Skip to content
Back home
Data protection

Privacy Policy

The data PawClaw.ai needs for accounts, payments, and AI agents, how it is used, and how you can control it.

Updated July 27, 2026

PawClaw.ai

Passwords are hashed

PawClaw.ai does not store your original account password.

Secrets are encrypted

Tokens and sensitive deployment parameters are protected at rest.

Data stays manageable

Channels and agent instances can be disconnected or deleted.

1

Overview

This policy explains how PawClaw.ai processes data when you register, pay, install, and use OpenClaw and Hermes Agent instances.

We process data to provide the service, secure it, meter usage, support users, and meet legal obligations.

2

Account and authentication data

  • email, name, account role, and creation or update dates;
  • a password hash — the original password is not stored in the database;
  • a session token stored locally and in a browser cookie for sign-in;
  • blocking, access-attempt, and security-event information.
Do not share your password or session token. Change your password and contact support if you suspect compromise.
3

Payments, balances, and AI usage

We store internal monetary and AI balances, transaction history, amounts, currencies, payment status, external payment identifiers, coupons, and deployment price snapshots.

Payment instrument data may be processed by a payment provider under its own policy. PawClaw.ai receives only necessary status and identifiers unless a payment form says otherwise.

  • model usage volume and calculated cost;
  • free request or token consumption and the relevant billing period;
  • limits for user-specific AI-provider keys.
4

Agent and infrastructure data

  • agent name, type, version, installation status, and provider;
  • deployment parameters, model, channels, settings, and environment variables;
  • technical addresses, ports, container identifiers, logs, and diagnostics;
  • files, memory, and configuration stored in the agent's separate environment;
  • backups when that feature is enabled and available.
5

Messages, files, and agent actions

Web and channel messages, attachments, instructions, tool results, and responses are sent to the agent and selected AI provider as needed to perform your task.

PawClaw.ai does not train its own foundation model on your conversations. Third-party AI providers process submitted data under their own terms and privacy settings.

Do not submit sensitive or regulated data unless the selected model, channel, and integration are appropriate for that data.
6

Keys, tokens, and secret protection

Deployment parameters, gateway tokens, dashboard passwords, and bot tokens are encrypted in the database. Account passwords are hashed using bcrypt.

Secrets are decrypted only when required for the relevant function. No storage or transmission method eliminates all risk.

7

Third-party recipients

Depending on the features you choose, data may be sent to:

  • infrastructure providers that host agent containers;
  • AI and model providers that generate responses and run tools;
  • Telegram, WhatsApp, Discord, Slack, and other connected channels;
  • payment providers that process and confirm payments;
  • security, monitoring, and support providers.
A third-party provider may operate outside your country. Using that integration may involve cross-border data transfer.
8

Cookies and local storage

The interface uses cookies and browser local storage for authentication. They may contain a session token and selected active agent.

These technologies are required for sign-in, navigation, and dashboard state. Blocking them may prevent the service from working.

9

Retention and deletion

We retain data while the account or feature is needed to provide the service, settle transactions, maintain security, and meet legal requirements. Technical logs and payment records may be kept longer for incident investigation, abuse prevention, or accounting.

Deleting an instance triggers removal of its working environment and related settings. Contact hello@pawclaw.ai to request account deletion; active instances may need to be removed first.

Deleted data may remain temporarily in technical backups until scheduled overwrite.
10

Your choices and rights

  • request information about data linked to your account;
  • correct your name, email, or other inaccurate data where supported;
  • disconnect a channel or delete a bot token;
  • delete an agent instance and its working environment;
  • request account deletion unless retention is legally required;
  • submit a privacy question or complaint.
11

Changes and contact

We may update this policy when the product, infrastructure, or legal requirements change. The current update date appears at the top of the page.

Contact hello@pawclaw.ai with privacy, access, or deletion questions.

PawClaw.ai

A question about your data?

Contact us about access, correction, or deletion of your information.

Contact us