Privacy Policy
Last updated: June 18, 2026
0. Data Controller
For the purposes of the EU/EEA General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and equivalent regimes, the data controller is Clawmont, operated by its founder, established in the Republic of Lithuania (EU). You can reach the controller for any request under this Policy, or any compliance query, at [email protected].
1. What We Collect
Clawmont collects the minimum data required to operate the service:
- Account data: email address, hashed credentials, and billing metadata (handled by our payment processors - Paddle as Merchant of Record where it operates checkout, otherwise Stripe; we never see or store card numbers).
- Alert metadata: threat type, timestamp, severity level, and rule matched. Alert payloads are encrypted at rest.
- Usage analytics: page views, feature usage, and aggregate site-interaction signals such as heatmaps and consented session replays (no PII, all typed input masked; Cloudflare Web Analytics is cookieless, and PostHog loads only with your consent - see Section 12).
- Optional telemetry: anonymized event metadata, only if you turn it on - see the next section.
2. Telemetry (Off by Default)
The plugin includes optional anonymized telemetry that is opt-in: it sends nothing unless you enable it. When enabled, it sends only hashed event metadata: event type, timestamp, module, severity bucket, size bucket, duration, plugin version, OS, and architecture. The client strips any field outside this fixed allow-list before sending, so prompt text, file paths, and code can never be included - even by accident. You can turn telemetry off at any time, and the plugin works identically either way.
3. What We Do Not Collect
Clawmont is an in-process security layer that runs locally on your OpenClaw gateway. Your AI conversations, prompts, model responses, and source code never leave your machine. We do not have access to your chat content.
4. How We Use Your Data
- To operate and improve the Clawmont service.
- To send security alert notifications to your configured channels.
- To process payments via our payment processors - Paddle (as Merchant of Record) and/or Stripe (we never see or store card numbers).
- To send transactional emails (receipts, security alerts, account notices).
5. Legal Bases for Processing (EU/EEA)
Where the GDPR applies, we process personal data on the following legal bases: performance of a contract (to provide the service you purchase, manage your account, and deliver alerts); legitimate interests (to operate, secure, and improve the service and measure aggregate site usage, balanced against your rights); consent (for non-essential analytics such as PostHog and for optional telemetry, which you can withdraw at any time); and compliance with a legal obligation (tax, accounting, and responding to lawful requests).
6. How We Share Your Data
We do not sell your personal data and do not share it for advertising. We share it only with the service providers (processors) needed to run Clawmont, each acting under our instructions and a data-processing agreement, and only with what they need:
- Paddle - payment processing as Merchant of Record (where Paddle operates checkout, Paddle is the seller of record and processes your payment and billing data as an independent controller under its own privacy policy).
- Stripe - payment processing and tax compliance (where Stripe operates checkout).
- Supabase - authentication and database hosting.
- Resend - transactional email delivery.
We may also disclose data where required by law, to enforce our terms, or to protect the rights, safety, and security of users and the public.
7. International Data Transfers
Some of our processors - in particular payment and infrastructure providers - may process personal data outside the EU/EEA, including in the United States. Where we transfer personal data outside the EU/EEA, we rely on an applicable European Commission adequacy decision or on appropriate safeguards such as the Commission's Standard Contractual Clauses, together with supplementary measures where required. You can request information about the safeguards in place by emailing [email protected].
8. Data Retention
Alert metadata is retained for 90 days by default on the optional Guardrails cloud service. Account data is deleted within 30 days of account closure. We keep billing and tax records for as long as required by applicable law. You can export or delete your data at any time by emailing support.
9. How We Protect Your Data
We apply technical and organizational measures appropriate to the risk, including encryption in transit (TLS), encryption of alert payloads at rest, access controls, and data minimization. No method of transmission or storage is ever completely secure; if a personal-data breach occurs, we will notify you and the competent supervisory authority where and as the law requires.
10. Your Privacy Rights
Subject to applicable law, you may request access to, correction of, deletion of, restriction or portability of your personal data, and you may object to processing or withdraw consent at any time (without affecting processing already carried out). Email [email protected]; deletion requests are honored within 30 days and exports are delivered in a portable machine-readable format. We may need to verify your identity before acting on a request.
US state privacy rights. If you are a resident of California or another US state with a comprehensive privacy law, you have the right to know, access, correct, and delete your personal information and to opt out of its sale or sharing. As noted above, we do not sell or share personal information and do not use it for cross-context behavioral advertising, and we will not discriminate against you for exercising your rights. To exercise them, email the address above.
11. Children's Privacy
Clawmont is a professional security tool and is not directed to children. We do not knowingly collect personal data from anyone under 16 (or the minimum age of digital consent in your country). If you believe a child has provided us personal data, contact [email protected] and we will delete it.
12. Cookies and Local Storage
The Clawmont marketing site (clawmont.com) uses the following privacy-first analytics. Cloudflare Web Analytics provides aggregate traffic measurement - page views and referrers - and is cookieless and privacy-first: it sets no cookies, collects no personal data or cross-site identifiers, and therefore loads for all visitors. PostHog provides product analytics (page views, button clicks via autocapture, and time-on-page), heatmaps, and - only where analytics consent applies - session replay (a visual reconstruction of how a page was scrolled and clicked) to understand how visitors use the site. Session replay never captures what you type: all keyboard and form input is masked with placeholder characters inside your browser before anything is transmitted. Surveys, dead-click capture, exception capture, and performance capture are disabled. PostHog creates a persistent profile only for identified (logged-in) users. We also collect first-party usage analytics stored on our own servers: anonymous interaction and funnel events such as page views, scroll depth, clicks, and which checkout/onboarding steps you reach; a small set of onboarding funnel milestones (step reached, install completed - never content, keys, or personal data) is also mirrored to PostHog so we can measure where the signup funnel loses people. This collects no personal data and uses a randomly-generated session identifier kept in your browser's local storage purely to group events from a single visit (it resets after 30 minutes of inactivity). None of these tools is configured with advertising IDs, and all are used solely to improve the site - not for advertising (see PostHog's privacy policy). Visitors in the EU/EEA are shown a consent bar before any non-essential analytics load: choosing "Essential only" prevents both PostHog and the first-party usage analytics (and the local-storage identifier) from loading at all (Cloudflare Web Analytics, being cookieless, sets no such cookies); the choice is stored in your browser's local storage and can be reset by clearing site data. Our payment processor (Paddle or Stripe, depending on which operates the checkout) sets its own strictly-necessary cookies on the checkout page (see Paddle's and Stripe's privacy policies). No third-party advertising or social-media trackers are loaded. The plugin itself runs offline by default and does not set cookies. You can also opt out at any time using your browser's standard analytics-blocking controls or an extension such as uBlock Origin.
13. Changes to This Policy
We may update this policy from time to time. We will post the revised version here with a new "Last updated" date and, for material changes that affect your rights, notify registered users by email. Continued use of the service after the changes take effect constitutes acceptance of the updated policy.
14. Governing Law and Supervisory Authority
This policy and the underlying processing activities are governed by the laws of the Republic of Lithuania and applicable EU law (notably the GDPR, Regulation (EU) 2016/679). Statutory rights for EU/EEA residents (access, rectification, erasure, restriction, portability, and objection) apply in full, and you have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) or with the supervisory authority in your country of residence. Residents of other jurisdictions retain the mandatory data-protection rights granted by their local law.
15. Contact
Questions about this policy? Email [email protected].