{"platform":"Clawvisor","slug":"clawvisor","category":"Workflow & Automation","website":"https://clawvisor.com","risk_rating":"low","verification":"fully_verified","verification_detail":{"tier":"fully_verified","partial_reason_code":"none","partial_reason_label":"Complete","blocked_core_documents":[]},"rating":{"value":"low","unknown_reason_code":"none","unknown_reason_label":"Rated"},"corpus_status":"corpus_complete","canonical":"https://airinetwork.com/platform/clawvisor","machine_url":"https://airinetwork.com/api/machine/platform/clawvisor","last_reviewed":"2026-08-24","findings_count":31,"findings":[{"id":"privacy-data-use-f7bdcc8c359cefc21055","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-f7bdcc8c359cefc21055","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" When you use Clawvisor&#x27;s LLM proxy, Clawvisor processes prompts, conversation history, tool definitions, tool calls, tool results, model outputs, streaming chunks, and related request/response content only transiently to provide proxy features such as credential substitution, tool-call inspection, task-scope enforcement, human approval, redaction, rewriting, blocking, and audit logging. Clawvisor does not persist raw LLM request bodies, raw LLM response bodies, or full model streams.\n We may store metadata and redacted audit records, such as provider, model, endpoint, timestamp, status code, streaming flag, tool name, decision, outcome, task ID, agent ID, and sanitized parameters. Redacted audit records are retained as audit logs. Short-lived pending approval state, nonces, and resolver state may be stored temporarily and deleted when the approval, stream, or request no longer needs them. Operational trace/debug logs, when generated, are redacted or sanitized and retained only as needed for service operation, security, support, or compliance, then deleted according to the applicable account deletion or operational log retention process.","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20When%20you%20use,operational%20log%20retention%20process.","structural_citation":"Privacy Policy › “2a. LLM Proxy Data Handling”","citation_basis":"heading_path","char_start":2722,"char_end":3882,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"privacy-data-use-d2ba87e76f2783ecd647","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-d2ba87e76f2783ecd647","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" When you self-host Clawvisor, your credentials, audit logs, agent configurations, and all data processed by your instance remain under your control. The cloud relay is enabled by default for local daemon installations, and push notifications are enabled when you pair a mobile device; connection metadata for these services (described in Section 3a) is processed by Clawvisor&#x27;s infrastructure. We do not collect telemetry or usage analytics from self-hosted instances unless you explicitly opt in. When enabled, anonymous telemetry includes aggregate event counts (tasks created, gateway requests processed, approvals issued) and is not linked to any user identity or credentials.","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20When%20you%20self-host,user%20identity%20or%20credentials.","structural_citation":"§ 3 (Self-Hosted Instances)","citation_basis":"section_number","char_start":3920,"char_end":4606,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"privacy-data-use-8226f2897160331c3b8a","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-8226f2897160331c3b8a","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Local daemon installations connect to the Clawvisor cloud relay by default. The following data is transmitted to Clawvisor infrastructure:\n Connection metadata: Daemon ID, Ed25519 public key, IP address, and connection/disconnection timestamps. \n Tunnel traffic: All traffic between your daemon and connecting clients is encrypted in transit (TLS). A subset of security-sensitive routes — including agent gateway requests, task management, and connection requests — additionally enforce end-to-end encryption (X25519/HKDF + AES-256-GCM), making their contents unreadable by the relay server. Other routes, including the MCP protocol used by IDE plugins such as Claude Desktop, are protected by TLS in transit but are readable by the relay server. Credentials stored in your local vault are never transmitted through the relay. \n Authentication: The relay stores your daemon&#x27;s Ed25519 public key for challenge-response authentication. \n When you pair a mobile device, push notifications are enabled. The following is transmitted:\n Device tokens: Required to deliver notifications to your mobile device. \n Notification payloads: Payloads include event type, task purpose, risk level, and action summary. They do not include credentials, API response bodies, or message contents. \n Connection metadata and device tokens are retained while the relay connection or push subscription is active and are deleted upon de-registration or account removal.","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20Local%20daemon%20installations,de-registration%20or%20account%20removal.","structural_citation":"Privacy Policy › “3a. Self-Hosted — Cloud Relay and Push Notifications”","citation_basis":"heading_path","char_start":4672,"char_end":6122,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"privacy-data-use-f21c93d8c10c5ad6a6d2","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-f21c93d8c10c5ad6a6d2","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Cloud service: API credentials you store are encrypted with AES-256-GCM on our infrastructure. Credentials are decrypted only in memory during request execution and are never logged.\n Self-hosted: Credentials are stored encrypted on your infrastructure. We have no access to your credentials, data, or server environment. Credentials are decrypted only in memory during request execution and are never logged.\n Cloud relay: When a daemon connects to the cloud relay, all tunnel traffic is encrypted in transit via TLS. A subset of routes — agent gateway requests, task operations, and connection requests — additionally enforce end-to-end encryption between the client and daemon, making their contents unreadable by the relay. Other routes, including the MCP protocol used by IDE plugins, are protected by TLS only. Credentials stored in the local vault are never transmitted to the relay.","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20Cloud%20service%3A%20API,transmitted%20to%20the%20relay.","structural_citation":"§ 5 (Credentials and Security)","citation_basis":"section_number","char_start":3469,"char_end":4360,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}},{"id":"privacy-data-use-6ab8b52e2e2a74727113","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-6ab8b52e2e2a74727113","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" When you use the LLM proxy, you authorize Clawvisor to process LLM requests, responses, tool definitions, tool calls, tool results, streaming chunks, and related content as needed to provide proxy features. This processing may include inspecting, buffering, redacting, rewriting, holding for approval, blocking, synthesizing approval prompts or audit summaries, and re-emitting LLM requests, responses, tool calls, and tool results.\n Clawvisor does not persist raw LLM request bodies, raw LLM response bodies, or full model streams when operating the LLM proxy. Raw content is processed in memory or transient buffers only as needed to forward, inspect, redact, rewrite, approve, block, or audit requests and responses. Clawvisor may retain metadata, redacted audit logs, pending approval state, nonces, resolver state, sanitized trace/debug logs, and other operational records needed to provide and secure the service.\n You remain responsible for the LLM providers, accounts, models, endpoints, credentials, prompts, tools, and outputs you configure or authorize through Clawvisor, including any provider terms, usage policies, rate limits, safety systems, account restrictions, and charges that apply.","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20When%20you%20use,and%20charges%20that%20apply.","structural_citation":"§ 7 (LLM Proxy Operation)","citation_basis":"section_number","char_start":5182,"char_end":6386,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}},{"id":"privacy-data-use-a7397b29fe09fbaa6a6e","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-a7397b29fe09fbaa6a6e","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" The intent verification feature uses a third-party LLM to check whether agent requests are consistent with approved purposes. This check is best-effort and may not catch all misuse. It is not a substitute for careful task scope design and human oversight.\n Chain context tracking: When enabled, the output of API calls executed on your behalf — which may include email bodies, message content, file contents, contact details, and other data returned by third-party APIs — is sent partially or in full to the configured LLM provider to extract structural references such as IDs, email addresses, and phone numbers. Credentials are never sent. Self-hosted users select their own LLM provider and are responsible for reviewing that provider&#x27;s data handling policies. On the cloud service, this processing occurs within Clawvisor&#x27;s Google Cloud infrastructure.\n Task risk assessment: When enabled, task purpose descriptions and authorized action scopes are sent to the configured LLM for risk evaluation. This assessment is advisory and does not guarantee that high-risk tasks will be blocked.","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20The%20intent%20verification,tasks%20will%20be%20blocked.","structural_citation":"§ 13 (AI Feature Disclaimers)","citation_basis":"section_number","char_start":10351,"char_end":11451,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}},{"id":"privacy-data-use-cb6e2592bb8f825e07c3","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-cb6e2592bb8f825e07c3","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Clawvisor, Inc., a Delaware corporation (\"Clawvisor,\" \"we,\" \"us,\" or \"our\"), is the data controller for information collected through the cloud service and the clawvisor.com website. Clawvisor is a credential-vaulting gateway for AI agents, available both as a hosted cloud service at app.clawvisor.com (\"the Service\") and as self-hosted software you run on your own infrastructure (\"the Software\"). This Privacy Policy covers the clawvisor.com website, the cloud service, and describes what data a self-hosted Clawvisor instance processes.","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20Clawvisor%2C%20Inc.%2C%20a,self-hosted%20Clawvisor%20instance%20processes.","structural_citation":"§ 1 (Overview)","citation_basis":"section_number","char_start":118,"char_end":659,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"privacy-data-use-d1099cac628307d88456","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-d1099cac628307d88456","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" When you use the Clawvisor cloud service, we collect, store, or use the following data:\n Account data: Email address and bcrypt-hashed password for authentication. If you sign in via SAML SSO, your email address is received from your organization&#x27;s identity provider. \n Authentication session data: We use strictly necessary authentication cookies, including an HttpOnly refresh-token cookie, to keep you signed in and protect account access. These cookies are not used for analytics, advertising, or cross-site tracking. \n Credentials you store: API keys and OAuth tokens you add to the vault, encrypted with AES-256-GCM at rest. \n Agent tokens: Stored as SHA-256 hashes. The raw token is shown once at creation and never stored. Agent tokens may also be issued to third-party applications (such as IDE plugins) through an OAuth 2.1 authorization flow that you explicitly approve. \n OAuth client registrations: When a third-party application connects via OAuth, we store its client name and redirect URIs. Authorization codes are short-lived and deleted after use. \n Chain context facts: When intent verification with chain context is enabled, structural references (such as email addresses, IDs, and phone numbers) may be extracted from API responses and stored temporarily to validate follow-up requests within the same task. These facts are automatically deleted when the task completes, expires, or is revoked. \n Audit logs: Every gateway request is logged with the service, action, sanitized parameters, decision, and outcome. ","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20When%20you%20use,decision%2C%20and%20outcome.%20","structural_citation":"§ 2 (Cloud Service — Data We Collect)","citation_basis":"section_number","char_start":707,"char_end":2246,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"privacy-data-use-30050d7954c0976e80fb","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-30050d7954c0976e80fb","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":"Raw credentials are never included in logs. \n LLM proxy records: Metadata, redacted audit records, short-lived approval state, nonces, resolver state, and operational trace/debug logs related to LLM proxy traffic, as described in Section 2a. Raw LLM request bodies, raw LLM response bodies, and full model streams are not persisted. \n Notification configs: Telegram bot tokens and chat IDs for approval notifications, if configured. ","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=Raw%20credentials%20are%20never,notifications%2C%20if%20configured.%20","structural_citation":"§ 2 (Cloud Service — Data We Collect)","citation_basis":"section_number","char_start":2246,"char_end":2679,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"privacy-data-use-7f6f66fa6f33b8697907","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-7f6f66fa6f33b8697907","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Enforce authorization policies (restrictions, task scopes, approvals, and LLM proxy controls) ","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20Enforce%20authorization%20policies,LLM%20proxy%20controls)%20","structural_citation":"Privacy Policy › “Route and mediate user-directed LLM proxy traffic on your behalf”","citation_basis":"heading_path","char_start":6371,"char_end":6466,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"privacy-data-use-7398e50c2801b5d0b147","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-7398e50c2801b5d0b147","surface":"privacy_data_use","risk":"low","confidence":"high","tier":"All","verified":true,"quote":" We do not sell your data or use it for advertising.","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20We%20do%20not,use%20it%20for%20advertising.","structural_citation":"Privacy Policy › “Generate audit logs for your review”","citation_basis":"heading_path","char_start":6505,"char_end":6557,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"privacy-data-use-2455c747966eb6638dac","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-2455c747966eb6638dac","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Our marketing site is hosted on Ploy and uses two privacy-focused, cookie-free analytics tools: Ploy&#x27;s built-in first-party analytics and Plausible Analytics. Neither tool uses cookies or collects personal data, and both are compliant with GDPR, CCPA, and PECR. All data is aggregated and no individual visitors can be identified. Server logs may record IP addresses and request metadata as part of standard web hosting, which are retained for security purposes and automatically purged.\n The hosted application at app.clawvisor.com uses strictly necessary cookies for authentication and security, such as an HttpOnly refresh-token cookie. These cookies are required to provide the Service and are not used for advertising or analytics.","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20Our%20marketing%20site,for%20advertising%20or%20analytics.","structural_citation":"§ 5 (Website and Cookies)","citation_basis":"section_number","char_start":6593,"char_end":7335,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"privacy-data-use-bcfe8e937b591606f9de","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-bcfe8e937b591606f9de","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":"For task risk assessment, only the task purpose and authorized actions are sent. When chain context is enabled, the output of API calls executed on your behalf — which may include email bodies, message content, file contents, and other data returned by third-party APIs — is sent partially or in full to the configured LLM provider to extract structural references such as IDs and addresses. Credentials are never sent. On the cloud service, this processing occurs within Clawvisor&#x27;s Google Cloud infrastructure. Self-hosted users select and configure their own LLM provider for these features; data handling is governed by that provider&#x27;s terms. Cloud service: The cloud service uses Anthropic Claude Haiku 4.5 (or newer), Claude Sonnet 4.6 (or newer), and Google Gemini 2.5 Flash-Lite (or newer), hosted on Google Cloud Vertex AI within Clawvisor&#x27;s own GCP project. Google processes this data as a sub-processor under its Cloud Data Processing Addendum. For Clawvisor internal AI features, no user data is sent to Anthropic or any other model provider directly, and no user data is used for model training. Self-hosted: You choose and configure your own LLM provider (Anthropic, OpenAI, Ollama, Groq, or Vertex AI). Data handling is governed by your chosen provider&#x27;s terms. \n User-directed LLM proxy traffic: When you configure or use Clawvisor&#x27;s LLM proxy to call OpenAI-compatible, Anthropic-compatible, or other LLM provider endpoints, request and response content is sent to the provider endpoint you configure, select, or instruct Clawvisor to use. ","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=For%20task%20risk%20assessment%2C,Clawvisor%20to%20use.%20","structural_citation":"§ 6 (Third-Party Services)","citation_basis":"section_number","char_start":8818,"char_end":10400,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"privacy-data-use-82d099b3e90384e6ecd4","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-82d099b3e90384e6ecd4","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Credentials are encrypted at rest with AES-256-GCM. The vault key is stored separately from the database. Passwords are hashed with bcrypt. Agent tokens are stored as one-way hashes. No credentials appear in logs, error messages, or API responses. The cloud service infrastructure is hosted on Google Cloud Platform (GCP).","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20Credentials%20are%20encrypted,Google%20Cloud%20Platform%20(GCP).","structural_citation":"§ 8 (Data Security)","citation_basis":"section_number","char_start":12250,"char_end":12573,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"privacy-data-use-880843c4479551252d70","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-880843c4479551252d70","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Clawvisor is not directed at individuals under the age of 13. We do not knowingly collect personal information from children.","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20Clawvisor%20is%20not,personal%20information%20from%20children.","structural_citation":"§ 10 (Children&#x27;s Privacy)","citation_basis":"section_number","char_start":13673,"char_end":13799,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"privacy-data-use-6e2b5d99e415402e74b6","permalink":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-6e2b5d99e415402e74b6","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" We may update this Privacy Policy from time to time. For material changes, we will notify you at least thirty (30) days in advance by email or through a prominent notice within the Service. Changes will be posted on this page with an updated date.","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20We%20may%20update,with%20an%20updated%20date.","structural_citation":"§ 12 (Changes to This Policy)","citation_basis":"section_number","char_start":14173,"char_end":14421,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"moderation-enforcement-4f825127c7210f33f40e","permalink":"https://airinetwork.com/platform/clawvisor/finding/moderation-enforcement-4f825127c7210f33f40e","surface":"moderation_enforcement","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" You are responsible for all actions taken through your account or instance, including actions initiated by AI agents you configure. \n You are responsible for registering your own credentials with third-party providers, including external API providers (Google, GitHub, Slack, etc.) and LLM providers, and for complying with their terms of service, usage policies, rate limits, safety systems, account restrictions, and billing rules. \n You must not use the Service or the Software to bypass or evade any third-party provider&#x27;s usage limits, safety systems, authorization model, account restrictions, credential requirements, or access controls. \n Self-hosted: You are responsible for securing your instance, including the vault key, database, and server environment. \n Relay traffic: The cloud relay is enabled by default for local daemon installations. Traffic between your daemon and connecting clients is encrypted in transit (TLS). Certain routes — including agent gateway requests, task management, and connection requests — additionally enforce end-to-end encryption, meaning the relay server cannot read their contents. Other routes, including MCP tool calls and dashboard API requests, are encrypted in transit but are readable by the relay server. Credentials stored in your local vault are never transmitted to the relay. \n Key management: You are responsible for safeguarding your daemon&#x27;s cryptographic keys (daemon-ed25519.key and daemon-x25519.key). Loss of these keys requires re-pairing your device. \n You must not use the Service or the Software for any unlawful purpose or in violation of any applicable laws. ","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20You%20are%20responsible,any%20applicable%20laws.%20","structural_citation":"§ 4 (Your Responsibilities)","citation_basis":"section_number","char_start":1787,"char_end":3426,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}},{"id":"moderation-enforcement-eda688d40a367287d78f","permalink":"https://airinetwork.com/platform/clawvisor/finding/moderation-enforcement-eda688d40a367287d78f","surface":"moderation_enforcement","risk":"medium","confidence":"high","tier":"All","verified":true,"quote":" Local daemon installations connect to the Clawvisor cloud relay by default for remote access. Push notifications are enabled when you pair a mobile device. These services are provided on a best-effort basis. We do not guarantee uptime, availability, or uninterrupted operation of the relay or push services.\n We reserve the right to suspend or revoke relay access for any instance that violates these Terms or engages in abuse, including but not limited to: proxying traffic unrelated to Clawvisor&#x27;s intended purpose, or generating excessive connection volume.\n The relay is intended solely for tunneling Clawvisor gateway traffic between your daemon and authorized clients. It must not be used as a general-purpose proxy or VPN.","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20Local%20daemon%20installations,general-purpose%20proxy%20or%20VPN.","structural_citation":"§ 6 (Cloud Relay and Push Notifications)","citation_basis":"section_number","char_start":4411,"char_end":5146,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}},{"id":"data-retention-3b5c71c6b2d0d81940c1","permalink":"https://airinetwork.com/platform/clawvisor/finding/data-retention-3b5c71c6b2d0d81940c1","surface":"data_retention","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" For the cloud service, either party may terminate at any time. We may suspend or terminate your access if you violate these Terms. Upon termination, your data will be permanently purged within thirty (30) days, except where retention is required by applicable law. You may request immediate deletion by contacting support@clawvisor.com.","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20For%20the%20cloud,deletion%20by%20contacting%20support%40clawvisor.com.","structural_citation":"§ 9 (Termination)","citation_basis":"section_number","char_start":7162,"char_end":7499,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}},{"id":"data-retention-ddc337247975228d530f","permalink":"https://airinetwork.com/platform/clawvisor/finding/data-retention-ddc337247975228d530f","surface":"data_retention","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Cloud service: Your data is retained while your account is active. Upon account deletion, all associated data — including credentials, audit logs, agent configurations, and account information — is permanently purged within thirty (30) days, except where retention is required by applicable law. You may request deletion at any time by contacting support@clawvisor.com.\n Audit logs: Audit logs on the cloud service are retained for the lifetime of your account. You may export or request deletion of your audit history at any time.\n Authentication sessions: Authentication session cookies expire according to the configured session lifetime, and are cleared or invalidated when you log out or when the session is revoked or expires.\n LLM proxy artifacts: Raw LLM request bodies, raw LLM response bodies, and full model streams are not persisted. Redacted audit logs and sanitized operational trace/debug logs may be retained as described in Section 2a. Pending approvals, nonces, resolver state, and similar short-lived proxy state are deleted when no longer needed for the approval, stream, request, or related operational process.\n Self-hosted: You control data retention entirely. Expired sessions, pending approvals, and chain context facts are cleaned up automatically by background processes within your instance.","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20Cloud%20service%3A%20Your,processes%20within%20your%20instance.","structural_citation":"§ 7 (Data Retention)","citation_basis":"section_number","char_start":10900,"char_end":12220,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"indemnity-liability-08032f281f5818a15c91","permalink":"https://airinetwork.com/platform/clawvisor/finding/indemnity-liability-08032f281f5818a15c91","surface":"indemnity_liability","risk":"medium","confidence":"high","tier":"All","verified":true,"quote":" The Service and the Software are provided \"as is\" without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service or the Software will be uninterrupted, error-free, or that it will prevent all unauthorized agent actions, unsafe LLM requests, unsafe tool calls, provider-policy violations, or undesired model outputs.\n LLM proxy inspection, redaction, rewriting, approval, blocking, and risk classification are best-effort. We do not warrant that proxy mediation will preserve semantic equivalence of modified content, catch every policy issue, prevent provider account suspension or rate limiting, avoid unexpected provider charges, or maintain compatibility with every provider API, model, streaming format, or tool-call format.","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20The%20Service%20and,format%2C%20or%20tool-call%20format.","structural_citation":"§ 10 (No Warranty)","citation_basis":"section_number","char_start":7528,"char_end":8395,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}},{"id":"indemnity-liability-242388f5560e6cab36cd","permalink":"https://airinetwork.com/platform/clawvisor/finding/indemnity-liability-242388f5560e6cab36cd","surface":"indemnity_liability","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" For the cloud service, we use reasonable efforts to maintain availability but do not guarantee uninterrupted or error-free operation. The Service may be temporarily unavailable for scheduled or unscheduled maintenance.\n Clawvisor shall not be liable for any delay or failure to perform resulting from causes beyond its reasonable control, including but not limited to acts of God, natural disasters, pandemic, war, terrorism, labor disputes, government actions, power or internet failures, failures of third-party infrastructure providers (including cloud hosting platforms), or failures, outages, rate limits, account restrictions, billing controls, or suspensions imposed by third-party API or LLM providers.","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20For%20the%20cloud,API%20or%20LLM%20providers.","structural_citation":"§ 8 (Service Availability)","citation_basis":"section_number","char_start":6423,"char_end":7134,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}},{"id":"indemnity-liability-dec8177e45742b362b1b","permalink":"https://airinetwork.com/platform/clawvisor/finding/indemnity-liability-dec8177e45742b362b1b","surface":"indemnity_liability","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" To the fullest extent permitted by law, Clawvisor, Inc. and its officers, directors, employees, and affiliates shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, revenue, or profits arising from your use of the Service or the Software. This includes damages resulting from actions taken by AI agents, credential exposure, service interruptions, LLM proxy misclassification, modified, delayed, blocked, incomplete, or re-emitted outputs, tool-call handling, provider outages, provider rate limits, account suspensions, provider billing issues, or alleged violations of provider terms or policies.\n To the extent permitted by applicable law, Clawvisor&#x27;s total aggregate liability for all claims arising out of or related to the Service or the Software shall not exceed the greater of (a) the amounts you paid to Clawvisor in the twelve (12) months preceding the claim, or (b) one hundred U.S. dollars (US $100).","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20To%20the%20fullest,U.S.%20dollars%20(US%20%24100).","structural_citation":"§ 11 (Limitation of Liability)","citation_basis":"section_number","char_start":8436,"char_end":9416,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}},{"id":"indemnity-liability-68c041b1c56a3a3cf8d9","permalink":"https://airinetwork.com/platform/clawvisor/finding/indemnity-liability-68c041b1c56a3a3cf8d9","surface":"indemnity_liability","risk":"medium","confidence":"high","tier":"All","verified":true,"quote":" You agree to indemnify, defend, and hold harmless Clawvisor, Inc. and its officers, directors, employees, and affiliates from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys&#x27; fees) arising out of or related to: (a) your use of the Service or the Software; (b) actions taken by AI agents you configure, authorize, or approve; (c) your violation of these Terms or any applicable law; (d) your use of third-party API or LLM provider credentials registered with the Service; (e) prompts, tools, tool calls, model outputs, or provider endpoints you configure, authorize, or approve; (f) your violation of third-party provider terms, usage policies, rate limits, safety systems, or account restrictions; or (g) attempts to bypass provider authorization models, safety systems, limits, or access controls.","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20You%20agree%20to,limits%2C%20or%20access%20controls.","structural_citation":"§ 12 (Indemnification)","citation_basis":"section_number","char_start":9449,"char_end":10311,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}},{"id":"subprocessors-data-sharing-b3c436508f4a2ee5c8b1","permalink":"https://airinetwork.com/platform/clawvisor/finding/subprocessors-data-sharing-b3c436508f4a2ee5c8b1","surface":"subprocessors_data_sharing","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Clawvisor interacts with third-party services only when you configure it to, whether on the cloud service or a self-hosted instance:\n External APIs (Google, GitHub, Slack, etc.) are called on your behalf when agents make requests. You register your own API credentials with each provider. Data exchanged with these services is subject to their respective privacy policies. \n SAML identity providers: If you configure SAML SSO, authentication requests are sent to your organization&#x27;s identity provider. We store the IdP&#x27;s entity ID, SSO URL, and signing certificate to validate responses. Your email address is extracted from the SAML assertion. \n Telegram is used for approval notifications if you configure a bot. Message content includes service names, actions, and truncated parameters. \n Resend is used for email verification on the cloud service. Your email address is shared with Resend to deliver verification messages. \n Cloud relay and push: Local daemon installations connect to the Clawvisor cloud relay by default, and push notifications are enabled when you pair a mobile device. Data handling for these services is described in Section 3a. \n Clawvisor internal AI features: If you enable optional intent verification or task risk assessment, Clawvisor uses AI models to evaluate agent requests. For intent verification, only request metadata (service, action, parameters, and agent-provided reason) is sent to the model. ","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20Clawvisor%20interacts%20with,to%20the%20model.%20","structural_citation":"§ 6 (Third-Party Services)","citation_basis":"section_number","char_start":7372,"char_end":8818,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"subprocessors-data-sharing-2d93f57528e0fac419e4","permalink":"https://airinetwork.com/platform/clawvisor/finding/subprocessors-data-sharing-2d93f57528e0fac419e4","surface":"subprocessors_data_sharing","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":"This includes prompts, conversation history, tool definitions, tool calls, tool results, model outputs, and streaming chunks as needed to provide the proxy. Clawvisor&#x27;s non-persistence promise for raw LLM request bodies, raw LLM response bodies, and full model streams is described in Section 2a. The provider&#x27;s handling of data after it receives proxy traffic is governed by that provider&#x27;s privacy terms, data processing terms, and account settings. ","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=This%20includes%20prompts%2C%20conversation,and%20account%20settings.%20","structural_citation":"§ 6 (Third-Party Services)","citation_basis":"section_number","char_start":10400,"char_end":10867,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"subprocessors-data-sharing-4c9cd588ea96dd19bb78","permalink":"https://airinetwork.com/platform/clawvisor/finding/subprocessors-data-sharing-4c9cd588ea96dd19bb78","surface":"subprocessors_data_sharing","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" The cloud service uses the following sub-processors to deliver the Service:\n Google Cloud Platform — Cloud infrastructure and data processing. \n Resend — Email delivery. \n Telegram — Notification delivery. \n Ploy — Marketing website hosting and analytics. \n Plausible Analytics — Website analytics. ","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20The%20cloud%20service,%E2%80%94%20Website%20analytics.%20","structural_citation":"§ 11 (Sub-Processors)","citation_basis":"section_number","char_start":13831,"char_end":14131,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"audit-rights-dpa-residency-44b7fa97d099793bb05c","permalink":"https://airinetwork.com/platform/clawvisor/finding/audit-rights-dpa-residency-44b7fa97d099793bb05c","surface":"audit_rights_dpa_residency","risk":"low","confidence":"high","tier":"All","verified":true,"quote":" For the cloud service, you may request access to, correction of, or deletion of your personal data by emailing support@clawvisor.com. For self-hosted instances, you have direct access to all your data.\n If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data. Our legal bases for processing are: performance of our contract with you (providing the Service), and legitimate interests (security, fraud prevention, and service improvement). The cloud service infrastructure is hosted in the United States on Google Cloud Platform. Transfers of personal data from the EEA/UK to the United States are governed by Google&#x27;s Data Processing Addendum, which incorporates Standard Contractual Clauses (SCCs) approved by the European Commission. To exercise your rights, contact support@clawvisor.com.","caution":null,"provenance":{"source_url":"https://clawvisor.com/privacy","snapshot_sha256":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e","wayback_url":null,"deep_link":"https://clawvisor.com/privacy#:~:text=%20For%20the%20cloud,your%20rights%2C%20contact%20support%40clawvisor.com.","structural_citation":"§ 9 (Your Rights)","citation_basis":"section_number","char_start":12601,"char_end":13632,"retrieved_at":"2026-07-20T00:01:37.788161+00:00"}},{"id":"governing-law-disputes-b69c82cc414f36452407","permalink":"https://airinetwork.com/platform/clawvisor/finding/governing-law-disputes-b69c82cc414f36452407","surface":"governing_law_disputes","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" These Terms of Service (\"Terms\") are a legal agreement between you and Clawvisor, Inc., a Delaware corporation (\"Clawvisor,\" \"we,\" \"us,\" or \"our\"). By accessing or using the Clawvisor cloud service (\"the Service\") or the Clawvisor self-hosted software (\"the Software\"), you agree to be bound by these Terms. If you do not agree, do not use the Service or the Software.","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20These%20Terms%20of,Service%20or%20the%20Software.","structural_citation":"§ 1 (Acceptance of Terms)","citation_basis":"section_number","char_start":132,"char_end":501,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}},{"id":"governing-law-disputes-f7485d976d914876f614","permalink":"https://airinetwork.com/platform/clawvisor/finding/governing-law-disputes-f7485d976d914876f614","surface":"governing_law_disputes","risk":"medium","confidence":"high","tier":"All","verified":true,"quote":" These Terms are governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-law provisions. Any disputes arising out of or related to these Terms or the Service shall be resolved exclusively in the state or federal courts located in Delaware. You consent to personal jurisdiction in those courts.","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20These%20Terms%20are,jurisdiction%20in%20those%20courts.","structural_citation":"§ 14 (Governing Law and Disputes)","citation_basis":"section_number","char_start":11495,"char_end":11861,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}},{"id":"governing-law-disputes-4872d3e20df716bd41ac","permalink":"https://airinetwork.com/platform/clawvisor/finding/governing-law-disputes-4872d3e20df716bd41ac","surface":"governing_law_disputes","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" We may update these Terms from time to time. For material changes, we will notify you at least thirty (30) days in advance by email or through a prominent notice within the Service. Changes will be posted on this page with an updated date. Continued use of the Service or the Software after the effective date of revised Terms constitutes acceptance of those Terms.","caution":null,"provenance":{"source_url":"https://clawvisor.com/terms","snapshot_sha256":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7","wayback_url":null,"deep_link":"https://clawvisor.com/terms#:~:text=%20We%20may%20update,acceptance%20of%20those%20Terms.","structural_citation":"§ 15 (Changes to Terms)","citation_basis":"section_number","char_start":11895,"char_end":12261,"retrieved_at":"2026-07-20T00:01:38.55246+00:00"}}],"documents":[{"doc_type":"privacy","pdf_page_count":null,"extraction_method":"static","page_level_citations":false,"last_captured":"2026-08-24","last_verified_scan":"2026-08-24","verified_scan_count":2},{"doc_type":"terms","pdf_page_count":null,"extraction_method":null,"page_level_citations":false,"last_captured":"2026-07-20","last_verified_scan":"2026-07-20","verified_scan_count":1}],"clause_intelligence":{"clauses_count":44,"risk_patterns_count":5,"stance_events_count":5,"patterns_by_family":{"ip_ownership":1,"legal_burden":2,"privacy_sharing":2},"risk_summary":{"high":2,"medium":3},"evidence":[{"pattern_key":"platform_claims_ownership","pattern_family":"ip_ownership","risk_rating":"high","confidence":"high","stance_key":"content_ownership","stance_value":"platform_claims_or_reserves_rights","evidence":"Local daemon installations connect to the Clawvisor cloud relay by default for remote access. Push notifications are enabled when you pair a mobile device. These services are provided on a best-effort basis. We do not guarantee uptime, availability, or uninterrupted operation of the relay or push services. We reserve the right to suspend or revoke relay access for any instance that violates these Terms or engages ...","reason":"The clause appears to reserve or claim ownership rights for the platform.","matcher_version":"clause-intelligence-2026-06-17.1","citation":{"surface":"moderation_enforcement","quote":"Local daemon installations connect to the Clawvisor cloud relay by default for remote access. Push notifications are enabled when you pair a mobile device. These services are provided on a best-effort basis. We do not guarantee uptime, availability, or uninterrupted operation of the relay or push services. We reserve the right to suspend or revoke relay access for any instance that violates these Terms or engages in abuse, including but not limited to: proxying traffic unrelated to Clawvisor&#x27;s intended purpose, or generating excessive connection volume. The relay is intended solely for tunneling Clawvisor gateway traffic between your daemon and authorized clients. It must not be used as a general-purpose proxy or VPN.","source_url":"https://clawvisor.com/terms","deep_link":"https://clawvisor.com/terms#:~:text=%20Local%20daemon%20installations,general-purpose%20proxy%20or%20VPN.","structural_citation":"§ 6 (Cloud Relay and Push Notifications)","citation_basis":"section_number","char_start":4411,"char_end":5146}},{"pattern_key":"liability_limitation","pattern_family":"legal_burden","risk_rating":"medium","confidence":"high","stance_key":"legal_burden","stance_value":"liability_limited","evidence":"The Service and the Software are provided \"as is\" without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service or the Software will be uninterrupted, error-free, or that it will prevent all unauthorized agent actions, unsafe LLM requests, unsafe tool calls, provider-policy vio...","reason":"The clause limits liability or disclaims warranties.","matcher_version":"clause-intelligence-2026-06-17.1","citation":{"surface":"indemnity_liability","quote":"The Service and the Software are provided \"as is\" without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service or the Software will be uninterrupted, error-free, or that it will prevent all unauthorized agent actions, unsafe LLM requests, unsafe tool calls, provider-policy violations, or undesired model outputs. LLM proxy inspection, redaction, rewriting, approval, blocking, and risk classification are best-effort. We do not warrant that proxy mediation will preserve semantic equivalence of modified content, catch every policy issue, prevent provider account suspension or rate limiting, avoid unexpected provider charges, or maintain compatibility with every provider API, model, streaming format, or tool-call format.","source_url":"https://clawvisor.com/terms","deep_link":"https://clawvisor.com/terms#:~:text=%20The%20Service%20and,format%2C%20or%20tool-call%20format.","structural_citation":"§ 10 (No Warranty)","citation_basis":"section_number","char_start":7528,"char_end":8395}},{"pattern_key":"indemnity_obligation","pattern_family":"legal_burden","risk_rating":"medium","confidence":"high","stance_key":"legal_burden","stance_value":"indemnity","evidence":"You agree to indemnify, defend, and hold harmless Clawvisor, Inc. and its officers, directors, employees, and affiliates from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys&#x27; fees) arising out of or related to: (a) your use of the Service or the Software; (b) actions taken by AI agents you configure, authorize, or approve; (c) your violation of these T...","reason":"The clause requires defense, indemnity, or hold-harmless obligations.","matcher_version":"clause-intelligence-2026-06-17.1","citation":{"surface":"indemnity_liability","quote":"You agree to indemnify, defend, and hold harmless Clawvisor, Inc. and its officers, directors, employees, and affiliates from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys&#x27; fees) arising out of or related to: (a) your use of the Service or the Software; (b) actions taken by AI agents you configure, authorize, or approve; (c) your violation of these Terms or any applicable law; (d) your use of third-party API or LLM provider credentials registered with the Service; (e) prompts, tools, tool calls, model outputs, or provider endpoints you configure, authorize, or approve; (f) your violation of third-party provider terms, usage policies, rate limits, safety systems, or account restrictions; or (g) attempts to bypass provider authorization models, safety systems, limits, or access controls.","source_url":"https://clawvisor.com/terms","deep_link":"https://clawvisor.com/terms#:~:text=%20You%20agree%20to,limits%2C%20or%20access%20controls.","structural_citation":"§ 12 (Indemnification)","citation_basis":"section_number","char_start":9449,"char_end":10311}},{"pattern_key":"personal_data_sale","pattern_family":"privacy_sharing","risk_rating":"high","confidence":"high","stance_key":"data_sharing","stance_value":"sale_or_sell","evidence":"We do not sell your data or use it for advertising.","reason":"The clause permits sale of personal data or information.","matcher_version":"clause-intelligence-2026-06-17.1","citation":{"surface":"privacy_data_use","quote":"We do not sell your data or use it for advertising.","source_url":"https://clawvisor.com/privacy","deep_link":"https://clawvisor.com/privacy#:~:text=%20We%20do%20not,use%20it%20for%20advertising.","structural_citation":"Privacy Policy › “Generate audit logs for your review”","citation_basis":"heading_path","char_start":6505,"char_end":6557}},{"pattern_key":"third_party_sharing","pattern_family":"privacy_sharing","risk_rating":"medium","confidence":"high","stance_key":"data_sharing","stance_value":"third_party_or_vendor_sharing","evidence":"To the fullest extent permitted by law, Clawvisor, Inc. and its officers, directors, employees, and affiliates shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, revenue, or profits arising from your use of the Service or the Software. This includes damages resulting from actions taken by AI agents, credential exposure, service interruptions, LLM pro...","reason":"The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.","matcher_version":"clause-intelligence-2026-06-17.1","citation":{"surface":"indemnity_liability","quote":"To the fullest extent permitted by law, Clawvisor, Inc. and its officers, directors, employees, and affiliates shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, revenue, or profits arising from your use of the Service or the Software. This includes damages resulting from actions taken by AI agents, credential exposure, service interruptions, LLM proxy misclassification, modified, delayed, blocked, incomplete, or re-emitted outputs, tool-call handling, provider outages, provider rate limits, account suspensions, provider billing issues, or alleged violations of provider terms or policies. To the extent permitted by applicable law, Clawvisor&#x27;s total aggregate liability for all claims arising out of or related to the Service or the Software shall not exceed the greater of (a) the amounts you paid to Clawvisor in the twelve (12) months preceding the claim, or (b) one hundred U.S. dollars (US $100).","source_url":"https://clawvisor.com/terms","deep_link":"https://clawvisor.com/terms#:~:text=%20To%20the%20fullest,U.S.%20dollars%20(US%20%24100).","structural_citation":"§ 11 (Limitation of Liability)","citation_basis":"section_number","char_start":8436,"char_end":9416}}]},"tier_conditions":[{"tier":"Api","surface":"indemnity_liability","verdict":"unknown","confidence":"high","citation_count":1,"citations":[{"finding_id":"e99c49b9-0f95-48b5-ab7e-5ce60d08632c","quote":" You agree to indemnify, defend, and hold harmless Clawvisor, Inc. and its officers, directors, employees, and affiliates from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys&#x27; fees) arising out of or related to: (a) your use of the Service or the Software; (b) actions taken by AI agents you configure, authorize, or approve; (c) your violation of these Terms or any applicable law; (d) your use of third-party API or LLM provider credentials registered with the Service; (e) prompts, tools, tool calls, model outputs, or provider endpoints you configure, authorize, or approve; (f) your violation of third-party provider terms, usage policies, rate limits, safety systems, or account restrictions; or (g) attempts to bypass provider authorization models, safety systems, limits, or access controls.","source_url":"https://clawvisor.com/terms","deep_link":"https://clawvisor.com/terms#:~:text=%20You%20agree%20to,limits%2C%20or%20access%20controls.","structural_citation":"§ 12 (Indemnification)"}]},{"tier":"Api","surface":"moderation_enforcement","verdict":"improves","confidence":"high","citation_count":1,"citations":[{"finding_id":"0feeba8f-ab0f-4cb6-a8f3-8cd40010fc39","quote":" You are responsible for all actions taken through your account or instance, including actions initiated by AI agents you configure. \n You are responsible for registering your own credentials with third-party providers, including external API providers (Google, GitHub, Slack, etc.) and LLM providers, and for complying with their terms of service, usage policies, rate limits, safety systems, account restrictions, and billing rules. \n You must not use the Service or the Software to bypass or evade any third-party provider&#x27;s usage limits, safety systems, authorization model, account restrictions, credential requirements, or access controls. \n Self-hosted: You are responsible for securing your instance, including the vault key, database, and server environment. \n Relay traffic: The cloud relay is enabled by default for local daemon installations. Traffic between your daemon and connecting clients is encrypted in transit (TLS). Certain routes — including agent gateway requests, task management, and connection requests — additionally enforce end-to-end encryption, meaning the relay server cannot read their contents. Other routes, including MCP tool calls and dashboard API requests, are encrypted in transit but are readable by the relay server. Credentials stored in your local vault are never transmitted to the relay. \n Key management: You are responsible for safeguarding your daemon&#x27;s cryptographic keys (daemon-ed25519.key and daemon-x25519.key). Loss of these keys requires re-pairing your device. \n You must not use the Service or the Software for any unlawful purpose or in violation of any applicable laws. ","source_url":"https://clawvisor.com/terms","deep_link":"https://clawvisor.com/terms#:~:text=%20You%20are%20responsible,any%20applicable%20laws.%20","structural_citation":"§ 4 (Your Responsibilities)"}]},{"tier":"Api","surface":"privacy_data_use","verdict":"improves","confidence":"high","citation_count":6,"citations":[{"finding_id":"76b17329-5ba4-40d6-87fe-91b4ea318d82","quote":" Local daemon installations connect to the Clawvisor cloud relay by default. The following data is transmitted to Clawvisor infrastructure:\n Connection metadata: Daemon ID, Ed25519 public key, IP address, and connection/disconnection timestamps. \n Tunnel traffic: All traffic between your daemon and connecting clients is encrypted in transit (TLS). A subset of security-sensitive routes — including agent gateway requests, task management, and connection requests — additionally enforce end-to-end encryption (X25519/HKDF + AES-256-GCM), making their contents unreadable by the relay server. Other routes, including the MCP protocol used by IDE plugins such as Claude Desktop, are protected by TLS in transit but are readable by the relay server. Credentials stored in your local vault are never transmitted through the relay. \n Authentication: The relay stores your daemon&#x27;s Ed25519 public key for challenge-response authentication. \n When you pair a mobile device, push notifications are enabled. The following is transmitted:\n Device tokens: Required to deliver notifications to your mobile device. \n Notification payloads: Payloads include event type, task purpose, risk level, and action summary. They do not include credentials, API response bodies, or message contents. \n Connection metadata and device tokens are retained while the relay connection or push subscription is active and are deleted upon de-registration or account removal.","source_url":"https://clawvisor.com/privacy","deep_link":"https://clawvisor.com/privacy#:~:text=%20Local%20daemon%20installations,de-registration%20or%20account%20removal.","structural_citation":"Privacy Policy › “3a. Self-Hosted — Cloud Relay and Push Notifications”"},{"finding_id":"b2bb0cf5-1406-4125-a8bf-3911680cfa1f","quote":" Cloud service: API credentials you store are encrypted with AES-256-GCM on our infrastructure. Credentials are decrypted only in memory during request execution and are never logged.\n Self-hosted: Credentials are stored encrypted on your infrastructure. We have no access to your credentials, data, or server environment. Credentials are decrypted only in memory during request execution and are never logged.\n Cloud relay: When a daemon connects to the cloud relay, all tunnel traffic is encrypted in transit via TLS. A subset of routes — agent gateway requests, task operations, and connection requests — additionally enforce end-to-end encryption between the client and daemon, making their contents unreadable by the relay. Other routes, including the MCP protocol used by IDE plugins, are protected by TLS only. Credentials stored in the local vault are never transmitted to the relay.","source_url":"https://clawvisor.com/terms","deep_link":"https://clawvisor.com/terms#:~:text=%20Cloud%20service%3A%20API,transmitted%20to%20the%20relay.","structural_citation":"§ 5 (Credentials and Security)"},{"finding_id":"c1a80f25-3bd3-4fcd-9a87-95cfa7ded4cc","quote":" The intent verification feature uses a third-party LLM to check whether agent requests are consistent with approved purposes. This check is best-effort and may not catch all misuse. It is not a substitute for careful task scope design and human oversight.\n Chain context tracking: When enabled, the output of API calls executed on your behalf — which may include email bodies, message content, file contents, contact details, and other data returned by third-party APIs — is sent partially or in full to the configured LLM provider to extract structural references such as IDs, email addresses, and phone numbers. Credentials are never sent. Self-hosted users select their own LLM provider and are responsible for reviewing that provider&#x27;s data handling policies. On the cloud service, this processing occurs within Clawvisor&#x27;s Google Cloud infrastructure.\n Task risk assessment: When enabled, task purpose descriptions and authorized action scopes are sent to the configured LLM for risk evaluation. This assessment is advisory and does not guarantee that high-risk tasks will be blocked.","source_url":"https://clawvisor.com/terms","deep_link":"https://clawvisor.com/terms#:~:text=%20The%20intent%20verification,tasks%20will%20be%20blocked.","structural_citation":"§ 13 (AI Feature Disclaimers)"},{"finding_id":"03492c43-f1df-456f-a1ab-5f8290480018","quote":" When you use the Clawvisor cloud service, we collect, store, or use the following data:\n Account data: Email address and bcrypt-hashed password for authentication. If you sign in via SAML SSO, your email address is received from your organization&#x27;s identity provider. \n Authentication session data: We use strictly necessary authentication cookies, including an HttpOnly refresh-token cookie, to keep you signed in and protect account access. These cookies are not used for analytics, advertising, or cross-site tracking. \n Credentials you store: API keys and OAuth tokens you add to the vault, encrypted with AES-256-GCM at rest. \n Agent tokens: Stored as SHA-256 hashes. The raw token is shown once at creation and never stored. Agent tokens may also be issued to third-party applications (such as IDE plugins) through an OAuth 2.1 authorization flow that you explicitly approve. \n OAuth client registrations: When a third-party application connects via OAuth, we store its client name and redirect URIs. Authorization codes are short-lived and deleted after use. \n Chain context facts: When intent verification with chain context is enabled, structural references (such as email addresses, IDs, and phone numbers) may be extracted from API responses and stored temporarily to validate follow-up requests within the same task. These facts are automatically deleted when the task completes, expires, or is revoked. \n Audit logs: Every gateway request is logged with the service, action, sanitized parameters, decision, and outcome. ","source_url":"https://clawvisor.com/privacy","deep_link":"https://clawvisor.com/privacy#:~:text=%20When%20you%20use,decision%2C%20and%20outcome.%20","structural_citation":"§ 2 (Cloud Service — Data We Collect)"},{"finding_id":"08b057ce-fbd2-4051-9796-1f58bb81fc25","quote":"For task risk assessment, only the task purpose and authorized actions are sent. When chain context is enabled, the output of API calls executed on your behalf — which may include email bodies, message content, file contents, and other data returned by third-party APIs — is sent partially or in full to the configured LLM provider to extract structural references such as IDs and addresses. Credentials are never sent. On the cloud service, this processing occurs within Clawvisor&#x27;s Google Cloud infrastructure. Self-hosted users select and configure their own LLM provider for these features; data handling is governed by that provider&#x27;s terms. Cloud service: The cloud service uses Anthropic Claude Haiku 4.5 (or newer), Claude Sonnet 4.6 (or newer), and Google Gemini 2.5 Flash-Lite (or newer), hosted on Google Cloud Vertex AI within Clawvisor&#x27;s own GCP project. Google processes this data as a sub-processor under its Cloud Data Processing Addendum. For Clawvisor internal AI features, no user data is sent to Anthropic or any other model provider directly, and no user data is used for model training. Self-hosted: You choose and configure your own LLM provider (Anthropic, OpenAI, Ollama, Groq, or Vertex AI). Data handling is governed by your chosen provider&#x27;s terms. \n User-directed LLM proxy traffic: When you configure or use Clawvisor&#x27;s LLM proxy to call OpenAI-compatible, Anthropic-compatible, or other LLM provider endpoints, request and response content is sent to the provider endpoint you configure, select, or instruct Clawvisor to use. ","source_url":"https://clawvisor.com/privacy","deep_link":"https://clawvisor.com/privacy#:~:text=For%20task%20risk%20assessment%2C,Clawvisor%20to%20use.%20","structural_citation":"§ 6 (Third-Party Services)"},{"finding_id":"02c8f968-3ec7-4476-8934-279974a2a228","quote":" Credentials are encrypted at rest with AES-256-GCM. The vault key is stored separately from the database. Passwords are hashed with bcrypt. Agent tokens are stored as one-way hashes. No credentials appear in logs, error messages, or API responses. The cloud service infrastructure is hosted on Google Cloud Platform (GCP).","source_url":"https://clawvisor.com/privacy","deep_link":"https://clawvisor.com/privacy#:~:text=%20Credentials%20are%20encrypted,Google%20Cloud%20Platform%20(GCP).","structural_citation":"§ 8 (Data Security)"}]},{"tier":"Api","surface":"subprocessors_data_sharing","verdict":"conditional","confidence":"high","citation_count":1,"citations":[{"finding_id":"4ad1313c-958b-4208-8f6a-c0fea85f78a1","quote":" Clawvisor interacts with third-party services only when you configure it to, whether on the cloud service or a self-hosted instance:\n External APIs (Google, GitHub, Slack, etc.) are called on your behalf when agents make requests. You register your own API credentials with each provider. Data exchanged with these services is subject to their respective privacy policies. \n SAML identity providers: If you configure SAML SSO, authentication requests are sent to your organization&#x27;s identity provider. We store the IdP&#x27;s entity ID, SSO URL, and signing certificate to validate responses. Your email address is extracted from the SAML assertion. \n Telegram is used for approval notifications if you configure a bot. Message content includes service names, actions, and truncated parameters. \n Resend is used for email verification on the cloud service. Your email address is shared with Resend to deliver verification messages. \n Cloud relay and push: Local daemon installations connect to the Clawvisor cloud relay by default, and push notifications are enabled when you pair a mobile device. Data handling for these services is described in Section 3a. \n Clawvisor internal AI features: If you enable optional intent verification or task risk assessment, Clawvisor uses AI models to evaluate agent requests. For intent verification, only request metadata (service, action, parameters, and agent-provided reason) is sent to the model. ","source_url":"https://clawvisor.com/privacy","deep_link":"https://clawvisor.com/privacy#:~:text=%20Clawvisor%20interacts%20with,to%20the%20model.%20","structural_citation":"§ 6 (Third-Party Services)"}]},{"tier":"Free","surface":"indemnity_liability","verdict":"improves","confidence":"high","citation_count":2,"citations":[{"finding_id":"79d5ad30-4c3d-484b-a503-5f04fafa45d7","quote":" The Service and the Software are provided \"as is\" without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service or the Software will be uninterrupted, error-free, or that it will prevent all unauthorized agent actions, unsafe LLM requests, unsafe tool calls, provider-policy violations, or undesired model outputs.\n LLM proxy inspection, redaction, rewriting, approval, blocking, and risk classification are best-effort. We do not warrant that proxy mediation will preserve semantic equivalence of modified content, catch every policy issue, prevent provider account suspension or rate limiting, avoid unexpected provider charges, or maintain compatibility with every provider API, model, streaming format, or tool-call format.","source_url":"https://clawvisor.com/terms","deep_link":"https://clawvisor.com/terms#:~:text=%20The%20Service%20and,format%2C%20or%20tool-call%20format.","structural_citation":"§ 10 (No Warranty)"},{"finding_id":"cef31847-a8af-414f-a540-ab653609ed55","quote":" For the cloud service, we use reasonable efforts to maintain availability but do not guarantee uninterrupted or error-free operation. The Service may be temporarily unavailable for scheduled or unscheduled maintenance.\n Clawvisor shall not be liable for any delay or failure to perform resulting from causes beyond its reasonable control, including but not limited to acts of God, natural disasters, pandemic, war, terrorism, labor disputes, government actions, power or internet failures, failures of third-party infrastructure providers (including cloud hosting platforms), or failures, outages, rate limits, account restrictions, billing controls, or suspensions imposed by third-party API or LLM providers.","source_url":"https://clawvisor.com/terms","deep_link":"https://clawvisor.com/terms#:~:text=%20For%20the%20cloud,API%20or%20LLM%20providers.","structural_citation":"§ 8 (Service Availability)"}]},{"tier":"Free","surface":"privacy_data_use","verdict":"improves","confidence":"high","citation_count":1,"citations":[{"finding_id":"35e7cbc2-e595-4315-abd3-bbeb636a83a7","quote":" Our marketing site is hosted on Ploy and uses two privacy-focused, cookie-free analytics tools: Ploy&#x27;s built-in first-party analytics and Plausible Analytics. Neither tool uses cookies or collects personal data, and both are compliant with GDPR, CCPA, and PECR. All data is aggregated and no individual visitors can be identified. Server logs may record IP addresses and request metadata as part of standard web hosting, which are retained for security purposes and automatically purged.\n The hosted application at app.clawvisor.com uses strictly necessary cookies for authentication and security, such as an HttpOnly refresh-token cookie. These cookies are required to provide the Service and are not used for advertising or analytics.","source_url":"https://clawvisor.com/privacy","deep_link":"https://clawvisor.com/privacy#:~:text=%20Our%20marketing%20site,for%20advertising%20or%20analytics.","structural_citation":"§ 5 (Website and Cookies)"}]},{"tier":"Paid","surface":"indemnity_liability","verdict":"conditional","confidence":"high","citation_count":1,"citations":[{"finding_id":"3ec65a86-afbd-42c4-8dd5-a78080b20350","quote":" To the fullest extent permitted by law, Clawvisor, Inc. and its officers, directors, employees, and affiliates shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, revenue, or profits arising from your use of the Service or the Software. This includes damages resulting from actions taken by AI agents, credential exposure, service interruptions, LLM proxy misclassification, modified, delayed, blocked, incomplete, or re-emitted outputs, tool-call handling, provider outages, provider rate limits, account suspensions, provider billing issues, or alleged violations of provider terms or policies.\n To the extent permitted by applicable law, Clawvisor&#x27;s total aggregate liability for all claims arising out of or related to the Service or the Software shall not exceed the greater of (a) the amounts you paid to Clawvisor in the twelve (12) months preceding the claim, or (b) one hundred U.S. dollars (US $100).","source_url":"https://clawvisor.com/terms","deep_link":"https://clawvisor.com/terms#:~:text=%20To%20the%20fullest,U.S.%20dollars%20(US%20%24100).","structural_citation":"§ 11 (Limitation of Liability)"}]},{"tier":"Standard","surface":"audit_rights_dpa_residency","verdict":"conditional","confidence":"high","citation_count":1,"citations":[{"finding_id":"c0698f19-b977-484e-a9a0-5bb6125d86f2","quote":" For the cloud service, you may request access to, correction of, or deletion of your personal data by emailing support@clawvisor.com. For self-hosted instances, you have direct access to all your data.\n If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data. Our legal bases for processing are: performance of our contract with you (providing the Service), and legitimate interests (security, fraud prevention, and service improvement). The cloud service infrastructure is hosted in the United States on Google Cloud Platform. Transfers of personal data from the EEA/UK to the United States are governed by Google&#x27;s Data Processing Addendum, which incorporates Standard Contractual Clauses (SCCs) approved by the European Commission. To exercise your rights, contact support@clawvisor.com.","source_url":"https://clawvisor.com/privacy","deep_link":"https://clawvisor.com/privacy#:~:text=%20For%20the%20cloud,your%20rights%2C%20contact%20support%40clawvisor.com.","structural_citation":"§ 9 (Your Rights)"}]}],"disclaimer":"Informational only, not legal advice. Every finding is a verbatim quote from a fully-read, gate-verified document; verify via snapshot_sha256 + wayback_url. Partially-verified platforms show findings only from their verified document(s).","benchmark":{"disclaimer":"Automated assessment against a published rubric — not legal advice.","bands":[]},"@jsonld":{"@context":"https://schema.org","@type":"Dataset","name":"Clawvisor — AI policy risk findings","description":"Verified, cited policy findings for Clawvisor across 13 risk surfaces.","url":"https://airinetwork.com/platform/clawvisor","creator":{"@type":"Organization","name":"AIRIN","url":"https://airinetwork.com"},"isAccessibleForFree":true,"license":"https://airinetwork.com/terms","additionalProperty":[{"@type":"PropertyValue","name":"verification","value":"fully_verified"},{"@type":"PropertyValue","name":"tier_condition_count","value":8}],"hasPart":[{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-f7bdcc8c359cefc21055","text":" When you use Clawvisor's LLM proxy, Clawvisor processes prompts, conversation history, tool definitions, tool calls, tool results, model outputs, streaming chunks, and related request/response content only transiently to provide proxy features such as credential substitution, tool-call inspection, task-scope enforcement, human approval, redaction, rewriting, blocking, and audit logging. Clawvisor does not persist raw LLM request bodies, raw LLM response bodies, or full model streams.\n We may store metadata and redacted audit records, such as provider, model, endpoint, timestamp, status code, streaming flag, tool name, decision, outcome, task ID, agent ID, and sanitized parameters. Redacted audit records are retained as audit logs. Short-lived pending approval state, nonces, and resolver state may be stored temporarily and deleted when the approval, stream, or request no longer needs them. Operational trace/debug logs, when generated, are redacted or sanitized and retained only as needed for service operation, security, support, or compliance, then deleted according to the applicable account deletion or operational log retention process.","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-d2ba87e76f2783ecd647","text":" When you self-host Clawvisor, your credentials, audit logs, agent configurations, and all data processed by your instance remain under your control. The cloud relay is enabled by default for local daemon installations, and push notifications are enabled when you pair a mobile device; connection metadata for these services (described in Section 3a) is processed by Clawvisor's infrastructure. We do not collect telemetry or usage analytics from self-hosted instances unless you explicitly opt in. When enabled, anonymous telemetry includes aggregate event counts (tasks created, gateway requests processed, approvals issued) and is not linked to any user identity or credentials.","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-8226f2897160331c3b8a","text":" Local daemon installations connect to the Clawvisor cloud relay by default. The following data is transmitted to Clawvisor infrastructure:\n Connection metadata: Daemon ID, Ed25519 public key, IP address, and connection/disconnection timestamps. \n Tunnel traffic: All traffic between your daemon and connecting clients is encrypted in transit (TLS). A subset of security-sensitive routes — including agent gateway requests, task management, and connection requests — additionally enforce end-to-end encryption (X25519/HKDF + AES-256-GCM), making their contents unreadable by the relay server. Other routes, including the MCP protocol used by IDE plugins such as Claude Desktop, are protected by TLS in transit but are readable by the relay server. Credentials stored in your local vault are never transmitted through the relay. \n Authentication: The relay stores your daemon's Ed25519 public key for challenge-response authentication. \n When you pair a mobile device, push notifications are enabled. The following is transmitted:\n Device tokens: Required to deliver notifications to your mobile device. \n Notification payloads: Payloads include event type, task purpose, risk level, and action summary. They do not include credentials, API response bodies, or message contents. \n Connection metadata and device tokens are retained while the relay connection or push subscription is active and are deleted upon de-registration or account removal.","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-f21c93d8c10c5ad6a6d2","text":" Cloud service: API credentials you store are encrypted with AES-256-GCM on our infrastructure. Credentials are decrypted only in memory during request execution and are never logged.\n Self-hosted: Credentials are stored encrypted on your infrastructure. We have no access to your credentials, data, or server environment. Credentials are decrypted only in memory during request execution and are never logged.\n Cloud relay: When a daemon connects to the cloud relay, all tunnel traffic is encrypted in transit via TLS. A subset of routes — agent gateway requests, task operations, and connection requests — additionally enforce end-to-end encryption between the client and daemon, making their contents unreadable by the relay. Other routes, including the MCP protocol used by IDE plugins, are protected by TLS only. Credentials stored in the local vault are never transmitted to the relay.","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-6ab8b52e2e2a74727113","text":" When you use the LLM proxy, you authorize Clawvisor to process LLM requests, responses, tool definitions, tool calls, tool results, streaming chunks, and related content as needed to provide proxy features. This processing may include inspecting, buffering, redacting, rewriting, holding for approval, blocking, synthesizing approval prompts or audit summaries, and re-emitting LLM requests, responses, tool calls, and tool results.\n Clawvisor does not persist raw LLM request bodies, raw LLM response bodies, or full model streams when operating the LLM proxy. Raw content is processed in memory or transient buffers only as needed to forward, inspect, redact, rewrite, approve, block, or audit requests and responses. Clawvisor may retain metadata, redacted audit logs, pending approval state, nonces, resolver state, sanitized trace/debug logs, and other operational records needed to provide and secure the service.\n You remain responsible for the LLM providers, accounts, models, endpoints, credentials, prompts, tools, and outputs you configure or authorize through Clawvisor, including any provider terms, usage policies, rate limits, safety systems, account restrictions, and charges that apply.","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-a7397b29fe09fbaa6a6e","text":" The intent verification feature uses a third-party LLM to check whether agent requests are consistent with approved purposes. This check is best-effort and may not catch all misuse. It is not a substitute for careful task scope design and human oversight.\n Chain context tracking: When enabled, the output of API calls executed on your behalf — which may include email bodies, message content, file contents, contact details, and other data returned by third-party APIs — is sent partially or in full to the configured LLM provider to extract structural references such as IDs, email addresses, and phone numbers. Credentials are never sent. Self-hosted users select their own LLM provider and are responsible for reviewing that provider's data handling policies. On the cloud service, this processing occurs within Clawvisor's Google Cloud infrastructure.\n Task risk assessment: When enabled, task purpose descriptions and authorized action scopes are sent to the configured LLM for risk evaluation. This assessment is advisory and does not guarantee that high-risk tasks will be blocked.","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-cb6e2592bb8f825e07c3","text":" Clawvisor, Inc., a Delaware corporation (\"Clawvisor,\" \"we,\" \"us,\" or \"our\"), is the data controller for information collected through the cloud service and the clawvisor.com website. Clawvisor is a credential-vaulting gateway for AI agents, available both as a hosted cloud service at app.clawvisor.com (\"the Service\") and as self-hosted software you run on your own infrastructure (\"the Software\"). This Privacy Policy covers the clawvisor.com website, the cloud service, and describes what data a self-hosted Clawvisor instance processes.","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-d1099cac628307d88456","text":" When you use the Clawvisor cloud service, we collect, store, or use the following data:\n Account data: Email address and bcrypt-hashed password for authentication. If you sign in via SAML SSO, your email address is received from your organization's identity provider. \n Authentication session data: We use strictly necessary authentication cookies, including an HttpOnly refresh-token cookie, to keep you signed in and protect account access. These cookies are not used for analytics, advertising, or cross-site tracking. \n Credentials you store: API keys and OAuth tokens you add to the vault, encrypted with AES-256-GCM at rest. \n Agent tokens: Stored as SHA-256 hashes. The raw token is shown once at creation and never stored. Agent tokens may also be issued to third-party applications (such as IDE plugins) through an OAuth 2.1 authorization flow that you explicitly approve. \n OAuth client registrations: When a third-party application connects via OAuth, we store its client name and redirect URIs. Authorization codes are short-lived and deleted after use. \n Chain context facts: When intent verification with chain context is enabled, structural references (such as email addresses, IDs, and phone numbers) may be extracted from API responses and stored temporarily to validate follow-up requests within the same task. These facts are automatically deleted when the task completes, expires, or is revoked. \n Audit logs: Every gateway request is logged with the service, action, sanitized parameters, decision, and outcome. ","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-30050d7954c0976e80fb","text":"Raw credentials are never included in logs. \n LLM proxy records: Metadata, redacted audit records, short-lived approval state, nonces, resolver state, and operational trace/debug logs related to LLM proxy traffic, as described in Section 2a. Raw LLM request bodies, raw LLM response bodies, and full model streams are not persisted. \n Notification configs: Telegram bot tokens and chat IDs for approval notifications, if configured. ","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-7f6f66fa6f33b8697907","text":" Enforce authorization policies (restrictions, task scopes, approvals, and LLM proxy controls) ","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-7398e50c2801b5d0b147","text":" We do not sell your data or use it for advertising.","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-2455c747966eb6638dac","text":" Our marketing site is hosted on Ploy and uses two privacy-focused, cookie-free analytics tools: Ploy's built-in first-party analytics and Plausible Analytics. Neither tool uses cookies or collects personal data, and both are compliant with GDPR, CCPA, and PECR. All data is aggregated and no individual visitors can be identified. Server logs may record IP addresses and request metadata as part of standard web hosting, which are retained for security purposes and automatically purged.\n The hosted application at app.clawvisor.com uses strictly necessary cookies for authentication and security, such as an HttpOnly refresh-token cookie. These cookies are required to provide the Service and are not used for advertising or analytics.","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-bcfe8e937b591606f9de","text":"For task risk assessment, only the task purpose and authorized actions are sent. When chain context is enabled, the output of API calls executed on your behalf — which may include email bodies, message content, file contents, and other data returned by third-party APIs — is sent partially or in full to the configured LLM provider to extract structural references such as IDs and addresses. Credentials are never sent. On the cloud service, this processing occurs within Clawvisor's Google Cloud infrastructure. Self-hosted users select and configure their own LLM provider for these features; data handling is governed by that provider's terms. Cloud service: The cloud service uses Anthropic Claude Haiku 4.5 (or newer), Claude Sonnet 4.6 (or newer), and Google Gemini 2.5 Flash-Lite (or newer), hosted on Google Cloud Vertex AI within Clawvisor's own GCP project. Google processes this data as a sub-processor under its Cloud Data Processing Addendum. For Clawvisor internal AI features, no user data is sent to Anthropic or any other model provider directly, and no user data is used for model training. Self-hosted: You choose and configure your own LLM provider (Anthropic, OpenAI, Ollama, Groq, or Vertex AI). Data handling is governed by your chosen provider's terms. \n User-directed LLM proxy traffic: When you configure or use Clawvisor's LLM proxy to call OpenAI-compatible, Anthropic-compatible, or other LLM provider endpoints, request and response content is sent to the provider endpoint you configure, select, or instruct Clawvisor to use. ","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-82d099b3e90384e6ecd4","text":" Credentials are encrypted at rest with AES-256-GCM. The vault key is stored separately from the database. Passwords are hashed with bcrypt. Agent tokens are stored as one-way hashes. No credentials appear in logs, error messages, or API responses. The cloud service infrastructure is hosted on Google Cloud Platform (GCP).","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-880843c4479551252d70","text":" Clawvisor is not directed at individuals under the age of 13. We do not knowingly collect personal information from children.","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/privacy-data-use-6e2b5d99e415402e74b6","text":" We may update this Privacy Policy from time to time. For material changes, we will notify you at least thirty (30) days in advance by email or through a prominent notice within the Service. Changes will be posted on this page with an updated date.","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/moderation-enforcement-4f825127c7210f33f40e","text":" You are responsible for all actions taken through your account or instance, including actions initiated by AI agents you configure. \n You are responsible for registering your own credentials with third-party providers, including external API providers (Google, GitHub, Slack, etc.) and LLM providers, and for complying with their terms of service, usage policies, rate limits, safety systems, account restrictions, and billing rules. \n You must not use the Service or the Software to bypass or evade any third-party provider's usage limits, safety systems, authorization model, account restrictions, credential requirements, or access controls. \n Self-hosted: You are responsible for securing your instance, including the vault key, database, and server environment. \n Relay traffic: The cloud relay is enabled by default for local daemon installations. Traffic between your daemon and connecting clients is encrypted in transit (TLS). Certain routes — including agent gateway requests, task management, and connection requests — additionally enforce end-to-end encryption, meaning the relay server cannot read their contents. Other routes, including MCP tool calls and dashboard API requests, are encrypted in transit but are readable by the relay server. Credentials stored in your local vault are never transmitted to the relay. \n Key management: You are responsible for safeguarding your daemon's cryptographic keys (daemon-ed25519.key and daemon-x25519.key). Loss of these keys requires re-pairing your device. \n You must not use the Service or the Software for any unlawful purpose or in violation of any applicable laws. ","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/moderation-enforcement-eda688d40a367287d78f","text":" Local daemon installations connect to the Clawvisor cloud relay by default for remote access. Push notifications are enabled when you pair a mobile device. These services are provided on a best-effort basis. We do not guarantee uptime, availability, or uninterrupted operation of the relay or push services.\n We reserve the right to suspend or revoke relay access for any instance that violates these Terms or engages in abuse, including but not limited to: proxying traffic unrelated to Clawvisor's intended purpose, or generating excessive connection volume.\n The relay is intended solely for tunneling Clawvisor gateway traffic between your daemon and authorized clients. It must not be used as a general-purpose proxy or VPN.","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/data-retention-3b5c71c6b2d0d81940c1","text":" For the cloud service, either party may terminate at any time. We may suspend or terminate your access if you violate these Terms. Upon termination, your data will be permanently purged within thirty (30) days, except where retention is required by applicable law. You may request immediate deletion by contacting support@clawvisor.com.","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/data-retention-ddc337247975228d530f","text":" Cloud service: Your data is retained while your account is active. Upon account deletion, all associated data — including credentials, audit logs, agent configurations, and account information — is permanently purged within thirty (30) days, except where retention is required by applicable law. You may request deletion at any time by contacting support@clawvisor.com.\n Audit logs: Audit logs on the cloud service are retained for the lifetime of your account. You may export or request deletion of your audit history at any time.\n Authentication sessions: Authentication session cookies expire according to the configured session lifetime, and are cleared or invalidated when you log out or when the session is revoked or expires.\n LLM proxy artifacts: Raw LLM request bodies, raw LLM response bodies, and full model streams are not persisted. Redacted audit logs and sanitized operational trace/debug logs may be retained as described in Section 2a. Pending approvals, nonces, resolver state, and similar short-lived proxy state are deleted when no longer needed for the approval, stream, request, or related operational process.\n Self-hosted: You control data retention entirely. Expired sessions, pending approvals, and chain context facts are cleaned up automatically by background processes within your instance.","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/indemnity-liability-08032f281f5818a15c91","text":" The Service and the Software are provided \"as is\" without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service or the Software will be uninterrupted, error-free, or that it will prevent all unauthorized agent actions, unsafe LLM requests, unsafe tool calls, provider-policy violations, or undesired model outputs.\n LLM proxy inspection, redaction, rewriting, approval, blocking, and risk classification are best-effort. We do not warrant that proxy mediation will preserve semantic equivalence of modified content, catch every policy issue, prevent provider account suspension or rate limiting, avoid unexpected provider charges, or maintain compatibility with every provider API, model, streaming format, or tool-call format.","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/indemnity-liability-242388f5560e6cab36cd","text":" For the cloud service, we use reasonable efforts to maintain availability but do not guarantee uninterrupted or error-free operation. The Service may be temporarily unavailable for scheduled or unscheduled maintenance.\n Clawvisor shall not be liable for any delay or failure to perform resulting from causes beyond its reasonable control, including but not limited to acts of God, natural disasters, pandemic, war, terrorism, labor disputes, government actions, power or internet failures, failures of third-party infrastructure providers (including cloud hosting platforms), or failures, outages, rate limits, account restrictions, billing controls, or suspensions imposed by third-party API or LLM providers.","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/indemnity-liability-dec8177e45742b362b1b","text":" To the fullest extent permitted by law, Clawvisor, Inc. and its officers, directors, employees, and affiliates shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, revenue, or profits arising from your use of the Service or the Software. This includes damages resulting from actions taken by AI agents, credential exposure, service interruptions, LLM proxy misclassification, modified, delayed, blocked, incomplete, or re-emitted outputs, tool-call handling, provider outages, provider rate limits, account suspensions, provider billing issues, or alleged violations of provider terms or policies.\n To the extent permitted by applicable law, Clawvisor's total aggregate liability for all claims arising out of or related to the Service or the Software shall not exceed the greater of (a) the amounts you paid to Clawvisor in the twelve (12) months preceding the claim, or (b) one hundred U.S. dollars (US $100).","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/indemnity-liability-68c041b1c56a3a3cf8d9","text":" You agree to indemnify, defend, and hold harmless Clawvisor, Inc. and its officers, directors, employees, and affiliates from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your use of the Service or the Software; (b) actions taken by AI agents you configure, authorize, or approve; (c) your violation of these Terms or any applicable law; (d) your use of third-party API or LLM provider credentials registered with the Service; (e) prompts, tools, tool calls, model outputs, or provider endpoints you configure, authorize, or approve; (f) your violation of third-party provider terms, usage policies, rate limits, safety systems, or account restrictions; or (g) attempts to bypass provider authorization models, safety systems, limits, or access controls.","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/subprocessors-data-sharing-b3c436508f4a2ee5c8b1","text":" Clawvisor interacts with third-party services only when you configure it to, whether on the cloud service or a self-hosted instance:\n External APIs (Google, GitHub, Slack, etc.) are called on your behalf when agents make requests. You register your own API credentials with each provider. Data exchanged with these services is subject to their respective privacy policies. \n SAML identity providers: If you configure SAML SSO, authentication requests are sent to your organization's identity provider. We store the IdP's entity ID, SSO URL, and signing certificate to validate responses. Your email address is extracted from the SAML assertion. \n Telegram is used for approval notifications if you configure a bot. Message content includes service names, actions, and truncated parameters. \n Resend is used for email verification on the cloud service. Your email address is shared with Resend to deliver verification messages. \n Cloud relay and push: Local daemon installations connect to the Clawvisor cloud relay by default, and push notifications are enabled when you pair a mobile device. Data handling for these services is described in Section 3a. \n Clawvisor internal AI features: If you enable optional intent verification or task risk assessment, Clawvisor uses AI models to evaluate agent requests. For intent verification, only request metadata (service, action, parameters, and agent-provided reason) is sent to the model. ","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/subprocessors-data-sharing-2d93f57528e0fac419e4","text":"This includes prompts, conversation history, tool definitions, tool calls, tool results, model outputs, and streaming chunks as needed to provide the proxy. Clawvisor's non-persistence promise for raw LLM request bodies, raw LLM response bodies, and full model streams is described in Section 2a. The provider's handling of data after it receives proxy traffic is governed by that provider's privacy terms, data processing terms, and account settings. ","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/subprocessors-data-sharing-4c9cd588ea96dd19bb78","text":" The cloud service uses the following sub-processors to deliver the Service:\n Google Cloud Platform — Cloud infrastructure and data processing. \n Resend — Email delivery. \n Telegram — Notification delivery. \n Ploy — Marketing website hosting and analytics. \n Plausible Analytics — Website analytics. ","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/audit-rights-dpa-residency-44b7fa97d099793bb05c","text":" For the cloud service, you may request access to, correction of, or deletion of your personal data by emailing support@clawvisor.com. For self-hosted instances, you have direct access to all your data.\n If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data. Our legal bases for processing are: performance of our contract with you (providing the Service), and legitimate interests (security, fraud prevention, and service improvement). The cloud service infrastructure is hosted in the United States on Google Cloud Platform. Transfers of personal data from the EEA/UK to the United States are governed by Google's Data Processing Addendum, which incorporates Standard Contractual Clauses (SCCs) approved by the European Commission. To exercise your rights, contact support@clawvisor.com.","isBasedOn":"https://clawvisor.com/privacy","dateCreated":"2026-07-20T00:01:37.788161+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/governing-law-disputes-b69c82cc414f36452407","text":" These Terms of Service (\"Terms\") are a legal agreement between you and Clawvisor, Inc., a Delaware corporation (\"Clawvisor,\" \"we,\" \"us,\" or \"our\"). By accessing or using the Clawvisor cloud service (\"the Service\") or the Clawvisor self-hosted software (\"the Software\"), you agree to be bound by these Terms. If you do not agree, do not use the Service or the Software.","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/governing-law-disputes-f7485d976d914876f614","text":" These Terms are governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-law provisions. Any disputes arising out of or related to these Terms or the Service shall be resolved exclusively in the state or federal courts located in Delaware. You consent to personal jurisdiction in those courts.","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/clawvisor/finding/governing-law-disputes-4872d3e20df716bd41ac","text":" We may update these Terms from time to time. For material changes, we will notify you at least thirty (30) days in advance by email or through a prominent notice within the Service. Changes will be posted on this page with an updated date. Continued use of the Service or the Software after the effective date of revised Terms constitutes acceptance of those Terms.","isBasedOn":"https://clawvisor.com/terms","dateCreated":"2026-07-20T00:01:38.55246+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"}}],"variableMeasured":[{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" When you use Clawvisor's LLM proxy, Clawvisor processes prompts, conversation history, tool definitions, tool calls, tool results, model outputs, streaming chunks, and related request/response content only transiently to provide proxy features such as credential substitution, tool-call inspection, task-scope enforcement, human approval, redaction, rewriting, blocking, and audit logging. Clawvisor does not persist raw LLM request bodies, raw LLM response bodies, or full model streams.\n We may store metadata and redacted audit records, such as provider, model, endpoint, timestamp, status code, streaming flag, tool name, decision, outcome, task ID, agent ID, and sanitized parameters. Redacted audit records are retained as audit logs. Short-lived pending approval state, nonces, and resolver state may be stored temporarily and deleted when the approval, stream, or request no longer needs them. Operational trace/debug logs, when generated, are redacted or sanitized and retained only as needed for service operation, security, support, or compliance, then deleted according to the applicable account deletion or operational log retention process.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “2a. LLM Proxy Data Handling”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20When%20you%20use,operational%20log%20retention%20process."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" When you self-host Clawvisor, your credentials, audit logs, agent configurations, and all data processed by your instance remain under your control. The cloud relay is enabled by default for local daemon installations, and push notifications are enabled when you pair a mobile device; connection metadata for these services (described in Section 3a) is processed by Clawvisor's infrastructure. We do not collect telemetry or usage analytics from self-hosted instances unless you explicitly opt in. When enabled, anonymous telemetry includes aggregate event counts (tasks created, gateway requests processed, approvals issued) and is not linked to any user identity or credentials.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 3 (Self-Hosted Instances)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20When%20you%20self-host,user%20identity%20or%20credentials."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" Local daemon installations connect to the Clawvisor cloud relay by default. The following data is transmitted to Clawvisor infrastructure:\n Connection metadata: Daemon ID, Ed25519 public key, IP address, and connection/disconnection timestamps. \n Tunnel traffic: All traffic between your daemon and connecting clients is encrypted in transit (TLS). A subset of security-sensitive routes — including agent gateway requests, task management, and connection requests — additionally enforce end-to-end encryption (X25519/HKDF + AES-256-GCM), making their contents unreadable by the relay server. Other routes, including the MCP protocol used by IDE plugins such as Claude Desktop, are protected by TLS in transit but are readable by the relay server. Credentials stored in your local vault are never transmitted through the relay. \n Authentication: The relay stores your daemon's Ed25519 public key for challenge-response authentication. \n When you pair a mobile device, push notifications are enabled. The following is transmitted:\n Device tokens: Required to deliver notifications to your mobile device. \n Notification payloads: Payloads include event type, task purpose, risk level, and action summary. They do not include credentials, API response bodies, or message contents. \n Connection metadata and device tokens are retained while the relay connection or push subscription is active and are deleted upon de-registration or account removal.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “3a. Self-Hosted — Cloud Relay and Push Notifications”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20Local%20daemon%20installations,de-registration%20or%20account%20removal."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" Cloud service: API credentials you store are encrypted with AES-256-GCM on our infrastructure. Credentials are decrypted only in memory during request execution and are never logged.\n Self-hosted: Credentials are stored encrypted on your infrastructure. We have no access to your credentials, data, or server environment. Credentials are decrypted only in memory during request execution and are never logged.\n Cloud relay: When a daemon connects to the cloud relay, all tunnel traffic is encrypted in transit via TLS. A subset of routes — agent gateway requests, task operations, and connection requests — additionally enforce end-to-end encryption between the client and daemon, making their contents unreadable by the relay. Other routes, including the MCP protocol used by IDE plugins, are protected by TLS only. Credentials stored in the local vault are never transmitted to the relay.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 5 (Credentials and Security)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20Cloud%20service%3A%20API,transmitted%20to%20the%20relay."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" When you use the LLM proxy, you authorize Clawvisor to process LLM requests, responses, tool definitions, tool calls, tool results, streaming chunks, and related content as needed to provide proxy features. This processing may include inspecting, buffering, redacting, rewriting, holding for approval, blocking, synthesizing approval prompts or audit summaries, and re-emitting LLM requests, responses, tool calls, and tool results.\n Clawvisor does not persist raw LLM request bodies, raw LLM response bodies, or full model streams when operating the LLM proxy. Raw content is processed in memory or transient buffers only as needed to forward, inspect, redact, rewrite, approve, block, or audit requests and responses. Clawvisor may retain metadata, redacted audit logs, pending approval state, nonces, resolver state, sanitized trace/debug logs, and other operational records needed to provide and secure the service.\n You remain responsible for the LLM providers, accounts, models, endpoints, credentials, prompts, tools, and outputs you configure or authorize through Clawvisor, including any provider terms, usage policies, rate limits, safety systems, account restrictions, and charges that apply.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 7 (LLM Proxy Operation)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20When%20you%20use,and%20charges%20that%20apply."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" The intent verification feature uses a third-party LLM to check whether agent requests are consistent with approved purposes. This check is best-effort and may not catch all misuse. It is not a substitute for careful task scope design and human oversight.\n Chain context tracking: When enabled, the output of API calls executed on your behalf — which may include email bodies, message content, file contents, contact details, and other data returned by third-party APIs — is sent partially or in full to the configured LLM provider to extract structural references such as IDs, email addresses, and phone numbers. Credentials are never sent. Self-hosted users select their own LLM provider and are responsible for reviewing that provider's data handling policies. On the cloud service, this processing occurs within Clawvisor's Google Cloud infrastructure.\n Task risk assessment: When enabled, task purpose descriptions and authorized action scopes are sent to the configured LLM for risk evaluation. This assessment is advisory and does not guarantee that high-risk tasks will be blocked.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 13 (AI Feature Disclaimers)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20The%20intent%20verification,tasks%20will%20be%20blocked."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" Clawvisor, Inc., a Delaware corporation (\"Clawvisor,\" \"we,\" \"us,\" or \"our\"), is the data controller for information collected through the cloud service and the clawvisor.com website. Clawvisor is a credential-vaulting gateway for AI agents, available both as a hosted cloud service at app.clawvisor.com (\"the Service\") and as self-hosted software you run on your own infrastructure (\"the Software\"). This Privacy Policy covers the clawvisor.com website, the cloud service, and describes what data a self-hosted Clawvisor instance processes.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 1 (Overview)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20Clawvisor%2C%20Inc.%2C%20a,self-hosted%20Clawvisor%20instance%20processes."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" When you use the Clawvisor cloud service, we collect, store, or use the following data:\n Account data: Email address and bcrypt-hashed password for authentication. If you sign in via SAML SSO, your email address is received from your organization's identity provider. \n Authentication session data: We use strictly necessary authentication cookies, including an HttpOnly refresh-token cookie, to keep you signed in and protect account access. These cookies are not used for analytics, advertising, or cross-site tracking. \n Credentials you store: API keys and OAuth tokens you add to the vault, encrypted with AES-256-GCM at rest. \n Agent tokens: Stored as SHA-256 hashes. The raw token is shown once at creation and never stored. Agent tokens may also be issued to third-party applications (such as IDE plugins) through an OAuth 2.1 authorization flow that you explicitly approve. \n OAuth client registrations: When a third-party application connects via OAuth, we store its client name and redirect URIs. Authorization codes are short-lived and deleted after use. \n Chain context facts: When intent verification with chain context is enabled, structural references (such as email addresses, IDs, and phone numbers) may be extracted from API responses and stored temporarily to validate follow-up requests within the same task. These facts are automatically deleted when the task completes, expires, or is revoked. \n Audit logs: Every gateway request is logged with the service, action, sanitized parameters, decision, and outcome. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 2 (Cloud Service — Data We Collect)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20When%20you%20use,decision%2C%20and%20outcome.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":"Raw credentials are never included in logs. \n LLM proxy records: Metadata, redacted audit records, short-lived approval state, nonces, resolver state, and operational trace/debug logs related to LLM proxy traffic, as described in Section 2a. Raw LLM request bodies, raw LLM response bodies, and full model streams are not persisted. \n Notification configs: Telegram bot tokens and chat IDs for approval notifications, if configured. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 2 (Cloud Service — Data We Collect)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=Raw%20credentials%20are%20never,notifications%2C%20if%20configured.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" Enforce authorization policies (restrictions, task scopes, approvals, and LLM proxy controls) ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Route and mediate user-directed LLM proxy traffic on your behalf”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20Enforce%20authorization%20policies,LLM%20proxy%20controls)%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"low","description":" We do not sell your data or use it for advertising.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Generate audit logs for your review”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20We%20do%20not,use%20it%20for%20advertising."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" Our marketing site is hosted on Ploy and uses two privacy-focused, cookie-free analytics tools: Ploy's built-in first-party analytics and Plausible Analytics. Neither tool uses cookies or collects personal data, and both are compliant with GDPR, CCPA, and PECR. All data is aggregated and no individual visitors can be identified. Server logs may record IP addresses and request metadata as part of standard web hosting, which are retained for security purposes and automatically purged.\n The hosted application at app.clawvisor.com uses strictly necessary cookies for authentication and security, such as an HttpOnly refresh-token cookie. These cookies are required to provide the Service and are not used for advertising or analytics.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 5 (Website and Cookies)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20Our%20marketing%20site,for%20advertising%20or%20analytics."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":"For task risk assessment, only the task purpose and authorized actions are sent. When chain context is enabled, the output of API calls executed on your behalf — which may include email bodies, message content, file contents, and other data returned by third-party APIs — is sent partially or in full to the configured LLM provider to extract structural references such as IDs and addresses. Credentials are never sent. On the cloud service, this processing occurs within Clawvisor's Google Cloud infrastructure. Self-hosted users select and configure their own LLM provider for these features; data handling is governed by that provider's terms. Cloud service: The cloud service uses Anthropic Claude Haiku 4.5 (or newer), Claude Sonnet 4.6 (or newer), and Google Gemini 2.5 Flash-Lite (or newer), hosted on Google Cloud Vertex AI within Clawvisor's own GCP project. Google processes this data as a sub-processor under its Cloud Data Processing Addendum. For Clawvisor internal AI features, no user data is sent to Anthropic or any other model provider directly, and no user data is used for model training. Self-hosted: You choose and configure your own LLM provider (Anthropic, OpenAI, Ollama, Groq, or Vertex AI). Data handling is governed by your chosen provider's terms. \n User-directed LLM proxy traffic: When you configure or use Clawvisor's LLM proxy to call OpenAI-compatible, Anthropic-compatible, or other LLM provider endpoints, request and response content is sent to the provider endpoint you configure, select, or instruct Clawvisor to use. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 6 (Third-Party Services)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=For%20task%20risk%20assessment%2C,Clawvisor%20to%20use.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" Credentials are encrypted at rest with AES-256-GCM. The vault key is stored separately from the database. Passwords are hashed with bcrypt. Agent tokens are stored as one-way hashes. No credentials appear in logs, error messages, or API responses. The cloud service infrastructure is hosted on Google Cloud Platform (GCP).","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 8 (Data Security)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20Credentials%20are%20encrypted,Google%20Cloud%20Platform%20(GCP)."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" Clawvisor is not directed at individuals under the age of 13. We do not knowingly collect personal information from children.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 10 (Children's Privacy)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20Clawvisor%20is%20not,personal%20information%20from%20children."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" We may update this Privacy Policy from time to time. For material changes, we will notify you at least thirty (30) days in advance by email or through a prominent notice within the Service. Changes will be posted on this page with an updated date.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 12 (Changes to This Policy)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20We%20may%20update,with%20an%20updated%20date."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"moderation_enforcement","value":"unknown","description":" You are responsible for all actions taken through your account or instance, including actions initiated by AI agents you configure. \n You are responsible for registering your own credentials with third-party providers, including external API providers (Google, GitHub, Slack, etc.) and LLM providers, and for complying with their terms of service, usage policies, rate limits, safety systems, account restrictions, and billing rules. \n You must not use the Service or the Software to bypass or evade any third-party provider's usage limits, safety systems, authorization model, account restrictions, credential requirements, or access controls. \n Self-hosted: You are responsible for securing your instance, including the vault key, database, and server environment. \n Relay traffic: The cloud relay is enabled by default for local daemon installations. Traffic between your daemon and connecting clients is encrypted in transit (TLS). Certain routes — including agent gateway requests, task management, and connection requests — additionally enforce end-to-end encryption, meaning the relay server cannot read their contents. Other routes, including MCP tool calls and dashboard API requests, are encrypted in transit but are readable by the relay server. Credentials stored in your local vault are never transmitted to the relay. \n Key management: You are responsible for safeguarding your daemon's cryptographic keys (daemon-ed25519.key and daemon-x25519.key). Loss of these keys requires re-pairing your device. \n You must not use the Service or the Software for any unlawful purpose or in violation of any applicable laws. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 4 (Your Responsibilities)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20You%20are%20responsible,any%20applicable%20laws.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]},{"@type":"PropertyValue","name":"moderation_enforcement","value":"medium","description":" Local daemon installations connect to the Clawvisor cloud relay by default for remote access. Push notifications are enabled when you pair a mobile device. These services are provided on a best-effort basis. We do not guarantee uptime, availability, or uninterrupted operation of the relay or push services.\n We reserve the right to suspend or revoke relay access for any instance that violates these Terms or engages in abuse, including but not limited to: proxying traffic unrelated to Clawvisor's intended purpose, or generating excessive connection volume.\n The relay is intended solely for tunneling Clawvisor gateway traffic between your daemon and authorized clients. It must not be used as a general-purpose proxy or VPN.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 6 (Cloud Relay and Push Notifications)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20Local%20daemon%20installations,general-purpose%20proxy%20or%20VPN."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]},{"@type":"PropertyValue","name":"data_retention","value":"unknown","description":" For the cloud service, either party may terminate at any time. We may suspend or terminate your access if you violate these Terms. Upon termination, your data will be permanently purged within thirty (30) days, except where retention is required by applicable law. You may request immediate deletion by contacting support@clawvisor.com.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 9 (Termination)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20For%20the%20cloud,deletion%20by%20contacting%20support%40clawvisor.com."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]},{"@type":"PropertyValue","name":"data_retention","value":"unknown","description":" Cloud service: Your data is retained while your account is active. Upon account deletion, all associated data — including credentials, audit logs, agent configurations, and account information — is permanently purged within thirty (30) days, except where retention is required by applicable law. You may request deletion at any time by contacting support@clawvisor.com.\n Audit logs: Audit logs on the cloud service are retained for the lifetime of your account. You may export or request deletion of your audit history at any time.\n Authentication sessions: Authentication session cookies expire according to the configured session lifetime, and are cleared or invalidated when you log out or when the session is revoked or expires.\n LLM proxy artifacts: Raw LLM request bodies, raw LLM response bodies, and full model streams are not persisted. Redacted audit logs and sanitized operational trace/debug logs may be retained as described in Section 2a. Pending approvals, nonces, resolver state, and similar short-lived proxy state are deleted when no longer needed for the approval, stream, request, or related operational process.\n Self-hosted: You control data retention entirely. Expired sessions, pending approvals, and chain context facts are cleaned up automatically by background processes within your instance.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 7 (Data Retention)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20Cloud%20service%3A%20Your,processes%20within%20your%20instance."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"indemnity_liability","value":"medium","description":" The Service and the Software are provided \"as is\" without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service or the Software will be uninterrupted, error-free, or that it will prevent all unauthorized agent actions, unsafe LLM requests, unsafe tool calls, provider-policy violations, or undesired model outputs.\n LLM proxy inspection, redaction, rewriting, approval, blocking, and risk classification are best-effort. We do not warrant that proxy mediation will preserve semantic equivalence of modified content, catch every policy issue, prevent provider account suspension or rate limiting, avoid unexpected provider charges, or maintain compatibility with every provider API, model, streaming format, or tool-call format.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 10 (No Warranty)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20The%20Service%20and,format%2C%20or%20tool-call%20format."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]},{"@type":"PropertyValue","name":"indemnity_liability","value":"unknown","description":" For the cloud service, we use reasonable efforts to maintain availability but do not guarantee uninterrupted or error-free operation. The Service may be temporarily unavailable for scheduled or unscheduled maintenance.\n Clawvisor shall not be liable for any delay or failure to perform resulting from causes beyond its reasonable control, including but not limited to acts of God, natural disasters, pandemic, war, terrorism, labor disputes, government actions, power or internet failures, failures of third-party infrastructure providers (including cloud hosting platforms), or failures, outages, rate limits, account restrictions, billing controls, or suspensions imposed by third-party API or LLM providers.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 8 (Service Availability)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20For%20the%20cloud,API%20or%20LLM%20providers."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]},{"@type":"PropertyValue","name":"indemnity_liability","value":"unknown","description":" To the fullest extent permitted by law, Clawvisor, Inc. and its officers, directors, employees, and affiliates shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, revenue, or profits arising from your use of the Service or the Software. This includes damages resulting from actions taken by AI agents, credential exposure, service interruptions, LLM proxy misclassification, modified, delayed, blocked, incomplete, or re-emitted outputs, tool-call handling, provider outages, provider rate limits, account suspensions, provider billing issues, or alleged violations of provider terms or policies.\n To the extent permitted by applicable law, Clawvisor's total aggregate liability for all claims arising out of or related to the Service or the Software shall not exceed the greater of (a) the amounts you paid to Clawvisor in the twelve (12) months preceding the claim, or (b) one hundred U.S. dollars (US $100).","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 11 (Limitation of Liability)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20To%20the%20fullest,U.S.%20dollars%20(US%20%24100)."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]},{"@type":"PropertyValue","name":"indemnity_liability","value":"medium","description":" You agree to indemnify, defend, and hold harmless Clawvisor, Inc. and its officers, directors, employees, and affiliates from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your use of the Service or the Software; (b) actions taken by AI agents you configure, authorize, or approve; (c) your violation of these Terms or any applicable law; (d) your use of third-party API or LLM provider credentials registered with the Service; (e) prompts, tools, tool calls, model outputs, or provider endpoints you configure, authorize, or approve; (f) your violation of third-party provider terms, usage policies, rate limits, safety systems, or account restrictions; or (g) attempts to bypass provider authorization models, safety systems, limits, or access controls.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 12 (Indemnification)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20You%20agree%20to,limits%2C%20or%20access%20controls."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]},{"@type":"PropertyValue","name":"subprocessors_data_sharing","value":"unknown","description":" Clawvisor interacts with third-party services only when you configure it to, whether on the cloud service or a self-hosted instance:\n External APIs (Google, GitHub, Slack, etc.) are called on your behalf when agents make requests. You register your own API credentials with each provider. Data exchanged with these services is subject to their respective privacy policies. \n SAML identity providers: If you configure SAML SSO, authentication requests are sent to your organization's identity provider. We store the IdP's entity ID, SSO URL, and signing certificate to validate responses. Your email address is extracted from the SAML assertion. \n Telegram is used for approval notifications if you configure a bot. Message content includes service names, actions, and truncated parameters. \n Resend is used for email verification on the cloud service. Your email address is shared with Resend to deliver verification messages. \n Cloud relay and push: Local daemon installations connect to the Clawvisor cloud relay by default, and push notifications are enabled when you pair a mobile device. Data handling for these services is described in Section 3a. \n Clawvisor internal AI features: If you enable optional intent verification or task risk assessment, Clawvisor uses AI models to evaluate agent requests. For intent verification, only request metadata (service, action, parameters, and agent-provided reason) is sent to the model. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 6 (Third-Party Services)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20Clawvisor%20interacts%20with,to%20the%20model.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"subprocessors_data_sharing","value":"unknown","description":"This includes prompts, conversation history, tool definitions, tool calls, tool results, model outputs, and streaming chunks as needed to provide the proxy. Clawvisor's non-persistence promise for raw LLM request bodies, raw LLM response bodies, and full model streams is described in Section 2a. The provider's handling of data after it receives proxy traffic is governed by that provider's privacy terms, data processing terms, and account settings. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 6 (Third-Party Services)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=This%20includes%20prompts%2C%20conversation,and%20account%20settings.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"subprocessors_data_sharing","value":"unknown","description":" The cloud service uses the following sub-processors to deliver the Service:\n Google Cloud Platform — Cloud infrastructure and data processing. \n Resend — Email delivery. \n Telegram — Notification delivery. \n Ploy — Marketing website hosting and analytics. \n Plausible Analytics — Website analytics. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 11 (Sub-Processors)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20The%20cloud%20service,%E2%80%94%20Website%20analytics.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"audit_rights_dpa_residency","value":"low","description":" For the cloud service, you may request access to, correction of, or deletion of your personal data by emailing support@clawvisor.com. For self-hosted instances, you have direct access to all your data.\n If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data. Our legal bases for processing are: performance of our contract with you (providing the Service), and legitimate interests (security, fraud prevention, and service improvement). The cloud service infrastructure is hosted in the United States on Google Cloud Platform. Transfers of personal data from the EEA/UK to the United States are governed by Google's Data Processing Addendum, which incorporates Standard Contractual Clauses (SCCs) approved by the European Commission. To exercise your rights, contact support@clawvisor.com.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/privacy"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 9 (Your Rights)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/privacy#:~:text=%20For%20the%20cloud,your%20rights%2C%20contact%20support%40clawvisor.com."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:37.788161+00:00"}]},{"@type":"PropertyValue","name":"governing_law_disputes","value":"unknown","description":" These Terms of Service (\"Terms\") are a legal agreement between you and Clawvisor, Inc., a Delaware corporation (\"Clawvisor,\" \"we,\" \"us,\" or \"our\"). By accessing or using the Clawvisor cloud service (\"the Service\") or the Clawvisor self-hosted software (\"the Software\"), you agree to be bound by these Terms. If you do not agree, do not use the Service or the Software.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 1 (Acceptance of Terms)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20These%20Terms%20of,Service%20or%20the%20Software."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]},{"@type":"PropertyValue","name":"governing_law_disputes","value":"medium","description":" These Terms are governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-law provisions. Any disputes arising out of or related to these Terms or the Service shall be resolved exclusively in the state or federal courts located in Delaware. You consent to personal jurisdiction in those courts.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 14 (Governing Law and Disputes)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20These%20Terms%20are,jurisdiction%20in%20those%20courts."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]},{"@type":"PropertyValue","name":"governing_law_disputes","value":"unknown","description":" We may update these Terms from time to time. For material changes, we will notify you at least thirty (30) days in advance by email or through a prominent notice within the Service. Changes will be posted on this page with an updated date. Continued use of the Service or the Software after the effective date of revised Terms constitutes acceptance of those Terms.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"848ed4fc6588bc6519d30f1f2bd9471240b7ef158cfa892647b671743c7ce6c7"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://clawvisor.com/terms"},{"@type":"PropertyValue","name":"structural_citation","value":"§ 15 (Changes to Terms)"},{"@type":"PropertyValue","name":"citation_basis","value":"section_number"},{"@type":"PropertyValue","name":"deep_link","value":"https://clawvisor.com/terms#:~:text=%20We%20may%20update,acceptance%20of%20those%20Terms."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:01:38.55246+00:00"}]}]}}