Privacy Policy
CLOVERA PRIVACY POLICY
Last updated: July 26, 2026
Contact: kitteniverseclovera@gmail.com
1. Scope
This Privacy Policy explains how Clovera, a service operated by Kitteniverse Studios, collects, uses, stores, shares, and protects personal data in connection with the service.
2. Data We May Collect
Clovera may collect:
(a) account data: a username, a password (stored only as a hash), a language preference, and optional profile details such as a display name, pronouns, custom status, profile photo, and banner. Registration requires only a username and a password. Clovera does not ask for, and does not collect, an email address or a telephone number; an internal, non-deliverable placeholder address is generated for the account record so that the account table has a unique identifier;
(b) technical data: the IP address of each connection (retained only as a one-way keyed digest, never as the address itself), a digest of the surrounding network range, the network operator's autonomous system number, a network category such as fixed-line, mobile, or datacenter, the browser's User-Agent string, and a browser security identifier described in Section 14. Clovera does not derive or store the geographic location of users from their IP addresses;
(c) usage data: login times, failed login attempts, interactions, reports, blocks, community participation, and feature usage;
(d) content data: messages, posts, comments, blog articles, attachments, profile text, and other user-submitted content;
(e) safety and moderation data: report records, enforcement history, detection signals, and abuse-prevention logs.
3. How Data Is Used
Clovera may use personal data to:
(a) create and manage accounts;
(b) provide messaging, community, feed, moderation, and support functions;
(c) protect users and the service from spam, fraud, abuse, illegal activity, and security threats;
(d) enforce platform rules and legal obligations;
(e) improve reliability, performance, and user experience;
(f) communicate service notices, policy updates, and support responses. Because Clovera holds no email address, these are delivered inside the service — as on-screen notices, as the acceptance screen shown when the policies are revised, and, where a user has enabled them, as push notifications. Clovera cannot contact users outside the service unless they write to the contact address first.
4. Legal Bases
For users in the European Economic Area, United Kingdom, or similar jurisdictions, Clovera may process personal data under one or more lawful bases, including:
(a) performance of a contract;
(b) legitimate interests, such as security, fraud prevention, moderation, and service improvement;
(c) consent, where required;
(d) compliance with legal obligations.
5. Data Sharing
Clovera does not sell personal data. Clovera does not use analytics, advertising, or audience-measurement services. Data may be shared:
(a) with the providers listed in Section 16, each of which receives only the data described there and acts on Clovera's behalf or under its own terms as stated in that Section;
(b) when necessary to investigate abuse, enforce rules, or respond to lawful requests;
(c) in connection with legal claims, safety incidents, or protection of rights;
(d) if the service is reorganized, sold, or transferred, subject to applicable law.
6. International Transfers
Because Clovera is an international online service, data may be processed in countries other than the user's own. Every provider named in Section 16 may process data on servers outside the user's country, including outside Türkiye and the European Economic Area. This applies to content submitted to KittenAI features (Section 15), to the IP address and challenge token sent to a bot-protection provider, to the IP address and User-Agent disclosed to Google when a page loads its hosted fonts, and to push notification delivery. Where required by law, Clovera relies on the transfer mechanisms provided under each provider's terms, such as an adequacy decision (including the EU–U.S. Data Privacy Framework where applicable) or standard contractual clauses.
7. Retention
Clovera keeps personal data only for as long as reasonably necessary for the purposes described in this Policy, including operation of the service, safety, dispute resolution, legal compliance, and enforcement. Different categories of data may be kept for different periods depending on risk and legal need.
Account content, login records, and failed login records are retained for as long as the purposes above require and are not deleted on a fixed schedule; login and session records tied to an account are removed when that account is deleted under Section 17. Failed login records are not linked to any account, because a failed attempt may not correspond to a real user; they consist of an IP digest, the username that was attempted, the reason for the failure, and the User-Agent string.
When a user deletes one of their own messages, the message is marked as deleted and stops being shown to the participants, but the encrypted copy remains in Clovera's database rather than being erased immediately. This is deliberate: a message deleted seconds after it was sent is frequently the subject of an abuse report, and destroying it on request would make such reports impossible to assess. Deletion in the sense of destruction is described in Section 17.
8. Security
Clovera uses reasonable technical and organizational measures to help protect personal data. Private messages, group messages, channel messages, and post bodies are encrypted at the application layer while stored on Clovera's servers (encryption at rest using ChaCha20-Poly1305), and passwords are never stored in plaintext — they are protected using a strong hashing algorithm. This storage encryption is applied by Clovera's servers and is not end-to-end encryption: content is decrypted on the server when it is delivered to authorized participants and when a KittenAI feature or automated safety review is applied to it, as described in Section 15. No system is perfectly secure, and Clovera cannot guarantee absolute security.
9. User Rights
Where applicable, users may have rights to access, correct, delete, restrict, object to certain processing, or request portability of their personal data. Users may also withdraw consent where processing is based on consent. Requests may be sent to kitteniverseclovera@gmail.com. Clovera may need to verify identity before completing certain requests; because Clovera holds no email address or other contact detail for any account, identity is verified through the account itself, for example by asking the user to post or send a value from the account in question.
Some rights can be exercised directly in the service without making a request: profile details and the username can be edited in settings, individual messages and posts can be deleted by their author, active sessions on other devices can be revoked, and Live Translation can be turned off. Erasure of an entire account is handled as described in Section 17.
10. Children's Data
Clovera does not knowingly allow underage use where prohibited by law and does not knowingly process children's data in violation of applicable law. Clovera does not collect a date of birth and therefore cannot verify a user's age; the minimum age is stated in the Terms of Service and is relied upon as a representation by the user. If Clovera becomes aware of unlawful underage use, it may remove the account and related data as appropriate.
11. Cookies and Similar Technologies
Clovera sets the following in a user's browser:
(a) a session cookie, which keeps a signed-in user signed in and is necessary for the service to function;
(b) the browser security identifier described in Section 14;
(c) where the user selects "Keep me signed in on this network", a device cookie for that feature, described in Section 13;
(d) preference values, such as the chosen language and theme.
Clovera does not use advertising, audience-measurement, or cross-site tracking cookies of its own. Where bot protection is enabled, the bot-protection provider named in Section 16 loads its own script on the login and registration pages and may set its own cookies or browser storage for the purpose of distinguishing automated traffic; Clovera does not read those values and does not use them for any purpose of its own. A separate cookie notice may be provided where legally required.
12. Login and Connection Logging
Each time a user successfully logs in to Clovera, a one-way keyed cryptographic digest of the connecting IP address is recorded alongside the user account identifier and the timestamp of the login event. The raw IP address is never stored by Clovera; only its irreversible digest is retained.
Alongside the digest, Clovera records limited technical context about the connection that does not identify the user: a digest of the surrounding network range, the network operator's autonomous system number, and a network category such as fixed-line, mobile, or datacenter. This context is recorded at the time of login because it cannot be reconstructed afterwards, and it exists so that Clovera can tell an address genuinely shared by one household apart from an address shared by many thousands of unrelated subscribers of the same mobile carrier. Without it, ordinary users sharing a carrier network would be indistinguishable from users deliberately operating multiple accounts. Clovera derives the network operator and category from an offline database held on its own servers; no address is sent to any third party for this purpose, and no geographic location is derived.
Three related records are created by the same mechanism:
(a) a digest of the IP address used at registration is stored on the account record, so that a single address cannot be used to create an unlimited number of accounts;
(b) every active login session record stores a digest of the IP address and the User-Agent string of the device that created it. This is what allows a user to see their active sessions in settings and sign other devices out. It applies to every session, whether or not the user has selected the optional feature described in Section 13;
(c) a failed login attempt is recorded with a digest of the IP address, the username that was attempted, the reason for the failure, and the User-Agent string. These records exist to detect password-guessing and account-takeover attempts. They are not linked to any account, because the username attempted may not belong to an existing user.
This log is maintained for security purposes, including detection of unauthorized access, account recovery support, abuse investigation, and enforcement of platform rules. The data is not used for advertising, behavioral profiling, or cross-service tracking. The legal basis for this processing is Clovera's legitimate interest in protecting the security of user accounts and the integrity of the platform (Article 6(1)(f) GDPR where applicable).
Login records and session records tied to an account are removed when the account is deleted under Section 17. Failed login records carry no account identifier and are therefore retained independently of any account.
13. IP-Based Persistent Session ("Keep me signed in")
Clovera offers an optional feature that allows users to remain signed in across sessions on a trusted network. When this feature is enabled by the user at login, Clovera derives a one-way keyed cryptographic digest of the user's IP address and stores that digest, together with a digest of a random device token placed in a cookie on that browser, in association with the user account. The raw IP address is never stored in this context; only its digest is retained.
The stored digest is used solely to automatically restore the user's authenticated session when a subsequent request originates from the same IP address on the same device. This data is not used for advertising, tracking across third-party services, or any purpose other than session continuity.
Users may disable this feature at any time by logging out. Upon logout, the IP-bound token associated with that network and device is permanently deleted. Otherwise the token remains valid for as long as the user account exists and the user has not explicitly logged out from that network; the accompanying device cookie expires five years after it is set. The token is also removed when the account is deleted under Section 17.
The legal basis for this processing is the user's freely given, specific, and informed consent (Article 6(1)(a) GDPR where applicable), expressed by actively selecting the "Keep me signed in on this network" option at login. Users who do not select this option have no IP-bound persistent token stored for them. This is a distinct record from the session IP digest described in Section 12(b), which is created for every session regardless of this choice.
Users should exercise caution and not enable this feature on shared, public, or untrusted networks or devices.
14. Browser Security Identifier
When a user signs in or creates an account, Clovera stores a randomly generated identifier in a cookie on that browser (the cookie named "clv_bid"). The identifier is a random value that contains no personal data and is not derived from any characteristic of the user, the device, or the browser. Only a one-way digest of the identifier is retained on Clovera's servers, recorded alongside the login event.
Purpose. The identifier allows Clovera to recognise that two sign-ins came from the same browser. This is used solely to investigate account security and abuse — for example unauthorised access to an account, evasion of an enforcement action through a replacement account, and coordinated abuse involving multiple accounts. It is not used for advertising, audience measurement, personalisation, profiling, or tracking of users across other websites or services, and it is never shared with third parties for those purposes.
Why this data is used. An IP address alone is an unreliable indicator, because many mobile and residential networks place large numbers of unrelated subscribers behind a single shared address. Relying on IP addresses alone would therefore produce incorrect conclusions about ordinary users. The browser identifier is used to reduce that error rate, so that security decisions are based on more reliable evidence rather than on the coincidence of a shared network.
Issuance and scope. The identifier is issued only in connection with an authentication event — signing in or creating an account. It is not issued to visitors who are not signing in. The cookie is set with the HttpOnly attribute and, over secure connections, the Secure attribute, so it is not readable by scripts running in the browser.
Retention. The cookie expires no later than twelve months after it is set. The server-side digest is retained with the associated login record and is deleted when that record is deleted, including when the account is deleted under Section 17.
User control. The identifier is deliberately not deleted at logout, because an identifier that disappeared at logout could not serve its security purpose. Users may delete the cookie at any time through their browser settings, and may prevent it from being stored by using their browser's cookie controls. Deleting the cookie does not affect access to the account or the availability of any feature.
Legal basis. Where the GDPR applies, Clovera relies on its legitimate interests in the security of user accounts and the integrity of the platform (Article 6(1)(f) GDPR), and treats the storing of the identifier as strictly necessary for the security of the sign-in the user has requested. Clovera does not present a consent banner for it, and the identifier is stored on every sign-in. Users have the right to object to this processing under Article 21 GDPR; objections may be sent to kitteniverseclovera@gmail.com, and a user who objects can also prevent the identifier from being stored at all using their browser's cookie controls, without any loss of access or functionality.
15. KittenAI Features and AI Processing (Google)
Clovera includes built-in artificial intelligence features under the name "KittenAI", including conversation summaries, message translation, Live Translation, reply suggestions, Catch-Up digests, the KittenAI chat assistant, writing assistance, and automated content moderation. KittenAI is powered by Google's Gemini models, accessed through the Google Gemini API. Google acts as a third-party processor for these features.
When a KittenAI feature runs, the relevant content is decrypted on Clovera's servers and transmitted to Google for processing. Depending on the feature, this content may include:
(a) the text of direct messages, group messages, and channel messages, together with the display names of the participants, where a summary, translation, reply suggestion, or Catch-Up digest is produced from a conversation;
(b) posts, post comments, blog articles, usernames, profile text, and messages submitted to the KittenAI chat assistant;
(c) images such as profile photos, banners, server icons, and post attachments (for automated image moderation).
When each feature runs:
(a) User-initiated features (summarize, translate, reply suggestion, community idea, Catch-Up, writing assistance, and the KittenAI chat) run only when the user actively requests them.
(b) Live Translation runs only if the user has turned it on in their settings, and can be turned off at any time. It is off by default.
(c) Automated content moderation runs automatically, without being requested, on the following: feed posts and their comments — including posts that are not public — blog articles, usernames chosen at registration or changed later, profile photos, profile banners, server icons, and messages sent by creator bots. It also runs on messages and forum posts in a community's channels where that community has enabled moderation. Moderation of a user's own private messages and group messages does not take place; those are sent to Google only where a participant uses one of the features in (a) or (b) on the conversation.
Important: content a user sends to other users may be processed by KittenAI if another participant in the conversation uses an AI feature on that conversation (for example, translating, summarizing, or requesting a Catch-Up digest of it), or if the content is subject to automated safety moderation. By participating in conversations on Clovera, users acknowledge that other participants may use these features.
Clovera transmits only the content reasonably needed for the requested feature, together with limited context such as the target language. No account identifier is transmitted; the user identifier is used only inside Clovera to apply per-user rate limits. Translation results are cached in encrypted form on Clovera's servers to reduce repeat processing. Content transmitted to Google is processed by Google subject to Google's applicable API and data processing terms. Clovera uses a Gemini API service tier under which content submitted through the API is not used to train or improve Google's models and is not reviewed by human reviewers for that purpose, and Clovera does not permit its processors to use this content for their own advertising purposes.
Legal bases (where GDPR or similar law applies): user-initiated features and Live Translation are processed on the basis of the user's request and consent (Article 6(1)(a) and, where the feature is part of the requested service, Article 6(1)(b) GDPR); automated safety moderation is processed on the basis of Clovera's legitimate interests in keeping the platform safe and lawful (Article 6(1)(f) GDPR) and compliance with legal obligations (Article 6(1)(c) GDPR).
Where Turkish Law No. 6698 (KVKK) applies, the transmission of content to Google constitutes a cross-border transfer of personal data. Such transfers are carried out in accordance with the KVKK's cross-border transfer provisions, including — where required — appropriate safeguards and/or the user's explicit consent, which Clovera obtains through the user's affirmative activation or use of the relevant KittenAI feature. Users who do not use KittenAI features and have not enabled Live Translation do not have their private message content sent to Google, except where automated safety moderation applies as described above. Full KVKK disclosures, including data subject rights under Article 11 of the KVKK, are provided in the separate KVKK Privacy Notice available in-app at /legal/kvkk-notice (shown in Turkish or English according to the user's language setting).
Users may object to or limit this processing by not using KittenAI features and disabling Live Translation. Questions and objections may be sent to kitteniverseclovera@gmail.com.
16. Third-Party Services That Receive Data
Beyond Google's role in Section 15, the following services receive personal data when Clovera is used. Each is listed with what it receives and why.
(a) Hosting and infrastructure. Clovera's application and database run on a third-party hosting platform. It necessarily handles all data stored or transmitted by the service, in order to run it. Its role is that of a processor acting on Clovera's instructions.
(b) Google Fonts (Google LLC / Google Ireland Limited). Clovera's pages load two typefaces from Google's font servers. Because the browser fetches them directly, Google receives the visitor's IP address, User-Agent string, and the fact that a Clovera page was loaded. This happens on every page view, including for visitors who are not signed in and have no account. It is used only to display the site's typography; Clovera receives nothing back and no identifier of its own is involved. Where the GDPR applies, the legal basis is Clovera's legitimate interest in presenting the service consistently (Article 6(1)(f) GDPR). Users who prefer to avoid this transfer can block requests to Google's font domains in their browser; the service remains fully usable with fallback typefaces.
(c) Bot protection — Cloudflare Turnstile (Cloudflare, Inc.) and hCaptcha (Intuition Machines, Inc.). Where the operator has enabled bot protection, the login and registration pages load a challenge script from the relevant provider, and Clovera sends that provider the challenge token together with the visitor's IP address in order to verify the result. The IP address is sent in full to the provider for this check, even though Clovera itself stores only a digest of it. The provider may also set its own cookies or browser storage and collect signals about the browser in order to distinguish automated traffic. This applies only to the login and registration pages and only while the protection is enabled. The purpose is to prevent automated account creation and credential-guessing; where the GDPR applies, the legal basis is Clovera's legitimate interest in the security of the service (Article 6(1)(f) GDPR).
(d) Push notification delivery. If a user enables push notifications, their browser registers with the push service operated by the browser's vendor (for example Google, Mozilla, Apple, or Microsoft, depending on the browser). Clovera stores the resulting subscription endpoint and encryption keys and sends notification messages through that service. The push service therefore learns that a notification was sent to that subscription and the timing of it; the notification content is encrypted in transit to the browser. Push notifications are off unless the user turns them on, and turning them off removes the subscription.
Clovera does not use analytics, advertising, tag-management, or audience-measurement services, and embeds no third-party content other than what is listed above.
17. Account Deletion and Erasure
Clovera does not currently provide a button that deletes an account. Erasure is carried out by the data controller on request: a user who wants their account and its data erased should write to kitteniverseclovera@gmail.com from, or while signed in to, the account concerned, and the request will be carried out manually. Because no email address is held for any account, the request must include enough information for the controller to be satisfied that it comes from the account holder, as described in Section 9.
When such a request is carried out, Clovera erases the account record, its login and failed-session records, its session records and browser-identifier digests, the persistent-session tokens belonging to it, the account's messages, posts, comments, blog articles, and uploaded files, and the registration IP digest. Content that other users have received may remain visible to them where it forms part of their own conversation history, and records that Clovera must keep to comply with a legal obligation, to defend a legal claim, or to prevent the recurrence of serious abuse may be retained for as long as that purpose requires. Erasure is performed so that the erased data cannot be retrieved or reused.
Individual items can be removed without erasing the account: a user can delete their own messages, posts, comments, and blog articles at any time, and can replace or remove their profile photo and banner. As Section 7 explains, a deleted message stops being shown but its stored copy is not destroyed immediately.
18. Complaints
Users in jurisdictions with data protection rights may have the right to complain to a relevant supervisory authority if they believe their personal data has been handled unlawfully.
19. Changes to This Policy
Clovera may revise this Policy to reflect changes in the service, in the technology used to operate it, or in applicable law. Each revision is identified by the revision date shown at the top of this document.
Where a revision materially changes how personal data is collected, used, or shared, Clovera will bring the change to users' attention before it takes effect for them, will identify the substance of what has changed rather than merely stating that the Policy has been updated, and will ask users to accept the revised Policy before continuing to use the service. Revisions that do not affect the substance of the processing — such as corrections of typographical errors, clarifications of existing wording, or updated contact details — may be published with a new revision date without seeking renewed acceptance.
A material revision does not retroactively change the basis on which personal data was processed before that revision took effect.
20. Record of Revisions
26 July 2026 — Revised the KVKK Privacy Notice referred to in Section 15 and made it one of the documents each user confirms at registration and on re-acceptance. Corrected this Policy against the service as actually built, following a review of every factual claim in it: named every third party that receives personal data and what each one receives (new Section 16, covering hosted fonts, bot protection, and push delivery, none of which were previously disclosed); stated that no email address is collected and what follows from that for notices and identity verification; removed the statement that approximate location is derived from IP addresses, which Clovera does not do; described the logging of registration addresses, per-session address digests, and failed login attempts, which were not previously described; corrected the statement that users who decline "Keep me signed in" have no address digest stored for their sessions; corrected the described scope of automated moderation, which also covers non-public posts, comments, blog articles, server icons, and bot messages; replaced the undertaking to obtain consent before storing the browser security identifier with an accurate account of the basis actually relied on; described what a message deletion does and does not destroy; and added Section 17 explaining that account erasure is carried out on request rather than by a self-service control.
25 July 2026 — Introduced the browser security identifier described in Section 14. Extended the login records described in Section 12 to include the network category and network operator of the connection. Changed the digest stored in place of an IP address to a keyed digest, so that it can no longer be reversed into the original address. Users were asked to accept these changes before continuing to use the service.
8 July 2026 — Previous revision.