LocalClaw account service
Privacy Policy
This policy explains the data used by the LocalClaw website and the optional My Machines account workspace.
Account data
When you sign in with Google, LocalClaw receives the basic identity information needed to create your account: your name, email address, profile image and Google account identifier. Google does not provide your password to LocalClaw.
Hardware profiles
My Machines stores only the hardware details you choose to enter, such as a machine name, operating system, processor, GPU, RAM, VRAM, workload and optimization preference. These details are used to calculate and display compatible local AI models.
Sessions and security
Session tokens, IP addresses and browser user-agent information may be processed to keep accounts signed in and protect the service. Sessions expire after 30 days unless renewed through continued use. Signing out invalidates the active browser session.
Website analytics
Public LocalClaw pages use DataFast and Microsoft Clarity to understand page visits, referrals, devices and interactions. The private account workspace uses DataFast to connect an authenticated account journey to a sponsorship checkout. These services process analytics data under their own privacy terms. The account workspace is not used to collect prompts, local files, device serial numbers or operating-system credentials.
Sponsorship campaigns and payment
If you create a sponsorship campaign, LocalClaw stores the campaign name, advertiser name, HTTPS destination, short message, selected fixed position, dates, logo metadata, purchase state and delivery analytics. Sponsor logos are stored in a private Cloudflare R2 bucket and are served publicly only while the paid campaign is active.
Stripe hosts Checkout and manages payment methods, receipts, subscriptions and renewal cancellation. LocalClaw stores Stripe object identifiers and payment state needed to reconcile a campaign, but does not receive or store full card numbers. When DataFast analytics cookies are available, their visitor and session identifiers are copied into Stripe Checkout metadata so DataFast can attribute aggregate sponsorship revenue to the originating visit. No card data is sent to DataFast.
Sponsor delivery measurement
When an active sponsor placement is viewed or clicked, LocalClaw uses a random first-party, HttpOnly cookie to deduplicate short bursts and estimate unique campaign visitors. LocalClaw stores a one-way hash of that random identifier, not its raw value, IP address or Google account. Campaign owners receive aggregate impressions, estimated unique visitors, clicks and CTR, not visitor identities.
Infrastructure and service providers
- Google provides account authentication.
- Cloudflare Pages, Functions and D1 host the website, account API and account database.
- Cloudflare R2 stores uploaded sponsor logos.
- Stripe processes sponsor payments and optional automatic renewals.
- DataFast and Microsoft Clarity provide analytics on public website pages.
Retention and deletion
Account, machine and sponsor campaign data remain stored while needed to provide the service, document payment and resolve support or legal obligations. Short-lived metric deduplication rows can be removed without changing historical aggregate totals. To request access, correction or deletion, email helplocalclaw@gmail.com from the address associated with the account.
Contact
Questions about this policy can be sent to helplocalclaw@gmail.com.