Publishing Checklist
CLOVERA PUBLISHING CHECKLIST Last updated: September 14, 2026 Before publishing these documents on the live site, confirm the following: - The contact email is active and monitored. - The service actually follows the policies stated here. - The age requirement shown on Clovera matches the Terms. - The privacy page matches the real data collected by the app and backend. In particular: what the login record holds, which records keep a digest of an IP address, whether anything is placed in a user's browser to recognise it again, and what restores a persistent session. - Any analytics, cookies, ads, or third-party processors are actually disclosed. - Any special local legal requirements for your target countries have been reviewed. - The Google Gemini API tier actually in use (free vs. paid) and its data-use terms have been verified — in particular whether Google may use submitted content for model improvement — and the AI disclosures in the Privacy Policy and GDPR Notice match those terms. - The in-app consent/opt-in flows for KittenAI features (feature buttons, the Live Translation toggle, and any registration-time policy acceptance) match the legal bases claimed in the Privacy Policy and GDPR Notice. - For cross-border transfers under Turkish law, the mechanism relied on for each recipient — an adequacy decision, or one of the appropriate safeguards in Article 9 of the KVKK with the notification or authorisation that safeguard requires — is in place and matches Section 7 of the KVKK Notice, which no longer treats the use of a feature as explicit consent. - The list of KittenAI features and moderated content types in the legal documents matches what the app actually sends to Google. - The serious-crime screen for messages has been reviewed by counsel for every jurisdiction Clovera is offered in before it is switched on, and the state of that switch in the deployment matches what the Privacy Policy, the KVKK Notice, the GDPR Notice, and the in-app notice say. While it is off, no text in those documents may state that private messages are being read. - The categories the serious-crime screen flags, as they are written in the prompt in kittenai/core.py, are the same closed list that Section 15(e) of the Privacy Policy sets out, and nothing has been added to the prompt without being added to the published documents. - Every third-party service that receives user data is named in the Privacy Policy, the KVKK Notice, and the GDPR Notice, and no service has been added to the app without being added to those documents. - Calls and voice channels in the deployment are still carried by Clovera's own relay alone. The documents say that no STUN server, TURN relay, or other outside party takes part and that nothing is recorded; if a deployment ever configures an external relay, or if the client is changed to connect participants directly, that provider and the disclosure of each participant's address to the other participants have to be added to the Privacy Policy, the KVKK Notice and the GDPR Notice before the change goes live. - The list of records in which a digest of an address is kept — Section 12 of the Privacy Policy, Section 9 of the KVKK Notice, Section 4(b) of the GDPR Notice — still matches the code. Any new table that stores one has to be added to all three, and to the list in Section 3 of the Terms. - What is stored unencrypted, as Section 8 of the Privacy Policy and Section 18 of the KVKK Notice describe it, still matches the code: uploaded files of every kind, blog titles, scheduled messages, KittenAI assistant conversations, profile text and the names of communities, channels and groups. If encryption is applied to any of them, or removed from anything else, both texts are corrected in the same revision. - Requests to erase an account can actually be carried out by whoever monitors the contact address, and are recorded as the retention and destruction rules require. - The notices the DSA Information promises are actually delivered: a reporter is told the outcome of their report, and a user whose content is removed is told that it was, with the route to contest it. - The assessment of whether the service has a substantial connection to the Union, on which Section 1 of the DSA Information rests, has been made against the service as it actually stands and is revisited as it grows. If it is offered in the Union, a legal representative is designated in writing and named in that Section. - Section 1 of the DSA Information says the promotional material is published in English only. That is still true of the deployment: the landing page, the descriptions served to search engines and any advertising carry no German, French, Spanish, Italian or Portuguese. The interface and the translation feature are unaffected and are meant to stay that way. - The number of recipients in any single Member State, relative to that State's population, is still low enough that the position in Section 1 of the DSA Information holds. This is the criterion that revives the obligation on its own as the service grows, whatever language the marketing is in. - What is readable without an account in the deployment — public posts, blog articles, publicly listed communities and their channels and forums — matches Section 14 of the Privacy Policy, Section 8 of the KVKK Notice and Section 5 of the GDPR Notice, including whether indexing of channel and forum pages is switched on. - The summary of changes shown on the re-acceptance screen names the substance of the revision users are being asked to accept, in every language, and says nothing that the documents no longer say. A user who reads only that screen must not be misled. - The keyed-digest configuration that the address digests depend on is present in the deployment. Without it those digests are not keyed, and the description of them in the Privacy Policy, the KVKK Notice and the GDPR Notice overstates the protection. - Where the Digital Services Act applies, the position on a legal representative for the Union stated in Section 1 of the DSA Information is the true position, and the representative's details are published there once designated. - The technical configuration the published texts depend on has been verified against the deployment notes held with the legal review file. - A written procedure exists for a personal data breach, naming who assesses it, who notifies the supervisory authority within the 72 hours that Section 8 of the Privacy Policy and Section 18 of the KVKK Notice commit to, and who posts the in-service notice. That period cannot be met by improvising after an incident, and the notice route is the only one there is, since no contact detail is held for any account. - The registration position under the Data Controllers' Registry has been checked against the exemption figures currently in force, not the ones in force when this was last looked at, and against whether the processing of special-category data has become a main activity — which is a question the serious-crime screen reopens if it is switched on. - The size thresholds recorded at the end of the legal review file are re-tested against real numbers: recipients per EU Member State, any United Kingdom user base, one million daily accesses from Türkiye, five million users, one hundred thousand users or 25M USD revenue. Each of those revives an obligation this deployment currently does not carry. - If Clovera later becomes a registered company, these documents are updated to show the correct operator details.