At Agent 37 Inc. ("Agent 37," "we," "our," or "us"), privacy is foundational to how we built our service. We provide managed OpenClaw and Hermes hosting. This Privacy Policy explains how we collect, use, store, and protect your data when you use our platform.
1. Data Collection
We only collect information necessary to provide our managed hosting service:
Account Information - Email address and authentication data stored securely via Firebase Auth.
Billing Information - Payment data processed securely through our third-party payment processor, Stripe. We do not store your full credit card number.
Instance Configuration - Instance ID, tier, status, and settings necessary to provision and manage your service.
2. What We Do NOT Collect or Store
We do not collect or store the following data in our own databases or systems:
Chat conversations - Your messages stay on your instance and are not sent to or stored by Agent 37.
AI responses - All LLM API calls go directly from your instance to your chosen provider.
Your API keys - Keys you configure in your instance are stored only within your container.
OpenClaw memory and files - Your bot's memory, configuration files, and workspace data remain on your instance.
Your instance runs on managed infrastructure that we administer. While we do not access your instance data in the normal course of operations, we do maintain infrastructure-level access to the servers that host your container for the purposes of provisioning, updates, and support.
3. How Your Data Flows
When using Agent 37, data flows as follows:
You send a message via your chosen platform (WhatsApp, Telegram, Discord, Slack, etc.).
The platform sends the message directly to your OpenClaw instance.
Your instance sends an API request directly to your LLM provider using your own API keys.
The LLM provider responds directly to your instance.
Your instance sends the response back to you via the messaging platform.
Agent 37 infrastructure is never in the path of your conversations. We provide compute, networking, and uptime - nothing more.
4. How We Use Your Data
We use your collected data for the following purposes:
Service Provisioning - To create, configure, and manage your instance.
Authentication - To verify your identity and provide secure access to your account.
Payment Processing - To process subscriptions and manage billing.
Communication - To send service updates, billing notifications, and respond to support requests.
Service Improvement - To analyze usage patterns and improve reliability and performance.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
5. Data Storage and Security
We protect your data with industry-standard security measures:
Encryption - All data is encrypted in transit (TLS) and at rest.
Instance Isolation - Each customer receives their own isolated container environment with dedicated resources.
Database Security - Account data is stored in Firebase's secure infrastructure.
Network Security - OpenClaw gateway binds to localhost within your container, preventing external access to internal services.
HTTPS Everywhere - All instance URLs are served over HTTPS with auto-provisioned TLS certificates.
Signed Access Tokens - Terminal, desktop, and file browser sessions use short-lived, cryptographically signed tokens.
Each of these services has their own privacy policies and data handling practices.
7. Google API Services and User Data
Our application integrates with Google API Services for authentication. This section explains how we handle Google user data:
Data We Access - Email address and profile information used for account creation and sign-in.
How We Use It - Account management and authentication only.
Storage - Google account information is stored securely in Firebase with encryption at rest.
Sharing - We do not share your Google user data with third parties for marketing purposes. Data may be shared with Firebase (authentication) and Stripe (payment processing), or as required by law.
Your Control - You can revoke our application's access to your Google data at any time through your Google Account settings. Deleting your account with us removes your Google user data within 30 days.
8. Data Retention and Deletion
We retain your account and instance data while your subscription is active. Upon cancellation or account deletion request, all associated data - including your instance and any stored configuration - is permanently deleted within 30 days.
You may request account deletion at any time by contacting info@agent37.com.
9. Your Privacy Rights
You have the right to:
Access your personal data
Correct inaccurate data
Delete your account and all associated data
Export your data
10. Children's Privacy
Our service is not intended for children under 13. We do not knowingly collect information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete that information.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated policy on this page with a revised "Last updated" date. Continued use of the service after changes are posted constitutes acceptance of the revised policy.
12. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at info@agent37.com.