Skip to content
clovrix
PlatformDemoHow it worksPricingFAQ
Sign inGet started
PlatformDemoHow it worksPricingFAQSign in to your workspace
Back to Clovrix

Clovrix / Legal

Privacy Policy

What information Clovrix handles, why we need it, and the choices you have when you use the service.

Effective 11 September 2026Terms of Service

On this page

  1. Who and what this covers
  2. Information we handle
  3. Why we use it
  4. Your applications and traffic
  5. Cookies and browser storage
  6. Sharing and service providers
  7. Where information is processed
  8. Retention and account deletion
  9. Your choices and rights
  10. Security and younger users
  11. Updates and contact
Need a hand?

For questions about these policies, talk to us.

[email protected]

At a glance

We handle account, network, and billing information to run Clovrix. Your own applications remain under your control. Some security and accounting records can remain after an account is deleted.

This overview is a guide. The full policy below explains the details.

1. Who and what this covers

Clovrix is operated from Thailand. The operator responsible for the account and operational information described in this policy is identified in Section 1 of our Terms of Service.

This Privacy Policy explains how Clovrix handles personal information when you visit our website, create an account, pay for a plan, connect a server, or contact us. Clovrix is responsible for the account and operational information described here. You can reach us at [email protected].

Applications published by customers are operated by those customers. A Clovrix hostname or network connection does not mean we operate the underlying website or application. Its operator is responsible for explaining its own collection and use of personal information.

2. Information we handle

Account and security
Email address, username, password hashes, verification and recovery records, session records, and account changes. We also record your agreement to the Terms of Service, the version accepted, and the time of acceptance. If you enable two-factor authentication, we store the protected information needed to verify your authenticator and recovery codes.
Servers and networking
Server names and identifiers, network addresses, operating system and agent versions, health reports, selected region, routing and domain configuration, public keys, and the credentials needed to authorise your agents.
Usage and billing
Your selected plan, subscription and payment status, billing provider identifiers, traffic measurements, invoices or payment references, and records used to calculate charges and prevent duplicate billing.
Trial eligibility
Payment-method information supplied by Stripe and protected identifiers derived from email addresses and payment-method fingerprints to detect repeated trials. These identifiers can still relate to a person; hashing does not make them anonymous.
Requests and diagnostics
IP addresses, requested URLs, referrer information, browser or device details, timestamps, response status, traffic volume, and error or security events handled by our servers and network providers.
Support messages
Your contact details, the contents of messages you send us, and information needed to investigate the issue. Avoid including passwords, private keys, or other secrets.

We obtain information directly from you, from your browser and connected agents, from operation of the network, and from service providers such as Stripe. Payment details are entered into Stripe’s payment interfaces. Clovrix does not store full card numbers or card security codes in its application database.

3. Why we use it

We use personal information to create and secure accounts, verify email ownership, connect servers, route traffic, provide the console you enable, calculate usage, collect payments, deliver service messages, answer support requests, and maintain the service.

We also use it to prevent fraud and abuse, enforce trial and plan limits, investigate failures, preserve accurate accounting records, protect customers and former account holders, and meet applicable legal obligations.

With your separate, optional consent, we measure which Google ads lead to completed account registrations. This measurement is not required to register or use Clovrix, and accepting the Terms of Service does not give advertising consent.

Where data protection law requires a legal basis, these activities rely on performing our agreement with you, meeting legal obligations, or legitimate interests in operating and securing the service and preventing abuse, subject to the rights and safeguards required by that law. Where consent is required for a particular activity, we will seek it separately; consent can be withdrawn for that activity.

Account, security, networking, and payment information is necessary to provide the corresponding features. If you do not provide required information, we may be unable to create your account, connect your server, complete a purchase, or resolve a request.

4. Your applications and traffic

Clovrix and its network providers process the traffic needed to deliver your connections. Managed HTTPS uses TLS termination at proxy layers, so you should not treat the forwarding service as end-to-end encrypted storage. Raw TCP applications need their own encryption where appropriate.

The files and applications on your own machines remain under your control. Network processing can still expose connection metadata and requested URLs to the systems that handle requests. Avoid putting secrets or unnecessary personal information into URLs.

If you enable the browser console, Clovrix processes authorisation and session-lifecycle information. Your node’s console broker keeps a limited amount of recent output in memory to support reconnection; commands run on your machine with the permissions you configured.

If your application handles other people’s personal information, you are responsible for its lawful use, appropriate notices and permissions, and any additional processing agreement required for your use case. Contact us before using the service where you need such an agreement.

5. Cookies and browser storage

The dashboard uses an essential, secure, HTTP-only session cookie to keep you signed in. Temporary browser session storage helps the registration and account-recovery flows remember details such as a pending email address or a status message.

Optional advertising measurement is off until you select “Allow measurement.” If you allow it, we save Google ad-click identifiers from your visit in a cookie shared between clovrix.com and app.clovrix.com for up to 90 days. After successful email verification, the account-completion page uses the Google Ads tag to report a sign-up with the ad-click information and a random event identifier that prevents duplicate counting. Google also receives technical information such as your IP address, browser details, and the completion-page address, and may use advertising measurement cookies.

We do not send your email address, username, password, account identifier, verification token, or payment details in this conversion event. We do not enable enhanced conversions, personalised advertising, or Google Analytics. The Google Ads tag is kept off sign-in and verification forms, your dashboard, and your server console.

Use “Reject optional” to decline, or reopen “Cookie settings” in the website footer or on account pages to change your choice or withdraw consent. We remember your choice for up to 180 days. Withdrawing consent stops future measurement and removes the advertising attribution cookies we control; it does not undo data already sent to Google. A temporary, random completion receipt in the browser tab is valid for one hour. It is removed after the tag processes the event, if you decline, or when an expired receipt is next checked. Browser restrictions or opening your verification email in another browser can prevent attribution.

Cloudflare may process browser and connection information, and use security-related cookies or similar technology, when protecting and delivering the sites. Cloudflare Turnstile is used in relevant account and billing flows to help distinguish people from automated abuse.

You can manage cookies and stored site data through your browser. Blocking essential cookies can prevent sign-in or other account features from working. For the security challenge’s processing, see Cloudflare’s Turnstile Privacy Addendum.

6. Sharing and service providers

We use providers to run the service and share the information necessary for their roles:

Cloudflare
DNS, web delivery, TLS and network security, and Turnstile checks. Cloudflare processes requests and security signals. Cloudflare Privacy Policy.
DigitalOcean
Hosting for the management service and regional infrastructure, including stored account and operational data and traffic processed on that infrastructure. DigitalOcean Privacy Policy.
Stripe
Checkout, subscriptions, payment processing, billing management, and fraud prevention. Stripe receives the information you enter in its payment flow and returns payment and subscription information to Clovrix. Stripe Privacy Policy.
Resend
Delivery of verification, account-security, and other transactional emails, including recipient addresses and the message content required for delivery. Resend Privacy Policy.
MEGA S4
Storage of encrypted database backups used for recovery. Backup files are encrypted before upload. MEGA Privacy Policy.
Google Ads
Optional advertising measurement after your consent, using the ad-click, conversion, and technical information described in Section 5. Google may process this information internationally. Google Privacy Policy and how Google uses information from sites that use its services.

Providers may also act independently for their own legal, security, or payment-processing obligations, as described in their notices. We may disclose information when required by law or when necessary to protect rights, investigate abuse, or respond to a security incident. A business reorganisation or transfer may involve relevant records, subject to applicable law and appropriate notice.

Clovrix does not use the landing site for advertising profiling or sell account information to advertisers.

7. Where information is processed

Clovrix currently uses regional infrastructure in Singapore and Bangalore, India. Your selected network region does not mean all account, payment, email, backup, or security information stays in that region. Our providers operate internationally and may process information in other countries.

Cross-border processing remains subject to applicable data protection requirements. Where a transfer requires a particular legal safeguard or agreement, that requirement must be met. Contact us if you need information about the locations or transfer arrangements relevant to your use before supplying personal information with specific residency requirements.

8. Retention and account deletion

We keep active account and configuration information for the operation of your account. You can request account deletion in your workspace. Deletion withdraws managed network resources and revokes agent credentials before completing removal of the active account. A failed cleanup can be retried; software and files on your own machines are not remotely removed.

Account deletion does not immediately erase every record. In particular:

  • Reserved usernames and ownership proofs: we retain a deleted username and a protected email-ownership proof to prevent someone else from inheriting its managed hostname and to support a former owner’s reclaim request.
  • Trial-abuse records: protected email and payment-method identifiers, trial claims, and paid-history markers can remain after deletion. The current system has no automatic expiry for these records because it enforces a lifetime trial-eligibility policy.
  • Accounting and billing reviews: usage receipts, checkpoints, payment references, and records needed to investigate charges or prevent duplicate billing may remain after resource deletion. Some accounting records have no automatic expiry in the current system.
  • Backups and provider records: encrypted backups are removed through their backup-retention cycle rather than edited immediately for each deletion. Payment and email providers may retain their own records under their policies and legal obligations.

For operational logs, support records, and other information without a fixed period stated here, retention depends on the purpose of the record, unresolved issues, security needs, and legal requirements. Contact us to ask about a particular category or request deletion. Applicable rights and legal retention obligations can affect what we can remove.

9. Your choices and rights

You can manage available account details, security settings, billing, and deletion through your workspace. Depending on the law that applies, you may also have rights to access a copy of your personal information, correct it, request erasure or restriction, object to particular processing, obtain portable information, or withdraw consent for processing based on consent.

Send requests to [email protected]. We may need reasonable information to verify that a request concerns your account. We will respond according to applicable law and explain any limitation, such as records required for a legal obligation or the rights of another person.

Automated checks can affect trial eligibility and access when payment or allowance conditions are not met. Contact us if you believe a result is incorrect so it can be investigated. You may complain to the data protection authority or other regulator available to you under applicable law.

10. Security and younger users

We use safeguards such as protected authentication records, access controls, encrypted network connections, and encrypted database backups. No online service or system can guarantee complete security. Protect your account credentials and keep your own servers updated.

Users must have the legal capacity or authorisation required to use the service. If a child’s information has been provided without the permission required by applicable law, contact us so we can investigate and take appropriate action.

11. Updates and contact

We may update this policy when the service or our information-handling practices change. The date at the top identifies the latest revision. We will provide additional notice of material changes where required, through the website, your workspace, or your account email.

For privacy questions or requests, contact [email protected]. Please describe your concern without including passwords, recovery codes, or private keys. Our Terms of Service explain the conditions for using Clovrix.

Back to top Read our Terms of Service
clovrix

Private infrastructure. Public possibilities.

PricingFAQYour workspaceContact
© 2026 Clovrix
Terms of ServicePrivacy Policy