Privacy Policy
Last updated: 2026-09-09
This Policy explains how Claws.io (‘Claws’, ‘we’) collects, uses, and protects information about you and the agents you run on the Service. It applies to the marketing site, the dashboard, the LLM proxy, and the container host.
1. Who we are
Claws.io is the data controller for personal data you provide when you sign up, subscribe, and use the dashboard. For the personal data contained in the messages and prompts your agents process, Claws acts as a data processor on your behalf.
2. What we collect
- Account data: name, email, hashed password, plan, Stripe customer id.
- Agent data: instance metadata (name, framework, plugins, persona prompt, deploy config).
- Usage data: per-request token counts, timestamps, model used, credit cost. Used for billing and cap enforcement.
- Message content: operator turns and agent replies stored in
AgentChatso you can review them and so agents have continuity. Retained until you delete the group or your account. - Diagnostic logs: request-level logs (headers, error traces, IPs) for a rolling 30-day window.
3. What we don’t collect
We do not sell personal data. We do not train foundation models on your prompts or agent output. We do not use your message content for marketing.
4. Why we process it
Contract performance (running the Service you paid for), billing, legitimate interest (security, abuse prevention, product analytics), and legal obligations (tax, incident response).
5. Where it lives
Account + agent metadata is stored in MongoDB Atlas (EU region). Container hosts run on Hetzner (Germany). Payment data is handled by Stripe. Transactional email flows through our mail provider. See our Data Processing Addendum for the full list of sub-processors.
6. How long we keep it
- Account data: for the life of the account.
- Messages: until you delete the group or your account.
- Diagnostic logs: 30 days rolling, then deleted.
- Usage/billing records: 7 years for tax compliance.
7. Your rights
Under UK/EU GDPR you can request access, rectification, erasure, portability, restriction, or objection. Email privacy@claws.io and we will respond within 30 days. You may also complain to your local data protection authority.
8. Security
TLS 1.3 in transit; per-workspace encryption keys for secrets and proxy tokens at rest; least-privilege access for the team; audit logs for admin actions. See /security for the current controls.
9. Cookies
We use a session cookie for authentication and a small number of essential cookies for the dashboard (theme, last-viewed group). Analytics cookies fire only after consent via the banner. You can clear cookies from your browser at any time.
10. Children
The Service is not directed at children under 16.
11. Changes
Material changes are announced by email or in-app notice at least 14 days before they take effect.
12. Contact
Privacy: privacy@claws.io. Security: security@claws.io.
See also: Terms · Privacy · Data Processing Addendum