This policy explains what personal data FreeOpenClaw collects when you visit freeopenclaw.ai or use our hosting service, how we use it, and the choices you have.
FreeOpenClaw (“we”, “us”) operates this independent hosting service and is not affiliated with the OpenClaw project.
1. Information we collect
We collect only what we need to run the service, keep it secure and understand how it is used.
- Account information: your email address. If you sign in with Google, we also receive your name and profile picture from Google. We never receive your Google password.
- Instance records: the name you give your instance, its status, the operations you run (create, start, stop, delete), resource settings and related timestamps.
- Instance contents: OpenClaw's configuration, your conversations and files, and the model API keys you enter in OpenClaw. These stay in your instance's own data space, as described in section 3.
- Technical and security data: IP addresses (including the address used to sign up), approximate country, time zone, browser and device information, a random device identifier stored in your browser, and access and error logs.
- Usage and attribution data: pages you visit, product events such as creating or opening an instance, the site that referred you, and campaign parameters in the link you arrived from.
- Communications: messages you send to support and the delivery status of emails we send you.
2. How we use information
- To provide the service: signing you in, creating and running your instance, and giving you secure access to it.
- To keep the service secure and fair: preventing abuse and duplicate accounts, enforcing usage rules and managing limited hosting capacity.
- To communicate with you: sign-in codes, important service notices and replies to your support requests.
- To understand and improve the product, and to measure which channels bring new users.
- To comply with legal obligations.
If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on these legal bases: performing our contract with you, our legitimate interests in operating and securing the service, your consent for analytics and advertising cookies, and compliance with legal obligations.
3. Your instance and model API keys
- Your OpenClaw configuration, conversations, files and API keys are stored in a data space that belongs to your instance only. We do not sell this content or use it to train models.
- When you open your instance, traffic between your browser and OpenClaw passes through our access gateway. The gateway checks your access and records connection details such as time, instance and result. It does not store the content of your conversations.
- Your instance sends requests directly to the model provider you configure, using your API key. That provider processes the data under its own terms and privacy policy and bills you directly.
- We do not look at the contents of your instance except where needed to operate, secure or troubleshoot the service, when you ask us to, or where the law requires it.
- Stopping an instance keeps its data. Deleting an instance permanently removes its data space. Stored data is not a backup, so keep your own copies of anything important.
4. Cookies and similar technologies
- Essential: your sign-in session, instance access sessions, your language choice, your cookie consent choice and the device identifier used for security.
- Attribution: first-party cookies that remember the page you first landed on, the referring site, campaign parameters and any referral code, so we can tell which channels bring new users.
- Analytics and advertising: PostHog product analytics and, where enabled, Google and X (Twitter) advertising tags. In the European Economic Area and similar regions, these load only after you accept them in the cookie banner.
You can clear or block cookies in your browser. Blocking essential cookies prevents sign-in.
5. Service providers
We use these providers to run the service. They process data on our behalf and only for these purposes. We do not sell personal data.
- Google Cloud: servers, databases, logs and performance traces.
- Cloudflare: network delivery and protection against attacks.
- Email delivery providers such as Resend or SendGrid: sign-in codes and service emails.
- PostHog: product analytics.
- Google: sign-in with Google and, where enabled, advertising measurement.
- X (Twitter): advertising measurement, where enabled.
We may also disclose information when the law requires it, to protect the rights and safety of our users or the service, or as part of a merger or acquisition, in which case this policy continues to apply.
6. Where data is stored
Our servers and your instance run on Google Cloud in the United States. If you use the service from another country, your data is transferred to and processed in the United States. Where required, these transfers rely on safeguards provided by our service providers, such as standard contractual clauses.
7. How long we keep data
- Account information: while your account exists. If you ask us to delete your account, we delete or anonymize it within 30 days, except for records we must keep for legal, security or abuse-prevention reasons.
- Instance data: until you delete the instance, or until we delete it under our Terms of Service after giving notice.
- Records of deleted instances: kept for reference and abuse prevention, without the instance's contents.
- Logs and traces: kept for a limited period, typically about 30 days.
- Database backups: kept for a short period and replaced on a rolling basis.
8. Security
Each instance runs in an isolated sandbox with its own storage. Connections use HTTPS. Instance access links are reusable and have no automatic expiry; anyone with the complete link can manage the instance. Keep these links private. The database stores only hashes of instance access tokens. No method of storage or transmission is completely secure, but we work to protect your data and will notify you of a breach where the law requires it.
9. Your rights and choices
- You can stop or delete your instance at any time in the console.
- Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent.
- To exercise these rights or delete your account, email us from the address linked to your account. We respond within 30 days.
- If you are in the European Economic Area or the United Kingdom, you can also complain to your local data protection authority.
10. Children
The service is not intended for children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the service changes. We will post the new version here with a new date and, for significant changes, notify you by email or on the site before they take effect.
Questions about this page? Email [email protected].