Privacy Policy
Effective date: March 12, 2026
ClawHatch ("we," "us," "our") operates the ClawHatch AI assistant platform at clawhatch.app. This policy explains what personal data we collect, how we process it, who we share it with, and what rights you have.
1. What We Collect
- Account & profile information: Your name, phone number, and profile details provided by the messaging platform you use (e.g., Telegram username, WhatsApp profile name).
- Message content: The messages you send to and receive from your AI assistant through WhatsApp, Telegram, or other supported channels.
- Routing & usage data: Timestamps, message delivery metadata, and basic operational logs needed to deliver the service reliably.
We do not collect data beyond what is necessary to provide the service.
2. How We Process Your Data
When you send a message to your AI assistant:
- Your message is received by our platform server, which routes it to your dedicated virtual private server (VPS) — infrastructure provisioned exclusively for you.
- On your VPS, your AI assistant processes the message. As part of this processing, message content is sent to third-party AI model providers (such as Anthropic and OpenAI) via their APIs to generate responses.
- The AI's response is routed back through our platform and delivered to you via your messaging app.
We do not train AI models on your messages. We do not sell or share your personal data with advertisers. We do not read your messages unless required for technical support you've requested or to comply with a legal obligation.
3. Data Storage
- Messages & conversation history: Stored on your dedicated VPS. Your data is not pooled with other users — each user's VPS is isolated.
- Routing data: Minimal delivery metadata is stored on our platform server for as long as your account is active.
- AI provider processing: Messages sent to AI model providers are processed according to their respective data policies. We use API agreements that prohibit model training on user data where available.
4. Third Parties
We share data with the following categories of third parties, solely to provide the service:
- Messaging platforms: Meta (WhatsApp Business API) and Telegram (Bot API) transmit your messages. Their own privacy policies govern their handling of your data.
- AI model providers: Anthropic, OpenAI, and similar providers process your message content to generate AI responses. These providers operate under API terms that restrict use of your data for model training.
- Infrastructure hosting: Hetzner and Vultr host the VPS instances that run your AI assistant. They provide compute and storage but do not access your data.
We do not share your data with any other third parties except where required by law.
5. International Data Transfers
Your dedicated VPS may be hosted in different regions depending on availability and performance. AI model API calls are processed by US-based providers. Where your data is transferred outside the EU/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions to protect your data in accordance with GDPR requirements.
6. Data Retention
- Messages & conversation history: Retained on your VPS until you request deletion or your account is terminated.
- Routing data: Retained for as long as your account is active, then deleted within 30 days of account closure.
- Billing records: Retained as required by applicable tax and accounting laws.
7. Cookies
The ClawHatch platform is primarily accessed through messaging apps, not a web browser. Our website uses no tracking cookies and no third-party analytics cookies. Any cookies used are strictly necessary for basic website functionality.
8. Your Rights Under GDPR
If you are in the EU/EEA, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data (see our Data Deletion page)
- Restrict or object to processing of your data
- Data portability — receive your data in a structured, machine-readable format
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email [email protected]. We will respond within 30 days.
9. Security
We protect your data with encryption in transit (TLS) for all communications. Each user's AI assistant runs on an isolated VPS with its own credentials and storage. Access to infrastructure is restricted and audited.
10. Children's Privacy
ClawHatch is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this policy from time to time. We will notify active users of significant changes via their messaging channel or email. The "Effective date" at the top of this page indicates when the policy was last revised.
12. Contact
For privacy-related questions or requests, contact us at:
[email protected]