Privacy policy
Last updated: September 18, 2026
Who we are
Kova is the portfolio platform for aimers. The controller responsible for your data under the GDPR is pyvno. This policy explains what personal data we collect, why we collect it, how we share it, and your rights under the General Data Protection Regulation (GDPR) and other applicable laws.
For privacy questions or data requests, contact: [email protected]
What data we collect
- Discord account data: when you sign in with Discord (the only sign-in method), we receive your Discord ID, username, avatar, and email address from Discord's OAuth service. We never receive your Discord password.
- Profile content: anything you voluntarily add to your Kova profile: display name, bio, country, theme customisations, decals, peripherals, showcase items (grouped into sections you create), videos, music playlists, kovaaks playlists, social and external links, games you play, and reviews you write.
- Linked external accounts: if you connect kovaaks, we store your kovaaks username and the Steam ID attached to that account. Both come from kovaaks' own records for your Discord account, so you can only connect an account that is already yours. We use them to fetch publicly visible scores, playtime, and benchmark ranks on your behalf. They are one connection: disconnecting removes both, along with anything derived from them.
- Aimgroup data: memberships, invites, applications you send or receive, application form answers, and any content you post as part of an aimgroup you own or co-manage.
- Tournament data: tournaments you host, participate in, or are invited to, along with match scores submitted during play.
- Giveaway data: giveaways you run as an aimgroup, and your entries into giveaways you join (whether entered on the site or via the Discord bot).
- Marketplace data: listings you create and any messages exchanged with other users through the marketplace.
- Feedback: feature requests, bug reports, and improvement ideas you submit, any screenshot you attach, and your votes on submissions. Submitted ideas are shown publicly on the feedback board with your username as the byline.
- Reports: if you report a profile or aimgroup, we store your report (including any free-text reason) and link it to your account so moderators can act on it. Reporting without an account is possible too, in which case we store the email address you give us, and use it only to tell you what we decided.
- Notifications: in-app notification records (e.g. invites, application updates) and your per-type notification preferences.
- Comments and vouches: comments you leave on other profiles, and vouches you give a coach or a marketplace seller. Both are shown publicly with your username.
- Coaching: if you offer coaching, your listing; if you request it, the request, your message, and the proposed session time.
- Scores you set on kova: results from the in-browser aim and reaction tools under "tools".
- Appeals: if your account is suspended or banned and you submit an appeal, we store the appeal and our decision.
- Uploaded files: avatars, banners, peripheral images, showcase icons, review images, aimgroup images, decals, an optional background music track for your profile, and any kovaaks crosshairs, sounds, themes, or palettes you share. Files are stored on Cloudflare R2.
- Usage data: profile view counts and basic uptime/error logs. We do not use third-party analytics, advertising cookies, or cross-site tracking.
- Session data: one strictly-necessary authentication cookie that keeps you signed in. No tracking cookies are used.
Why we collect it
- To provide the service: account, profile, and feature data is required to create and operate your profile, aimgroups, tournaments, and marketplace listings. Legal basis: contract (Article 6(1)(b) GDPR).
- To display your public profile: profile content you add is shown publicly on your Kova page. You choose what to publish. Legal basis: consent.
- Analytics: view counts help you understand your profile's reach. Legal basis: legitimate interest (Article 6(1)(f) GDPR).
- Moderation: reports and account metadata let us enforce these terms and respond to abuse. Legal basis: legitimate interest.
Data sharing
We do not sell, rent, or share your personal data with third parties for marketing purposes. Data is shared only with:
- Discord: OAuth provider for sign-in, and the host of any server you connect to an aimgroup. When an aimgroup is connected, our bot posts the kova content you've enabled into that server and may read its member list and roles (see "connected Discord servers" below). Subject to Discord's own privacy policy.
- Cloudflare R2: stores uploaded images. Cloudflare acts as a data processor under our instructions.
- kovaaks.com: when you connect kovaaks, your Discord ID is sent to the public kovaaks API to find the account linked to it, and afterwards your kovaaks username and Steam ID are sent to fetch your public scores, scenarios played, playtime, and playlists. We do not receive a password or any private kovaaks data.
- EVXL: your Steam ID is sent to the public EVXL API to look up your benchmark ranks. EVXL is the source of every rank shown on kova, including rank badges, leaderboards, and Discord rank roles.
- Twitch: if you link a Twitch channel, its name is sent to Twitch's public API to check whether you are currently live, so the "live" badge can appear on your profile and on the homepage.
- Steam Web API: if you type a Steam profile URL into an aimgroup application, we send it to Steam's public API to check it is a real profile. Nothing is stored on your account from this.
- Spotify: when you add a Spotify playlist, your browser fetches its public cover image and metadata directly from Spotify.
- YouTube: profiles, forum posts, the feed and video reviews can embed a YouTube video. The player does not load with the page: until you press play, kova shows a thumbnail served from its own servers and YouTube receives nothing about you. Pressing play loads Google's player from youtube-nocookie.com, which then sees your IP address under Google's own privacy policy.
- X (Twitter): when a post's clip is embedded, the video itself is streamed through our own server, so X does not see you watching it. Its thumbnail image is loaded by your browser from X's image CDN.
- Hugging Face & jsdelivr: when you opt into automatic background removal on a peripheral image, your browser downloads an open-source background-removal model from the Hugging Face CDN (and its runtime from jsdelivr). Your image is never sent. The model runs locally in your browser.
- IONOS: IONOS SE (Montabaur, Germany) hosts the server and the database, on machines located in Germany. IONOS acts as a data processor under our instructions.
Where your data is processed
Kova itself runs entirely inside the EU: the server, the database, and every backup live on IONOS machines in Germany.
Some of the recipients listed above are based outside the EU/EEA, mainly in the United States: Discord, Cloudflare, Twitch, kovaaks, EVXL, Google, X, and Hugging Face. Where such a transfer happens, it is covered either by the recipient's certification under the EU-US Data Privacy Framework, or by the European Commission's Standard Contractual Clauses (Article 46 GDPR), together with that provider's own safeguards.
In a few cases your browser contacts a third party directly rather than going through our server, so that provider sees your IP address under its own privacy policy: loading a Spotify playlist cover, loading the thumbnail of an embedded X post, downloading the background-removal model from the Hugging Face CDN, and, only once you press play on an embedded video, loading YouTube's player.
Public versus private
Your public profile (everything on /{username}) is visible to anyone on the internet, including search engines. Aimgroup pages, tournament pages, marketplace listings, and feedback-board submissions are also public. Reports you file, your email address, your notification preferences, and your account settings are not public.
Connected Discord servers
Aimgroup owners can connect a Discord server and add our bot. When they do:
- The bot can read the server's member list and roles (including members who do not have a Kova account) in order to send member notifications and keep roles in sync. We store the mapping between Kova roles and Discord roles, and your Discord ID (which we already hold from sign-in) so the bot can mention you.
- The kova content the owner enables (your profile link, kovaaks personal bests and benchmark ranks, applications, giveaways, tournament results, and leaderboards) is posted into the channels they choose, where it is visible to that server.
- If the owner turns on role mirroring, changing a mapped role in Discord can change your role (and tier) in the aimgroup, and vice versa. Whoever controls the server's Discord roles can therefore control those aimgroup roles.
- When you apply to a connected aimgroup, the bot may DM you the outcome of your application.
The bot only acts in servers an aimgroup owner has explicitly connected, and posts only into channels they configure.
Data retention
Your data is retained for as long as your account exists. If you delete your account from your dashboard, all associated personal data (profile, uploaded images, aimgroup memberships, tournament entries, marketplace listings, notifications, and reports you filed) is permanently deleted within 30 days. Aggregate metrics (e.g. anonymised view counts) may be retained without personal identifiers.
Two things deliberately survive deletion, because both exist to stop a deleted account from being used to start over: if your account was banned, we keep the Discord ID it was banned on, so the ban cannot be undone by deleting and signing up again; and your username stays reserved rather than being freed for someone else to claim. Nothing else from your account is kept.
Server logs are kept for up to 30 days for security and uptime purposes, then rotated out.
Your rights (GDPR)
If you are located in the EU/EEA, you have the right to:
- Access: request a copy of the data we hold about you, or download it yourself via dashboard → user menu → "export your data".
- Rectification: correct inaccurate data directly in your dashboard, or by contacting us.
- Erasure: delete your account at any time from your dashboard. This permanently removes your data, apart from the two ban-evasion safeguards described under "data retention".
- Portability: your data export above provides a machine-readable JSON copy you can take elsewhere.
- Object: object to processing based on legitimate interest by emailing us.
- Lodge a complaint: with your local data protection authority if you believe we've mishandled your data.
To exercise any right, email [email protected]. We respond within 30 days.
Cookies
We set one strictly necessary cookie to maintain your sign-in session. No advertising or analytics cookies are set. You cannot opt out of the session cookie without losing the ability to sign in.
Children
Kova is not directed at children under 13 (or the minimum digital age of consent in your country, if higher). We do not knowingly collect data from anyone below that age. If you believe a child has signed up, contact us and we will remove the account.
Changes to this policy
We may update this policy as the platform evolves. Material changes will be announced on our Discord or via the platform. Continued use after changes constitutes acceptance.