SECURITY PROTOCOL NOTICE // COVE-DATA-CHARTER-v2

Privacy Notice & Data Charter

EFFECTIVE DATE: JULY 2026 // STATUTORY DATA COMPLIANCE NOTICE

[ FIDUCIARY // SCOPE ]

1. Legal Fiduciary & Scope of Processing

This Statutory Privacy Notice is issued by Hestarion Technologies Private Limited (the platform operator), acting as the Data Fiduciary under Section 2(i) of the Indian Digital Personal Data Protection Act, 2023 ("DPDP Act") and as the Data Controller under Article 4(7) of the General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act ("CCPA").

Cove provides an exclusive ephemeral network sanctuary. Access to and use of our services is strictly limited to individuals who are at least 18 years of age. We do not knowingly collect, process, or store personal data from minors. If we discover that any node has been authorized by or belongs to an individual under 18, we will immediately delete all associated session states and enforce hardware-level network exclusions under the platform's perimeter protection protocols.

[ INVENTORY // DATA COLLECTED ]

2. Complete Personal Data Inventory

We only collect personal data that is strictly necessary to operate our platform, match you with other users, and protect the community from fraud. Below is the complete data inventory detailing what is processed, the purpose, retention timeline, and sharing disclosures.

A. Profile Details (Alias & Bio)

What is collected: A self-selected display alias (username) and a short biography.

Purpose: To represent your presence and allow other daters to discover you.

Retention: Retained for the lifetime of your account. Permanently deleted immediately upon account closure.

Sharing: Disclosed publicly to matched daters on the platform. Never sold or shared with advertisers.

B. Profile Photos

What is collected: Visual media files uploaded to represent your profile.

Purpose: To allow potential matches to see you. Photos are blurred by default under our photo reveal rules.

Retention: Retained on secure Cloudflare R2 storage until deleted by you or upon account deletion.

Sharing: Shared strictly with matched users. Never shared with third parties.

C. Contact Information (Phone or Email)

What is collected: Phone number or email address.

Purpose: Account creation, secure multi-factor authentication, and liveness gating.

Retention: Stored strictly in an isolated, encrypted database (hashed using Argon2 for secure validation) until account closure. Decrypted only by authorized compliance officers for verification audits and abuse reviews.

Sharing: Never shared with third parties. Stored separately from application-level profiles to prevent lookup exposure.

D. Approximate Location

What is collected: Approximate latitude and longitude coordinates.

Purpose: To calculate match distance constraints and suggest nearby users.

Retention: Only your last known location is dynamically kept. No historical travel route log is maintained.

Sharing: Displayed to other users solely as a distance count (e.g. "5 km away"). Raw coordinates are never shared.

E. Ephemeral Messaging Payloads

What is collected: End-to-end encrypted direct chat texts and sent media files.

Purpose: Processing direct user communication.

Retention: Conversations are end-to-end encrypted (E2EE) and stored securely in encrypted format on the server. They remain stored until either participant manually triggers a scuttle to permanently erase the chat room and its messages from the server and client devices. (See Section 3 for safety report exceptions).

Sharing: Shared solely with the specific chat recipient in encrypted form. Entirely unreadable by Cove servers.

F. Technical Telemetry & Hardware Fingerprints

What is collected: Salted, one-way cryptographic hash of your device's hardware identifiers.

Purpose: Enforcing safety exiles, preventing banned actors from circumventing penalties, and fraud prevention.

Retention: Retained indefinitely in our secure blocklist system if a device has been exiled for severe safety violations.

Sharing: Not shared with any third party.

[ PROCESSING // SECURITY ]

3. Detailed Data Processing Inventory

A. Biometric Liveness Verification (Condition of Service)

Legal Basis: Legitimate Interest / Mandatory condition for platform access and catfish prevention.

To maintain the integrity of our sanctuary, completing our liveness verification challenge is a required condition of using the Cove platform. Verification selfies are uploaded securely and analyzed by our algorithms. Borderline cases are routed to a secure compliance queue for manual review by our Sentinel team. Once verification is resolved (approved or rejected), the verification selfie is permanently purged from our validation queues.

B. Media Sanitization Pipeline

Legal Basis: Legitimate Interest (User Security).

To prevent accidental leaks of your private data, our application processes all sent media files locally through our media sanitization script before network routing. This process permanently strips all EXIF metadata tags, GPS coordinates, and camera models from the uploaded file.

C. Ephemeral Messaging & Cryptographic Wiping

Legal Basis: Contractual Performance / Ephemerality Guarantee.

Direct messages and media are end-to-end encrypted. They are stored securely in encrypted format on our servers, and only the two participants hold the keys to decrypt them. They remain stored until either user manually clicks the "Vanish Chat" button, which executes an immediate database deletion to shred the room and all messages from both the server and client devices.

Safety Report Exception & Preservation: While conversations remain encrypted on our servers, if a user reports a message or media file for a severe safety violation (such as harassment or illegal content), the client-decrypted payload is securely transmitted to our safety queue and preserved for a period of 90 days. This preservation is strictly used to investigate terms violations and comply with global statutory reporting obligations (e.g. reporting to NCMEC or law enforcement).

[ COOKIES // SUBPROCESSORS ]

4. Sub-Processors & Cookie Disclosures

We work with select partners to host our servers and manage subscription verification. All partners are bound by strict data processing agreements.

Service TierProcessing FunctionData Transformed
Cloud InfrastructureServerless logic hosting, real-time message routingEncrypted media chunks, transient metadata
On-Device Vision SDKsLocal liveness analysisNone (Processed locally in volatile RAM)
Subscription ManagementApp Store / Play Store entitlement validationAnonymized purchase tokens & transactional states

Cookie & Local Storage Disclosure

Cove does not set tracking or advertising cookies on our website. We only utilize essential first-party local storage and session tokens to keep your node securely authenticated. Optionally, we use basic, privacy-respecting, anonymized website analytics (Cloudflare Web Analytics) to count site visits.

The Cove mobile application displays privacy-preserving, non-tracking sponsor campaigns using affiliate links. These ads do not track user behavior or profile users; they are uniform campaigns that may reward us if you click a link and make a purchase.

[ USER RIGHTS // STATUTORY ]

5. Global Data Subject & Statutory Rights

Regardless of your physical location, Cove provides global users with the following core rights under the Digital Personal Data Protection Act 2023, GDPR, and CCPA:

  • Right to Access & Portability: You may request a copy of the metadata we hold (alias, bio, and billing receipts).
  • Right to Correction/Rectification: You may correct or edit your profile alias or bio at any time in the app settings.
  • Right to Erasure (Right to Be Forgotten): You have the right to delete your account. Deletion immediately triggers a permanent cascade purge of your profile records.
  • Right to Withdraw Consent: You may withdraw your consent for future biometric liveness processing, which will terminate your active platform status.

To exercise any of these rights, please send an authenticated request to our legal desk at legal@covechat.app.

[ COMPLIANCE // OFFICER ]

6. Grievance Redressal & Contact Designation

Pursuant to Rule 5(9) of the Indian Information Technology Rules, 2011, and Section 8(9) of the Digital Personal Data Protection Act, 2023, Cove has appointed a Grievance Officer to address user complaints, privacy issues, and statutory data concerns.

Grievance Redressal Officer & Data Protection Contact

OFFICER:Mr. Rohan Deshmukh, Esq.
DESIGNATION:Data Protection Officer (DPO)
PHYSICAL OFFICE ADDRESS:Hestarion Technologies Private Limited,
Level 4, Dynasty Business Park, Andheri-Kurla Road,
Andheri East, Mumbai, Maharashtra 400059, India
LEGAL DESK EMAIL:legal@covechat.app
MEMBER SUPPORT EMAIL:support@covechat.app
STATUTORY TIMELINE:24-Hr Acknowledgment // 30-Day Resolution