← Back

Privacy Policy

Last updated: May 30, 2026

1. Overview

This Privacy Policy explains how Operator Research, Inc., a Delaware corporation ("Operator.io", "we", "us", or "our"), collects, uses, shares, and protects information when you use the Operator.io website, dashboard, APIs, browser extension, and the hosted OpenClaw agent instances we run on your behalf (collectively, the "Service"). It is part of and incorporated into our Terms of Service.

By using the Service you agree to the practices described here. If you do not agree, do not use the Service. For the terms that govern your use, see our Terms of Service.

2. Information We Collect

We collect the following categories of information, most of which you provide directly or generate through your use of the Service:

  • Account information. When you create an account, your email address and authentication credentials are handled through our authentication provider, Clerk.
  • Billing information. When you subscribe to a paid plan, our payment processor, Stripe, collects and stores your payment details. We do not store full credit card numbers on our servers.
  • Usage metadata. We record operational data such as instance identifiers, timestamps, request counts, and token consumption to provision instances, enforce rate limits, and calculate billing.
  • Instance configuration. The agent settings, provider keys, and tool preferences you save are stored as your instance configuration.
  • Agent conversations. Messages routed through our AI proxy are processed to deliver responses to your agent.
  • Browser cookie sync. If you use the Operator.io browser extension, it reads cookies from the site you are viewing and forwards them to your running instance, as described in the Browser cookie sync section below.
  • Support and communications. If you contact us, we keep your messages and contact details so we can respond.
  • Automatically collected data. When you visit our website we may collect standard log and device data such as IP address, browser type, and pages viewed, along with cookies described in the Cookies section.

3. Instance Configuration and Agent Conversations

Your instance configurations (agent settings, provider keys, tool preferences) are encrypted at rest using AES-256-GCM before storage. We decrypt configuration data only to provision or update your running instances. API keys stored in your configuration are hashed for lookup and encrypted separately for retrieval.

AI conversation messages routed through our proxy are encrypted at rest using AES-256-GCM. We process these messages to deliver the Service, enforce usage limits, and maintain security. We do not sell your data, and we do not use the contents of your instance configurations or your agent conversations to train AI models.

5. How We Use Information

We use the information we collect to:

  • Provide, operate, and maintain the Service, including provisioning instances and routing AI requests.
  • Process payments, manage subscriptions, and send transactional messages such as billing receipts and service notifications.
  • Enforce usage limits and protect the Service against fraud, abuse, and security threats.
  • Diagnose problems, monitor performance, and improve the reliability and features of the Service.
  • Respond to your support requests and communicate with you about the Service.
  • Comply with our legal obligations and enforce our Terms of Service.

We do not sell your personal information, and we do not use your instance data or agent conversations to train AI models.

7. How We Share Information

We do not sell your personal information. We share information only as described below:

Service providers. We rely on the following providers to operate the Service, and we share with each only the minimum data required for it to function:

  • Clerk, for authentication and session management.
  • Stripe, for payment processing and subscription billing.
  • Microsoft Azure, for infrastructure including container hosting, file storage, and AI inference.
  • Vercel, for hosting the dashboard and API.
  • AI model and web search providers, to fulfill the inference and search requests your agent makes.

Each provider processes data according to its own privacy policy. We also share information when required by law, to respond to lawful requests or legal process, to protect the rights, safety, and property of Operator.io, our users, or the public, and in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this Policy or notify you of any material change.

8. International Data Transfers

We are based in the United States and process data there and in other countries where we or our providers operate. If you access the Service from outside the United States, your information may be transferred to and processed in the United States, where data protection laws may differ from those in your country. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses for such transfers.

9. Data Retention

Instance data (configurations, workspace files) is retained while your account is active. If your subscription lapses and instances are suspended, we preserve snapshots of your data so it can be restored if you resubscribe. If you delete your account, we remove your instance data and personal information within 30 days, except where we must retain certain records longer, for example billing records kept to meet tax and accounting obligations. Backups are purged on a rolling basis.

10. Security

All data in transit uses TLS. Sensitive data at rest, including instance configurations, API keys, and conversation logs, is encrypted with AES-256-GCM. API keys are additionally hashed with SHA-256 for lookup. Access to production infrastructure is restricted to authorized personnel. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information using measures appropriate to its sensitivity.

11. Your Privacy Rights

Depending on where you live, you may have rights over your personal information, including the right to access a copy of it, to correct inaccurate data, to delete it, to restrict or object to certain processing, and to data portability. You can export your instance configuration from the dashboard at any time, and you can delete your instances through the dashboard, which removes the associated container and files.

To exercise any of these rights, or to request full account deletion or a copy of all data we hold about you, contact us at support@operator.io. We will verify your request and respond within the time required by applicable law. You will not be discriminated against for exercising your rights. If we deny your request, you may appeal by replying to our response.

12. US State Privacy Rights

If you are a resident of California or another US state with a comprehensive privacy law, you have the right to know and access the personal information we collect about you, to request its deletion, to correct inaccurate information, and to opt out of the sale or sharing of personal information and of targeted advertising.

We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use sensitive personal information for purposes that would require us to offer a right to limit. The categories of personal information we collect, the purposes for which we use them, and the parties with whom we share them are described in the sections above. You may submit a request using the contact details below, and you may use an authorized agent to submit a request on your behalf where the law allows, subject to verification.

13. Cookies and Tracking

We use cookies and similar technologies that are necessary to operate the website and keep you signed in, and a limited set of analytics to understand how the site is used so we can improve it. You can control cookies through your browser settings, though disabling some cookies may affect how the Service works. We do not use cookies to sell your information or for cross-context behavioral advertising.

14. Children's Privacy

The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.

15. Changes to This Policy

We may update this Policy as the Service evolves. If we make material changes, we will notify you by email or through a notice in the dashboard and update the date above. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

16. Contact

Questions about this Policy or your data can be sent to support@operator.io.