Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · clawvisor.com

Clawvisor

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-08-24
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

31 verified findings7 policy surfaces2/2 core docs verified
Risk triage

Watch: Moderation and enforcement

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
4
medium
2
low
2/2
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Clawvisor's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Fully verifiedWorkflow & Automation

Fully verified — complete core corpus captured and read in full.

Document status
  • Privacy Policy
    Verified - read in full - 18 citationsstaticLast captured 2026-08-24
  • Terms of Service
    Verified - read in full - 13 citationsLast captured 2026-07-20
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Describes the specific connection metadata transmitted from self-hosted instances to Clawvisor infrastructure, specifies end-to-end encryption for security-sensitive routes making their contents unreadable by the relay server — defines data flows and technical safeguards for self-hosted relay traffic.

" Local daemon installations connect to the Clawvisor cloud relay by default. The following data is transmitted to Clawvisor infrastructure: Connection metadata: Daemon ID, Ed25519 public key, IP address, and connection/disconnection timest..."
📍 Privacy Policy › “3a. Self-Hosted — Cloud Relay and Push Notifications”Jump to exact text →
plan language
Privacy & data use

Describes the technical security measures applied to credentials in both cloud and self-hosted deployments (AES-256-GCM encryption, in-memory-only decryption, no logging), states that Clawvisor has no access to credentials, data, or server environment in the self-hosted model, and describes TLS encryption for relay tunnel traffic; these statements define protective data-handling obligations and access restrictions that are user-favorable.

" Cloud service: API credentials you store are encrypted with AES-256-GCM on our infrastructure. Credentials are decrypted only in memory during request execution and are never logged. Self-hosted: Credentials are stored encrypted on your i..."
📍 § 5 (Credentials and Security)Jump to exact text →
plan language
Privacy & data use

Discloses that the intent verification feature sends agent requests to a third-party LLM and that chain context tracking, when enabled, sends API call outputs (which may include email bodies, message content, file contents, contact details, and other third-party API data) partially or in full to the configured LLM provider to extract structural references; also disclaims that these features are best-effort and not substitutes for human oversight.

" The intent verification feature uses a third-party LLM to check whether agent requests are consistent with approved purposes. This check is best-effort and may not catch all misuse. It is not a substitute for careful task scope design and ..."
📍 § 13 (AI Feature Disclaimers)Jump to exact text →
plan language
Privacy & data use

Enumerates the categories of personal data collected in the cloud service (account data, authentication session data, stored credentials) and specifies how authentication cookies are used, expressly restricting their use to authentication only and prohibiting use for analytics, advertising, or cross-site tracking — user-favorable restriction on cookie use scope.

" When you use the Clawvisor cloud service, we collect, store, or use the following data: Account data: Email address and bcrypt-hashed password for authentication. If you sign in via SAML SSO, your email address is received from your organ..."
📍 § 2 (Cloud Service — Data We Collect)Jump to exact text →
plan language
Privacy & data use

Describes cookie-free, privacy-focused analytics tools that do not collect personal data or identify individuals, restricts the hosted application's cookies to strictly necessary authentication purposes, and states that server log IP addresses are automatically purged — user-favorable restrictions on website data collection and cookie use.

" Our marketing site is hosted on Ploy and uses two privacy-focused, cookie-free analytics tools: Ploy's built-in first-party analytics and Plausible Analytics. Neither tool uses cookies or collects personal data, and both are compliant with..."
📍 § 5 (Website and Cookies)Jump to exact text →
plan language
Privacy & data use

Describes what data is sent to the configured LLM provider for task risk assessment and chain context features (task purpose, authorized actions, and potentially API call outputs including email bodies and file contents), specifies that credentials are never sent, and notes that cloud service processing occurs within Clawvisor's own cloud infrastructure — defines the scope of data shared with LLM providers and includes a user-favorable restriction prohibiting credential transmission.

"For task risk assessment, only the task purpose and authorized actions are sent. When chain context is enabled, the output of API calls executed on your behalf — which may include email bodies, message content, file contents, and other data..."
📍 § 6 (Third-Party Services)Jump to exact text →
plan language
Privacy & data use

Describes mandatory security measures applied to stored credentials and passwords (encryption at rest, separate vault key storage, one-way hashing), and prohibits credentials from appearing in logs, error messages, or API responses — establishes security obligations that protect user data.

" Credentials are encrypted at rest with AES-256-GCM. The vault key is stored separately from the database. Passwords are hashed with bcrypt. Agent tokens are stored as one-way hashes. No credentials appear in logs, error messages, or API re..."
📍 § 8 (Data Security)Jump to exact text →
plan language
Moderation & enforcement

Imposes obligations on the user to comply with third-party providers' terms, usage policies, rate limits, safety systems, account restrictions, and billing rules, and restricts the user from using the service or software to bypass or evade any third-party provider's usage limits, safety systems, authorization model, or account restrictions; establishes user accountability for AI agent actions taken through their account.

" You are responsible for all actions taken through your account or instance, including actions initiated by AI agents you configure. You are responsible for registering your own credentials with third-party providers, including external A..."
📍 § 4 (Your Responsibilities)Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 4
Tier-specific - 0
Total citations - 31
Severity
Surface
Document
Tier
Moderation & enforcement
High
" Local daemon installations connect to the Clawvisor cloud relay by default for remote access. Push notifications are enabled when you pair a mobile device. These services are provided on a best-effort basis. We do not guarantee uptime, availability, or uninterrupted operation of the relay or push services. We reserve the right to suspend or revoke relay access for any instance that violates these Terms or engages in abuse, including but not limited to: proxying traffic unrelated to Clawvisor's intended purpose, or generating excessive connection volume. The relay is intended solely for tunneling Clawvisor gateway traffic between your daemon and authorized clients. It must not be used as a general-purpose proxy or VPN."
§ 6 (Cloud Relay and Push Notifications)Jump to exact text →
Source: Terms of Service- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Reserves the right for Clawvisor to suspend or revoke relay access for instances that violate the Terms or engage in abuse (including proxying unrelated traffic or generating excessive connection volume); restricts use of the relay to its intended purpose and establishes Clawvisor's enforcement right to terminate relay access.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" The Service and the Software are provided "as is" without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service or the Software will be uninterrupted, error-free, or that it will prevent all unauthorized agent actions, unsafe LLM requests, unsafe tool calls, provider-policy violations, or undesired model outputs. LLM proxy inspection, redaction, rewriting, approval, blocking, and risk classification are best-effort. We do not warrant that proxy mediation will preserve semantic equivalence of modified content, catch every policy issue, prevent provider account suspension or rate limiting, avoid unexpected provider charges, or maintain compatibility with every provider API, model, streaming format, or tool-call format."
§ 10 (No Warranty)Jump to exact text →
Source: Terms of Service- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Disclaims all express and implied warranties (including merchantability, fitness for a particular purpose, and non-infringement) and specifically disclaims any warranty that the service will prevent unauthorized agent actions, unsafe LLM requests, unsafe tool calls, provider-policy violations, or undesired model outputs, noting that proxy inspection, redaction, rewriting, approval, blocking, and risk classification are best-effort only.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" You agree to indemnify, defend, and hold harmless Clawvisor, Inc. and its officers, directors, employees, and affiliates from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your use of the Service or the Software; (b) actions taken by AI agents you configure, authorize, or approve; (c) your violation of these Terms or any applicable law; (d) your use of third-party API or LLM provider credentials registered with the Service; (e) prompts, tools, tool calls, model outputs, or provider endpoints you configure, authorize, or approve; (f) your violation of third-party provider terms, usage policies, rate limits, safety systems, or account restrictions; or (g) attempts to bypass provider authorization models, safety systems, limits, or access controls."
§ 12 (Indemnification)Jump to exact text →
Source: Terms of Service- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Obligates the user to indemnify, defend, and hold harmless Clawvisor and its officers, directors, employees, and affiliates against claims, damages, losses, liabilities, costs, and expenses (including attorneys' fees) arising from the user's use of the service or software, actions by AI agents the user configures or approves, violations of the Terms or applicable law, use of third-party credentials registered with the service, and prompts, tool calls, model outputs, or provider endpoints.

AI-generated interpretation, not legal advice.

Governing law & disputes
High
" These Terms are governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-law provisions. Any disputes arising out of or related to these Terms or the Service shall be resolved exclusively in the state or federal courts located in Delaware. You consent to personal jurisdiction in those courts."
§ 14 (Governing Law and Disputes)Jump to exact text →
Source: Terms of Service- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Specifies that the Terms are governed by and construed under the laws of the State of Delaware without regard to conflict-of-law provisions, that disputes must be resolved exclusively in state or federal courts in Delaware, and that the user consents to personal jurisdiction in those courts; establishes the mandatory forum and applicable law for all disputes.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We do not sell your data or use it for advertising."
Privacy Policy › “Generate audit logs for your review”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Expressly prohibits selling user data or using it for advertising — user-favorable restriction on commercial exploitation of personal data.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" When you use Clawvisor's LLM proxy, Clawvisor processes prompts, conversation history, tool definitions, tool calls, tool results, model outputs, streaming chunks, and related request/response content only transiently to provide proxy features such as credential substitution, tool-call inspection, task-scope enforcement, human approval, redaction, rewriting, blocking, and audit logging. Clawvisor does not persist raw LLM request bodies, raw LLM response bodies, or full model streams. We may store metadata and redacted audit records, such as provider, model, endpoint, timestamp, status code, streaming flag, tool name, decision, outcome, task ID, agent ID, and sanitized parameters. Redacted audit records are retained as audit logs. Short-lived pending approval state, nonces, and resolver state may be stored temporarily and deleted when the approval, stream, or request no longer needs them. Operational trace/debug logs, when generated, are redacted or sanitized and retained only as needed for service operation, security, support, or compliance, then deleted according to the applicable account deletion or operational log retention process."
Privacy Policy › “2a. LLM Proxy Data Handling”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines transient processing of prompts, conversation history, tool calls, and model outputs solely to provide proxy features, and expressly prohibits persistence of raw LLM request/response bodies and full model streams — user-favorable restriction limiting how LLM proxy data may be stored and used.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" When you self-host Clawvisor, your credentials, audit logs, agent configurations, and all data processed by your instance remain under your control. The cloud relay is enabled by default for local daemon installations, and push notifications are enabled when you pair a mobile device; connection metadata for these services (described in Section 3a) is processed by Clawvisor's infrastructure. We do not collect telemetry or usage analytics from self-hosted instances unless you explicitly opt in. When enabled, anonymous telemetry includes aggregate event counts (tasks created, gateway requests processed, approvals issued) and is not linked to any user identity or credentials."
§ 3 (Self-Hosted Instances)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States that all data processed by self-hosted instances remains under the user's control and that telemetry is not collected from self-hosted instances unless the user explicitly opts in, restricting Clawvisor's data collection from self-hosted deployments — user-favorable restriction.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"Raw credentials are never included in logs. LLM proxy records: Metadata, redacted audit records, short-lived approval state, nonces, resolver state, and operational trace/debug logs related to LLM proxy traffic, as described in Section 2a. Raw LLM request bodies, raw LLM response bodies, and full model streams are not persisted. Notification configs: Telegram bot tokens and chat IDs for approval notifications, if configured. "
§ 2 (Cloud Service — Data We Collect)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States that raw credentials are never included in logs and that raw LLM request bodies, raw LLM response bodies, and full model streams are not persisted — prohibits persistence of sensitive content, which is user-favorable and restricts the company's data retention practices.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Our marketing site is hosted on Ploy and uses two privacy-focused, cookie-free analytics tools: Ploy's built-in first-party analytics and Plausible Analytics. Neither tool uses cookies or collects personal data, and both are compliant with GDPR, CCPA, and PECR. All data is aggregated and no individual visitors can be identified. Server logs may record IP addresses and request metadata as part of standard web hosting, which are retained for security purposes and automatically purged. The hosted application at app.clawvisor.com uses strictly necessary cookies for authentication and security, such as an HttpOnly refresh-token cookie. These cookies are required to provide the Service and are not used for advertising or analytics."
§ 5 (Website and Cookies)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes cookie-free, privacy-focused analytics tools that do not collect personal data or identify individuals, restricts the hosted application's cookies to strictly necessary authentication purposes, and states that server log IP addresses are automatically purged — user-favorable restrictions on website data collection and cookie use.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Clawvisor is not directed at individuals under the age of 13. We do not knowingly collect personal information from children."
§ 10 (Children's Privacy)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Restricts the service to users aged 13 and above and prohibits knowingly collecting personal information from children — user-favorable restriction protecting minors.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" To the fullest extent permitted by law, Clawvisor, Inc. and its officers, directors, employees, and affiliates shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, revenue, or profits arising from your use of the Service or the Software. This includes damages resulting from actions taken by AI agents, credential exposure, service interruptions, LLM proxy misclassification, modified, delayed, blocked, incomplete, or re-emitted outputs, tool-call handling, provider outages, provider rate limits, account suspensions, provider billing issues, or alleged violations of provider terms or policies. To the extent permitted by applicable law, Clawvisor's total aggregate liability for all claims arising out of or related to the Service or the Software shall not exceed the greater of (a) the amounts you paid to Clawvisor in the twelve (12) months preceding the claim, or (b) one hundred U.S. dollars (US $100)."
§ 11 (Limitation of Liability)Jump to exact text →
Source: Terms of Service- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Limits Clawvisor's liability to the fullest extent permitted by law by excluding indirect, incidental, special, consequential, or punitive damages and any loss of data, revenue, or profits; explicitly covers damages arising from AI agent actions, credential exposure, service interruptions, LLM proxy misclassification, modified or blocked outputs, tool-call handling, provider outages, rate limits, account suspensions, and provider billing issues.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" For the cloud service, you may request access to, correction of, or deletion of your personal data by emailing support@clawvisor.com. For self-hosted instances, you have direct access to all your data. If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data. Our legal bases for processing are: performance of our contract with you (providing the Service), and legitimate interests (security, fraud prevention, and service improvement). The cloud service infrastructure is hosted in the United States on Google Cloud Platform. Transfers of personal data from the EEA/UK to the United States are governed by Google's Data Processing Addendum, which incorporates Standard Contractual Clauses (SCCs) approved by the European Commission. To exercise your rights, contact support@clawvisor.com."
§ 9 (Your Rights)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Grants users the right to request access, correction, and deletion of personal data via a specified contact address for cloud service users, provides self-hosted users direct data access, and enumerates additional rights for users located in the EEA or United Kingdom under the named regulation (GDPR), including access, rectification, erasure, restriction of processing, data portability, and objection — operative rights clause specifying legal bases for processing (contract performance and legitimate interests).

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Local daemon installations connect to the Clawvisor cloud relay by default. The following data is transmitted to Clawvisor infrastructure: Connection metadata: Daemon ID, Ed25519 public key, IP address, and connection/disconnection timestamps. Tunnel traffic: All traffic between your daemon and connecting clients is encrypted in transit (TLS). A subset of security-sensitive routes — including agent gateway requests, task management, and connection requests — additionally enforce end-to-end encryption (X25519/HKDF + AES-256-GCM), making their contents unreadable by the relay server. Other routes, including the MCP protocol used by IDE plugins such as Claude Desktop, are protected by TLS in transit but are readable by the relay server. Credentials stored in your local vault are never transmitted through the relay. Authentication: The relay stores your daemon's Ed25519 public key for challenge-response authentication. When you pair a mobile device, push notifications are enabled. The following is transmitted: Device tokens: Required to deliver notifications to your mobile device. Notification payloads: Payloads include event type, task purpose, risk level, and action summary. They do not include credentials, API response bodies, or message contents. Connection metadata and device tokens are retained while the relay connection or push subscription is active and are deleted upon de-registration or account removal."
Privacy Policy › “3a. Self-Hosted — Cloud Relay and Push Notifications”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes the specific connection metadata transmitted from self-hosted instances to Clawvisor infrastructure, specifies end-to-end encryption for security-sensitive routes making their contents unreadable by the relay server — defines data flows and technical safeguards for self-hosted relay traffic.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Cloud service: API credentials you store are encrypted with AES-256-GCM on our infrastructure. Credentials are decrypted only in memory during request execution and are never logged. Self-hosted: Credentials are stored encrypted on your infrastructure. We have no access to your credentials, data, or server environment. Credentials are decrypted only in memory during request execution and are never logged. Cloud relay: When a daemon connects to the cloud relay, all tunnel traffic is encrypted in transit via TLS. A subset of routes — agent gateway requests, task operations, and connection requests — additionally enforce end-to-end encryption between the client and daemon, making their contents unreadable by the relay. Other routes, including the MCP protocol used by IDE plugins, are protected by TLS only. Credentials stored in the local vault are never transmitted to the relay."
§ 5 (Credentials and Security)Jump to exact text →
Source: Terms of Service- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes the technical security measures applied to credentials in both cloud and self-hosted deployments (AES-256-GCM encryption, in-memory-only decryption, no logging), states that Clawvisor has no access to credentials, data, or server environment in the self-hosted model, and describes TLS encryption for relay tunnel traffic; these statements define protective data-handling obligations and access restrictions that are user-favorable.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" When you use the LLM proxy, you authorize Clawvisor to process LLM requests, responses, tool definitions, tool calls, tool results, streaming chunks, and related content as needed to provide proxy features. This processing may include inspecting, buffering, redacting, rewriting, holding for approval, blocking, synthesizing approval prompts or audit summaries, and re-emitting LLM requests, responses, tool calls, and tool results. Clawvisor does not persist raw LLM request bodies, raw LLM response bodies, or full model streams when operating the LLM proxy. Raw content is processed in memory or transient buffers only as needed to forward, inspect, redact, rewrite, approve, block, or audit requests and responses. Clawvisor may retain metadata, redacted audit logs, pending approval state, nonces, resolver state, sanitized trace/debug logs, and other operational records needed to provide and secure the service. You remain responsible for the LLM providers, accounts, models, endpoints, credentials, prompts, tools, and outputs you configure or authorize through Clawvisor, including any provider terms, usage policies, rate limits, safety systems, account restrictions, and charges that apply."
§ 7 (LLM Proxy Operation)Jump to exact text →
Source: Terms of Service- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

User authorizes Clawvisor to process LLM requests, responses, tool definitions, tool calls, tool results, streaming chunks, and related content as necessary to provide proxy features (including inspecting, buffering, redacting, rewriting, holding for approval, blocking, synthesizing summaries, and re-emitting content); also states that Clawvisor does not persist raw LLM request or response bodies and processes raw content only in memory or transiently, which is a user-favorable protective limitation on data retention.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" The intent verification feature uses a third-party LLM to check whether agent requests are consistent with approved purposes. This check is best-effort and may not catch all misuse. It is not a substitute for careful task scope design and human oversight. Chain context tracking: When enabled, the output of API calls executed on your behalf — which may include email bodies, message content, file contents, contact details, and other data returned by third-party APIs — is sent partially or in full to the configured LLM provider to extract structural references such as IDs, email addresses, and phone numbers. Credentials are never sent. Self-hosted users select their own LLM provider and are responsible for reviewing that provider's data handling policies. On the cloud service, this processing occurs within Clawvisor's Google Cloud infrastructure. Task risk assessment: When enabled, task purpose descriptions and authorized action scopes are sent to the configured LLM for risk evaluation. This assessment is advisory and does not guarantee that high-risk tasks will be blocked."
§ 13 (AI Feature Disclaimers)Jump to exact text →
Source: Terms of Service- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Discloses that the intent verification feature sends agent requests to a third-party LLM and that chain context tracking, when enabled, sends API call outputs (which may include email bodies, message content, file contents, contact details, and other third-party API data) partially or in full to the configured LLM provider to extract structural references; also disclaims that these features are best-effort and not substitutes for human oversight.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Clawvisor, Inc., a Delaware corporation ("Clawvisor," "we," "us," or "our"), is the data controller for information collected through the cloud service and the clawvisor.com website. Clawvisor is a credential-vaulting gateway for AI agents, available both as a hosted cloud service at app.clawvisor.com ("the Service") and as self-hosted software you run on your own infrastructure ("the Software"). This Privacy Policy covers the clawvisor.com website, the cloud service, and describes what data a self-hosted Clawvisor instance processes."
§ 1 (Overview)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the data controller identity, describes the product scope (cloud service and self-hosted software), and establishes the territorial and product scope of the Privacy Policy — foundational definitional clause governing what entities and services this policy covers.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" When you use the Clawvisor cloud service, we collect, store, or use the following data: Account data: Email address and bcrypt-hashed password for authentication. If you sign in via SAML SSO, your email address is received from your organization's identity provider. Authentication session data: We use strictly necessary authentication cookies, including an HttpOnly refresh-token cookie, to keep you signed in and protect account access. These cookies are not used for analytics, advertising, or cross-site tracking. Credentials you store: API keys and OAuth tokens you add to the vault, encrypted with AES-256-GCM at rest. Agent tokens: Stored as SHA-256 hashes. The raw token is shown once at creation and never stored. Agent tokens may also be issued to third-party applications (such as IDE plugins) through an OAuth 2.1 authorization flow that you explicitly approve. OAuth client registrations: When a third-party application connects via OAuth, we store its client name and redirect URIs. Authorization codes are short-lived and deleted after use. Chain context facts: When intent verification with chain context is enabled, structural references (such as email addresses, IDs, and phone numbers) may be extracted from API responses and stored temporarily to validate follow-up requests within the same task. These facts are automatically deleted when the task completes, expires, or is revoked. Audit logs: Every gateway request is logged with the service, action, sanitized parameters, decision, and outcome. "
§ 2 (Cloud Service — Data We Collect)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Enumerates the categories of personal data collected in the cloud service (account data, authentication session data, stored credentials) and specifies how authentication cookies are used, expressly restricting their use to authentication only and prohibiting use for analytics, advertising, or cross-site tracking — user-favorable restriction on cookie use scope.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Clawvisor's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Clawvisor's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Clawvisor's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Clawvisor requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Clawvisor's published policies yet.

What the policies actually cover

0 topics

None of Clawvisor's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

44
clauses
5
patterns
5
stances
legal burden · 2privacy sharing · 2ip ownership · 1
ip ownershipHIGH§ 6 (Cloud Relay and Push Notifications)

The clause appears to reserve or claim ownership rights for the platform.

Local daemon installations connect to the Clawvisor cloud relay by default for remote access. Push notifications are enabled when you pair a mobile device. These services are provided on a best-effort basis. We do not guarantee uptime, availability, or uninterrupted operation of the relay or push services. We reserve the right to suspend or revoke relay access for any instance that violates these Terms or engages ...
Open source citation
legal burdenMEDIUM§ 10 (No Warranty)

The clause limits liability or disclaims warranties.

The Service and the Software are provided "as is" without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service or the Software will be uninterrupted, error-free, or that it will prevent all unauthorized agent actions, unsafe LLM requests, unsafe tool calls, provider-policy vio...
Open source citation
legal burdenMEDIUM§ 12 (Indemnification)

The clause requires defense, indemnity, or hold-harmless obligations.

You agree to indemnify, defend, and hold harmless Clawvisor, Inc. and its officers, directors, employees, and affiliates from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your use of the Service or the Software; (b) actions taken by AI agents you configure, authorize, or approve; (c) your violation of these T...
Open source citation
privacy sharingHIGHPrivacy Policy › “Generate audit logs for your review”

The clause permits sale of personal data or information.

We do not sell your data or use it for advertising.
Open source citation
privacy sharingMEDIUM§ 11 (Limitation of Liability)

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

To the fullest extent permitted by law, Clawvisor, Inc. and its officers, directors, employees, and affiliates shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, revenue, or profits arising from your use of the Service or the Software. This includes damages resulting from actions taken by AI agents, credential exposure, service interruptions, LLM pro...
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersmoderation enforcementworsensHIGH1
All applicable tiersprivacy data useworsensHIGH1
Apiindemnity liabilityconditionalMEDIUM1
Freeindemnity liabilityconditionalMEDIUM1
Pro / Paidindemnity liabilityconditionalMEDIUM1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

We do not sell your data or use it for advertising.
Open timeline citation
Jul 20, 2026content ownershipHIGH

Latest stance: platform claims or reserves rights on moderation enforcement

Local daemon installations connect to the Clawvisor cloud relay by default for remote access. Push notifications are enabled when you pair a mobile device. These services are provided on a best-effort basis. We do not guarantee uptime, availability, or uninterrupted operation of the relay or push services. We reserve the right to suspend or revoke relay access for any instance that violates these Terms or engages in abuse, including but not limited to: proxying traffic unrelated to Clawvisor's intended purpose, or generating excessive connection volume. The relay is intended solely for tunneling Clawvisor gateway traffic between your daemon and authorized clients. It must not be used as a general-purpose proxy or VPN.
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on indemnity liability

To the fullest extent permitted by law, Clawvisor, Inc. and its officers, directors, employees, and affiliates shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, revenue, or profits arising from your use of the Service or the Software. This includes damages resulting from actions taken by AI agents, credential exposure, service interruptions, LLM proxy misclassification, modified, delayed, blocked, incomplete, or re-emitted outputs, tool-call handling, provider outages, provider rate limits, account suspensions, provider billing issues, or alleged violations of provider terms or policies. To the extent permitted by applicable law, Clawvisor's total aggregate liability for all claims arising out of or related to the Service or the Software shall not exceed the greater of (a) the amounts you paid to Clawvisor in the twelve (12) months preceding the claim, or (b) one hundred U.S. dollars (US $100).
Open timeline citation
Jul 20, 2026legal burdenMEDIUM

Latest stance: liability limited on indemnity liability

The Service and the Software are provided "as is" without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service or the Software will be uninterrupted, error-free, or that it will prevent all unauthorized agent actions, unsafe LLM requests, unsafe tool calls, provider-policy violations, or undesired model outputs. LLM proxy inspection, redaction, rewriting, approval, blocking, and risk classification are best-effort. We do not warrant that proxy mediation will preserve semantic equivalence of modified content, catch every policy issue, prevent provider account suspension or rate limiting, avoid unexpected provider charges, or maintain compatibility with every provider API, model, streaming format, or tool-call format.
Open timeline citation
Jul 20, 2026legal burdenMEDIUM

Latest stance: indemnity on indemnity liability

You agree to indemnify, defend, and hold harmless Clawvisor, Inc. and its officers, directors, employees, and affiliates from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your use of the Service or the Software; (b) actions taken by AI agents you configure, authorize, or approve; (c) your violation of these Terms or any applicable law; (d) your use of third-party API or LLM provider credentials registered with the Service; (e) prompts, tools, tool calls, model outputs, or provider endpoints you configure, authorize, or approve; (f) your violation of third-party provider terms, usage policies, rate limits, safety systems, or account restrictions; or (g) attempts to bypass provider authorization models, safety systems, limits, or access controls.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-08-24· verified 2026-08-24
  • Terms of Service:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

44 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Clawvisor's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Every finding above is a verbatim quote from Clawvisor's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.