privacy data use · Privacy Policy
Clawvisor policy finding
“ Local daemon installations connect to the Clawvisor cloud relay by default. The following data is transmitted to Clawvisor infrastructure: Connection metadata: Daemon ID, Ed25519 public key, IP address, and connection/disconnection timestamps. Tunnel traffic: All traffic between your daemon and connecting clients is encrypted in transit (TLS). A subset of security-sensitive routes — including agent gateway requests, task management, and connection requests — additionally enforce end-to-end encryption (X25519/HKDF + AES-256-GCM), making their contents unreadable by the relay server. Other routes, including the MCP protocol used by IDE plugins such as Claude Desktop, are protected by TLS in transit but are readable by the relay server. Credentials stored in your local vault are never transmitted through the relay. Authentication: The relay stores your daemon's Ed25519 public key for challenge-response authentication. When you pair a mobile device, push notifications are enabled. The following is transmitted: Device tokens: Required to deliver notifications to your mobile device. Notification payloads: Payloads include event type, task purpose, risk level, and action summary. They do not include credentials, API response bodies, or message contents. Connection metadata and device tokens are retained while the relay connection or push subscription is active and are deleted upon de-registration or account removal.”
- Document
- Privacy Policy
- Captured
- 2026-07-20
- Location
- Privacy Policy › “3a. Self-Hosted — Cloud Relay and Push Notifications”
- Snapshot SHA-256
- 85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e
Informational only, not legal advice. Terms change; verify the source and capture date.