At BetterClaw, we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy outlines the types of information we collect, how we use it, and the choices you have regarding our use of your information across our website, iOS app, and agent services.
By using our services, you agree to the collection and use of information as described in this Privacy Policy.
1. Information We Collect
We collect several types of information to provide and improve our services to you:
1.1 Personal Information
When you use our AI agent infrastructure services, we may collect:
- Contact Information: Such as your name, email address, and phone number.
- Payment Information: Billing details, including credit card numbers, for processing transactions securely.
- Agent Configuration Data: Any agent configurations, skill definitions, and channel integrations that you set up through our platform.
- Content You Provide: Messages you send to your agents, photos, documents and other files you attach, and instructions, memories and settings you give your agents.
- Connected Account Data: When you connect a service (for example Gmail, Google Calendar or Search Console), the data your agents read from it while carrying out your requests.
1.2 Usage Information
We collect information about how you interact with our platform, including:
- IP address and browser type.
- Pages you visit and actions you take on the platform.
- Device information such as operating system and browser settings.
- Agent usage metrics and performance data.
In our iOS app, usage analytics are optional and can be turned off in Settings › Privacy & storage. When they are on, we record event types, counts, durations and on/off settings, such as sessions started, messages sent and notifications opened, linked to your account. We never include message content in these analytics. We use PostHog to process them and to help us understand usage and improve the app. We also receive crash and hang counts, without message content or file names, to monitor reliability.
1.3 Mobile App Information
When you use the BetterClaw iOS app, we also collect:
- Device and app details: device name and model, iOS version, app version, and an app installation identifier.
- A push notification token (through Apple Push Notification service) and your notification preferences.
- If usage analytics is turned on, the events described in Section 1.2.
The app accesses your camera or photo library only when you choose to attach a photo. Recent conversations and downloaded attachments are stored on your device, protected by iOS data protection. You can clear them from Settings › Privacy & storage. Clearing local data removes these copies from your device; it does not delete your cloud history.
1.4 How We Collect Information
We collect information:
- Directly from you, when you create an account, set up agents, send messages or upload files.
- Automatically, when you use our website and apps.
- From services you connect, with your authorization, such as Google through OAuth.
- From our payment and partner providers, such as Stripe and AppSumo.
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 To Provide Our Services
- Provision and manage your AI agent deployments.
- Securely store and manage your agent credentials and API keys.
- Process your messages, attachments, connected account data, instructions and memories to generate responses and carry out the requests, schedules and workflows you set up.
- Generate conversation titles and maintain your agent's long-term memory, as described in Section 3.2.
- Customize and improve your experience on our platform.
2.2 To Communicate with You
- Send updates on your account, service changes, or new features.
- Respond to your inquiries and provide customer support.
- Deliver push notifications according to your notification preferences.
2.3 For Marketing Purposes
With your consent, we may use your contact information to send promotional offers or product updates. You can opt out of marketing communications at any time by following the unsubscribe instructions provided in the emails.
2.4 For Security and Legal Purposes
- To protect our platform, business, and users from fraud, malicious activity, and unauthorized access.
- To comply with legal obligations and protect our legal rights.
3. How We Share Your Information
We do not sell or rent your personal information to third parties. However, we may share your information with trusted third parties as described below:
3.1 Service Providers
We use third-party service providers to facilitate our services, such as:
- Stripe: To process payments securely.
- Clerk: To provide sign-in and account authentication.
- Railway: To provide cloud infrastructure for our services.
- Fly.io: To host and operate agent runtimes and process the data needed to run your agents in sandboxed environments.
- Cloudflare R2: To store uploaded files and attachments.
- Google Cloud KMS: To protect the encryption keys used to secure your credentials.
- Loops: To send account and service emails.
- Help Scout: To provide customer support.
- Integration Providers: Composio, which brokers OAuth connections and API calls to third-party services on our behalf.
- PostHog: To process usage analytics.
- Google Tag Manager: For website analytics and marketing.
- Apple Push Notification service: To deliver notifications to your iOS device.
- Google Firebase Cloud Messaging: To deliver push notifications to our iOS app.
- AI Model Providers: To generate responses, carry out your requests, name conversations and maintain agent memory. See Section 3.2 for the information shared, the providers involved and how they use it.
All service providers are contractually required to use your information only to provide services to BetterClaw, and to protect it to the same or an equal standard as described in this Privacy Policy.
The current list of our sub-processors, with their purposes and locations, is on our Sub-processors page. If you use BetterClaw for your business, our Data Processing Addendum describes how we process personal data in your workspace on your behalf.
3.2 Third-Party AI Model Providers
BetterClaw agents are powered by large language models run by third-party AI model providers. When you use an agent, whether on the web, in our iOS app, or through a schedule or workflow, we send the information needed to answer your request to the AI model provider that runs that agent.
What is sent:
- Your messages and the conversation history.
- Photos, documents and other files you attach.
- Content your agent reads from accounts you have connected while working on your request.
- Your agent's instructions and relevant saved memories.
Who receives it:
- BetterClaw-managed models:OpenRouter, which routes each request to the provider of the model your agent uses, for example Z.ai, Moonshot AI, Anthropic, OpenAI or Google.
- Your own key or account: The provider you chose, for example Anthropic, OpenAI (including Sign in with ChatGPT) or Google Gemini. The data is sent under your account with that provider and is governed by your agreement with them.
BetterClaw background features apply whichever model your agent uses:
- Conversation titles: To name your conversations, we send the first message of each conversation, shortened when necessary, to OpenRouter, which processes it with an OpenAI model.
- Long-term memory: To maintain and retrieve your agent's memories, conversation content is processed by OpenAI under BetterClaw's account.
You can see the model each agent uses in its settings on the web, or in Settings › Agents in the iOS app.
How it is used: We send this content to provide the response or action you requested and the conversation title and memory features described above. We do not use your content to train AI models. Our agreement with OpenRouter prohibits using submitted data for model training. OpenAI's business terms prohibit using customer content to develop or improve its services without explicit agreement. We do not opt in to that use.
Protection: We share data only with AI model providers bound by terms that protect your data to the same or an equal standard as this Privacy Policy.
3.3 Legal Requirements
We may disclose your personal information if required by law or in response to valid legal requests, including court orders or government regulations. Where a public authority requests personal data we process on behalf of a business customer, we will, unless legally prohibited, notify that customer, try to redirect the authority to them, challenge requests we reasonably consider unlawful, and disclose only the minimum required, as set out in our Data Processing Addendum.
3.4 International Transfers
BetterClaw is operated by BitQit Private Limited, which is established in India. We and our sub-processors may process your information in India, the United States, and the other locations listed on our Sub-processors page. Where the law requires it, we protect these transfers with an appropriate safeguard, such as the European Commission’s Standard Contractual Clauses.
4. Data Retention
- We do not use your agent data, conversations, credentials, or configurations to train AI models, sell to third parties, build advertising profiles, or for any purpose beyond running your agent. Period.
- Any license you grant BetterClaw to process your data is limited solely to operating and delivering the agent infrastructure service.
- Your agent configurations and logs are retained as per your subscription plan to enable you to access historical data and analytics.
- Conversations: Your conversation history is stored in your workspace, subject to your plan's retention limits and your deletion choices. Chat history and agent memory are kept for the retention period of your plan, as published on our pricing page. Older chat history may be archived according to your plan.
- Attachments: Files you upload are stored to make them available in your workspace and to your agents. You can delete files or request their deletion by contacting us.
- Account deletion: Deleting your account starts the removal of your owned workspaces and agent resources, cancels active subscriptions, and revokes sign-in and device access. We retain an account record marked as deleted for audit purposes. We delete the content in your workspaces from our production systems within 30 days, and copies in backups are deleted in the ordinary course of backup rotation, and in any event within 90 days.
- Google user data is subject to its own retention and deletion terms, set out in Section 10.4.
- API keys and OAuth tokens are AES-256 encrypted and auto-purge from agent memory after 5 minutes.
- You may delete your agents, configurations, or data at any time directly from your account.
- You retain full ownership and intellectual property rights over all data and content processed through your agents.
5. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction to any inaccurate information.
- Deletion: Request the deletion of your personal data from our systems.
- Opt-Out: Opt out of marketing communications at any time.
- Withdraw Analytics Consent: Turn off usage analytics in the iOS app under Settings › Privacy & storage.
- Account Deletion: Delete your account from your web account settings, open Settings › Privacy & storage › Delete account in the iOS app to reach those settings, or contact us. See Section 4 for retention details.
To exercise these rights, please contact us at hello@betterclaw.io.
If your personal data is in a workspace that a BetterClaw customer controls, such as your employer or a business you correspond with, that customer is responsible for your data. We will direct your request to them, as described in our Data Processing Addendum.
6. Security
We take security seriously. All agent runtimes operate in Docker-sandboxed environments with encrypted credential storage (AES-256), workspace scoping, and gateway pairing. Credentials auto-purge from agent memory after 5 minutes. Every credential access is logged in your dashboard with full context: which key, which agent, which skill, when, and whether the access was granted or denied. We use industry-standard measures to protect your information from unauthorized access, disclosure, or destruction.
Despite these efforts, no method of transmission over the Internet or electronic storage is completely secure. Therefore, while we strive to protect your personal information, we cannot guarantee its absolute security.
7. Children's Privacy
Our services are not intended for individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a minor, please contact us immediately, and we will take steps to delete such information.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page, and we will notify you via email or other methods if there are any significant changes. Please review this Privacy Policy periodically for any updates.
9. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
Alternatively, you can send us postal mail at:
BitQit Private Limited
475 - 476, Vegas Towers
Sector 14, Dwarka
New Delhi - 110078
10. Google User Data
When you connect a Google account to BetterClaw via OAuth, we access, use, store, and share Google user data only as described in this section.
10.1 What we collect
With your explicit consent during OAuth, BetterClaw may request access to:
- Your Google account profile and email address, for account identification.
- Google Calendar events and calendar metadata, when you connect Google Calendar — used to read your existing events, create events on your behalf, and update or delete events you ask BetterClaw to manage.
- Google Search Console data (sites, search analytics, sitemaps, URL inspection results), when you connect Google Search Console — used to read data for sites you have already verified ownership of in Search Console.
- Google Ads account and campaign performance data, when you connect Google Ads — used to read account structure, campaigns, ad groups, ads, keywords, search terms, assets, targeting, and associated performance metrics for accounts you already have access to in Google Ads.
We only request the OAuth scopes required for the features you choose to use.
Google does not publish a read-only scope for the Google Ads API. The single scope we request (https://www.googleapis.com/auth/adwords) technically permits both reading and writing. BetterClaw uses it for reading only. Our application calls GoogleAdsService.Search, GoogleAdsService.SearchStream, and CustomerService.ListAccessibleCustomers exclusively. We do not create, modify, pause, or delete any campaign, ad, keyword, budget, audience, or conversion action, and no write method is reachable from our application code.
10.2 How we use it
Google user data is used solely to power user-initiated features inside BetterClaw. Specifically, we use it to:
- Display your data inside the BetterClaw interface (for example, an integrated agenda or a Search Console performance view).
- Perform actions you explicitly request, such as creating, updating, or deleting calendar events.
- Maintain authentication state so you do not have to re-authorize on every action.
We do not use Google user data for advertising, profiling, building user databases, training generative AI models, or any purpose unrelated to the feature you invoked.
For Google Ads specifically, we use the data to generate performance analysis and written recommendations inside BetterClaw — for example, period-over-period comparisons, spend and conversion trends, and identification of underperforming campaigns or wasted spend. All recommendations are advisory. Any change to your Google Ads account is made by you, in Google Ads. BetterClaw never executes it.
10.3 How we share it
Google user data is processed by:
- Our infrastructure providers described in Section 3.1: Railway for cloud infrastructure, Fly.io for agent processing, Cloudflare R2 for files stored in your workspace, and Google Cloud KMS for protecting encryption keys.
- Composio, which brokers OAuth connections and API calls to Google services on our behalf.
AI model providers. BetterClaw's analysis features are produced by large language models. Where you invoke a feature that analyses Google user data — such as a Google Ads performance review — the relevant data is sent to an AI model provider to generate that specific response. Other background processing is described in Section 3.2.
Depending on how your workspace is configured, one of two paths applies:
- Your own key (BYOK). You choose the AI model provider, supply the API key, and contract and pay that provider directly. Data is sent under your own account with that provider and is governed by your agreement with them.
- A BetterClaw-managed key. Where you use a managed key, BetterClaw sends the data to the model provider under our own account. In this case our sub-processor for AI inference is OpenRouter, which routes the request to the underlying model provider on our behalf. We contract with OpenRouter on terms that prohibit the use of submitted data for training AI models.
You can see which path applies to your workspace, and switch to your own key at any time, from your BetterClaw settings.
Google user data is not shared with any other third party. We do not use Google user data to train any AI model, and we do not permit our providers to do so.
10.4 How we retain and delete it
- Google OAuth access tokens and refresh tokens are encrypted at rest using AES-256 and are isolated per customer.
- Access tokens are short-lived and purge from active agent memory five minutes after use. Refresh tokens are retained only for as long as your connection remains active, so that scheduled features continue to work without repeated re-authorisation.
- Tokens are revoked and deleted when you disconnect the Google account from BetterClaw or delete your BetterClaw account.
- Google Ads data we retrieve is cached in storage isolated to your workspace so that period-over-period analysis is possible without repeatedly re-querying the Google Ads API. This cached data is retained for 30 days and then automatically purged. You may delete it earlier at any time from your account.
- Google Calendar and Search Console data is processed in memory to render your view and is not retained beyond the request.
- On disconnection or account deletion, all cached Google user data is purged within 30 days.
10.5 Revoking access
You can disconnect your Google account from BetterClaw at any time from the BetterClaw settings page. You can also revoke BetterClaw's access directly from your Google Account permissions page.
Disconnecting a Google account also deletes the associated cached Google user data described in Section 10.4.
10.6 Limited Use compliance
BetterClaw's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
