Effective Date: September 10, 2026
Coves Team ("we," "our," or "us") operates the Coves mobile application and website. This Privacy Policy explains how we collect, use, and protect your information when you use our service.
Summary: Coves is built on the atProto protocol. Your data is stored on your Personal Data Server (PDS), which you control. We only index and cache publicly available data from the network to provide our service.
When you sign in to Coves, we receive the following from your atProto identity:
When you use Coves, the content you create is written to your PDS:
| Data Type | Collected? |
|---|---|
| Passwords | No - OAuth only |
| Device identifiers (IMEI, serial numbers) | No |
| Location data | No |
| Contacts | No |
| Photos/media from your device | No |
| Analytics or telemetry | No |
| Advertising identifiers | No |
| Crash reports | No |
We use the information we collect to:
We do not use your information for advertising, profiling, or selling to third parties.
Important: Coves is built on the atProto (AT Protocol), a federated social networking protocol. This affects how your data works.
Your content (posts, comments, votes) is stored on your PDS, not on Coves servers. You may host your own PDS or use a hosted provider. You maintain control over your data at the PDS level.
Coves operates an AppView that indexes publicly available data from the atProto network firehose. This means:
Because atProto is federated, your public content may be visible on other applications and services that use the protocol. This is a feature of the protocol, not something Coves controls. When you post content, consider that it may be indexed and displayed by other atProto services.
We use the following third-party services:
We do not use third-party analytics, advertising networks, or tracking services.
You can request deletion of your Coves account at Delete Account. When your request is completed, we remove your profile, posts, comments, votes, subscriptions, and other associated account data from the active Coves AppView database. Signing out does not delete your account or content.
Copies of deleted data may remain in database backups for up to 30 days, until those backups expire. Backups are restricted to authorized personnel and used for disaster recovery, rather than serving content or restoring deleted accounts. If we restore a backup, we reapply completed deletion requests before returning the restored data to normal service.
We retain a limited deletion record containing your account identifier and the deletion date to prevent your deleted data from being imported into Coves again. Moderation and safety reports may also be retained where necessary to investigate abuse, protect users, or meet legal obligations. These records are separate from your public profile and content. They are retained only for those purposes and for as long as necessary.
Deleting your Coves AppView account does not delete your AT Protocol identity, account, records, or media stored on a Personal Data Server (PDS). This includes a Coves-hosted PDS. PDS deletion is a separate process. Other services may also hold copies of content that was previously public; Coves cannot directly delete copies controlled by those services.
You have the right to:
To exercise these rights, contact us at support@coves.social.
Coves is intended for users who are 18 years of age or older. We do not knowingly collect information from anyone under 18. If you are under 18, please do not use this service.
If we learn that we have collected personal information from a user under 18, we will take steps to delete that information promptly.
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
We encourage you to review this policy periodically.
We may introduce analytics, crash reporting, or other features in the future to improve the service. If we do, we will:
If you have questions about this Privacy Policy or our practices, contact us at:
Coves Team
Email: support@coves.social