Clawfleet
FeaturesPersonal AIFor AgenciesPricingBlog
Sign inDeploy now
Clawfleet

The simplest way to deploy and manage OpenClaw instances. Managed hosting for individuals. Deploy your AI assistant in 60 seconds.

Need multiple instances for your team or clients? Contact us.

Clawfleet is not affiliated with, endorsed by, or connected to the OpenClaw project. OpenClaw is an independent open-source project.

© 2026 Clawfleet. All Rights Reserved. Built with ♥ by Seven Hills Software

@harishganapathi

Product
  • Features
  • Pricing
  • Integrations
  • Changelog
  • Switching hosts?
Resources
  • Personas
  • Use Cases
  • Glossary
  • Blog
About
  • Contact
  • FAQ
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund Policy

Privacy Policy

Our privacy policy and how we use your data

Last updated: March 25, 2026

Table of Contents

  1. Who We Are
  2. Data We Collect
  3. Legal Basis for Processing
  4. How We Use Your Data
  5. Data Sharing & Third Parties
  6. International Transfers
  7. Data Retention
  8. Your Rights
  9. Automated Decision-Making
  10. Cookies
  11. Security
  12. Data Breach Notification
  13. Children
  14. Changes to This Policy
  15. Contact

1. Who We Are

Clawfleet ("we", "our", "us") is a service operated by Sevenhills Software LLP. Clawfleet provides managed hosting for OpenClaw AI assistant instances for individuals and agencies.

For the purposes of the EU General Data Protection Regulation (GDPR) and applicable Indian data protection laws, Sevenhills Software LLP is the data controller of your personal data.

Registered Address

Sevenhills Software LLP
TCE-TBI, Madurai - 625016
Tamil Nadu, India

Data Protection Contact: privacy@clawfleet.app

2. Data We Collect

Account data

When you sign up, we collect your email address and, optionally, your name. This is necessary to create and manage your account.

Instance configuration data

When you deploy an OpenClaw instance, we store your configuration choices: the AI model selected, your channel type (e.g. Telegram/Discord), and your API keys. API keys are encrypted at rest using AES-256-GCM via Supabase Vault before storage.

Usage and operational data

We collect aggregated usage metrics for your instances: token counts, cost estimates, model routing decisions, and infrastructure health signals. This data is used to generate your dashboards and billing summaries. It does not include the content of conversations between your users and your AI assistant unless you explicitly enable conversation tracing (see below).

Conversation traces (optional — off by default)

Conversation tracing is disabled by default. If you explicitly enable it in your instance settings, we collect execution traces including message metadata (timestamps, tool calls, token counts). When tracing is enabled at the default level, we store metadata only — not the full text of user messages. You can enable full-message tracing separately. You can disable tracing at any time in your instance settings, and existing traces are purged after 90 days.

Billing data

Payment information is collected and processed by Stripe. We store only a Stripe customer ID and subscription status — we never store full card numbers.

Technical and log data

We collect standard web server logs including IP addresses, browser type, and pages visited. This data is used for security monitoring and is retained for 30 days.

3. Legal Basis for Processing

Under the GDPR, we process your personal data on the following grounds:

  • Contract performance (Art. 6(1)(b)) — processing your account data and instance configurations is necessary to deliver the service you signed up for.
  • Legitimate interests (Art. 6(1)(f)) — security monitoring, fraud prevention, and service improvement.
  • Legal obligation (Art. 6(1)(c)) — retaining billing records as required by applicable tax law.
  • Consent (Art. 6(1)(a)) — for non-essential analytics cookies (you can withdraw consent at any time via our cookie banner).

Legitimate Interests Assessment Summary

We rely on legitimate interests for: (a) security monitoring — detecting and preventing fraud, abuse, and unauthorised access to your instances; (b) service improvement — analysing aggregated, anonymised usage patterns to improve performance and reliability. We have assessed that these interests do not override your fundamental rights and freedoms. You may object to processing based on legitimate interests at any time (see Section 8).

4. How We Use Your Data

  • To provision, operate, and maintain your AI instances
  • To provide your usage dashboards and cost reports
  • To process payments and manage subscriptions
  • To send transactional emails (account creation, trial reminders, deletion confirmation)
  • To investigate security incidents and prevent abuse
  • To improve our services (using aggregated, anonymised data)

5. Data Sharing & Third Parties

We do not sell your personal data. Ever.

We share data only with the following sub-processors, each bound by a Data Processing Agreement (DPA):

Sub-ProcessorPurposeLocation
SupabaseDatabase, authentication, encrypted credential storageEU (Frankfurt)
StripePayment processingUS (with EU SCCs)
Hetzner CloudKubernetes infrastructure for AI instancesEU (Finland, Germany)
ResendTransactional email deliveryUS (with EU SCCs)
PostHogProduct analytics (if you consent to analytics cookies)EU (Frankfurt)

We may also share data with law enforcement or regulators where required by law or a valid legal process.

6. International Transfers

Our primary infrastructure is located within the EU/EEA (Hetzner Finland/Germany, Supabase Frankfurt). Some sub-processors are based in the United States:

  • Stripe (US) — payment data is transferred under EU Standard Contractual Clauses (SCCs) and Stripe's Binding Corporate Rules.
  • Resend (US) — transactional email data is transferred under EU SCCs.

No personal data is transferred to countries without adequate protection unless appropriate safeguards (SCCs, adequacy decisions, or your explicit consent) are in place.

7. Data Retention

Data TypeRetention Period
Account dataRetained while active; deleted promptly upon account deletion
Instance configurations & API keysDeleted when the instance or account is deleted
Usage metrics & traces90 days, then automatically purged
Billing records8 years (required under Indian Companies Act, 2013 and GST regulations)
Web server logs30 days

8. Your Rights

Under the GDPR and applicable Indian data protection laws, you have the following rights. To exercise any of them, email privacy@clawfleet.app. We will respond within 30 days.

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — ask us to correct inaccurate data
  • Right to erasure — request deletion of your personal data. You can also delete your account directly from Settings → Danger Zone, which immediately purges all your data
  • Right to restriction — ask us to pause processing in certain circumstances
  • Right to data portability — request a structured, machine-readable export of your data
  • Right to object — object to processing based on legitimate interests (Section 3)
  • Right to withdraw consent — for cookie-based analytics, withdraw consent at any time via the cookie banner

Complaints

If you are unsatisfied with our response, you have the right to lodge a complaint with the relevant data protection authority:

  • India — You may contact us at privacy@clawfleet.app or write to our Grievance Officer at our registered address. Once the Data Protection Board of India is constituted under the Digital Personal Data Protection Act, 2023, you may lodge complaints with them.
  • EU — Find your national Data Protection Authority at edpb.europa.eu/members

9. Automated Decision-Making

Clawfleet uses automated processing for the following purposes:

  • Smart model routing — automatically selecting the most cost-effective AI model for a given request based on complexity analysis. This does not produce legal or similarly significant effects on you.
  • Usage-based billing — calculating costs based on token usage and model selection. You can review all cost calculations in your dashboard.

We do not make any decisions based solely on automated processing that produce legal effects or similarly significantly affect you (Art. 22 GDPR). If you have concerns about any automated processing, contact privacy@clawfleet.app.

10. Cookies

We use cookies and similar technologies. Below is a summary — see our full Cookie Policy for complete details.

TypeExamplesCan You Disable?
Strictly necessaryAuthentication session, cookie consent, Stripe fraud preventionNo (required for the site to function)
AnalyticsPostHog product analyticsYes — via cookie banner or browser settings

We do not use advertising or tracking cookies. We do not share cookie data with advertisers.

11. Security

We implement industry-standard security measures including:

  • TLS encryption for all data in transit
  • AES-256-GCM encryption at rest for API keys and credentials
  • Network isolation between tenants via Kubernetes NetworkPolicy
  • Row Level Security (RLS) enforced at the database layer
  • Regular security scanning and dependency auditing

No system is 100% secure. If you discover a vulnerability, please report it responsibly to security@clawfleet.app.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms:

  • We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Art. 33.
  • If the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay via email and an in-app notice (GDPR Art. 34).
  • Our notification will include the nature of the breach, the data affected, likely consequences, and the measures taken to address it.

13. Children

Clawfleet is not directed at children under 18. We do not knowingly collect data from children. If we become aware that a child under 18 has provided us with personal data, we will:

  • Promptly delete the account and all associated data within 48 hours
  • Notify the parent or guardian if contact information is available

If you believe a child has created an account, please contact us immediately at privacy@clawfleet.app.

14. Changes to This Policy

We may update this policy from time to time. When we make material changes, we will notify you by email or via an in-app notice at least 14 days before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent revision.

15. Contact

For any privacy-related questions or to exercise your data rights:

Email: privacy@clawfleet.app
Post: Sevenhills Software LLP, TCE-TBI, Madurai - 625016, Tamil Nadu, India