Privacy Policy
Last updated: March 23, 2026
1. Overview
ClawSouls ("we", "us", "our") operates the ClawSouls platform and ClawSouls Hosting service. This Privacy Policy explains how we collect, use, store, and protect your personal information.
2. Information We Collect
2.1 Account Information
When you sign in via Google or GitHub, we receive:
- Your name and email address
- Your profile picture (if available)
- Your GitHub username or Google account identifier
2.2 ClawSouls Hosting Data
When you use ClawSouls Hosting, we store:
- Agent configuration: SOUL.md, settings, channel connections
- Agent memory: Conversation history and memory files stored in your agent's isolated volume
- API keys: Encrypted at rest (AES-256-GCM). Used only to operate your agent.
- Chat messages: Web chat messages between you and your hosted agent
- Usage metadata: Instance status, creation time, region
2.3 Payment Information
Payment processing is handled by Dodo Payments (Merchant of Record). We do not store your credit card numbers or payment details. Dodo Payments processes and stores payment information in accordance with PCI DSS requirements.
2.4 Usage Data
We may collect anonymized usage analytics (page views, feature usage) to improve the Service. We do not sell or share this data with third parties for advertising purposes.
3. How We Use Your Information
- To provide and operate the Service
- To manage your account and hosted agents
- To process payments through Dodo Payments
- To send service-related notifications (downtime, updates, billing)
- To detect and prevent abuse or security threats
- To improve the Service
4. Data Storage & Security
- Database: Hosted on Supabase (AWS US-East-1), encrypted at rest.
- Agent instances: Hosted on Fly.io in your selected region. Each agent runs in an isolated container with dedicated storage.
- API keys: Encrypted with AES-256-GCM before storage. Keys are decrypted only when deploying configuration to your running instance. The encryption key is stored separately from the database and is never exposed to client-side code.
- Data portability: You can export your entire workspace (SOUL.md, memory, settings) as a downloadable archive at any time from your instance Settings.
- Access control: Row-level security ensures you can only access your own data.
- Instance isolation: Each hosted agent runs in its own dedicated Fly.io application with isolated compute, storage, and network. No data is shared between instances.
5. Data Retention
- Active accounts: Data retained as long as your account is active.
- Cancelled subscriptions: Agent data retained for 30 days after cancellation, then permanently deleted.
- Deleted accounts: All personal data deleted within 30 days of account deletion request.
- Chat history: Retained with your agent data. Deleted when the agent is deleted.
6. Data Sharing
We do not sell your personal data. We share data only with:
- Dodo Payments: Payment processing (as Merchant of Record)
- Fly.io: Infrastructure hosting for your agents
- Supabase: Database hosting
- LLM providers: Your API keys are used to make requests to LLM providers (e.g., OpenRouter, Anthropic) on your behalf. Your conversations are sent to these providers according to their privacy policies.
- Law enforcement: If required by law or valid legal process
7. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and all associated data
- Export: Download your agent configuration and memory files
- Objection: Object to processing of your data for certain purposes
To exercise these rights, contact contact@clawsouls.ai. We will respond within 30 days.
8. Cookies
We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising cookies.
9. Children
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children.
10. International Users
Your data may be processed in the United States (database), Japan or other regions (agent hosting), and Korea (operations). By using the Service, you consent to the transfer of your data to these locations.
11. Changes
We may update this Privacy Policy at any time. Material changes will be posted on this page with an updated date.
12. Contact
Privacy questions: contact@clawsouls.ai
Data Controller: ClawSouls (이재순), Seoul, Republic of Korea