ClawConnect ClawConnect

Privacy Policy

Last updated: June 30, 2026

1. Information We Collect

We collect information you provide directly when creating an account, including your email address, display name, profile photo, onboarding information, support messages, and billing contact details. Card payments are processed by Square; we receive transaction IDs, email addresses, and subscription status, but not your full card number or CVV.

We automatically collect AI usage data, device information for licence binding, anonymised web analytics, and error/performance logs needed to operate and improve the Service.

If an owner or authorised admin approves a support diagnostic action, the desktop app may return bounded, redacted log excerpts from allowlisted sources such as application logs, structured errors, runtime ledgers, and gateway or channel error logs. We do not use support diagnostics to browse arbitrary local files.

2. How We Use Your Information

We use your information to provide and maintain ClawConnect, process payments and subscriptions, track AI credit usage and billing, enforce licence terms and device binding, provide support, detect abuse and security threats, and generate anonymised aggregate analytics.

We do not currently use personal information for substantially automated decisions that produce legal or similarly significant effects. If that changes, we will update this policy before the relevant feature is used.

3. Data Storage and Security

Your account data is stored in Google Cloud Firestore (Firebase) with encryption at rest and in transit. All billing operations are server-side only — client applications cannot modify credits, plans, or payment data.

Platform Mode Security: When using platform-mode AI credits, your conversation content flows through our proxy to third-party AI providers. Content is processed in transit to route requests and is not stored by ClawConnect after the response is delivered. AI providers may retain data according to their own policies.

Desktop App Security: Authentication tokens stored in the desktop app are encrypted using OS-native keystores: macOS Keychain, Windows DPAPI, or Linux libsecret. The desktop app communicates with AI providers via a local nonce-based proxy — your real API credentials never leave the local machine.

Support Diagnostics: Remote support diagnostics are high-risk admin actions and must be explicitly approved before collection. Log sessions expire quickly, read only allowlisted sources, apply local redaction before upload, and reject output if common secret or local-path patterns survive redaction.

4. Third-Party Services

We use the following third-party services:

AI Provider Data Sharing: When using platform-mode AI credits, your conversation content is shared with the selected AI provider. This means:

If you have concerns about data sharing with AI providers, please review their respective privacy policies before using the service.

5. Data Retention

Account data is retained as long as your account is active. Usage logs (token counts, costs, models used) are retained for 90 days for billing reconciliation and 12 months in aggregated form for analytics.

Owner-approved support diagnostic command audit records and collected log artifacts are retained for 60 days, then deleted or made unavailable through the configured retention process.

Device binding records (licence fingerprints) are retained as long as the licence is active.

If you request account deletion, all associated data including usage logs, API keys, and device binding records will be removed within 30 days. Billing records required for compliance with tax and regulatory requirements will be retained for 7 years as required by Australian law.

6. Your Rights

ClawConnect operates under the Australian Privacy Act 1988 and the Australian Privacy Principles. You have the right to access your personal data, correct inaccurate data, request deletion of your data, export your data, withdraw consent for data processing where relevant, and complain to the Office of the Australian Information Commissioner if you believe your privacy has been breached. To exercise these rights, contact us at support@clawconnect.co.

GDPR & CCPA Acknowledgment: While ClawConnect operates primarily under Australian Privacy Act principles, we respect the data rights of international users. If you are located in the EU, you have rights under GDPR (data access, portability, right to be forgotten, etc.). If you are located in California, you have rights under CCPA (access, deletion, opt-out of sale, etc.). Contact us to exercise these rights.

7. Children's Privacy

ClawConnect is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that a minor has created an account, we will immediately delete all associated data and contact the account owner. Parents or guardians who believe a minor has provided information to ClawConnect should contact us immediately at support@clawconnect.co.

8. Device Fingerprinting

For Desktop app license binding, we create a device fingerprint by hashing your hardware identifiers (OS type, CPU model, system architecture, MAC addresses, and public IP). This fingerprint is used to enforce seat limits and prevent unauthorized device transfers — it is not used for tracking or analytics.

The fingerprint itself (the SHA-256 hash) is stored in your account; the raw hardware values are discarded. This allows us to detect if your license is used on unauthorized devices while protecting your hardware privacy.

9. Data Breach Notification

In the event of a suspected or confirmed data breach affecting personal information, we will assess whether it is an eligible data breach as quickly as practicable, taking reasonable steps to complete the assessment within 30 days where required. If notification is required under the Notifiable Data Breaches scheme, we will notify the OAIC and affected users as soon as practicable. Notifications will include:

We will also notify relevant international regulators and law enforcement as required by law.

10. Cookies

We use essential cookies for authentication (Firebase session). We use Google Analytics for anonymous usage statistics. Microsoft Clarity is not currently active; if enabled in the future, it would load only after your explicit opt-in and only on public marketing/apply pages (never signed-in areas), recording pseudonymous heatmaps and session replays with form inputs masked. When you arrive from ads or apply, Google Ads tags and the Meta Pixel may measure campaign performance (page views and application submits — not form answer text). We do not sell personal data.

11. Changes to This Policy

We may update this policy from time to time. We will notify users of material changes via the in-app announcement system or email. Continued use of the service after changes constitutes acceptance of the updated policy.

12. Contact

For privacy, security, or data-related questions, email support@clawconnect.co.

ClawConnect is operated by Yo-Da Lai · ABN 84 992 526 369.

If you are not satisfied with our response to a privacy concern, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.