ClawdSecbot Privacy Policy
This page is prepared for Apple App Store privacy compliance and explains how ClawdSecbot handles data. ClawdSecbot follows a privacy-first, local-only design.
Introduction
Aglaulus built ClawdSecbot as a desktop security tool for managing and protecting Openclaw agents. All data processing happens locally on your device.
Information We Do Not Collect
- Personal identity data (name, email, phone number).
- Device identifiers or hardware fingerprints.
- Location data, browsing history, or search history.
- Usage analytics, advertising identifiers, or external diagnostics.
- Financial, health, contacts, photos, or media data.
How ClawdSecbot Works
- Configuration data is saved in local storage within the app sandbox.
- A local proxy runs on localhost (127.0.0.1) to inspect and forward requests.
- Traffic is sent directly to your configured LLM providers, never via our servers.
- Conversation content is not sent to us.
Audit Logs and API Keys
- Security logs are generated and stored locally, and can be deleted by you at any time.
- For security auditing, local audit records may include truncated prompt snippets, model output summaries, and tool call arguments.
- These audit records are stored only on your device and are never transmitted to our servers.
- Sensitive header values are masked in logs.
- API keys are stored locally and used only for direct provider authentication.
- API keys are never transmitted to us.
Third-Party Services
When enabled by you, ClawdSecbot connects directly from your device to third-party LLM providers (for example OpenAI, Anthropic, and Google). Their own privacy policies apply.
The app may also request font resources from Google Fonts for UI rendering. Such requests are limited to loading font files and may include standard network metadata (for example IP address and user agent).
In the Apple App Store build, automatic update checks to our version endpoint are disabled.
Permissions Used
| Permission | Purpose |
|---|---|
| Network (Outbound) | Forward inspected requests to your configured LLM provider endpoints. |
| Network (Inbound) | Run local proxy on localhost for Openclaw requests on your device. |
| User-Selected File Access | Read and write Openclaw configuration files that you explicitly authorize. |
Contact
Email: zhuang.hu@dbappsecurity.com.cn
Website: https://bot.secnova.cn