← Back to Home

Privacy Policy

Last updated: March 5, 2026

This policy is available in English. For Korean users, key provisions required under the Personal Information Protection Act (PIPA) are included below.

1. Introduction

clawy.pro ("we", "us", or "our") operates the clawy.pro platform. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service, in accordance with the Korean Personal Information Protection Act ("PIPA", Article 30), the California Consumer Privacy Act ("CCPA/CPRA"), and other applicable data protection laws.

2. Information We Collect, Purpose & Retention

We collect the minimum personal information necessary to provide the Service. The following table details the categories of data, their processing purpose, and retention period.

CategoryItems CollectedPurposeRetention
AccountName, email, profile picture (from OAuth provider), wallet addressUser authentication, account managementUntil account deletion
Bot ConfigurationAI model selection, Telegram bot token (encrypted), bot purpose, API keys (encrypted)Bot provisioning & operationUntil bot deletion or account termination
Usage DataToken counts, API call metrics, feature usageUsage dashboard, billing, service improvement90 days (aggregated data retained longer)
PaymentStripe customer ID, subscription status, transaction history, USDC wallet address & tx hashesPayment processing, subscription management7 years (legal/accounting requirement)
Bot MemoryAI-generated summaries and context notes created by your botBot context continuity across sessionsStored only in your isolated container; deleted within 30 days of termination
Access LogsIP address, browser/device info, access timestampsSecurity monitoring, abuse prevention1 year

Conversation data: We do not collect or store your chat messages. Messages are transmitted directly from your bot container to AI providers for real-time inference and are not retained by clawy.pro. Your bot may independently generate summary notes and memory files within its own isolated container for context continuity; clawy.pro does not access or process these files.

We do not collect sensitive information (race, religion, health data, biometrics) or government-issued identification numbers.

3. How We Use Your Information

  • Provide, operate, and maintain the Service
  • Process payments and manage subscriptions
  • Display usage statistics and billing information
  • Send service-related notifications (e.g., trial expiration, bot updates)
  • Improve and develop the platform
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

We do not use your personal information for purposes beyond those listed above. If the purpose changes, we will notify you and obtain consent where required.

4. Third-Party Data Sharing

We share your data with the following third parties only as necessary to provide the Service:

RecipientData SharedPurpose
Supabase (US)Account info, bot configAuthentication, database hosting
Stripe (US)Payment infoPayment processing
Anthropic (US)Bot messagesAI model inference
Fireworks AI (US)Bot messagesAI model inference (Kimi K2.5, MiniMax M2.5)
Telegram (UAE/UK)Bot messages, Telegram user IDMessaging platform
PostHog (US)Usage analytics (anonymized)Product analytics
Brave Search (US)Search queries from botWeb search capability

We do not sell your personal data. We may disclose information if required by law, court order, or to protect our rights and safety.

5. Data Processing Entrustment

We entrust certain data processing tasks to the following service providers. These entities process data only for the purposes specified and under contractual obligations to protect your information:

Entrusted PartyEntrusted Tasks
Supabase Inc.Cloud database hosting, user authentication
Stripe Inc.Payment processing, subscription billing
Hetzner Online GmbHServer infrastructure hosting (Germany)
Vercel Inc.Web application hosting & deployment

6. Data Security Measures

We implement the following technical and organizational measures to ensure the safety of your personal information:

  • Encryption at rest: API keys and bot tokens encrypted with AES-256-GCM
  • Encryption in transit: All communications secured via TLS
  • Access control: Row-Level Security (RLS) enforced on all database tables; authentication required for all API routes
  • Container isolation: Each bot runs in an isolated Kubernetes pod with non-root privileges and read-only filesystem
  • Network isolation: Pod-to-pod communication blocked via NetworkPolicy
  • Access logging: Database and system access logs maintained and reviewed

7. Data Destruction Procedures

When personal information is no longer needed, we destroy it without delay:

  • Account deletion: Upon request, account data is marked for deletion and permanently removed within 30 days.
  • Bot termination: Bot containers (including bot memory files and workspace data) are destroyed within 30 days of subscription cancellation.
  • Encrypted data: API keys and tokens are securely overwritten before deletion.
  • Electronic records: Destroyed using technical methods that render recovery impossible.
  • Exceptions: Billing records required for tax/accounting compliance are retained for up to 7 years as permitted by law, then destroyed.

8. Your Rights

You (and your legal representative) have the following rights regarding your personal information:

  • Right to access: Request details of your personal data we hold
  • Right to correction: Request correction of inaccurate data
  • Right to deletion: Request deletion of your personal data
  • Right to suspend processing: Request that we stop processing your data
  • Right to data portability: Request your data in a machine-readable format
  • Right to withdraw consent: Withdraw consent for analytics tracking at any time

For California Residents (CCPA/CPRA)

In addition to the above, California residents have the right to:

  • Know the categories and specific pieces of personal information collected
  • Opt out of the sale or sharing of personal information (we do not sell your data)
  • Non-discrimination for exercising privacy rights

We will respond to verified requests within 30 days (PIPA) or 45 days (CCPA). To exercise any right, contact us at support@clawy.pro.

9. Cookies & Automatic Data Collection

We use the following cookies and automatic data collection technologies:

TypePurposeRequired
Session cookies (httpOnly)User authentication, session managementEssential
PostHog analyticsFeature usage tracking, product improvementOptional

How to refuse cookies: You can disable non-essential cookies through your browser settings (Settings > Privacy > Cookies). Disabling essential cookies may prevent you from using the Service. You may also opt out of PostHog analytics by contacting us.

10. International Data Transfers

Your data may be processed in the following locations where our infrastructure and service providers are hosted:

  • United States — Supabase, Stripe, Vercel, Anthropic, Fireworks AI, PostHog, Brave Search
  • Germany — Hetzner (Kubernetes cluster hosting bot containers)

By using the Service, you consent to the transfer and processing of your data in these locations. We ensure all service providers maintain adequate data protection standards through contractual agreements.

11. Children's Privacy

The Service is not intended for users under 14 years of age (under 16 in certain jurisdictions). We do not knowingly collect personal information from children. If we discover that a child's data has been collected, we will delete it promptly.

12. Privacy Officer & Grievance Contact

We have designated the following person as our Privacy Officer to handle all matters related to personal information protection and to address grievances:

Privacy Officer (개인정보 보호책임자)

Email: support@clawy.pro

If you are unsatisfied with our response, you may file a complaint with the following organizations:

  • Korea: Personal Information Protection Commission (PIPC) — pipc.go.kr / 1833-6972
  • Korea: Korea Internet & Security Agency (KISA) — privacy.kisa.or.kr / 118
  • US: Federal Trade Commission (FTC) — ftc.gov

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced at least 7 days in advance through the Service or via email. The revised policy takes effect on the posted date. Continued use of the Service constitutes acceptance.

  • Announcement date: March 5, 2026
  • Effective date: March 5, 2026

14. Contact

For questions about this Privacy Policy, contact us at support@clawy.pro.