Kove

Privacy.

What Kove holds, where it is stored, what leaves the server, and how you can export it or delete it.

Last updated 1 October 2026.

Who holds this.

Kove is made and run by one person, Filippo Brintazzoli, in Italy. Under the GDPR that makes him the data controller: he decides what Kove collects and why, and he is the person you write to about it. There is no company behind Kove.

How to reach him

Email [email protected]. That address answers questions about your data and requests to see it or delete it. For anything else, including trouble signing in, write to [email protected].

What Kove keeps.

Kove is a flexible health journal, so most of what it holds is health data. The GDPR calls that a special category and protects it more strictly than an email address, which is why signing up asks you to agree to it in so many words.

Your account

Your email address, your password as a hash and never as the password itself (none at all if you created the account with Google), the language you read Kove in, the moment you agreed to this, and the date of the policy you agreed to. Whether you have verified your email address, and when. If you create your account with Google or connect a Google account to sign in with, also that account's ID and the email address it showed.

Your journal

Whatever you decided to track, day by day, and the fields you track it in. The written note Kove keeps of each day is part of this. Health data.

What you told Kove about yourself

Height, sex, birth year, activity and fitness level, dietary preference, and any targets you set. Kove uses these to work out the daily figures it shows you. Health data.

Your conversations

Everything you write in chat and everything Kove writes back, kept so a thread is still there tomorrow. Health data.

Your pictures

Photographs you send in chat, and pictures you keep on a food, including those of labels Kove keeps by itself. They sit in the same database as everything else, on the same server, and go to no third party for storage. Health data.

What Kove remembers about you

A memory Kove keeps as you talk: a preference, an injury, a routine, a symptom you are having looked at. Kove writes this one, not you, and you can read all of it and edit any of it in Settings. Health data.

Your foods, plans and workouts

Saved foods and the collections you file them in, the products whose label you photographed, which Kove keeps by itself under Recently seen, training plans, and every set you have logged. What you eat and how you train is health data, and so is the name you give a collection.

Your reminders

The words you wrote, the times you chose, and a credential for each device that receives them.

Technical data

A session so you stay signed in, and counters that stop one account from overloading the server. Your network address reaches Kove's network provider in the ordinary course of being on the internet, and Kove keeps no log of it. Kove also counts how much its AI works for your account each day: how many requests, how many tokens, and what the AI provider charged for them. These are numbers only, kept so Kove knows what running an account costs, and they are deleted along with your data. It also keeps a record of the changes made to your account from the admin console, such as a trial extended or a password reset link: what and when, with nothing from your journal.

Your trial and your subscription

When your free trial ends and, if you subscribe, the plan, its status and its renewal date, as Dodo Payments reports them. Kove never sees or keeps your card, your billing address or your invoices.

If you joined the waitlist

An email address, and nothing else. This is the one thing here that is not health data, and it belongs to people who have not signed up. It sits with the company that hosts the form until an invite goes out, and you can ask for it to be deleted at any point without joining.

Why Kove is allowed to hold it

For everything above that is health data, the legal basis is your explicit consent: the box you tick at signup. You can withdraw it whenever you like by deleting your account, and that takes effect at once. For running the account itself, signing you in and sending a reset link, the basis is the agreement between you and Kove. For the counters that stop abuse, the daily count of AI use and the record of changes to the account, it is a legitimate interest in keeping Kove working for everybody else.

What leaves the server.

Kove does not share your journal, sell it, or hand it to anyone, and it is never used to train any model. Some of it passes through other services to work at all. Each one is a processor: it acts on Kove's instructions and for nothing else.

  • A cloud host, for the server itself.
  • A network provider, for getting Kove to you over an encrypted connection.
  • An AI provider, for turning what you write into entries and answering you.
  • A backup store, for the nightly copy.
  • The push services built into iOS and Android, for delivering a reminder.
  • Your own browser's maker, if you use dictation.
  • A form host, for the waitlist.
  • An email provider, for the address at the top of this page.
  • An email sending service, for your account's emails, like the link to reset your password.

Who they are today

The services can change over time, so they are listed here with their own date.

  • The server and its backups: Oracle Cloud, in Milan.
  • The network and the backup store: Cloudflare, with the backups in the EU.
  • The AI provider: OpenRouter, which passes your message to whichever model Kove is using. Kove's account is set so a request is never routed to a provider that would train on it. The provider may still keep a message for a short time, under its own rules.
  • Reminders: Apple and Google, whose push services deliver the notification.
  • Dictation: Apple or Google, depending on the browser you use.
  • The waitlist form: Tally.
  • Incoming email: Zoho, in its European data centre.
  • Account emails: Brevo, a French company, which delivers them and counts clicks on their links anonymously.

This list is current as of 30 September 2026.

What leaves the EU

Your journal is stored in the EU and stays there. Two things can leave it. What you write in chat goes to the AI provider, which may process it outside the European Economic Area. A reminder's payload passes through Apple's or Google's push service, encrypted so that only your own device can read it. Both are covered by the standard contractual clauses the GDPR provides for this.

When you pay

Payments are handled by Dodo Payments, which sells you the subscription in Kove's place as the merchant of record and handles the tax. At checkout it receives your email address and an account number that tells Kove whose payment it was, and you give it your card and billing country directly. For the payment it is a controller in its own right, under its own privacy policy, rather than a processor acting for Kove. Nothing from your journal ever reaches it.

If you sign in with Google

Signing in with Google is optional. You can create your account with it (with an invite code, like any account, and then Kove keeps no password at all), connect it yourself later, in Settings under Account, or, if your Kove email is a Gmail address you have verified, it connects the first time you sign in with that same Gmail. Kove keeps that account's ID and the email address it showed, and when you use it Google knows you signed in to Kove. For the sign-in Google is a controller in its own right, under its own privacy policy, rather than a processor acting for Kove. Nothing from your journal ever reaches it. You can disconnect it in Settings whenever you like, unless you created the account with it, since then it is how you sign in. Resetting your password disconnects it too.

What never leaves

The search that reads your journal runs on Kove's own machine, so your journal is never sent anywhere to be indexed. Dictation is transcribed by your browser, so Kove never receives your audio. The same goes for looking foods up in the reference tables, which sit on that same machine.

How long Kove keeps it.

Your account's data stays until you delete it. Kove does not expire your journal, thin it out, or close an account for being quiet. During the closed beta nothing is deleted for inactivity at all.

When you delete something

It goes from the live database immediately. A picture you delete has its bytes overwritten rather than flagged, so the image is gone and only the fact that a picture was there remains in the conversation.

Backups

Kove takes one backup a night and keeps it for 30 days, so something you delete today can still exist in a backup for up to a month. A scheduled rule removes them, so nothing older than that survives.

What you can do about it.

The GDPR gives you rights over your own data. In Kove you can do almost all of it from a button in the app. Here is a description of each.

See it and export it

Settings gives you the whole account as one archive of files: your days as a spreadsheet, your conversations as readable text, your pictures as pictures. It is free and needs nobody's permission, whether you are paying or not. That covers your right of access and your right to portability.

Correct it

Every value can be edited in the grid, in the day's own screen, or by telling Kove in chat. What Kove remembers about you is a text box you can rewrite.

Delete it

At three sizes. One thing, such as a photo, a saved food, a plan or a conversation. A category, such as every picture or every workout, from Settings. Or all of it, including the account itself. Deleting your account is also how you withdraw your consent, and it needs no reason and no correspondence.

The rest of them

You can also object to processing, ask for it to be restricted, and ask for a copy in a machine-readable form, which the export already covers. Write to [email protected]. Kove answers within a month, which is the GDPR's limit.

Complain

If you think Kove has handled your data badly, you can write to [email protected] first, and every report gets an answer. You can still complain at any time to the Italian data protection authority, the Garante per la protezione dei dati personali, at Piazza Venezia 11, 00187 Roma, or through garanteprivacy.it. You can also complain to the authority in the EU country where you live.

A few more things.

Nothing about you is decided automatically

Kove's AI structures what you write and offers suggestions you accept or ignore. It does not score you, rank you, or make any decision about you with a legal or similar effect, and there is no profiling of that kind anywhere in the product.

What sits on your device

One cookie, which is how you stay signed in, and some local settings such as which language you read and which tabs you keep. There is no analytics, no advertising, no tracking pixel and nothing from a third party, on this site or in the app. That is also why Kove has never asked you to accept cookies: there is nothing to accept.

Kove is for adults

You need to be 18 to use it. Kove shows calorie and weight figures, and it is not built with the safeguards a product for younger people would need.

Keeping it safe

The connection to Kove is encrypted, and so is the disk the server writes to. Passwords are stored as hashes, so nobody can read yours, including Kove.

If this page changes

The date at the top moves. A change that affects what you agreed to, rather than a correction to a detail, is also sent to you by email.

More about the terms.

This page is about your data. What Kove promises about the service itself, and what it asks of you, is in the terms of use.