Privacy and security
What happens to your messages
Section titled “What happens to your messages”Messages are processed in real time to produce an answer. TeleClaw does not sell your conversations and never uses them to train AI models — the model providers we use are contractually bound to the same.
What is kept is what the product needs to work:
- Agent memory — what your agent has learned, per chat. You can read and delete it at any time (see Agent memory).
- Workspace files — anything your agent created or you uploaded (see Manage files).
- Usage records — how many credits a run consumed, so billing and the usage screen work.
Deleting an agent removes its bot, memory and workspace. Reset agent does the same without deleting the agent itself.
Private vs public bots
Section titled “Private vs public bots”Every agent has an access mode in Settings → Access:
- Private — only you and the people on the allowed-users list can talk to it.
- Public — anyone who finds the bot can talk to it.
Credentials your agent uses
Section titled “Credentials your agent uses”Passwords, API keys and OAuth tokens live in Passwords & Keys and in Connectors, encrypted at rest. Prefer connectors over pasting a raw password: a connector can be revoked from the provider’s side without changing your password.
Encryption and compliance
Section titled “Encryption and compliance”Data is encrypted in transit (TLS 1.3) and at rest (AES-256). TeleClaw is operated by Qualtir and runs under GDPR-compliant processes with ISO 27001-certified information security management.
The full legal texts live on the marketing site: Privacy Policy, Terms, Security and the sub-processor list.