Privacy Policy
Effective Date: March 30, 2026
The Simple Version
Your agent runs in its own sealed container. Your data stays in your container. We don't sell it, mine it, or share it with advertisers. AI providers process your messages only to generate responses — not to train their models on your data. You can delete everything at any time.
1. Introduction
This Privacy Policy explains how KIPClaw ("we," "us," "our") collects, uses, stores, and protects your information when you use our AI agent services ("Service"), including KIP agents on Telegram, Discord, WhatsApp, Slack, and other platforms, the KIPClaw website, and related services.
We take your privacy seriously. Our architecture is designed around the principle that your data belongs to you.
2. Information We Collect
2.1 Information You Provide
- Account information: Email address, name, and billing information when you subscribe
- Messages and content: Text, images, files, and other content you send to your KIP agent
- Configuration: Preferences, instructions, and customizations you set for your agent
- Support communications: Messages you send to our support team
2.2 Information Collected Automatically
- Platform identifiers: Your username, user ID, or display name as provided by the messaging platform
- Usage metrics: Message counts, session timestamps, feature usage (aggregated, not message content)
- Technical data: Platform type, connection timestamps, error logs (no message content in logs)
2.3 Information We Do NOT Collect
- We do not read or review your conversations with your agent (unless you report an issue and share them with us)
- We do not use tracking cookies, ad pixels, or analytics SDKs on the bot
- We do not collect biometric data
- We do not build advertising profiles
3. How We Use Your Information
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide the Service | Messages, config, platform IDs | Contract performance |
| Process payments | Billing information | Contract performance |
| Improve reliability | Aggregated usage metrics, error logs | Legitimate interest |
| Prevent abuse | Usage patterns, platform IDs | Legitimate interest |
| Customer support | Support communications, account info | Contract performance |
| Legal compliance | As required | Legal obligation |
4. Sandbox Isolation Architecture
Each KIPClaw agent runs in its own sealed sandbox container. This means:
- Isolated compute: Your agent's process is separate from every other customer's agent
- Isolated storage: Your conversations, configuration, and data live in your container only
- Isolated network: Your agent communicates through its own dedicated network namespace
- No cross-contamination: A compromise or issue in one container cannot affect another
This is not shared hosting with database-level separation. Each agent is a truly isolated environment.
5. Third-Party AI Processing
Your messages are processed by third-party AI providers to generate responses. Currently, we use:
- Anthropic (Claude): Anthropic Privacy Policy
Key facts about AI processing:
- Messages are sent to the AI provider solely to generate responses
- We use API access, which means your data is not used to train AI models (Anthropic's API terms explicitly exclude training on API inputs)
- All communication with AI providers is encrypted in transit (TLS)
- We may add additional AI providers in the future; this policy will be updated accordingly
6. Data Sharing
We do not sell, rent, trade, or share your personal information with advertisers or data brokers. Ever.
We share information only in these limited circumstances:
- AI providers: Message content is sent to generate responses (see Section 5)
- Payment processors: Billing information is shared with our payment processor to handle subscriptions
- Legal requirements: When required by law, court order, or governmental request
- Safety: To protect the rights, safety, or property of KIPClaw, our users, or the public
- Business transfer: In connection with a merger, acquisition, or sale of assets (with prior notice)
7. Data Retention
| Data Type | Retention Period | Notes |
|---|---|---|
| Conversation data | Duration of subscription + 30 days | Deleted after grace period for data export |
| Account information | Duration of account + 90 days | Required for billing and legal compliance |
| Usage metrics | 12 months (aggregated) | No message content; used for reliability |
| Error logs | 90 days | No message content |
| Payment records | As required by law (typically 7 years) | Tax and financial compliance |
You may request deletion of your data at any time (see Section 9).
8. Data Security
We implement security measures appropriate to the sensitivity of the data we process:
- Encryption in transit: TLS for all communications between components, verified via extracted CA certificates (we never disable certificate verification)
- Sandbox isolation: Each agent runs in its own sealed container with dedicated network namespace
- Access controls: Token-based authentication for all gateway connections
- Secret management: Vault-based credential storage; secrets are never exposed in logs or client-facing interfaces
- Capability restriction: Agent containers run with minimal Linux capabilities (CIS Docker Benchmark 5.3)
- Config integrity: SHA-256 hash verification prevents configuration tampering
No system is 100% secure. If you discover a security vulnerability, please report it to security@KIPClaw.ai.
9. Your Rights
Depending on your jurisdiction (including GDPR, CCPA, and other privacy laws), you have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your data ("right to be forgotten")
- Export: Request your data in a portable, machine-readable format
- Objection: Object to processing based on legitimate interest
- Restriction: Request we limit how we process your data
- Withdraw consent: Where processing is based on consent, withdraw it at any time
To exercise any of these rights, email support@KIPClaw.ai. We will respond within 30 days (or sooner as required by applicable law).
California residents (CCPA): You have the right to know what personal information we collect and to opt out of the sale of personal information. We do not sell personal information.
10. Children's Privacy
The Service is not intended for children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect information from children. If we discover we have collected data from a child, we will delete it promptly. If you believe a child has used our Service, contact us at support@KIPClaw.ai.
11. International Data Transfers
Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where required.
12. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you via email or through the Service at least 14 days before the changes take effect. The effective date is listed at the top of this page.
13. Contact Us
For privacy questions, data requests, or concerns:
Email: support@KIPClaw.ai
Security issues: security@KIPClaw.ai