Privacy Policy

Last updated: February 18, 2026

Pragmatic Identity sp. z o.o., a company registered in Poland (KRS: 0000922559, NIP: 9151819429, REGON: 520003533), with its registered address at ul. Piłkarska 10, 55-114 Malin, Poland ("we", "our", or "us", also referred to as "useclaw.ai") operates the useclaw.ai website and hosted AI agent service ("Service"). This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our Service.

1. Information We Collect

Account Information

When you sign up, we collect your name and email address through our authentication provider (Clerk). If you sign in with Google or Apple, we receive your profile information (name, email, and profile picture where available) as authorized by you.

Payment Information

When you subscribe, your payment is processed by Apple's In-App Purchase system (for iOS app purchases) or other payment platforms as applicable. We do not store your full credit card number or payment method details. We receive from our payment processors: your payment status, subscription status, and transaction history.

Agent Data

Data processed by your AI agent in the course of providing the Service, including:

  • Emails sent and received through your agent's dedicated email address
  • Documents and files you provide to your agent for processing
  • Web search queries performed by your agent
  • Messages exchanged via connected platforms (e.g., Telegram)
  • Agent task logs, including inputs, outputs, and actions taken
  • Telegram account information (username, chat ID) if you connect Telegram to the Service

Usage Data

We automatically collect information about how you access and use the Service, including: IP address, browser type and version, device type, pages visited, time and date of visits, and referring URLs.

2. How We Use Your Information

We use your information for the following purposes:

  • To provide the Service: Operating your AI agent, sending and receiving emails, processing documents, and executing tasks on your behalf
  • To process payments: Managing your subscription and billing through Apple In-App Purchase or other payment platforms
  • To apply security measures: Running input screening, data leak prevention, and agent isolation to protect your data
  • To improve the Service: Analyzing usage patterns to improve reliability, performance, and features (using aggregated, non-personally-identifiable data only)
  • To communicate with you: Sending service-related notices, updates, security alerts, and support messages
  • To comply with law: Responding to legal process, enforcing our Terms, and protecting the rights and safety of our users

We do not use your Agent Data to train AI models, serve advertising, or for any purpose other than providing the Service to you.

3. How We Share Your Information

We share your information only as described below. We do not sell your personal data.

Third-Party AI Model Providers

To power your AI agent, we transmit your Agent Data (including email content, documents, and task instructions) to third-party AI model providers for processing. These providers process your data to generate agent responses and actions. We select providers with data handling practices that align with our commitment to your privacy. Our current AI providers include:

We will update this list if we add or change AI providers. AI model providers are contractually prohibited from using your data to train their models when accessed through our API.

Service Providers

We use the following third-party service providers:

Legal Requirements

We may disclose your information if required to do so by law, in response to valid legal process (such as a subpoena or court order), to protect our rights, or to protect the safety of our users or the public.

Business Transfers

If useclaw.ai is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website before your information becomes subject to a different privacy policy.

4. Data Security

We implement security measures designed to protect your personal data, including:

  • Agent isolation: Each agent runs in its own sandboxed environment, isolated from other users
  • Input screening: Content processed by your agent is scanned for potential prompt injection attacks (Beta feature)
  • Data leak prevention: Outgoing data is checked for sensitive information before being sent to AI providers (Beta feature)
  • Encryption: Data is encrypted in transit (TLS) and at rest
  • Access controls: We limit internal access to user data to authorized personnel who need it to operate the Service

No security system is perfect. While we strive to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials.

5. Data Breach Notification

In the event of a data breach that affects your personal data, we will notify you without undue delay and no later than 72 hours after becoming aware of the breach, as required by applicable law. Notification will be sent to the email address associated with your account and will include: the nature of the breach, the data affected, steps we are taking, and steps you can take to protect yourself.

6. Data Retention

  • Account data: Retained for as long as your account is active, plus 30 days after termination to allow for data export
  • Agent activity logs: Retained for 30 days, then automatically deleted
  • Payment records: Retained as required by tax and financial regulations (typically 7 years)
  • Usage analytics: Retained in aggregated, non-personally-identifiable form

Upon account termination, your agent's dedicated email address is deactivated. Any emails sent to the address after deactivation will be bounced (returned to sender) and will not be stored or forwarded by us.

After the applicable retention period, we delete or anonymize your data unless retention is required by law.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

All Users

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data
  • Export: Request your data in a portable, machine-readable format
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time

European Economic Area (EEA) and United Kingdom Residents — GDPR

If you are located in the EEA or the United Kingdom, our legal basis for processing your data is:

  • Contractual necessity: Processing required to provide the Service you subscribed to (account data, agent data, payment processing)
  • Legitimate interest: Usage analytics and service improvement, fraud prevention, and security
  • Legal obligation: Tax records, compliance with legal process
  • Consent: Where required, such as for optional marketing communications

You additionally have the right to: restrict processing of your data, object to processing based on legitimate interest, lodge a complaint with your local data protection authority, and not be subject to automated decision-making with legal effects (see Section 9). Our lead supervisory authority is the Polish data protection authority: Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw, Poland. UK residents may also lodge complaints with the UK Information Commissioner's Office (ICO).

California Residents — CCPA/CPRA

If you are a California resident, you have the right to:

  • Know what personal information we collect about you and how it is used and shared
  • Delete your personal information, subject to certain exceptions
  • Opt out of the sale or sharing of personal information — we do not sell or share your personal information for cross-context behavioral advertising
  • Non-discrimination for exercising your privacy rights

Categories of personal information collected: Identifiers (name, email), commercial information (subscription and payment history), internet activity (usage data), and professional information (if provided to your agent).

Exercising Your Rights

To exercise any of these rights, contact us at support@useclaw.ai. We will respond within 30 days (or sooner if required by applicable law). We may ask you to verify your identity before processing your request.

8. International Data Transfers

Your data may be transferred to and processed in the United States and other countries where our service providers operate. These countries may have data protection laws different from your country of residence. Our agreements with third-party service providers include data processing provisions with appropriate safeguards for international data transfers as required by applicable law. For details on how each provider handles international transfers, please refer to the privacy policies linked in Section 3 above.

9. Automated Decision-Making

The Service uses automated processing in the following ways:

  • Input screening: Automated scanning of content for potential prompt injection attacks. Flagged content may be blocked before reaching your agent.
  • Data leak prevention: Automated scanning of outgoing data for sensitive information (credit card numbers, API keys, etc.). Detected sensitive data may be redacted or blocked.
  • Agent actions: Your AI agent autonomously processes information and takes actions (sending emails, searching the web) based on your instructions.

These automated processes are integral to the Service. If you believe an automated decision has been made in error, you may contact us for review.

10. Cookies and Analytics

We use the following cookies and tracking technologies:

  • Essential cookies: Required for authentication and core Service functionality (Clerk session cookies). These cannot be disabled.
  • Analytics: We use Vercel Web Analytics to collect aggregated, anonymized usage data. Vercel Analytics does not use cookies and does not collect personally identifiable information.

We do not use third-party advertising cookies or trackers. You can manage cookie preferences in your browser settings. Disabling essential cookies may prevent you from using the Service.

11. Children's Privacy

The Service is not intended for anyone under the age of 18. We do not knowingly collect personal data from children under 18. If we learn that we have collected personal data from a child under 18, we will promptly delete that data. If you believe a child has provided us with personal data, please contact us at support@useclaw.ai.

12. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice via email or a prominent notice within the Service before the changes take effect. The "Last updated" date at the top of this page indicates when this Privacy Policy was last revised. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

13. Contact Us

If you have any questions about this Privacy Policy, want to exercise your data rights, or have a privacy concern, please contact us at:

  • Email: support@useclaw.ai
  • Pragmatic Identity sp. z o.o.
  • ul. Piłkarska 10, 55-114 Malin, Poland

For EEA and UK residents: If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. Our lead supervisory authority is UODO (Urząd Ochrony Danych Osobowych) in Warsaw, Poland.