Skip to content
Data protection

Privacy Policy

The data PawClaw.ai needs for accounts, payments, and AI agents, how it is used, and how you can control it.

Updated September 26, 2026

PawClaw.ai

Passwords are hashed

PawClaw.ai does not store your original account password.

Secrets are encrypted

Tokens and sensitive deployment parameters are protected at rest.

Data stays manageable

Channels and agent instances can be disconnected or deleted.

1

Overview

This policy explains how PawClaw.ai processes data when you register, pay, install, and use OpenClaw or Hermes Agent.

We process data to provide the service, secure it, meter usage, support users, and meet legal obligations.

2

Account and authentication data

  • email, name, account role, and creation or update dates;
  • a password hash — the original password is not stored in the database;
  • protected session cookies for sign-in and session renewal; browser JavaScript cannot access the primary authentication tokens;
  • blocking, access-attempt, and security-event information.
Do not share your password or session token. Change your password and contact support if you suspect compromise.
3

Sign in with Google

If you choose Sign in with Google, PawClaw.ai receives only your Google account's unique identifier, verified email address, and profile name through the minimum openid, email, and profile permissions. We do not request your Google password, contacts, Gmail, Drive, Calendar, or other Google data.

We use this data only to create or safely link your PawClaw.ai account, confirm email ownership, authenticate you, and protect the account. We store the provider identifier, email address, and verification status; we do not sell this data, use it for advertising or AI model training, or share it except as necessary to provide and secure the service or comply with law.

PawClaw.ai's use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

You can stop using Google sign-in and request deletion of related account data by contacting welforse@gmail.com.
4

Payments, balances, and AI usage

We store internal monetary and AI balances, transaction history, amounts, currencies, payment status, external payment identifiers, coupons, and deployment price snapshots.

Payment instrument data may be processed by a payment provider under its own policy. PawClaw.ai receives only necessary status and identifiers unless a payment form says otherwise.

  • model usage volume and calculated cost;
  • free request or token consumption and the relevant billing period;
  • limits for user-specific AI-provider keys.
5

Agent and infrastructure data

  • agent name, type, version, installation status, and provider;
  • deployment parameters, model, channels, settings, and environment variables;
  • technical addresses, ports, container identifiers, logs, and diagnostics;
  • files, memory, and configuration stored in the agent's separate environment;
  • regular technical platform backups and agent archives when the user invokes that feature.
6

Messages, files, and agent actions

Web and channel messages, attachments, instructions, tool results, and responses are sent to the agent and selected AI provider as needed to perform your task.

PawClaw.ai does not train its own foundation model on your conversations. Third-party AI providers process submitted data under their own terms and privacy settings.

Do not submit sensitive or regulated data unless the selected model, channel, and integration are appropriate for that data.
7

Keys, tokens, and secret protection

Deployment parameters, gateway tokens, dashboard passwords, and bot tokens are encrypted in the database. Account passwords are hashed using bcrypt.

Secrets are decrypted only when required for the relevant function. No storage or transmission method eliminates all risk.

8

Third-party recipients

Depending on the features you choose, data may be sent to:

  • infrastructure providers that host agent containers;
  • AI and model providers that generate responses and run tools;
  • Telegram, WhatsApp, Discord, Slack, and other connected channels;
  • payment providers that process and confirm payments;
  • security, monitoring, and support providers.
A third-party provider may operate outside your country. Using that integration may involve cross-border data transfer.
9

Cookies and local storage

The interface uses protected HttpOnly cookies for authentication. Local storage keeps interface settings such as theme and selected agent, while a short-lived CSRF protection token remains within the tab session.

On public pages, Yandex Metrica with Session Replay loads after analytics consent. Google Tag Manager loads after both analytics and marketing consent. Dashboard content is hidden from Session Replay. You can change your choice through Cookie settings in the footer.

These technologies are required for secure sign-in, navigation, and dashboard state. Blocking them may prevent the service from working.

10

Retention and deletion

We retain data while the account or feature is needed to provide the service, settle transactions, maintain security, and meet legal requirements. Technical logs and payment records may be kept longer for incident investigation, abuse prevention, or accounting.

Deleting an instance triggers removal of its working environment and related settings. Contact welforse@gmail.com to request account deletion; active instances may need to be removed first.

Deleted data may remain temporarily in technical backups until scheduled overwrite.
11

Your choices and rights

  • request information about data linked to your account;
  • correct your name, email, or other inaccurate data where supported;
  • disconnect a channel or delete a bot token;
  • delete an agent instance and its working environment;
  • request account deletion unless retention is legally required;
  • submit a privacy question or complaint.
12

Changes and contact

We may update this policy when the product, infrastructure, or legal requirements change. The current update date appears at the top of the page.

Contact welforse@gmail.com with privacy, access, or deletion questions.

PawClaw.ai

A question about your data?

Contact us about access, correction, or deletion of your information.

Contact us