privacy data use · Privacy Policy
Clawvisor policy finding
“ When you use the Clawvisor cloud service, we collect, store, or use the following data: Account data: Email address and bcrypt-hashed password for authentication. If you sign in via SAML SSO, your email address is received from your organization's identity provider. Authentication session data: We use strictly necessary authentication cookies, including an HttpOnly refresh-token cookie, to keep you signed in and protect account access. These cookies are not used for analytics, advertising, or cross-site tracking. Credentials you store: API keys and OAuth tokens you add to the vault, encrypted with AES-256-GCM at rest. Agent tokens: Stored as SHA-256 hashes. The raw token is shown once at creation and never stored. Agent tokens may also be issued to third-party applications (such as IDE plugins) through an OAuth 2.1 authorization flow that you explicitly approve. OAuth client registrations: When a third-party application connects via OAuth, we store its client name and redirect URIs. Authorization codes are short-lived and deleted after use. Chain context facts: When intent verification with chain context is enabled, structural references (such as email addresses, IDs, and phone numbers) may be extracted from API responses and stored temporarily to validate follow-up requests within the same task. These facts are automatically deleted when the task completes, expires, or is revoked. Audit logs: Every gateway request is logged with the service, action, sanitized parameters, decision, and outcome. ”
- Document
- Privacy Policy
- Captured
- 2026-07-20
- Location
- § 2 (Cloud Service — Data We Collect)
- Snapshot SHA-256
- 85c871ad5b3fc409e797c6103f3c76b3f36fe10e5dea7f167798a3fb44c5b55e
Informational only, not legal advice. Terms change; verify the source and capture date.