Features How it works Why cove Pricing Contact

cove; is built on a simple principle: your conversations are yours. We do not read your messages, sell your data, or show you ads. This policy explains exactly what we collect, why, and what control you have.

1. Who We Are

cove; is a messaging application operated from the Kingdom of Bahrain. For the purposes of the Personal Data Protection Law (Law No. 30 of 2018, "PDPL"), we are the data controller responsible for your personal data. You can reach us at support@getpike.chat.

2. What Data We Collect

2.1 Account Information

You sign in with Apple or Google only. We receive the identity token and basic account identifiers those providers return (such as a stable subject ID and, when you choose to share it, an email address). We also collect your chosen display name and name colours, your Cove code, and your profile photo (if you upload one). We do not use email, SMS, phone numbers, passwords, or one-time codes for authentication. Your Apple/Google identity is not shared with other users as a contact method.

2.2 Messages and Content

We store the messages you send and receive so they are available across your devices and after reinstallation. This includes text messages, photos and media you share, reactions, replies, and read receipts. When you enable disappearing messages, content is automatically deleted according to your chosen timeframe. View-once media is permanently removed after it has been opened.

2.3 Usage Data

We collect minimal technical data to keep the service running: your device type and operating system (for compatibility), your IP address (for security and abuse prevention), automatic crash and performance telemetry via Sentry (with PII scrubbing; see §5), crash reports and error logs when you submit a bug report, and app version information.

2.4 Presence and Status

Your online status (Online, Away, Busy, Offline) is visible to your contacts. If you set a mood, connect a music service, or connect a gaming account, this information is displayed to your contacts according to your privacy settings. You can hide specific activity from specific contacts.

2.5 Device and Session Information

We store a record of which devices are logged into your account. This includes a unique identifier for each device and the time it last connected. This is used to show you active sessions, allow you to log out remotely, and power the new-device approval flow. We do not store device names, IMEI numbers, or any hardware identifiers.

2.6 What We Do Not Collect

We do not collect your location data, your contacts or address book, your browsing history, biometric data, or any data for advertising purposes. We do not use cookies or tracking technologies for marketing.

3. Legal Basis for Processing

Under the PDPL, we process your personal data on the following legal bases:

Consent: You provide explicit consent when you create your account and agree to this policy. You may withdraw consent at any time by deleting your account.

Contract necessity: Processing is necessary to provide you with the messaging service you signed up for, delivering messages, maintaining your contact list, and syncing across devices.

Legitimate interest: We process limited technical data to prevent abuse, detect fraud, and maintain the security and stability of the service, provided this does not override your fundamental rights.

4. How We Use Your Data

We use your data exclusively to deliver and maintain the messaging service, authenticate your identity when you sign in with Apple or Google, display your profile and status to your contacts, deliver messages and media between users, send you service notifications (such as new-message or login-approval alerts), improve app stability through anonymised crash analytics, and respond to bug reports and support requests you submit.

We never use your data for advertising, profiling, or automated decision-making. We never sell, rent, or trade your personal data.

5. Data Sharing

We share your data only in the following limited circumstances:

With your contacts: Your display name, profile photo, mood, status, and messages are visible to people in your circle. You control who sees what through your privacy settings.

Service providers: We use the following processors on our behalf under contractual obligations; they do not use your data for their own advertising:

We do not use Twilio or SMS for authentication. We do not use advertising or marketing analytics SDKs (no Meta Ads, AdMob, AppsFlyer, Adjust, Firebase Analytics, Mixpanel, Amplitude, or similar).

Legal requirements: We may disclose data if required by a valid court order, legal obligation, or lawful request from Bahraini authorities in accordance with the PDPL and applicable law.

6. Cross-Border Data Transfers

Your data is stored on servers operated by Supabase, which uses cloud infrastructure that may be located outside the Kingdom of Bahrain. In accordance with Article 12 of the PDPL and Ministerial Resolution No. 42 of 2022, we ensure that any cross-border transfer of personal data is made only to countries included on the approved list maintained by the Personal Data Protection Authority, or with your explicit consent as provided when you accept this policy.

We implement appropriate technical and organisational safeguards to ensure your data receives an equivalent level of protection regardless of where it is processed.

7. Data Retention

We retain your data for as long as your account is active. Messages are stored until you or the other participant clears the chat, or until disappearing message timers expire. View-once media is permanently deleted after opening. If you delete your account, your profile, contacts, sessions, and messages you sent are permanently removed from our servers after a grace period (see §9.2). Copies of messages you previously sent may remain in recipients’ conversations until they delete them. We cannot erase content from another user’s account.

8. Your Rights

Under the PDPL, you have the following rights:

Right to be informed: You have the right to know what personal data we hold about you and how we process it. This policy serves that purpose.

Right to access: You can download an account-data package (profile, contacts, sessions) from Settings → Storage & Data → Download my account data, and chat content via Backup chats / Export chat. You may also request a copy by contacting support@getpike.chat.

Right to rectification: You can update your profile information at any time through the app's Settings screen.

Right to deletion: You can delete individual chats, clear your data, or delete your entire account. You can also contact us to request complete erasure.

Right to object: You can object to specific types of processing by adjusting your privacy settings (hiding activity, muting contacts, etc.).

Right to not be subject to automated decision-making: We do not make any automated decisions that produce legal or significant effects on you.

To exercise any of these rights, contact us at support@getpike.chat. We will respond within 30 days.

9. Account Security Features

9.1 New Device Login Approval

When you sign into cove; on a new device while another device is already active, the new sign-in requires approval before it is granted access. Your existing device will receive a notification asking you to approve or deny the new login. If you approve it, the new device gets access and your old session ends. If you deny it, the new device is blocked. This means only you, with access to an already-trusted device, can authorise a new login. There is no recovery phrase or OTP bypass.

9.2 Account Deletion

When you choose to delete your account from Settings, you confirm with your Cove code and a fresh Apple or Google sign-in. Your account enters a 30-day grace period before permanent deletion. During that window your account appears offline to friends: contacts, conversations, messages, and settings stay intact, and messages sent to you are stored for delivery when you restore. New friend-request discovery is paused. If you cancel deletion or sign back in and restore within the grace period, your account returns with the same data, equivalent to having been offline. After the grace period ends, an automated process permanently removes your profile (and frees your Cove Code for reuse), severs contacts, deletes messages you sent, media you uploaded, stickers, sessions, and related account records from our servers. For Apple Sign-In accounts, we revoke the Apple token when deletion is requested (App Store requirement). We cannot recover accounts after permanent purge completes.

9.3 Account Freeze

If your device is lost or stolen, freeze your account from Settings inside the Cove app while signed in with Apple or Google. Freezing immediately ends all active sessions and prevents new sign-ins until you unfreeze. Nothing is deleted when your account is frozen. Unfreeze from the app after the cooldown by signing in again with the same Apple or Google account. The public freeze page is informational only and does not accept passwords, codes, or recovery phrases.

10. Data Security

We implement the following technical and organisational measures to protect your data: TLS encryption for all data in transit, encryption for data at rest, OAuth-only authentication (Apple/Google), row-level security policies ensuring users can only access their own data, new device approval required for logins when another device is active, screenshot blocking in disappearing message conversations, rate limiting on sensitive actions, and regular security audits.

11. Children

cove; is not intended for children under the age of 13. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 13, we will delete it immediately. If you believe a child has provided us with personal data, please contact support@getpike.chat.

12. In-App Purchases

cove; Pro is available as a subscription (monthly or yearly) or a one-time lifetime purchase, processed through Apple's App Store or Google Play, with entitlement verification via RevenueCat. We do not process or store your payment card information. It is handled by Apple or Google. We only receive confirmation that a purchase or active subscription exists (and associate it with your Cove account ID), which we use to activate Pro features on your account.

13. Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. If we make material changes, we will notify you through the app or by email before they take effect. Your continued use of cove; after changes are posted constitutes your acceptance of the updated policy.

14. Complaints

If you believe your data has been mishandled, you have the right to file a complaint with the Personal Data Protection Authority of the Kingdom of Bahrain (pdp.gov.bh). You may also contact us directly at support@getpike.chat and we will work to resolve your concern.

15. Contact

For any questions about this policy or your personal data:

Email: support@getpike.chat
Website: covechat.net
Governing Law: Kingdom of Bahrain