ClawKraft Privacy Policy

Effective: September 26, 2026

ClawKraft is an agent-execution and project-orchestration service. This policy describes the categories of data ClawKraft processes, why it is used, who may receive it, how long it is retained, and controls available to users.

Data we process

Depending on the features you use, ClawKraft may process account and authentication information; project and repository metadata you explicitly authorize; task, Program, WorkPacket, review, qualification and deployment state; tool/action records needed to operate and audit workflows; usage and cost records; support communications; and preferences such as collective-improvement consent.

Private project content

Private project source code, files, repository contents, infrastructure details, credentials and project-specific execution state are used only to provide the authorized ClawKraft service. ClawKraft does not place private project content into the shared shipped-capability catalog merely because a workflow succeeded.

Credentials and secrets

Raw credentials are handled through protected authorization or secret-broker flows and are not intentionally returned in normal task payloads, tool responses, logs, or public surfaces.

Capability improvement

Private capability discovery may produce reusable methods for the user's own authorized project scope. Optional collective improvement is separate and requires an explicit choice. Collective proposals are designed to contain target-neutral method structure rather than private source code, raw chats, repository names, credentials, private infrastructure identifiers, or project-specific implementation details.

Contribution credits

If a user opts into eligible collective contribution work, ClawKraft may record verified contribution usage and actual metered cost to calculate non-cash ClawKraft access credits under the applicable product policy.

Purposes

We use data to authenticate users, operate authorized workflows, preserve durable work state, qualify and review actions, prevent duplicate or stale work, provide support, measure reliability and usage, calculate eligible access credits, detect abuse, and improve ClawKraft features consistent with the user's settings.

Recipients

Data may be processed by infrastructure and service providers used to operate ClawKraft, and by third-party services the user explicitly connects or directs ClawKraft to use. Data is not intentionally disclosed to unrelated third parties except where required by law or necessary to protect users and the service.

Retention

Durable project, audit, acceptance, billing-credit and security records may be retained while needed to provide the service, preserve project history, meet contractual or legal obligations, resolve disputes, or maintain system integrity. Temporary authorization material and transient execution data are retained only for their operational lifetime where possible.

User controls

Users can control which projects and integrations ClawKraft is authorized to access, can revoke connected credentials, and can change collective-improvement preferences where available. Project access and generated private capabilities remain bounded to authorized scopes.

Security

ClawKraft uses authenticated MCP/OAuth flows, bounded source authority, protected credential handling, durable currentness/acceptance checks, and fail-closed review and deployment controls. No system can guarantee absolute security.

Children

ClawKraft is a developer/work product and is not directed to children.

Changes

Material changes to this policy will be published at this URL with an updated effective date.

Contact

Questions about privacy or data controls can be submitted through the ClawKraft support page.