Privacy Policy

Last updated: February 2026

Overview

At ClawHarbor, we take your privacy seriously. This policy explains what data we collect, how we use it, and your rights regarding your information.

Data We Collect

Account Information

When you create an account, we collect your email address, name, and payment information (processed securely by Stripe).

Conversation Data

Your conversations with your AI assistant are stored on your dedicated instance. We do not access, read, or analyze your conversation content unless required for technical support with your explicit permission. Logs are kept for debugging and improving service reliability.

Usage Analytics

We collect anonymized usage metrics (message counts, feature usage) to improve our service. This data cannot be linked back to individual conversations.

How We Use Your Data

  • To provide and maintain the Service
  • To process payments and send billing notifications
  • To send important service updates and security alerts
  • To improve our platform based on usage patterns
  • To respond to support requests

Data Storage & Security

Your data is stored on secure servers in the European Union. We implement:

  • Encryption at rest and in transit (TLS 1.3)
  • Isolated instances per customer
  • Regular security audits
  • Automated backups with 30-day retention

Third-Party Services

We use the following third-party services:

  • Stripe — Payment processing
  • Supabase — Authentication and database
  • OpenAI / Anthropic — AI model providers (via your API keys)

Each provider has their own privacy policy. When using your own API keys, conversations are sent directly to the AI provider according to their terms.

Your Rights (GDPR)

Under GDPR, you have the right to:

  • Access — Request a copy of your data
  • Rectification — Correct inaccurate data
  • Erasure — Request deletion of your data
  • Portability — Export your data in a standard format
  • Object — Opt out of certain data processing

To exercise these rights, contact us at [email protected]

Data Retention

We retain your data for as long as your account is active. Upon account deletion, we remove your data within 30 days, except where required by law for longer periods.

Cookies

We use essential cookies for authentication and session management. We do not use tracking cookies or share data with advertisers.

Changes to This Policy

We may update this policy occasionally. Significant changes will be communicated via email. Continued use of the Service after changes constitutes acceptance.

Contact

For privacy-related questions, contact us at [email protected]