extent of unlawful use of the service can continue to be measured. For the same measurement, Clovera also keeps daily counters of automated moderation events; these consist only of a date, an event name, and a number, and contain no user identifier, content, or address. Private messages are not read or scanned to produce these figures.
11. Automated Decision-Making
Automated content moderation may result in content being blocked, removed, or restricted without prior human review. Decisions in this scope may be produced by technical systems for the purposes of security, legal compliance, and the enforcement of platform rules. The content types on which moderation runs by itself are listed in Section 7.
To contest a moderation decision and request human review, you may contact kitteniverseclovera@gmail.com. Your request will be assessed according to the nature of the incident and concluded as soon as possible.
12. Your Rights under KVKK Article 11
Under Article 11 of the KVKK, by applying to the data controller you have the right to:
a) Learn whether your personal data is processed;
b) Request information if it has been processed;
c) Learn the purpose of processing and whether the data is used in accordance with that purpose;
ç) Know the third parties to whom your data is transferred, in Türkiye or abroad;
d) Request correction of incomplete or inaccurate data;
e) Request deletion or destruction of your data under the conditions of Article 7 of the KVKK;
f) Request that the operations under (d) and (e) be notified to third parties to whom the data has been transferred;
g) Object to a result arising against you through analysis carried out exclusively by automated systems;
ğ) Claim compensation for damages arising from unlawful processing.
Some of these rights can be exercised directly in the service without making an application: the account and its data can be erased from settings as described in Section 10, profile details and the username can be corrected in settings, messages and posts can be deleted by their author, active sessions on other devices can be terminated, and Live Translation can be turned off.
13. How to Apply
Requests regarding the rights above may be sent to kitteniverseclovera@gmail.com in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller. Clovera may need to verify identity before completing certain requests. Because no email address or other contact detail is held for any account, identity is verified through the account itself; for example, the user may be asked to send or post a particular value from the account concerned.
Applications are concluded within thirty days at the latest, as required by Article 13 of the KVKK. Where an application is made in writing, it must contain the minimum identity and contact details relating to the request. For electronic applications, the subject of the request must be stated clearly. Applications are made in Turkish.
14. Responding to an Application
Clovera either accepts the application or rejects it with an explanation of the grounds. The response is communicated in writing or electronically. Where a request is accepted, it is carried out as soon as possible and you are informed.
If responding to your application entails an additional cost, the fee determined under the applicable legislation may be charged. If the application arises from an error of the data controller, any fee charged is refunded.
15. Right to Complain
If your application is rejected, the response is found insufficient, or no response is given in time, you retain the right to lodge a complaint with the Turkish Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) under Article 14 of the KVKK.
16. Withdrawal of Consent and Feature Controls
For user-initiated KittenAI features, you can stop the processing at any time by not using them; for Live Translation, by turning it off in settings. You can withdraw your consent for "Keep me signed in on this network" by logging out from that network. Push notifications can be turned off in settings. Withdrawing your explicit consent does not affect the lawfulness of processing carried out before the withdrawal.
17. Children's Data
Clovera does not collect a date of birth and therefore cannot verify a user's age. The minimum age is stated in the Terms of Service and is relied upon as a representation by the user. If Clovera becomes aware of use below the age limit contrary to the legislation, it may remove the account and the related data as appropriate.
18. Data Security
Clovera takes all necessary technical and administrative measures to prevent the unlawful processing of and access to personal data, to ensure that data is preserved, and to maintain an appropriate level of security. Within this scope, access rights are restricted, logging and monitoring mechanisms are operated, security incidents are followed up, encryption and similar protective measures are applied where considered necessary, and obligations relating to data security are observed in relationships with data processors.
Private messages, group messages, channel messages, and post bodies are stored encrypted at the application layer on Clovera's servers (encryption at rest with ChaCha20-Poly1305); passwords are never held in plaintext and are protected with a strong hashing algorithm. This encryption is applied by Clovera's servers and is not end-to-end encryption: content is decrypted on the server when it is delivered to authorised participants and when a KittenAI feature or automated safety review is run on it.
19. Retention and Destruction Policy
Clovera conducts its personal data retention and destruction processes taking into account the category of data, the purpose of processing, the retention period, legal obligations, and security needs. Personal data whose retention period has expired or whose purpose of processing has ceased is destroyed in accordance with the legislation, using whichever of deletion, destruction, or anonymisation is appropriate. Destruction operations are based on the criteria of inaccessibility, irretrievability, and non-reusability.
20. Updates
This notice may be updated in line with changes in legislation, updates to the structure of the service, or changes in data processing activities. The current text is made available through appropriate channels.
Data Controller: The natural person operating the project
Contact: kitteniverseclovera@gmail.com