Privacy Policy
Last updated: July 25, 2026
1. Information We Collect
We collect the following types of information:
- Account information: Your name, email address, and profile picture (provided by Google or GitHub when using OAuth login), or your email and password when registering with credentials.
- Payment information: When you subscribe, payment is processed by Stripe. We store your Stripe customer ID and subscription details but never store your credit card number or payment method details directly.
- Configuration data: OpenClaw configurations you create and save to your account.
- API keys: If you provide your own API keys (e.g., OpenRouter, Google), they are stored encrypted on our servers and used solely to operate your bot instances.
- Usage data: We log page views for all visitors, including IP address, browser user agent, referring URL, approximate geographic location (derived from IP), UTM campaign parameters, platform click identifiers appended by referring services (such as fbclid, twclid, gclid), the Sec-Fetch-Site request context, and detection of in-app webview browsers (such as WeChat or Twitter in-app browser). These signals are used to understand traffic sources when the referring URL is not available.
- Security data: If you enable two-factor authentication, we store the credentials needed to verify your login.
2. How We Use Your Information
- To provide and maintain the service
- To authenticate your identity and secure your account
- To store and manage your OpenClaw configurations
- To manage Docker instances you launch
- To process payments and manage subscriptions
- To send transactional emails (subscription confirmations, credit alerts, account notifications)
- To prevent abuse and enforce rate limits
- To understand how the service is used and improve it
3. Data Storage and Security
Your data is stored on secure servers located in the United States and the European Union. When you deploy a bot instance, it runs on the server region we assign based on availability and load. We take reasonable measures to protect your data, including HTTPS encryption for all traffic, secure server access controls, and encrypted storage of sensitive credentials.
Each deployed bot instance runs in an isolated Docker container with its own dedicated storage. Instances are separated from each other — no user can access another user's data or configurations.
We do not use your configurations, conversations, or any instance data to train AI models.
4. Build & Resell: Our Role When You Serve Your Own Customers
Build & Resell lets an account holder create and operate bot instances for their own end customers. That arrangement splits responsibility for personal data, so it is worth stating plainly who does what.
- For your own account — your registration details, billing records, security logs, and support correspondence — we are the controller. Sections 1 through 3 describe how we handle it.
- For the content your end customers create inside instances you deploy for them — their messages, files, and workspace data — you are the controller and we act on your instructions as a processor. We process that content to operate the instances, to keep the platform secure and available, and to comply with law. We do not use it to train AI models, and we do not use it for our own marketing.
- We remain an independent controller for the limited operational records generated by running that infrastructure, such as billing and usage counters, abuse and security logs, and system diagnostics tied to your account.
- We have no direct relationship with your end customers. If one of them asks to access, correct, export, or delete their data, direct that request to us through your account and we will support you in answering it.
- The sub-processors that handle your end customers’ instance content are the hosting providers whose machines run the containers (Hetzner and Netcup), Cloudflare in front of instance traffic, and the AI model providers a bot routes to — either through OpenRouter or through a provider key you supply. Hosting regions are described in Section 3. The remaining services in Section 5 — Google and GitHub sign-in, and Stripe — serve your own account and payments and are not involved in your end customers’ content.
- If you need a written data processing agreement for your own customers, contact [email protected].
5. Third-Party Services
We use the following third-party services to operate OpenClaw Launch:
- Google OAuth: For authentication. Subject to Google's Privacy Policy.
- GitHub OAuth: For authentication. Subject to GitHub's Privacy Statement.
- Stripe: For payment processing. Your payment information is handled directly by Stripe and subject to Stripe's Privacy Policy. We never store your card details.
- Hetzner and Netcup: Server infrastructure. Bot instances, their stored data, and our databases run on machines operated by these providers.
- Cloudflare: For CDN, DDoS protection, and DNS. Cloudflare may process your IP address and request metadata.
- OpenRouter: AI model routing for bot instances. We provision API keys on your behalf to route requests to LLM providers.
When you deploy an instance, your configuration is passed to a Docker container that connects to third-party LLM providers (such as OpenAI, Anthropic, Google, or DeepSeek) and chat platforms (such as Telegram, Discord, or the built-in Web UI) on your behalf. Your use of those services is subject to their respective privacy policies.
6. Data Retention
We retain your account data and configurations for as long as your account is active. You can delete your configurations at any time from the dashboard. If you delete your account, your data is permanently removed within 30 days.
7. Your Rights
You have the right to:
- Access your stored data
- Delete your configurations
- Delete your account and associated data
- Request a copy of your personal data
- Opt out of non-essential emails
- If you are in the European Economic Area or UK, you may also lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at [email protected].
8. Cookies
We use the following cookies:
- Session cookie: Essential for authentication. Required for the service to function.
- Visitor ID cookie (vid): A randomly generated identifier stored for up to 1 year, used to understand usage patterns. This cookie contains no personal information.
- UTM attribution cookie: Stores the referral source (UTM parameters and platform click identifiers) when you first visit the site, retained for 30 days.
We do not use third-party tracking cookies or advertising cookies.
9. Children's Privacy
OpenClaw Launch is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Changes to This Policy
We may update this privacy policy from time to time. We will notify users of significant changes by updating the date at the top of this page.
11. Contact
If you have questions about this privacy policy, please contact us at [email protected].