Passwords are hashed
PawClaw.ai does not store your original account password.
The data PawClaw.ai needs for accounts, payments, and AI agents, how it is used, and how you can control it.
PawClaw.ai does not store your original account password.
Tokens and sensitive deployment parameters are protected at rest.
Channels and agent instances can be disconnected or deleted.
This policy explains how PawClaw.ai processes data when you register, pay, install, and use OpenClaw or Hermes Agent.
We process data to provide the service, secure it, meter usage, support users, and meet legal obligations.
If you choose Sign in with Google, PawClaw.ai receives only your Google account's unique identifier, verified email address, and profile name through the minimum openid, email, and profile permissions. We do not request your Google password, contacts, Gmail, Drive, Calendar, or other Google data.
We use this data only to create or safely link your PawClaw.ai account, confirm email ownership, authenticate you, and protect the account. We store the provider identifier, email address, and verification status; we do not sell this data, use it for advertising or AI model training, or share it except as necessary to provide and secure the service or comply with law.
PawClaw.ai's use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
We store internal monetary and AI balances, transaction history, amounts, currencies, payment status, external payment identifiers, coupons, and deployment price snapshots.
Payment instrument data may be processed by a payment provider under its own policy. PawClaw.ai receives only necessary status and identifiers unless a payment form says otherwise.
Web and channel messages, attachments, instructions, tool results, and responses are sent to the agent and selected AI provider as needed to perform your task.
PawClaw.ai does not train its own foundation model on your conversations. Third-party AI providers process submitted data under their own terms and privacy settings.
Deployment parameters, gateway tokens, dashboard passwords, and bot tokens are encrypted in the database. Account passwords are hashed using bcrypt.
Secrets are decrypted only when required for the relevant function. No storage or transmission method eliminates all risk.
Depending on the features you choose, data may be sent to:
The interface uses protected HttpOnly cookies for authentication. Local storage keeps interface settings such as theme and selected agent, while a short-lived CSRF protection token remains within the tab session.
On public pages, Yandex Metrica with Session Replay loads after analytics consent. Google Tag Manager loads after both analytics and marketing consent. Dashboard content is hidden from Session Replay. You can change your choice through Cookie settings in the footer.
These technologies are required for secure sign-in, navigation, and dashboard state. Blocking them may prevent the service from working.
We retain data while the account or feature is needed to provide the service, settle transactions, maintain security, and meet legal requirements. Technical logs and payment records may be kept longer for incident investigation, abuse prevention, or accounting.
Deleting an instance triggers removal of its working environment and related settings. Contact welforse@gmail.com to request account deletion; active instances may need to be removed first.
We may update this policy when the product, infrastructure, or legal requirements change. The current update date appears at the top of the page.
Contact welforse@gmail.com with privacy, access, or deletion questions.
Contact us about access, correction, or deletion of your information.