Privacy Policy
Last updated: 2 April 2026
1. Who we are
Kolvera is operated by Kolvera Energy Pty Ltd, an Australian company. We provide home energy monitoring for residential solar and battery systems connected to the National Electricity Market (NEM). We may offer future opt-in optimisation or virtual power plant (VPP) products on supported systems, but those are not part of the live customer product today.
In this policy, "we", "us", and "our" refer to Kolvera Energy Pty Ltd. "You" and "your" refer to the individual using our platform.
2. What information we collect
Account information
When you create an account, we collect your name, email address, and postcode. Account authentication is handled by Clerk (a third-party authentication provider). We do not store your password.
Energy system data
When you connect your solar inverter or battery system, we collect data from your manufacturer's cloud platform, including: solar production, battery state of charge, charge and discharge rates, grid import and export, energy consumption, and system health metrics. This data is collected periodically via the manufacturer's API.
Authentication and credentials
To connect to your energy system, we may require your manufacturer account credentials (email and password) or your device serial number. Where the manufacturer provides OAuth or token-based authentication, we store only the access token. For manufacturers that require credential-based re-authentication (e.g. GoodWe SEMS Portal), your email and password are encrypted using AES-256-GCM and stored securely. All stored credentials and tokens are encrypted at rest and used solely to communicate with your energy system on your behalf.
Location data
We collect your postcode to determine your NEM region (for wholesale electricity pricing) and your electricity tariff structure. We do not collect your precise address unless you provide it voluntarily.
Usage data
We use Google Analytics to collect anonymised usage data on selected public marketing and legal pages. We do not use Google Analytics as the default analytics layer across the authenticated dashboard, admin, or installer product surfaces. See our Cookie Policy for more detail.
Waitlist, installer, and investor enquiry data
When you join a waitlist or submit an installer, partner, or investor request form, we collect the contact and context details you provide, such as your name, email address, organisation, role, postcode, battery or system details, and any message you include. We use this information to review the request, respond to it, and where you explicitly request it, keep you updated about launch or onboarding progress for that product area.
3. How we use your information
We use your information to:
- Monitor your solar production and battery system in real time
- Calculate energy savings, missed earnings, and battery performance
- Show pricing, tariff, and savings context in the monitoring product
- Send you notifications about price events, system alerts, and earnings
- Review installer, partner, support, and investor enquiries
- Send launch or onboarding updates for a product area when you have specifically asked for them
- Improve our platform and develop new features
- Provide customer support
If Kolvera later launches an opt-in optimisation or VPP product, we may also use the relevant system and consent data needed to operate that product. If that happens, we will update this policy and present any product-specific consent steps before activation.
We do not sell your personal information to third parties. We do not use your data for advertising.
4. Third-party services
We use the following third-party services:
| Service | Purpose | Data shared |
|---|---|---|
| Clerk | Authentication | Email, name |
| Supabase (PostgreSQL) | Database hosting | All platform data (encrypted at rest) |
| Vercel | Application hosting | Server logs, request metadata |
| Google Analytics | Public-site usage analytics | Anonymised browsing behaviour on selected public pages |
| Resend | Transactional and enquiry email delivery | Investor enquiry details and related email metadata where applicable |
| Tesla, Enphase, Alpha ESS, Deye/Solarman, Fronius, Sungrow, GoodWe | Energy system data | API tokens (to read your system data) |
| AEMO | Electricity market reference data | Public or licensed market/pricing data used in monitoring and future market products |
Some of these providers may store or process data outside Australia, including in the United States or other countries where they operate. When we disclose personal information overseas, we take reasonable steps to ensure it is handled consistently with this policy and Australian privacy-law expectations.
5. Data security
We take reasonable steps to protect your information:
- All credentials and API tokens are encrypted using AES-256-GCM before storage
- All data is transmitted over HTTPS (TLS 1.2+)
- Database access is restricted and encrypted at rest
- Authentication is handled by Clerk with industry-standard security
No method of electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Data retention
We retain your energy system data for as long as your account is active. Historical data (solar production, battery cycles, earnings) is kept to provide you with long-term performance reports and settlement records.
If you delete your account from our account deletion page or from System settings inside the app, we will remove the app account and associated monitoring data. In some cases we may retain limited security, fraud-prevention, or regulatory records where required by law. We may also retain anonymised, aggregated data for research and platform improvement.
Waitlist signups and investor or installer enquiries are retained while the request is active and afterwards only as reasonably needed for security, compliance, dispute handling, or relationship history. Where a waitlist request later turns into a live customer or partner relationship, the relevant record may be kept as part of that account history.
7. Your rights
Under the Australian Privacy Act 1988, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Disconnect your energy system from our platform at any time
- Withdraw consent for any future battery dispatch control product you opt into
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)
You can request account deletion directly at kolveraenergy.com/support/delete-account. For other privacy requests, contact us at the details below.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice on our platform. The "Last updated" date at the top of this page indicates when this policy was last revised.
10. Contact us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:
Kolvera Energy Pty Ltd
Email: support@kolveraenergy.com
Web: kolveraenergy.com