Privacy Policy
This policy explains what GodotClaw ("we", "us") collects, why, and what we will never do. It is written to be read, not skimmed past. The short version: your project stays on your machine, we never train on your code, and we collect the minimum needed to run the service.
1. What we collect
- Account data. Email address, display name, and authentication identifiers when you create an account or join the waitlist.
- Billing data. Subscription tier, credit balance and payment status. Card details are handled by our payment processor and never touch our servers.
- Usage metadata. Request counts, model routing decisions, credit spend and error diagnostics - so we can show you transparent per-request costs and keep the service reliable.
- Conversations (optional). If you enable cloud sync, conversation history is stored so it can be restored across sessions. If you choose local-first history, it stays on your disk and we store nothing.
2. What we never collect
- Your project files. The GodotClaw server is stateless with respect to your project. It has no access to your disk, shell or editor - it can only ask the local plugin to act, and the plugin acts on your machine.
- Your source code for training. We never train models on your code, your assets, or your conversations. No exceptions, no opt-out buried in settings.
- BYOK prompt content. On bring-your-own-keys or local models, prompts route directly to your provider. We meter request counts for your own limits and analytics - not content.
3. How we use data
To operate the service (routing, credits, restore-on-reopen), to bill you accurately, to debug failures you report, and to email you about your account. We don't sell data, run ads, or share data with third parties beyond the processors listed below.
4. Processors
We use a small set of subprocessors: cloud hosting for the agent server, a payment processor for billing, and model providers you select (on managed plans). Each receives only what it needs to perform its function.
5. Retention & deletion
You can export or permanently wipe any project's conversation history at any time from the dock. Deleting your account removes account, billing and conversation data within 30 days, except records we're legally required to keep.
6. Security
Transport is encrypted end to end. API keys you add are encrypted at rest and never logged. On-prem deployments keep everything - including the agent server - inside your infrastructure.
7. Your rights
Depending on your jurisdiction (GDPR, CCPA and similar), you may have rights to access, correct, export or delete your data. Email privacy@godotclaw.com and we'll handle it - a human reads that inbox.
8. Changes
If this policy changes materially, we'll email account holders before the change takes effect and keep prior versions available on request.