MyClaw Privacy Policy

Last updated: March 26, 2026

Consolidated Website Draft.

Prepared for the MyClaw.ai privacy policy update based on the current website text and requested additions.

This draft is a policy-writing deliverable and should be reviewed by legal counsel before publication.

MyClaw ("us," "we," or "our") operates the MyClaw.ai website and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use the Service. We are committed to protecting your privacy and handling your data with transparency.

Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge the practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Service.

1. Information We Collect

1.1 Information You Provide Directly

  • Account information. When you create an account or reserve an instance, we collect your name, email address, and any other information you provide during registration.
  • Payment information. When you make a purchase, payment details such as your credit card number and billing address are collected and processed directly by our payment processor, Stripe. We do not store your full credit card number on our servers. We may receive limited payment information from Stripe, such as the last four digits of your card, card brand, and expiration date, for account records and billing support.
  • Communications. When you contact us by email, support channels, or feedback forms, we collect the content of your messages, your email address, and any other information you choose to provide.
  • Instance data. We may process configurations, prompts, files, and other data you store on your managed instance as part of providing the Service and enabling AI-related functionality.

1.2 Information Collected Automatically

  • Log data. We may automatically collect information such as your IP address, browser type and version, operating system, referring and exit pages, date and time stamps, and clickstream data.
  • Device information. We may collect device type, unique device identifiers, screen resolution, and hardware model.
  • Usage data. We may collect information about pages visited, features used, actions taken, time spent on pages, and interaction patterns within the Service.
  • Location data. We may infer your approximate geographic location based on your IP address. We do not collect precise GPS location data.

1.3 Information from Third Parties

We may receive information about you from third-party services you use to sign in to or connect with the Service, such as OAuth providers, and from our payment processor regarding the status of your transactions.

2. How We Use Your Information

2.1 To Provide and Maintain the Service

  • Create and manage your account.
  • Provision, configure, and maintain your cloud instance.
  • Process payments and manage your subscription.
  • Perform backups and data recovery.
  • Provide customer support and respond to your inquiries.

2.2 To Improve and Develop the Service

  • Analyze usage patterns and trends to improve user experience.
  • Identify and fix bugs, errors, and performance issues.
  • Develop new features and functionality.
  • Conduct research and analysis to better understand our users.

2.3 To Communicate With You

  • Send transactional communications such as billing receipts, account confirmations, reservation updates, and support responses.
  • Notify you of service launches, updates, maintenance windows, and security alerts.
  • Send promotional communications about new features or offers, where permitted by law. You can opt out of marketing communications at any time.

2.4 To Ensure Security and Prevent Fraud

  • Detect, investigate, and prevent fraudulent transactions, unauthorized access, abuse of the Service, and violations of our Terms.
  • Protect the rights, property, and safety of MyClaw, our users, and the public.

3. Legal Basis for Processing (EEA/UK Users)

3.1 Legal Bases

If you are located in the European Economic Area (EEA) or the United Kingdom (UK), we process your personal data under the following legal bases:

  • Performance of a contract - to provide, operate, and support the Service you request, including account management, billing, and instance provisioning.
  • Legitimate interests - to improve our Service, secure our systems, prevent fraud, analyze product usage, and communicate with users about the operation of the Service, provided those interests are not overridden by your rights and freedoms.
  • Legal obligations - to comply with applicable laws, regulations, lawful requests, tax and accounting requirements, and enforcement obligations.
  • Consent - where you have provided explicit consent, such as when you opt in to certain communications or other optional processing. You may withdraw your consent at any time, without affecting the lawfulness of processing based on consent before withdrawal.

3.2 Additional GDPR Rights Context

Where required by applicable law, we will identify the legal basis that applies to the relevant processing activity and honor the rights available to you under the GDPR and other applicable privacy laws.

4. Information Sharing and Disclosure

4.1 Service Providers

We may share information with trusted third-party service providers that help us operate, maintain, and improve the Service, subject to appropriate contractual and confidentiality obligations. These providers may include payment processors, cloud infrastructure providers, analytics providers, email delivery providers, customer support tools, and security vendors.

The Service relies on the following key subprocessors:

  • Stripe - payment processing.
  • Amazon Web Services (AWS) - cloud infrastructure hosting.
  • Supabase - database hosting and backend services.

These subprocessors process personal data on our behalf in accordance with our instructions and are subject to contractual obligations designed to protect your data.

4.2 Legal Requirements

We may disclose your information if required to do so by law or in the good-faith belief that such action is necessary to comply with a legal obligation, protect and defend our rights or property, prevent or investigate wrongdoing, or protect the safety of users or the public.

4.3 Business Transfers

If MyClaw is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, your personal information may be transferred as part of that transaction. Where required by law, we will provide notice of any material change in the ownership or use of your personal information.

4.4 With Your Consent

We may share your information for other purposes with your explicit consent.

4.5 No Sale for Third-Party Marketing

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

5. Cookies and Tracking Technologies

5.1 Cookies

We use cookies and similar technologies to operate, secure, and improve the Service. Cookies are small data files stored on your device or browser.

  • Cookies may be used for authentication and account management.
  • Cookies may be used for security and fraud prevention.
  • Cookies may be used for analytics and performance monitoring.
  • Cookies may be used for user preferences and personalization.

5.2 Third-Party Cookies

We may allow third-party service providers, such as analytics providers or service delivery partners, to place cookies or similar technologies on your device to help us understand how the Service is used, measure performance, or support Service functionality.

5.3 Managing Cookies

Most web browsers allow you to control cookies through their settings. You can set your browser to refuse all or some cookies, or to alert you when websites set or access cookies. If you disable cookies, some parts of the Service may become unavailable or may not function properly.

6. Data Security

We take the security of your data seriously and implement appropriate technical and organizational measures designed to protect personal information. These measures may include encryption of data in transit, encryption of sensitive data at rest where appropriate, access controls, authentication mechanisms, regular security reviews, isolated instance environments, and backup protections. However, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

7. Data Retention

We retain personal data only for as long as necessary to provide the Service, fulfill the purposes described in this Privacy Policy, and comply with legal, tax, accounting, security, dispute resolution, and enforcement obligations.

For example, we may retain account data while your account is active, payment and billing records for applicable compliance periods, log data for security and analytics purposes for a limited period, and support records for as long as reasonably necessary to resolve issues and improve support operations.

When we no longer need personal data for these purposes, we will delete it, anonymize it, or securely store it until deletion is possible. Instance data stored within user-managed environments is retained according to the lifecycle of the user's active instance and may be deleted when the instance is terminated.

8. Your Privacy Rights

8.1 General Rights

  • Depending on your location and subject to applicable law, you may have the right to access your personal data.
  • You may have the right to request correction of inaccurate or incomplete personal data.
  • You may have the right to request deletion of your personal data.
  • You may have the right to restrict or object to certain processing.
  • You may have the right to request data portability in a structured, commonly used, and machine-readable format.
  • Where we rely on consent, you may withdraw consent at any time.

8.2 For EEA/UK Residents (GDPR)

If you are a resident of the EEA or the UK, you may also have the right to lodge a complaint with your local data protection authority if you believe our processing of your personal data violates applicable law.

8.3 For California Residents (CCPA/CPRA)

  • If you are a California resident, you may have the right to request disclosure of the personal information we collect, use, disclose, sell, or share about you, as applicable.
  • You may have the right to request deletion of your personal information, subject to certain exceptions.
  • You may have the right to request correction of inaccurate personal information.
  • You may have the right to opt out of the sale or sharing of personal information, where applicable.

We will not discriminate against you for exercising these rights.

8.4 Exercising Your Rights

To exercise any applicable privacy right, please contact us at contact@myclaw.ai. We may need to verify your identity before processing your request. We will respond within the timeframe required by applicable law.

9. International Data Transfers

Your information may be transferred to, stored in, and processed in countries outside your jurisdiction, including the United States, where data protection laws may differ from those in your place of residence.

Where required by applicable data protection law, we take appropriate safeguards to protect personal data transferred internationally, including the use of contractual safeguards such as Standard Contractual Clauses or other lawful transfer mechanisms.

10. Children's Privacy

The Service is not intended for children under 18, and we do not knowingly collect personal information from children under 18. If you believe that a child has provided us with personal information in violation of this section, please contact us so that we can take appropriate steps.

11. Third-Party Links and Services

The Service may contain links to third-party websites, applications, integrations, or services that are not operated by us. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies before providing personal information to them.

12. Do Not Track Signals

Because there is no consistent industry standard for how to interpret browser-based Do Not Track signals, we do not currently respond to them unless and until a recognized standard is established.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will revise the "Last updated" date above and, where required by law, provide additional notice.

14. Contact Us