cove; is built on a simple principle: your conversations are yours. We do not read your messages, sell your data, or show you ads. This policy explains exactly what we collect, why, and what control you have.

1. Who We Are

cove; is a messaging application operated from the Kingdom of Bahrain. For the purposes of the Personal Data Protection Law (Law No. 30 of 2018, "PDPL"), we are the data controller responsible for your personal data. You can reach us at support@covechat.net.

2. What Data We Collect

2.1 Account Information

When you create an account, we collect your email address (for authentication only), your chosen display name and name colours, your cove code (@handle), and your profile photo (if you upload one). Your email address is used solely to send you a one-time verification code and is never shared with other users or third parties.

2.2 Messages and Content

We store the messages you send and receive so they are available across your devices and after reinstallation. This includes text messages, photos and media you share, reactions, replies, and read receipts. When you enable disappearing messages, content is automatically deleted according to your chosen timeframe. View-once media is permanently removed after it has been opened.

2.3 Usage Data

We collect minimal technical data to keep the service running: your device type and operating system (for compatibility), your IP address (for security and abuse prevention), crash reports and error logs (only when you submit a bug report), and app version information.

2.4 Presence and Status

Your online status (Online, Away, Busy, Offline) is visible to your contacts. If you set a mood, connect a music service, or connect a gaming account, this information is displayed to your contacts according to your privacy settings. You can hide specific activity from specific contacts.

2.5 Two-Factor Authentication

If you enable two-factor authentication (2FA), we store your phone number to send you one-time SMS verification codes. This number is used solely for 2FA verification on sensitive account actions — freezing your account, unfreezing it, and changing your registered email address. Your phone number is never visible to other users, never shared with third parties, and never used for marketing. Only the last 4 digits are displayed during the verification flow to confirm the correct number is on file.

2.6 Device and Session Information

We store a record of which devices are logged into your account. This includes a unique identifier for each device and the time it last connected. This is used to show you active sessions, allow you to log out remotely, and power the new-device approval flow. We do not store device names, IMEI numbers, or any hardware identifiers.

2.7 What We Do Not Collect

We do not collect your location data, your contacts or address book, your browsing history, biometric data, or any data for advertising purposes. We do not use cookies or tracking technologies for marketing.

3. Legal Basis for Processing

Under the PDPL, we process your personal data on the following legal bases:

Consent: You provide explicit consent when you create your account and agree to this policy. You may withdraw consent at any time by deleting your account.

Contract necessity: Processing is necessary to provide you with the messaging service you signed up for — delivering messages, maintaining your contact list, and syncing across devices.

Legitimate interest: We process limited technical data to prevent abuse, detect fraud, and maintain the security and stability of the service, provided this does not override your fundamental rights.

4. How We Use Your Data

We use your data exclusively to deliver and maintain the messaging service, authenticate your identity when you sign in, display your profile and status to your contacts, deliver messages and media between users, send you service notifications (like OTP codes), improve app stability through anonymised crash analytics, and respond to bug reports and support requests you submit.

We never use your data for advertising, profiling, or automated decision-making. We never sell, rent, or trade your personal data.

5. Data Sharing

We share your data only in the following limited circumstances:

With your contacts: Your display name, profile photo, mood, status, and messages are visible to people in your circle. You control who sees what through your privacy settings.

Service providers: We work with a small number of infrastructure providers to operate the service. These providers process data on our behalf under strict contractual obligations and may not use your data for their own purposes.

Legal requirements: We may disclose data if required by a valid court order, legal obligation, or lawful request from Bahraini authorities in accordance with the PDPL and applicable law.

6. Cross-Border Data Transfers

Your data is stored on servers operated by Supabase, which uses cloud infrastructure that may be located outside the Kingdom of Bahrain. In accordance with Article 12 of the PDPL and Ministerial Resolution No. 42 of 2022, we ensure that any cross-border transfer of personal data is made only to countries included on the approved list maintained by the Personal Data Protection Authority, or with your explicit consent as provided when you accept this policy.

We implement appropriate technical and organisational safeguards to ensure your data receives an equivalent level of protection regardless of where it is processed.

7. Data Retention

We retain your data for as long as your account is active. Messages are stored until you or the other participant clears the chat, or until disappearing message timers expire. View-once media is permanently deleted after opening. If you delete your account, all your personal data, messages, and media are permanently removed within 30 days in accordance with the deletion process described in Section 9.3 below.

8. Your Rights

Under the PDPL, you have the following rights:

Right to be informed: You have the right to know what personal data we hold about you and how we process it. This policy serves that purpose.

Right to access: You can request a copy of all personal data we hold about you by contacting support@covechat.net.

Right to rectification: You can update your profile information at any time through the app's Settings screen.

Right to deletion: You can delete individual chats, clear your data, or delete your entire account. You can also contact us to request complete erasure.

Right to object: You can object to specific types of processing by adjusting your privacy settings (hiding activity, muting contacts, etc.).

Right to not be subject to automated decision-making: We do not make any automated decisions that produce legal or significant effects on you.

To exercise any of these rights, contact us at support@covechat.net. We will respond within 30 days.

9. Account Security Features

9.1 New Device Login Approval

When you sign into cove; on a new device while another device is already active, the new sign-in requires approval before it is granted access. Your existing device will receive a notification asking you to approve or deny the new login. If you approve it, the new device gets access and your old session ends. If you deny it, the new device is blocked. This means only you — with access to an already-trusted device — can authorise a new login. If you do not have access to your old device, a one-time code is sent to your registered email address to verify your identity.

9.2 Two-Factor Authentication

You can enable two-factor authentication in Settings → Security. When 2FA is on, sensitive account actions — including freezing your account, unfreezing it, and changing your registered email — require verification via a one-time SMS code sent to your registered phone number. If 2FA is not enabled, these actions are verified via a one-time code sent to your email. We strongly recommend enabling 2FA for the strongest protection against unauthorised account access.

9.3 Account Deletion

When you choose to delete your account from Settings, your account enters a short grace period before permanent deletion. This gives you a window to change your mind. After the grace period ends, an automated process permanently and irreversibly removes all your personal data from our servers — including your profile, messages, media, contacts, and session history. We cannot recover deleted accounts after this process completes.

9.4 Account Freeze

If your device is lost or stolen, you can freeze your account at covechat.net/freeze. The process verifies your identity via a one-time code: if you have 2FA enabled, you'll receive an SMS to your registered phone number; if not, a code is sent to your registered email. Once verified, freezing immediately ends all active sessions and prevents any new sign-ins until you unfreeze. Nothing is deleted when your account is frozen — all your messages and data are preserved. You can unfreeze at any time after a 24-hour cooldown period using the same verification flow. The cooldown exists to prevent rapid freeze/unfreeze attempts by an unauthorised party.

10. Data Security

We implement the following technical and organisational measures to protect your data: TLS encryption for all data in transit, encryption for data at rest, row-level security policies ensuring users can only access their own data, new device approval required for logins when another device is active, two-factor authentication via SMS OTP for sensitive account actions, screenshot blocking in disappearing message conversations, rate limiting on authentication and sensitive actions, and regular security audits.

11. Children

cove; is not intended for children under the age of 13. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 13, we will delete it immediately. If you believe a child has provided us with personal data, please contact support@covechat.net.

12. In-App Purchases

cove; Pro is available as a monthly subscription, an annual subscription, or a one-time lifetime purchase, all processed through Apple's App Store or Google Play. We do not process or store your payment information — it is handled entirely by Apple or Google. We only receive confirmation that a purchase or subscription is active, which we use to activate Pro features on your account. Subscription management and cancellation is handled through your App Store or Google Play account settings.

13. Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. If we make material changes, we will notify you through the app or by email before they take effect. Your continued use of cove; after changes are posted constitutes your acceptance of the updated policy.

14. Complaints

In accordance with the PDPL, you have the right to raise concerns with the Personal Data Protection Authority of the Kingdom of Bahrain (pdp.gov.bh). For questions or requests relating to your data, you may contact us directly at support@covechat.net.

Security notice: Do not share your password, payment information, or personal details with anyone claiming to represent cove;. We will never ask for these. Our only official support channel is support@covechat.net. If you encounter someone impersonating cove;, please report them immediately using the Report feature on their profile, and block them.

15. User Conduct

By using cove;, you agree to the following:

We reserve the right to permanently remove any account that violates these terms, freeze the associated username, and prevent the associated email address from registering again.

16. Account Termination and Bans

If a user is found to have violated our conduct terms — including impersonation, harassment, fraud, or any malicious use of the platform — we may, at our sole discretion:

  1. Permanently delete their account and all associated data
  2. Freeze their username so it cannot be reclaimed by any account
  3. Permanently block their email address from registering on cove;

Banned users may not create new accounts using the same email address. Attempts to do so will be rejected.

17. Legal Consequences

cove; operates under the laws of the Kingdom of Bahrain. Misuse of cove; — including but not limited to impersonation, fraud, harassment, and unauthorised access — may constitute criminal offences under:

Where conduct on cove; appears to constitute a criminal offence, we reserve the right to report incidents to the competent authorities, including the General Directorate of Anti-Corruption and Economic and Electronic Security under the Bahraini Ministry of Interior (Hotline: 992), and to cooperate fully with any investigation.

Users are reminded that Bahraini law applies to online conduct, and that criminal proceedings may result in imprisonment and substantial financial penalties.

18. Your Data and Exports

You can export a copy of your account information and chat history at any time directly from the app. To do so, go to Settings → Privacy → Export My Data.

Your export is generated and saved directly to your device's local storage. We do not store export files on our servers or any external cloud service — the file never leaves your device unless you choose to share it yourself.

The exported file includes your profile information, your contact list, and your chat history at the time of the request. It does not include media files you have already cleared, messages with expired disappearing timers, or view-once content that has already been opened, as this content is permanently deleted and cannot be recovered.

If you also wish to request a formal copy of the personal data we hold on our servers, you may contact us at support@covechat.net. We will respond within 30 days in accordance with your rights under Section 8.

19. Contact

For any questions about this policy or your personal data:

Email: support@covechat.net
Website: covechat.net
Governing Law: Kingdom of Bahrain