Privacy Policy
Last updated: 3 August 2026
This Privacy Policy explains how Krova Inc. (“Krova Cloud”, “we”, “us”) collects, uses, shares and protects personal data when you use our website, dashboard, API and related services (together, the “Service”). It applies to people who create or use a Krova Cloud account and to visitors of our public website. Personal data that you process through your Cubes as part of your own application is covered in Section 8 below. This policy is not a contract and does not create rights beyond those required by applicable law.
On this page
- 1. Who we are
- 2. What data we collect
- 3. How we use your data
- 4. Legal bases (EEA / UK users)
- 5. Sharing and subprocessors
- 6. International data transfers
- 7. Retention
- 8. End-user personal data inside your Cubes
- 9. Your rights
- 10. Marketing communications
- 11. Security
- 12. Children
- 13. Cookies
- 14. Changes to this policy
- 15. Contact
1. Who we are
Krova Inc. is the controller of the personal data described in this policy, unless stated otherwise. Our registered address is 131 Continental Dr, Suite 305, Newark, DE 19713, US. For privacy questions, requests or complaints, please contact us at [email protected].
2. What data we collect
2.1 Account data
- Email address, name and (if you sign in with Google) the profile photo URL associated with that Google account.
- Authentication identifiers from our authentication system (session tokens, magic-link tokens, OAuth account references).
- Your role within a space (owner, admin, member, viewer) and any permissions granted to you.
2.2 Authentication and session data
- IP address and user-agent string of the device used to sign in, recorded against each session for security purposes.
- Magic-link request timestamps, sign-in attempts and session expiry information.
2.3 Billing data
- Credit balance, top-up history, ledger entries and invoice metadata.
- Identifiers issued by our payment provider for your customer record, checkouts and orders. We do not store full payment card details on our systems; those are held by the payment provider under its own privacy notice.
2.4 Operational and product data
- The resources you create (such as Cubes, storage volumes, snapshots, backups, custom domains and access keys) and metadata about them.
- Operational, lifecycle and audit logs of actions taken through the dashboard and API, and real-time events used to stream status updates back to your browser.
2.5 Email delivery telemetry
We record delivery events for transactional and marketing emails (e.g. delivered, bounced, complained, failed) returned to us by our email-delivery provider. These records are stored against your user identifier for a limited period and pruned periodically.
2.6 Marketing contacts, consent and email engagement
We run our own marketing email list rather than keeping our audience with a third-party marketing platform. For every address on it we hold a contact record: the email address, a name where we have one, where the address came from (account signup, our blog newsletter form, or an import we made), and a separate consent record for each topic.
- Record of consent. When you opt in we record when you did, which form or flow it came from, and the IP address the opt-in was submitted from. That is what answers “who asked for this mail” if it is ever questioned, and because our blog newsletter form is public and unauthenticated, the IP address is also how we identify someone using it to sign up addresses that are not theirs.
- Contacts without a Krova Cloud account. Subscribing to our blog newsletter does not require an account, so we hold contact records for people who have never had one. Such a record contains the address, the topic subscribed to and the consent record above — and nothing about an account, because there is none.
- Account summary used to choose what we send. For contacts who do have an account, we keep a cached summary of that account next to the contact so we can decide which messages are relevant: an activation stage, which products you use (Cube, Nest, both or neither), how many Cubes you have and how many are running, how many spaces you belong to, your total prepaid credit balance across the spaces you own, your signup date, the date of your most recent sign-in, and whether your email address is verified. It is recomputed from data we already hold — when your account changes, and at least daily. None of it comes from outside Krova Cloud: we do not buy contact data or have it enriched by a third party.
- Click tracking. Links in our marketing email point at a redirect on our own domain. When you follow one, we record which message and which link you clicked, the time, a keyed one-way hash of your IP address (the hash, not the address) and your browser's user-agent string. We do not put an open-tracking pixel in marketing email — the engagement we record is the click.
- Do-not-send list. When a message hard-bounces or is reported as spam, we add that email address to a do-not-send list that our marketing sending checks before every message. It is held by address, so it keeps working even when nothing else about the recipient remains.
2.7 Website and product analytics
We use Google Tag Manager to load Google Analytics and may use similar analytics, performance and product-telemetry tools to understand how visitors and customers interact with our website and dashboard. These tools may collect information such as your IP address, device, browser, operating system, referrer, pages viewed, links clicked, session duration, interaction events, general (city / country) location inferred from IP, and a pseudonymous identifier stored in cookies or local storage. See our Cookie Policy for details about the specific cookies set.
2.8 Customer Content inside your Cubes
Anything you install on, upload to or generate within a Cube is Customer Content. We do not routinely inspect Customer Content. We may access host-level metadata about a Cube (resource usage, boot state, network attributes) and, where necessary, the Customer Content itself to operate the Service, troubleshoot incidents, enforce our Terms of Service or Acceptable Use Policy, investigate suspected abuse, fraud or security threats, or comply with applicable law or a legal request.
3. How we use your data
We use personal data to:
- create and operate your account, authenticate you and provide the features of the Service;
- measure and bill resource usage, process payments, apply surcharges, grant or claw back credit, and pursue unpaid amounts;
- send transactional emails (sign-in links, billing alerts, security notices, abuse notifications, service announcements);
- send service updates and, where permitted, marketing communications you can opt out of at any time, choose which of those messages is relevant to you using the account summary described in Section 2.6, and measure which links in them are clicked;
- keep a record of who asked for marketing email and who asked to stop receiving it, so that we can prove consent and so that an address we have been told not to mail is not mailed again;
- secure the Service against abuse, fraud, intrusion and outages, including by analysing access logs, rate-limiting behaviour, building profiles of suspicious activity and sharing information with law-enforcement bodies where appropriate;
- comply with our legal obligations and enforce our Terms of Service and Acceptable Use Policy;
- measure and improve the performance, security and design of the Service, including by analysing usage trends and building aggregated or de-identified statistics that we may use freely for any purpose;
- establish, exercise or defend legal claims.
4. Legal bases (EEA / UK users)
If you are in the European Economic Area or the United Kingdom, our legal bases for processing your personal data are:
- Contract: to create your account, provide the Service and process payments under our Terms.
- Legitimate interests: to secure the Service, prevent and investigate abuse and fraud, recover unpaid amounts, measure and improve our product, and run our business efficiently. We balance these interests against your rights and freedoms.
- Legal obligation: to keep records required by tax, accounting, sanctions or other applicable laws and to respond to lawful requests from authorities.
- Consent: where required, for example for certain marketing communications or non-essential cookies. You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Sharing and subprocessors
We do not sell your personal data for monetary consideration, and we do not share personal data with third parties for cross-context behavioural advertising. We share personal data only with the following categories of recipients and only as needed to provide, secure, market or improve the Service or as required by law. You may request the current list of subprocessors we use as described on our Subprocessors page.
- Infrastructure providers — server and storage providers that host our infrastructure. Customer Content sits on infrastructure operated by these providers.
- Payment provider — Stripe, for payment processing of prepaid credit top-ups. The payment provider receives billing identifiers and processes card data under its own privacy notice.
- Cloudflare — DNS, CDN and bot/abuse mitigation for our own sites and control plane.
- Email-delivery provider — for transactional and marketing email and delivery telemetry; receives your email address and message content.
- Real-time messaging — real-time UI update events are delivered to your browser using self-hosted messaging software running on our own infrastructure; these events are not routed to a third-party messaging provider.
- Analytics and product telemetry — Google (Tag Manager, Analytics) and any similar analytics or product- telemetry providers we use from time to time. These providers may set cookies in your browser; see our Cookie Policy.
- Google — if you choose Google as your sign-in method, Google receives an authentication request and returns your profile information to us under Google's privacy policy.
- Professional advisers and authorities — lawyers, accountants, auditors and law-enforcement or regulatory bodies where we determine, in our discretion, that disclosure is appropriate, including in response to lawful requests or to protect our or others' rights, property or safety.
- Corporate transactions — counterparties, advisers and successors in connection with a merger, acquisition, financing, reorganisation or sale of all or part of our business or assets. The recipient may continue to use your personal data as described in this policy or under a replacement policy we make available.
6. International data transfers
Our subprocessors operate globally and your personal data may be transferred to and processed in countries outside your country of residence, including outside the EEA, the United Kingdom and Switzerland. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or other mechanisms permitted by applicable law or published by the relevant subprocessor.
7. Retention
We keep personal data only for as long as we reasonably need it for the purposes described in this policy, and longer where required or permitted by applicable law (for example, tax, accounting, anti-fraud, audit, dispute-handling and the establishment, exercise or defence of legal claims). Indicative retention periods are:
- Account data: for the lifetime of your account, and deleted within approximately 90 days after your account is closed or terminated, except where we need to retain it longer for billing, dispute or legal-compliance purposes (for example, the categories described elsewhere in this section). Your email address is a deliberate exception: it is kept on the marketing records described in the next two entries.
- Marketing contact and consent records: for as long as we run the marketing list. When you unsubscribe, ask us to forget you, or close your account, we retire the contact — it is marked deleted, unlinked from your account and unsubscribed from every topic, and the account summary in Section 2.6 stops being refreshed — but we do not delete the email address or the record of the original opt-in (when, from which form, from which IP address). That is the point of keeping it: the address is how we recognise you and do not mail you again, and deleting it would let the same address be added back through our public newsletter form with no trace that it had ever unsubscribed. The do-not-send list is kept on the same basis, and by address for the same reason. If you would rather these records were erased than kept as a suppression, tell us — see Section 9.
- Marketing send and click records: which message we sent you, when, and which tracked links were clicked, kept as the history of the marketing programme. The message bodies are pruned with the rest of the email outbox; the send and click records themselves are not deleted on a fixed schedule.
- Session and authentication data: for the duration of the session, plus a security-forensics window.
- Billing records and invoices: for the period required by applicable tax and accounting law (typically up to 10 years).
- Audit and lifecycle logs: for as long as necessary for security, compliance and dispute-handling purposes.
- Email delivery telemetry, job logs and similar operational telemetry: for a limited period and pruned periodically.
- Customer Content (Cubes, snapshots, backups): until you delete it or your account is closed or terminated; residual copies may persist in backups and operational systems for a reasonable rotation period before permanent removal.
We may retain personal data for longer where necessary to investigate or defend against suspected fraud, abuse, security incidents, chargebacks or legal claims, or as required by law.
8. End-user personal data inside your Cubes
If your application processes personal data of your own end users inside a Cube, you act as the controller (or equivalent) of that data and Krova Cloud acts as your processor (or equivalent) for that processing only. You must have a lawful basis for that processing, inform your end users as required by law and implement appropriate technical and organisational measures inside your Cube. We process such data only on your documented instructions, as described in our Terms and any data-processing addendum we make available where one is required. If you need a signed data-processing agreement to cover this processing, see our Data Processing Addendum, which you can rely on as our standard terms for that relationship.
9. Your rights
Depending on where you live, you may have the right, subject to applicable conditions and exemptions, to:
- access the personal data we hold about you;
- correct inaccurate or incomplete personal data;
- request deletion of your personal data;
- restrict or object to certain processing, including direct marketing;
- receive a portable copy of personal data you provided to us; and
- lodge a complaint with your local data-protection authority.
You can exercise many of these rights directly from your profile (for example by editing your details, exporting your data or deleting your account). For anything else, write to us at [email protected] or [email protected]. We will respond within the timeframe required by applicable law. We may need to verify your identity, ask for additional information or, where permitted by law, decline or charge a reasonable fee for manifestly unfounded or excessive requests.
9.1 India (Digital Personal Data Protection Act)
If you are in India, you have rights under India's Digital Personal Data Protection Act, 2023, including the right to access and correct your personal data, to have it erased, to grievance redressal, and to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. To exercise any of these rights or to raise a grievance, contact us at [email protected].
10. Marketing communications
We may send you marketing communications about Krova Cloud — for example product updates, tips and offers. Where applicable law requires prior consent (including in the European Economic Area and the United Kingdom), we will only send marketing communications after you have given that consent. Elsewhere, we rely on the soft-opt-in or the legitimate interest of marketing our own similar products and services to existing customers.
Consent is recorded separately for each topic. Subscribing to our blog newsletter grants that newsletter and nothing else — it does not enrol you in the product emails we send account holders — and the marketing-email setting in your profile controls those product emails rather than the newsletter.
You can opt out of marketing communications at any time by:
- toggling the marketing-email setting in your profile in the dashboard; or
- clicking the unsubscribe link in any marketing email we send.
The unsubscribe link lets you stop only the sequence that message came from, pause all marketing for 90 days without withdrawing your consent, or stop every marketing topic at once.
When you unsubscribe, or ask us to forget you, we keep your email address and the record of your original opt-in instead of deleting them. That record is what stops the address being mailed again, which is why it is deliberately not removed along with the rest of your account data — see Section 7. For the same reason, an address that has been forgotten cannot be re-subscribed by typing it into our public newsletter form; that would let anyone who knows the address undo your request. Coming back means signing in and opting in again, or asking us at [email protected].
Opting out of marketing does not stop transactional or service-related emails (sign-in links, billing notifications, security alerts, abuse notices and service announcements) that are necessary to operate the Service.
11. Security
We use industry-standard administrative, technical and physical safeguards designed to protect personal data against unauthorised access, alteration, disclosure and destruction, including encryption of sensitive secrets, transport-layer encryption, audit logging, access controls and isolation between customer environments. No system is perfectly secure, however, and we do not guarantee the security of any personal data or Customer Content. You are responsible for the security of any software and data you put inside your Cubes and on any devices you use to access the Service.
12. Children
The Service is not intended for, and we do not knowingly collect personal data from, anyone under 18 (or the age of majority in your jurisdiction, if higher). If you believe a child has provided us with personal data, please contact us so we can take appropriate action, including deleting the account.
13. Cookies
We use a limited set of cookies and similar technologies to operate the Service and to measure how it is used. For details, see our Cookie Policy.
14. Changes to this policy
We may update this policy from time to time. When we make changes, we will update the “Last updated” date above. Where we make material changes, we will use reasonable efforts to give additional notice — for example, by email or an in-product banner — but no specific notice period is guaranteed. Your continued use of the Service after the updated policy takes effect constitutes acceptance of it.
15. Contact
For any privacy question or to exercise your rights, contact us at [email protected] or [email protected].
Krova Inc. · krova.cloud
