Privacy Policy
CLOVERA PRIVACY POLICY
Last updated: September 14, 2026
Contact: kitteniversestudios@gmail.com
1. Scope
This Privacy Policy explains how Clovera, a service operated by Kitteniverse Studios, collects, uses, stores, shares, and protects personal data in connection with the service.
2. Data We May Collect
Clovera may collect:
(a) account data: a username, a password (stored only as a hash), a language preference, and optional profile details such as a display name, pronouns, a short biography, a custom status, an accent colour, a profile photo, and a banner. A user who wants the birthday marker shown on their profile may also give the day and month of their birthday; the year is never asked for and is never stored, so Clovera holds no date of birth and cannot derive an age from what it holds. Registration requires only a username and a password. Clovera does not ask for, and does not collect, an email address or a telephone number; an internal, non-deliverable placeholder address is generated for the account record so that the account table has a unique identifier;
(b) technical data: the IP address of each connection, which the server sees while a request is being handled and which is afterwards retained only as a one-way keyed digest, and only in the records listed in Section 12; and the browser's User-Agent string. Clovera does not derive or store the geographic location of users from their IP addresses, does not record the operator or the type of the network a user connects from, and places no identifier in a user's browser for the purpose of recognising that browser again;
(c) usage data: login times, failed login attempts, interactions, reports, blocks, community participation, and feature usage;
(d) content data: messages, posts, comments, blog articles, attachments, profile text, and other user-submitted content, including a message written now and scheduled to be sent later, and what a user writes to the KittenAI assistant;
(e) safety and moderation data: report records, enforcement history, detection signals, and abuse-prevention logs;
(f) call and voice-channel data: that a call took place, between which two accounts, whether it was answered, and when it began and ended; and, while a user is in a voice channel of a community, which channel they are in and whether they are muted, deafened, or sharing a screen. What is spoken or shown during a call is not recorded, as Section 8 explains.
3. How Data Is Used
Clovera may use personal data to:
(a) create and manage accounts;
(b) provide messaging, community, feed, moderation, and support functions;
(c) protect users and the service from spam, fraud, abuse, illegal activity, and security threats;
(d) enforce platform rules and legal obligations;
(e) improve reliability, performance, and user experience;
(f) communicate service notices, policy updates, and support responses. Because Clovera holds no email address, these are delivered inside the service — as on-screen notices, as the acceptance screen shown when the policies are revised, and, where a user has enabled them, as push notifications. Clovera cannot contact users outside the service unless they write to the contact address first.
4. Legal Bases
For users in the European Economic Area, United Kingdom, or similar jurisdictions, Clovera may process personal data under one or more lawful bases, including:
(a) performance of a contract;
(b) legitimate interests, such as security, fraud prevention, moderation, and service improvement;
(c) consent, where required;
(d) compliance with legal obligations.
5. Data Sharing
Clovera does not sell personal data. Clovera does not use analytics, advertising, or audience-measurement services. Data may be shared:
(a) with the providers listed in Section 16, each of which receives only the data described there and acts on Clovera's behalf or under its own terms as stated in that Section;
(b) when necessary to investigate abuse, enforce rules, or respond to lawful requests;
(c) in connection with legal claims, safety incidents, or protection of rights;
(d) if the service is reorganized, sold, or transferred, subject to applicable law.
6. International Transfers
Because Clovera is an international online service, data may be processed in countries other than the user's own. Every provider named in Section 16 may process data on servers outside the user's country, including outside Türkiye and the European Economic Area. This applies to content submitted to KittenAI features (Section 15), to the IP address and challenge token sent to a bot-protection provider, to the IP address and User-Agent disclosed to Google when a page loads its hosted fonts, and to push notification delivery. Where required by law, Clovera relies on the transfer mechanisms provided under each provider's terms, such as an adequacy decision (including the EU–U.S. Data Privacy Framework where applicable) or standard contractual clauses.
7. Retention
Clovera keeps personal data only for as long as reasonably necessary for the purposes described in this Policy, including operation of the service, safety, dispute resolution, legal compliance, and enforcement. Different categories of data may be kept for different periods depending on risk and legal need.
Account content, login records, and failed login records are retained for as long as the purposes above require and are not deleted on a fixed schedule; login and session records tied to an account are removed when that account is deleted under Section 17. Failed login records are not linked to any account, because a failed attempt may not correspond to a real user; they consist of an IP digest, the username that was attempted, the reason for the failure, and the User-Agent string.
When a user deletes one of their own messages, the message is marked as deleted and stops being shown to the participants, but the stored copy remains in Clovera's database rather than being erased immediately — encrypted in the case of a direct message, in plain text in the case of a group or community message, as Section 8 explains. This is deliberate: a message deleted seconds after it was sent is frequently the subject of an abuse report, and destroying it on request would make such reports impossible to assess. Deletion in the sense of destruction is described in Section 17.
Abuse reports filed by users carry a category chosen by the reporter (for example fraud, threats, or content involving minors) and a free-text explanation. When a report is reviewed, the outcome of the review is recorded with it. Once a report has been settled — upheld or dismissed — for 180 days, its free-text explanation is erased; the category, outcome, and dates are kept so that the amount of unlawful use of the service can continue to be measured. For the same measurement, Clovera also keeps daily counters of automated moderation events; these counters consist of a date, an event name, and a number, and contain no user identifier, content, or address. Private messages are not read or scanned to produce any of these figures.
8. Security
Clovera uses reasonable technical and organizational measures to help protect personal data. Direct messages between two people are encrypted at the application layer while stored on Clovera's servers (encryption at rest using ChaCha20-Poly1305), as are post bodies, post comments, blog articles and their comments, and the cached translations of direct messages. Passwords are never stored in plaintext — they are protected using a strong hashing algorithm.
Group messages, community channel messages, forum threads and forum replies, and the questions and options of polls are not encrypted at rest. They are stored in plain text in Clovera's database. This is a deliberate choice made on 14 September 2026, and it is a change from the previous revision, which encrypted them: a message written to a group, and above all a message written in a community to people the sender may never have met, has to be capable of being examined when it is reported, when a community is being investigated for organising abuse, and when a lawful order requires it — without that examination depending on a decryption step that hides how readable this content already is to the operator of the service. A user should therefore treat anything written in a group chat, a community channel, a forum, or a poll as content the operator of Clovera can read, and Clovera prefers to say so plainly rather than describe as encrypted something it can decrypt at will.
Files are not encrypted at rest, whatever they are attached to. A photograph, a video, a recorded voice message or a document sent in a direct message, a group chat or a community channel, and a profile photo or a banner, are stored on Clovera's servers in the form in which they arrived; only the message text around them is encrypted. Who may fetch such a file is controlled — a file attached to something that is not public is served only to an account already entitled to see it, as Section 14 describes — but the operator of the service can open it. The same is true of several other things a user writes, which are stored in plain text: the title of a blog article, a message scheduled to be sent later while it waits to be sent, what a user writes to the KittenAI assistant and what it answers, profile text, and the names of communities, channels, and groups.
Calls, voice channels, and screen sharing are not stored at all. A one-to-one call started from a direct message carries sound only; a voice channel in a community carries sound and, where a member shares a screen, the picture of that screen or window and its sound where the sharer includes it. None of this is peer-to-peer, and none of it passes through a third party: each participant's stream travels over an encrypted connection to Clovera's own server, which forwards it to the other participants from memory and keeps no copy. Nothing is recorded, nothing is written to disk, and nothing is transmitted to Google or to any other provider — no KittenAI feature and no automated review is applied to a call. What remains afterwards is what Section 2(f) describes. A user should nevertheless understand that the sound of a call passes through Clovera's server in a form that server can read, which is what makes it different from an end-to-end encrypted call.
The encryption applied to direct messages is applied by Clovera's servers and is not end-to-end encryption either: Clovera holds the key, and content is decrypted on the server when it is delivered to authorized participants and when a KittenAI feature or an automated safety review is applied to it, as described in Section 15. No system is perfectly secure, and Clovera cannot guarantee absolute security.
If a breach of security leads to the destruction, loss, alteration, or unauthorised disclosure of or access to personal data, whether by accident or otherwise, Clovera assesses it as soon as it becomes aware of it. Where the law requires notification, Clovera notifies the competent supervisory authority — in Türkiye the Personal Data Protection Board, within 72 hours of becoming aware of the breach, and where the GDPR applies the competent authority within the same period — and, where the breach is likely to result in a high risk to the people affected, tells them as well.
How that notice would reach a user follows from Section 2(a): because Clovera holds no email address and no telephone number for any account, it cannot be sent out of band. A notice to users is therefore given inside the service and on this site — an on-screen notice to every account, and a push notification where the user has enabled them — and describes what happened, what data was involved, what Clovera has done about it, and what the user can do. A person who has stopped using the service, or whose account has been erased, cannot be reached by Clovera at all. That is a consequence of collecting no contact details, and it is stated here rather than left to be discovered at the time.
9. User Rights
Where applicable, users may have rights to access, correct, delete, restrict, object to certain processing, or request portability of their personal data. Users may also withdraw consent where processing is based on consent. Requests may be sent to kitteniversestudios@gmail.com. Clovera may need to verify identity before completing certain requests; because Clovera holds no email address or other contact detail for any account, identity is verified through the account itself, for example by asking the user to post or send a value from the account in question.
Some rights can be exercised directly in the service without making a request: the account and its data can be erased from settings as described in Section 17, profile details and the username can be edited in settings, individual messages and posts can be deleted by their author, active sessions on other devices can be revoked, and Live Translation can be turned off.
10. Children's Data
Clovera does not knowingly allow underage use where prohibited by law and does not knowingly process children's data in violation of applicable law. Clovera does not collect a date of birth and therefore cannot verify a user's age: the day and month of a birthday may be given voluntarily for the marker shown on a profile, but the year is never collected, so no age can be derived from it. The minimum age is stated in the Terms of Service and is relied upon as a representation by the user. If Clovera becomes aware of unlawful underage use, it may remove the account and related data as appropriate.
11. Cookies and Similar Technologies
Clovera sets the following in a user's browser:
(a) a session cookie, which keeps a signed-in user signed in and is necessary for the service to function;
(b) where the user selects "Keep me signed in on this network", a device cookie for that feature, described in Section 13;
(c) preference values, such as the chosen language and theme.
None of these is used to recognise a browser for any purpose other than the one stated. Clovera does not place a separate security or fingerprinting identifier in the browser, and does not attempt to tell that two sign-ins came from the same browser.
Clovera does not use advertising, audience-measurement, or cross-site tracking cookies of its own. Where bot protection is enabled, the bot-protection provider named in Section 16 loads its own script on the login and registration pages and may set its own cookies or browser storage for the purpose of distinguishing automated traffic; Clovera does not read those values and does not use them for any purpose of its own. A separate cookie notice may be provided where legally required.
12. Login Records and What Is Kept From an IP Address
Each time a user successfully logs in to Clovera, a record of that login is written. It consists of the user account identifier, the time of the login, and the browser's User-Agent string, and nothing else. In particular it contains nothing derived from the IP address of the connection: no address, no digest of one, no digest of the surrounding network range, no network operator, and no network category. Clovera formerly recorded an address digest and that network context against every login and no longer does. The reason is that behind proxies and mobile carriers the address reaching the server was frequently not the user's own, so the record linked together accounts that had nothing to do with each other.
The IP address of a connection is still seen by Clovera's servers while a request is being handled, and is used at that moment to apply rate limits, to check the address against a ban already in force, and, where bot protection is enabled, to verify a challenge with the provider named in Section 16. Once the request has been handled, the address is retained only as a one-way keyed cryptographic digest, and only in the six records below. The raw address is not stored in any of them.
(a) Registration. A digest of the address used at registration is stored on the account record, so that a single address cannot be used to create an unlimited number of accounts.
(b) Sessions. Every active session record stores a digest of the address and the User-Agent string of the device that created it. This is what allows a user to see their active sessions in settings and sign other devices out. It applies to every session, whether or not the user has selected the optional feature described in Section 13. Two further uses are made of this digest: the one in (e) below, and the one Section 15(d) describes, which is also made of the registration digest.
(c) Failed logins. A failed login attempt is recorded with a digest of the address, the username that was attempted, the reason for the failure, and the User-Agent string. A recovery key offered and refused is recorded in the same way, with the reason recorded as a bad recovery key. These records exist to detect password-guessing and account-takeover attempts. They are not linked to any account, because the username attempted may not belong to an existing user.
(d) Persistent sessions, and enforcement derived from them. Where a user has selected "Keep me signed in on this network", a digest of the address is stored with the device token, as Section 13 describes. Where an account is later banned, the digests stored with its persistent-session tokens are recorded as banned addresses, so that the same address can be refused, and that ban record may outlive the account.
(e) Account recovery requests. Clovera holds no email address, so a user who has lost their password and their recovery keys may instead ask for the reset to be approved from a device that is still signed in to the account. That request is stored with the account it concerns, a random token, an expiry, the User-Agent string of the browser that made it, and a digest of the address it was made from. The digest is used for one thing: it is compared with the digests held on that account's own session records, so that the person deciding on the request, on their other device, is shown whether it came from an address the account has signed in from before or from one it has not. Both the User-Agent string and that answer are shown to them, because a request to reset a password is exactly the kind of thing a person needs enough information to refuse. The request is deleted with the account.
(f) Rate-limit counters. An action that is rate-limited — signing in, registering, asking for a recovery, and some content actions — is counted against a row holding the digest of the address, the name of the action, a count, and the times at which the window opened and was last touched. The count returns to zero when the window passes. The row carries no account identifier, holds nothing about what was done beyond the name of the action, and is not deleted on a fixed schedule.
The digest is produced with a keyed one-way function (HMAC-SHA-256) using a secret key held only by Clovera. The key matters: the space of possible IPv4 addresses is small enough that an unkeyed digest of an address could be reversed by exhaustive search, and keying removes that possibility for anyone who does not hold the key.
These records are maintained for security purposes, including detection of unauthorized access, account recovery support, abuse investigation, and enforcement of platform rules. They are not used for advertising, behavioral profiling, or cross-service tracking. The legal basis for this processing is Clovera's legitimate interest in protecting the security of user accounts and the integrity of the platform (Article 6(1)(f) GDPR where applicable).
Login records, session records, persistent-session tokens, recovery requests and the registration digest are removed when the account is deleted under Section 17. Failed login records and rate-limit counters carry no account identifier and are therefore retained independently of any account. A ban recorded against an address digest may be kept after an erasure, as Section 17 explains.
13. Persistent Session ("Keep me signed in on this network")
Clovera offers an optional feature that allows users to remain signed in across browser sessions. When the user selects it at login, Clovera places a random device token in a cookie on that browser and stores, in association with the user account, a digest of that token together with a one-way keyed cryptographic digest of the IP address the user was connecting from. The raw IP address is not stored in this context; only its digest is retained.
The session is restored on a later visit when the browser presents that device cookie and the stored token matches it. Restoration does not in fact depend on the visit coming from the same network: despite the wording of the option, a request from a different address restores the session in the same way. Clovera states this plainly because the wording suggests otherwise, and because it affects how a user should judge the risk of enabling the feature on a device that other people can reach.
The address digest stored with the token is not used to restore the session. It is retained for a second purpose, and this is the only other thing it is used for: if the account is later banned, the digests held with its persistent-session tokens are recorded as banned addresses, so that the same address can be refused when it is used again. The digest is not used for advertising, for tracking across third-party services, or for any purpose beyond those described here.
Users may remove a persistent token at any time, by any of three routes: logging out deletes the token belonging to that browser, "Sign out of all other devices" in settings deletes the tokens belonging to every other browser, and each token can be revoked individually in Settings → Sessions. A token that is not revoked remains valid for as long as the account exists; the accompanying device cookie expires five years after it is set. Tokens are also removed when the account is deleted under Section 17, and when the account is banned.
The legal basis for creating the token and for restoring the session with it is the user's freely given, specific, and informed consent (Article 6(1)(a) GDPR where applicable), expressed by actively selecting the option at login, and withdrawable at any time by any of the three routes above. The legal basis for the second use of the address digest — recording it as a banned address when the account is banned — is Clovera's legitimate interest in making an enforcement decision effective (Article 6(1)(f) GDPR where applicable); that use is not covered by the consent, does not depend on it, and cannot arise for a token that has already been deleted. Users have the right to object to it under Article 21 GDPR.
Users who do not select this option have no persistent token and no digest stored for them under this Section. This is a distinct record from the session IP digest described in Section 12(b), which is created for every session regardless of this choice.
Users should exercise caution and not enable this feature on shared, public, or untrusted networks or devices.
14. Who Can See What a User Writes
Parts of Clovera can be read without an account, and some of them are offered to search engines. This Section says which, because "public" on Clovera means visible to the open internet, not merely visible to other signed-in users.
(a) Readable by anyone and offered to search engines. A post whose author marked it public, a published blog article, and the front page of a community whose owner has listed it publicly can be read by any visitor, with no account and no sign-in. These pages are listed in Clovera's sitemap, so search engines and AI crawlers may fetch and index them. What is shown with them is shown to the same audience: the author's username, display name, profile photo and banner, the reactions and comments on the item, and any file attached to a public post, which is served to visitors without a session for that reason.
(b) Readable by anyone holding the link, but kept out of search indexes. Inside a community whose owner has both listed it publicly and left it open to guests, the text and announcement channels, the forum listing and the forum threads can be read without an account. Those pages are excluded from the sitemap and are served with an instruction not to index them, in the page itself and in the response headers, so that a community can be found through a search engine while the messages written inside it are not put into a search index. Voice, mission, counting and showcase channels are never readable this way, and a channel that its permissions hide from everyone stays hidden from visitors too. The operator of the service can switch indexing of channel or forum pages on; unless it has been switched on, those pages are not offered for indexing.
(c) Guest reading is on unless the owner turns it off. A community that is listed publicly is open to guest reading by default. Its owner can close it in Community settings → Visibility, which keeps the community listed in Discover and closes its contents. The whole of public reading can also be switched off by the operator of the service for the deployment as a whole.
(d) Not readable without an account. Direct messages, group chats, communities that are not listed publicly, channels closed by permission, posts that are not marked public, and the files attached to any of these require an account that was already entitled to see them. Writing is never possible without an account: every action that creates or changes anything requires one.
(e) Who can hear a call. A one-to-one call is heard by the other participant only. A voice channel is heard, and a shared screen is seen, by the members of the community who are in that channel at the time and who are entitled to open it; anyone entitled to open the channel can join it and can see who is already in it. A visitor without an account can never join or hear a voice channel, and a voice channel is never readable from outside the service, as (b) above says. Beyond the participants, the sound and the shared picture pass through Clovera's own server, which forwards them without keeping a copy; Section 8 sets out what that means.
Content that other people, search engines or crawlers have already read, copied, indexed or cached while it was public does not become unreadable when its author later deletes it or makes it private. Clovera removes it from its own service, and ceasing to serve it is what eventually causes search engines to drop it, but Clovera cannot retrieve what a third party has already taken. A user should treat anything marked public as published.
15. KittenAI Features and AI Processing (Google)
Clovera includes built-in artificial intelligence features under the name "KittenAI", including conversation summaries, message translation, Live Translation, reply suggestions, Catch-Up digests, the KittenAI chat assistant, writing assistance, and automated content moderation. KittenAI is powered by Google's Gemini models, accessed through the Google Gemini API. Google acts as a third-party processor for these features.
When a KittenAI feature runs, the relevant content is decrypted on Clovera's servers and transmitted to Google for processing. Depending on the feature, this content may include:
(a) the text of direct messages, group messages, and channel messages, together with the display names of the participants, where a summary, translation, reply suggestion, or Catch-Up digest is produced from a conversation, or where the user attaches one of their own direct or group conversations to the KittenAI chat assistant as context, in which case the last forty messages of it are sent with the sender names;
(b) posts, post comments, blog articles, usernames, profile text, and messages submitted to the KittenAI chat assistant, together with the earlier messages of that assistant conversation, which are sent again as context each time the user writes to it;
(c) images such as profile photos, banners, server icons, and post attachments (for automated image moderation).
When each feature runs:
(a) User-initiated features (summarize, translate, reply suggestion, community idea, Catch-Up, writing assistance, and the KittenAI chat) run only when the user actively requests them.
(b) Live Translation runs only if the user has turned it on in their settings, and can be turned off at any time. It is off by default.
(c) Automated content moderation runs automatically, without being requested, on the following: feed posts and their comments — including posts that are not public — blog articles, usernames chosen at registration or changed later, profile text (display name, pronouns, custom status, bio, and custom profile sections), profile photos, profile banners, server icons, messages sent by creator bots, the name, description, welcome message, and channel names of a community, and the name of a group chat. It also runs on messages and forum posts in a community's channels where that community has enabled moderation. This general moderation never runs on a user's own direct messages or group messages; the only automated process that reads those is the serious-crime screen described in (e), and only where the operator has switched it on. Otherwise, direct and group messages are sent to Google only where a participant uses one of the features in (a) or (b) on the conversation.
(d) Account, community, and group review (the "KittenMOD sweep"). At intervals, Clovera also looks for accounts used for spam, communities and groups set up to deceive or to organise attacks, and coordinated attacks on people or communities. This review sends to Google only the texts listed in (c) — a community's name, description, welcome message, and channel names; a group chat's name; an account's profile text; and content already covered by (c). Everything else it uses is counted on Clovera's own servers from usage data (Section 2(c)) without any content being read or transmitted: how often an account publishes and sends channel messages; how many distinct people it sent direct messages to who never wrote back, and how many of them blocked it; how many people it added to newly created groups and how many of those blocked it; how many friend requests it sent; how many people blocked or reported it; how many of its items automated moderation has removed; how many members of a community blocked or reported its owner; how many invite links a community created; whether a community's recent messages were removed by automated moderation in large proportion; whether a burst of newly registered accounts joined a community together and had content removed there; and whether an account's registration or sign-in address digest (Section 12) matches an address digest recorded when another account was banned, which Sections 12 and 13 already name as a purpose. No private message or group message is opened for this review; the screen in (e) is the only process that opens one. The outcome is a case for a human administrator, containing the counts above and the category found, stored encrypted; where a community is judged to be a scam, an impersonation, or a vehicle for attacks, it may in addition be placed on hold (removed from discovery and closed to new members, its existing members unaffected) until the administrator has looked, and that hold is reversible. Automated review never suspends or bans an account, closes a community, or dissolves a group; those decisions are taken by a human administrator, as Section 2 of the DSA Information states.
(e) Serious-crime screen for messages. Clovera can be configured by its operator to run an automated screen over the text of direct messages and group messages. It is switched off by default; where it is switched off, no direct message or group message is read by it and nothing in this paragraph takes place. Where the operator switches it on, the following applies, and this paragraph describes it in full.
Purpose and question asked. The screen exists for one purpose: to keep Clovera from being used as an instrument of organised and other grave crime. Each message is put to KittenAI on its own, with one question — whether the message is itself a step in one of the following: running a criminal organisation, including recruitment, tasking, the division of proceeds, protection rackets and extortion; trafficking or smuggling people, forced labour, or forced prostitution; terrorism, including recruitment, financing, and attack planning; dealing in drugs, firearms, or explosives, including instructions for making weapons or explosives; the sexual abuse of children, including soliciting, arranging, or sharing such material; arranging violence for another party, including contract killing, kidnapping, and a credible and specific plan to kill or seriously injure a named person; and laundering money, trading stolen payment or identity data, or producing counterfeit money or documents.
What the screen is not. It is not general moderation of private conversation and cannot be used as such. Insults, threats made in anger, swearing, hate, harassment, bullying, sexual talk between adults, jokes, boasting, roleplay, fiction, personal drug use, and discussion of crime, politics, courts, or police as a subject are outside it and are not flagged by it, however unpleasant they may be. Nothing the screen reads is used to build a profile of a user, to rank a user, to target anything at a user, or for any purpose other than the one stated above.
What is transmitted. Only the text of the single message is sent to Google, with no username, no display name, no identifier, and no other message from the conversation. Messages that carry a file, and messages that have been deleted, are not read at all.
What is kept. Where the screen answers that a message is not within those categories — which is the answer in the ordinary case — nothing whatever is recorded about it and no trace of the reading is kept. Where it answers that a message is within them, Clovera opens a case for a human administrator containing the date, the category found, the sending account, the name of the group chat where the message was sent in one, and an excerpt of at most 200 characters of the message, stored encrypted. The identity of the other participants is not recorded in the case.
What happens next. The screen cannot delete a message, hide it, block its delivery, restrict an account, or take any other action. The message is delivered and stays where it is. A human administrator reads the case and decides: either the case is dismissed, and the message is left untouched, or the message is removed and the account recorded for enforcement. Any suspension, ban, or referral to an authority is a human decision taken on the case, never an automated one.
Legal bases (where GDPR or similar law applies): Clovera's legitimate interests in preventing its service from being used for serious crime and in protecting the people who use it (Article 6(1)(f) GDPR), and compliance with legal obligations to act against illegal content and to cooperate with lawful orders (Article 6(1)(c) GDPR). The screen is confined to the categories above, is off unless deliberately enabled, transmits one message at a time without identifiers, retains nothing where no category is found, and can take no action of its own; these limits are what keep the interference with the confidentiality of correspondence to what the purpose requires. The objection right in Section 9 applies to this processing, and the operator remains bound by the confidentiality-of-communications rules of each jurisdiction in which Clovera is offered.
Important: content a user sends to other users may be processed by KittenAI if another participant in the conversation uses an AI feature on that conversation (for example, translating, summarizing, or requesting a Catch-Up digest of it), or if the content is subject to automated safety moderation. By participating in conversations on Clovera, users acknowledge that other participants may use these features.
No KittenAI feature is applied to a call, a voice channel, or a shared screen. Sound and pictures are never transmitted to Google or to any other provider, are not transcribed, and are not moderated; the only content KittenAI receives is written content, of the kinds listed above.
A conversation with the KittenAI chat assistant is kept on Clovera's servers in plain text so that it can be shown again when the user returns, and so that it can be given back to Google as context for the next question. It stays until the user clears it with the button on that page, or until the account is erased.
Clovera transmits only the content reasonably needed for the requested feature, together with limited context such as the target language. No account identifier is transmitted; the user identifier is used only inside Clovera to apply per-user rate limits. Translation results are cached in encrypted form on Clovera's servers to reduce repeat processing. Content transmitted to Google is processed by Google subject to Google's applicable API and data processing terms. Clovera uses a Gemini API service tier under which content submitted through the API is not used to train or improve Google's models and is not reviewed by human reviewers for that purpose, and Clovera does not permit its processors to use this content for their own advertising purposes.
Legal bases (where GDPR or similar law applies): user-initiated features and Live Translation are processed on the basis of the user's request and consent (Article 6(1)(a) and, where the feature is part of the requested service, Article 6(1)(b) GDPR); automated safety moderation is processed on the basis of Clovera's legitimate interests in keeping the platform safe and lawful (Article 6(1)(f) GDPR) and compliance with legal obligations (Article 6(1)(c) GDPR).
Where Turkish Law No. 6698 (KVKK) applies, the transmission of content to Google constitutes a cross-border transfer of personal data, as does the processing carried out by every other provider named in Section 16. Such transfers are carried out in accordance with Article 9 of the KVKK, which since its amendment permits a transfer on the basis of an adequacy decision, failing that on the basis of one of the appropriate safeguards the Article lists, and only for transfers that are occasional on the basis of one of the exceptions in its final paragraph. Using a KittenAI feature is not itself the explicit consent the KVKK requires: explicit consent under that Law has to be given expressly, on specific information, and freely, and it is sought separately where a transfer rests on it. The KVKK Privacy Notice states which basis is relied on. Users who do not use KittenAI features and have not enabled Live Translation do not have their private message content sent to Google, except where automated safety moderation applies as described above. Full KVKK disclosures, including data subject rights under Article 11 of the KVKK, are provided in the separate KVKK Privacy Notice available in-app at /legal/kvkk-notice (shown in Turkish or English according to the user's language setting).
Users may object to or limit this processing by not using KittenAI features and disabling Live Translation. Questions and objections may be sent to kitteniversestudios@gmail.com, and the account, community, and group review described in (d) is among the processing to which the objection right in Section 9 applies.
16. Third-Party Services That Receive Data
Beyond Google's role in Section 15, the following services receive personal data when Clovera is used. Each is listed with what it receives and why.
(a) Hosting and infrastructure. Clovera's application and database run on a third-party hosting platform. It necessarily handles all data stored or transmitted by the service, in order to run it. Its role is that of a processor acting on Clovera's instructions.
(b) Google Fonts (Google LLC / Google Ireland Limited). Clovera's pages load two typefaces from Google's font servers. Because the browser fetches them directly, Google receives the visitor's IP address, User-Agent string, and the fact that a Clovera page was loaded. This happens on every page view, including for visitors who are not signed in and have no account. It is used only to display the site's typography; Clovera receives nothing back and no identifier of its own is involved. Where the GDPR applies, the legal basis is Clovera's legitimate interest in presenting the service consistently (Article 6(1)(f) GDPR). Users who prefer to avoid this transfer can block requests to Google's font domains in their browser; the service remains fully usable with fallback typefaces.
(c) Bot protection — Cloudflare Turnstile (Cloudflare, Inc.) and hCaptcha (Intuition Machines, Inc.). Where the operator has enabled bot protection, the login and registration pages load a challenge script from the relevant provider, and Clovera sends that provider the challenge token together with the visitor's IP address in order to verify the result. The IP address is sent in full to the provider for this check, even though Clovera itself stores only a digest of it. The provider may also set its own cookies or browser storage and collect signals about the browser in order to distinguish automated traffic. This applies only to the login and registration pages and only while the protection is enabled. The purpose is to prevent automated account creation and credential-guessing; where the GDPR applies, the legal basis is Clovera's legitimate interest in the security of the service (Article 6(1)(f) GDPR).
(d) Push notification delivery. If a user enables push notifications, their browser registers with the push service operated by the browser's vendor (for example Google, Mozilla, Apple, or Microsoft, depending on the browser). Clovera stores the resulting subscription endpoint and encryption keys and sends notification messages through that service. The push service therefore learns that a notification was sent to that subscription and the timing of it; the notification content is encrypted in transit to the browser. A notification says what kind of event occurred and, where there is one, the username of the person who caused it — that someone sent a message, mentioned the user, or called them. It never carries the text of a message. Push notifications are off unless the user turns them on, and turning them off removes the subscription.
Clovera does not use analytics, advertising, tag-management, or audience-measurement services, and embeds no third-party content other than what is listed above.
17. Account Deletion and Erasure
A user can erase their own account from the account settings, under "Delete account". The erasure runs immediately and cannot be reversed: there is no waiting period during which the account could be restored. Confirming it requires the account password and the account's own username. An account that owns a community with other members in it cannot be erased until that community has been handed to another member or closed, so that a community is not destroyed along with the account that created it; a community whose only member is the account holder is closed with the account.
A user who cannot reach that control may still write to kitteniversestudios@gmail.com from, or while signed in to, the account concerned, and the erasure will be carried out manually by the data controller. Because no email address is held for any account, such a request must include enough information for the controller to be satisfied that it comes from the account holder, as described in Section 9.
However it is carried out, erasure removes the account record, its login records, its session records, the persistent-session tokens belonging to it, any recovery request made for it, the account's direct, group, and channel messages, its posts, comments, blog articles, polls, reactions, and uploaded files, its conversation with the KittenAI assistant, the records of the calls it made or received and its presence in voice channels, the recovery keys issued to it, any bots it created together with those bots' own accounts, and the registration IP digest. A message the account deleted earlier is destroyed at this point too, rather than being kept as Section 7 describes.
Three things are not removed. Failed login records survive an erasure, because they carry no account identifier and may not correspond to a real user at all, as Sections 7 and 12(c) explain, and so do the rate-limit counters described in Section 12(f), for the same reason. Content that other users have received may remain visible to them where it forms part of their own conversation history. And records that Clovera must keep to comply with a legal obligation, to defend a legal claim, or to prevent the recurrence of serious abuse — including a ban already in force — may be retained for as long as that purpose requires, with any link to the erased account removed where the record can stand without it.
Erasure is performed so that the erased data cannot be retrieved or reused. Clovera keeps a record that an erasure took place, holding the date, whether it was carried out by the account holder or by the controller, and the number of records and files removed. That record deliberately contains nothing identifying the erased account, since a log naming it would recreate the very data the erasure destroyed.
Individual items can be removed without erasing the account: a user can delete their own messages, posts, comments, and blog articles at any time, and can replace or remove their profile photo and banner. As Section 7 explains, a deleted message stops being shown but its stored copy is not destroyed immediately.
18. Complaints
Users in jurisdictions with data protection rights may have the right to complain to a relevant supervisory authority if they believe their personal data has been handled unlawfully. A user in Türkiye may apply to Clovera first, as Section 13 of the KVKK Privacy Notice describes, and may then complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu). A user in the European Economic Area or the United Kingdom may lodge a complaint with the supervisory authority of their habitual residence, place of work, or the place of the alleged infringement (Article 77 GDPR). Complaining to an authority does not require complaining to Clovera first, and does not affect any other remedy.
19. Changes to This Policy
Clovera may revise this Policy to reflect changes in the service, in the technology used to operate it, or in applicable law. Each revision is identified by the revision date shown at the top of this document.
Where a revision materially changes how personal data is collected, used, or shared, Clovera will bring the change to users' attention before it takes effect for them, will identify the substance of what has changed rather than merely stating that the Policy has been updated, and will ask users to accept the revised Policy before continuing to use the service. Revisions that do not affect the substance of the processing — such as corrections of typographical errors, clarifications of existing wording, or updated contact details — may be published with a new revision date without seeking renewed acceptance.
A material revision does not retroactively change the basis on which personal data was processed before that revision took effect.
20. Record of Revisions
14 September 2026 — Described parts of the service this Policy had never mentioned, and completed two lists that were incomplete. Calls, voice channels and screen sharing are described for the first time: Section 2(f) says what is kept about them, Section 8 says that the sound of a call and the picture of a shared screen travel through Clovera's own server rather than between the participants directly or through any third party, that no copy is made and nothing is recorded, and Section 14(e) says who can hear a call. Section 8 also states what is not encrypted at rest, which it had described only for message text: no uploaded file is encrypted, including a photograph, a video, a recorded voice message or a document attached to a direct message, and neither are a blog article's title, a message waiting to be sent later, a conversation with the KittenAI assistant, profile text, or the names of communities, channels and groups. Section 12 adds the two further records in which a digest of an address is kept and which it did not list: a request to reset a password approved from another device, where the digest is compared with the digests of that account's own sessions so that the person approving it is told whether the request came from an address the account has used, and the rate-limit counters. Section 15 records that a user may attach one of their own conversations to the KittenAI assistant, that the assistant's conversation is stored in plain text and sent back to Google as context until the user clears it, and that no KittenAI feature is applied to a call. Section 2(a) adds the optional birthday day and month, and Section 10 says why that still leaves Clovera unable to verify an age. Section 16 says what a push notification contains, and Section 17 names what erasure removes in the records added here. Nothing in this revision adds any processing; it describes processing that was already taking place. Because it discloses uses of personal data and an audience for content that users were not told of, they are asked to accept it before continuing to use the service.
14 September 2026 — Corrected this Policy against the service as it is now built, after checking each factual claim in it. Sections 12 and 13 were the substance of it. Login records no longer contain anything derived from the IP address of the connection — no digest of the address, no digest of the surrounding network range, no network operator and no network category — and the passages that said they did have been rewritten to describe the four records in which an address digest is in fact kept. The browser security identifier that the former Section 14 described no longer exists anywhere in the service: no identifier is placed in a user's browser to recognise it again, that Section has been removed, and Section 11 now says so in terms. Section 13 corrects two statements about "Keep me signed in on this network" that were not true of the service: the session is restored by the device cookie alone and not by the address the request comes from, and the address digest stored with the token is used, if the account is later banned, to record that address as banned — so it is not, as this Policy previously said, used solely for session continuity. The legal basis for that second use is stated separately from the consent relied on for the feature itself. Section 14 is new and sets out who can read what a user writes, which this Policy had never addressed: that a public post, a blog article and the front page of a publicly listed community are readable by anyone and offered to search engines, that the channels and forums inside a publicly listed community are readable by anyone holding the link but kept out of search indexes, and that guest reading of such a community is on unless its owner turns it off. Section 15 no longer says that using a KittenAI feature amounts to the explicit consent the KVKK requires for a cross-border transfer. Section 18 names the authorities a complaint may be made to. Section 8 gains what this Policy had never said: what Clovera does if personal data is breached, whom it notifies and within what period, and how a notice can reach users at all when no contact details are held for them. Two notices were added to the service at the same time, and are recorded here because they are new uses of a user's account: a user who files an abuse report is now told inside the service when it has been reviewed and whether it was acted on, and a user whose content an administrator removes is now told inside the service that it was removed and how to contest that. Nothing here adds any processing, and the corrections to Sections 12 and 13 record less collection than this Policy previously described; because Section 13 discloses a use of personal data that users were not told of, and Section 14 discloses an audience for their content that they were not told of, users are asked to accept this revision before continuing to use the service.
14 September 2026 — Rewrote Section 8. Group messages, community channel messages, forum threads and replies, and poll questions and options are no longer encrypted at rest; they are stored in plain text. Direct messages between two people remain encrypted at rest, as do post bodies, post comments, blog articles and their comments, and the cached translations of direct messages. Nothing new is collected, no new content is transmitted to any processor, and the automated review described in Section 15 covers exactly what it covered before; what changes is the form in which group and community content sits in the database and, with it, what this Policy can honestly claim about it. The stored copy that survives a user's own deletion, described in Section 7, is therefore plain text for a group or community message and remains encrypted for a direct message. Because this revision lowers a security measure applied to content users have already written, it is brought to users' attention and acceptance is sought before it takes effect for them.
13 September 2026 — Added Section 15(e), the serious-crime screen for messages. Until this revision, no automated process read a user's direct messages or group messages at all, and Sections 15(c) and 15(d) said so. Clovera can now be configured by its operator to put the text of each direct and group message to KittenAI with one question — whether the message is a step in organised or other grave crime, in the closed list of categories set out in 15(e). The screen is off by default and does nothing unless the operator switches it on. It sends one message at a time, with no name or identifier attached; it keeps nothing where no category is found; where one is found it opens a case for a human administrator holding the date, the category, the sending account, and an excerpt of at most 200 characters, stored encrypted. It cannot delete a message, block its delivery, or restrict an account: the message is delivered and stays until a human decides otherwise. General moderation of private conversation is expressly not within it, and insults, hate, harassment, and other unpleasant but non-criminal content are outside its scope. Because this revision allows a new category of content — private correspondence — to be read by an automated process and transmitted to a processor, users are asked to accept it before continuing to use the service.
12 September 2026 — Extended automated content moderation in Section 15(c) to profile text, to the name, description, welcome message, and channel names of a community, and to the name of a group chat, all of which are now read by KittenAI. Added Section 15(d), describing the KittenMOD sweep: an automated review of accounts, communities, and groups that counts patterns of use on Clovera's own servers — publishing frequency, unanswered direct messages, group additions, blocks, reports, and a match between an address digest and a ban record — without opening any private or group message, sends nothing beyond the texts listed in 15(c) to Google, and produces a case for a human administrator. Stated that such a review may place a community on hold, reversibly, pending human review, and that it never suspends an account, closes a community, or dissolves a group by itself. Because this revision sends new categories of content to a processor and adds a new use of usage data, users are asked to accept it before continuing to use the service.
13 August 2026 — Described in Section 7 how abuse reports are used to measure unlawful use of the service: the reporter-chosen category and the review outcome recorded with each report, the erasure of a settled report's free-text explanation after 180 days, and the daily automated-moderation counters that carry no user identifier, content, or address. This revision adds a retention limit and an anonymous statistic and collects nothing new about anyone, so it is published without seeking renewed acceptance.
13 August 2026 — Rewrote Section 17 because account erasure is now a self-service control: an account can be erased from settings, immediately and irreversibly, where the previous revision said no such control existed and that erasure was carried out manually on request. Set out what that erasure removes in the terms the service actually implements, adding the recovery keys and creator bots it destroys and the earlier-deleted messages it finally purges, and stated plainly the three things it does not remove and why. Recorded that an account owning a community with other members must hand it over or close it first, so that erasing one account cannot destroy other people's content. Added that Clovera keeps a record of each erasure which identifies no account, as the retention and destruction obligation in the KVKK Notice requires. This revision expands what users can do without asking and removes nothing from them, so it is published without seeking renewed acceptance.
26 July 2026 — Revised the KVKK Privacy Notice referred to in Section 15 and made it one of the documents each user confirms at registration and on re-acceptance. Corrected this Policy against the service as actually built, following a review of every factual claim in it: named every third party that receives personal data and what each one receives (new Section 16, covering hosted fonts, bot protection, and push delivery, none of which were previously disclosed); stated that no email address is collected and what follows from that for notices and identity verification; removed the statement that approximate location is derived from IP addresses, which Clovera does not do; described the logging of registration addresses, per-session address digests, and failed login attempts, which were not previously described; corrected the statement that users who decline "Keep me signed in" have no address digest stored for their sessions; corrected the described scope of automated moderation, which also covers non-public posts, comments, blog articles, server icons, and bot messages; replaced the undertaking to obtain consent before storing the browser security identifier with an accurate account of the basis actually relied on; described what a message deletion does and does not destroy; and added Section 17 explaining that account erasure is carried out on request rather than by a self-service control.
25 July 2026 — Introduced the browser security identifier described in Section 14. Extended the login records described in Section 12 to include the network category and network operator of the connection. Changed the digest stored in place of an IP address to a keyed digest, so that it can no longer be reversed into the original address. Users were asked to accept these changes before continuing to use the service.
8 July 2026 — Previous revision.