ClawMobile Phone-native AI agents

Privacy Policy

ClawMobile Privacy Policy

This Privacy Policy explains how ClawMobile handles information when you use the ClawMobile Android app, ClawMobile iOS app, and related ClawMobile web pages that link to this policy.

Last updated: July 6, 2026 Android app iOS app ClawMobile web pages
Short version

ClawMobile is local-first and bring-your-own-provider.

Most ClawMobile app data is stored on your device. Real AI responses require you to configure a model provider or compatible endpoint, and task content may be sent to that provider when you run a model-backed task.

In the current Android and iOS builds, ClawMobile does not provide a ClawMobile account, subscription, payment processor, advertising SDK, third-party analytics SDK, third-party crash reporting SDK, or ClawMobile-hosted model router.

ClawMobile does not sell personal information.

Information we handle

Information you provide or choose to use in the app

Depending on the platform and features you use, ClawMobile may handle:

  • task prompts, chat messages, task results, and task history;
  • shared text, links, images, PDFs, and files imported through Android share intents, the iOS Share Extension, file pickers, or system handoffs;
  • voice input after you grant microphone and speech recognition access on iOS;
  • images, screenshots, OCR text, extracted text, selected file metadata, and image-understanding content used in tasks;
  • memory entries you create or ask the agent to save;
  • artifacts, reusable task drafts, skill drafts, generated skill guidance, demo recordings, fast paths, skill metadata, and skill run history;
  • model provider settings such as provider name, model name, base URL, token limits, and API keys;
  • optional Android Termux/OpenClaw setup settings such as SSH host, port, username, install directory, repository branch, companion port, gateway port, and setup logs;
  • optional Android SSH password, SSH private key, Telegram bot token, and Telegram user ID when you choose to configure those features;
  • optional Social settings such as Nostr identity, relays, trusted contacts, messages, and imported or shared packages.
On-device storage

Most app data is stored locally on your device.

ClawMobile stores local app data on your device, including task and conversation history, run timelines, tool-call summaries, token usage, local runtime logs, memory entries, memory search state, artifacts, imported shared content, skills, app settings, backend selection, permission choices, trusted contacts, Social conversations, local runtime state, and local provider settings.

On iOS, model API keys and Nostr private key material are stored in the iOS Keychain. On Android, model API keys, SSH passwords, SSH private keys, and Telegram bot tokens are stored in app-private preferences after Android Keystore-backed AES/GCM encryption. Other Android runtime data is stored in app-private storage.

This information remains on your device unless you delete it, clear app data, uninstall the app, share it, send it to a configured model provider, sync it through a user-configured relay or endpoint, copy it to another app, or use a feature that intentionally exports or hands off the content. Android backup behavior may depend on your device settings, operating system, and Google/Android backup configuration.

Model providers

Information sent to model providers

When you configure an external model provider or compatible endpoint and run a model-backed task, ClawMobile may send the information needed to complete that task to the provider you selected. This may include prompts, relevant conversation context, selected memory context, tool names, tool schemas, tool observations, tool results, error messages, shared text, URLs, images, PDFs, files, OCR text, screenshots, generated artifacts, generated skill drafts, demo summaries, fast-path descriptions, provider name, model name, base URL, token limits, request timing, and related routing details.

ClawMobile does not send every local item by default. The app selects context that is relevant to the task you start.

You control which provider or endpoint is configured. ClawMobile can connect to user-configured providers and endpoints such as OpenAI, Claude/Anthropic, OpenRouter, DeepSeek, Groq, Mistral, Together, Ollama, LM Studio, and custom OpenAI-compatible endpoints. Provider availability, retention, pricing, and data handling are controlled by the provider you choose. Review your provider's terms and privacy practices before sending sensitive information.

Android app

Android app-local runtime, Accessibility, ADB, and Termux/OpenClaw

ClawMobile for Android includes an app-local runtime that can run tasks inside the Android app. Depending on your settings and permissions, it may use local task history, saved memory, Android share-intent content selected by you, Android Accessibility summaries of the current visible screen, temporary screenshots captured through the Accessibility service, on-device OCR through Google ML Kit text recognition, visible Android intents, and optional built-in ADB support.

The optional Android Accessibility service can retrieve visible window content, observe supported accessibility events, perform gestures, and capture temporary screenshots as allowed by Android while the service is active. This can include text, labels, view IDs, package names, and visible UI structure from other apps. ClawMobile uses this information to perform user-requested tasks, build compact screen summaries, record demos for skill creation, and provide runtime observations to a configured model provider when relevant. You can disable the Accessibility service at any time in Android Settings.

Optional built-in ADB support requires you to enable Android developer options and approve debugging trust prompts. When enabled, ADB may allow ClawMobile to send input events, key events, text input, and diagnostic shell commands supported by the app. ADB is optional and is not required for basic app-local tasks.

ClawMobile can optionally connect to a Termux/OpenClaw backend controlled by you. In that mode, the Android app may use SSH to install, repair, start, or inspect a local runtime inside Termux. Termux/OpenClaw may process task content, model settings, tool observations, files, shell commands, ADB-related setup, OCR dependencies, skill data, and backend logs depending on what you configure and run.

iOS app

iOS permissions and platform boundaries

ClawMobile asks for iOS permissions only when you open or start a feature that needs them. Depending on the features you use, the app may request access to microphone and speech recognition for voice input; camera, photos, files, OCR, or image-understanding content you select; notifications for task status, reminders, scheduled follow-ups, and approval prompts; Shortcuts and App Intents for user-created workflows; calendar and reminders for user-requested actions; contacts only when you ask ClawMobile to search contacts; and location only when you ask for a location-related task and grant permission.

You can grant, deny, or revoke iOS permissions in iOS Settings.

ClawMobile for iOS cannot freely control your phone, read other apps, run arbitrary shell commands, or operate as a hidden background agent. The app works through user-visible app content, iOS permission prompts, supported system handoffs, and actions you start or approve. When iOS only allows a draft, share sheet, prompt, or handoff, ClawMobile shows that boundary where applicable.

Social

Trusted contacts and Nostr relays

ClawMobile includes optional trusted-contact messaging and package sharing through user-configured Nostr relays.

Social is not a public ClawMobile social network. ClawMobile does not provide a public feed, discovery page, comments system, moderation service, or hosted content service in the current builds.

When you use Social, messages and events may be sent through configured Nostr relays. Public Nostr events can be visible to relay operators and other users according to the Nostr protocol. Encrypted or structured payloads may still expose metadata such as public keys, relay URLs, timestamps, event IDs, and network metadata. You can remove trusted contacts and local Social conversation history where the app provides controls.

Network

Web, links, and network requests

ClawMobile requests network access for model providers, user-configured runtime endpoints, Nostr relays, URL reading, setup downloads, and other features that require networking. When you use web or link-reading features, ClawMobile may request URLs you select or provide.

Remote websites, relays, model providers, endpoint operators, and user-configured backends may receive normal network metadata such as IP address, user agent, request time, and requested URL.

On Android, the app allows cleartext HTTP only for loopback addresses such as 127.0.0.1 and localhost so it can talk to local runtimes on the same device.

If you visit ClawMobile web pages, the website host may process standard server logs needed to operate and secure the site. ClawMobile does not currently use advertising cookies or third-party analytics SDKs in the iOS or Android app.

Sharing

When information is shared or transmitted

ClawMobile may share or transmit information only in these situations:

  • to the model provider or compatible endpoint you configure when you run a model-backed task;
  • to websites, APIs, relays, local runtimes, or user-configured endpoints you ask the app to contact;
  • through Android share intents, iOS share sheets, Shortcuts, App Intents, notification actions, drafts, or other system handoffs you start or approve;
  • through Nostr relays you configure for Social messaging or package sharing;
  • through GitHub releases, Google Play, App Store, YouTube embeds, Formspree form handling, and other third-party services you open or use from ClawMobile web pages or app flows;
  • if required to comply with applicable law or to protect the app, users, or others from abuse or security threats.
Retention

Data retention and deletion

Local task history, memory, artifacts, settings, imported content, skills, demo recordings, runtime logs, Nostr data, backend configuration, and Social data remain on your device until you delete them, clear the relevant in-app data, uninstall the app, clear app data, or remove the app's local data through the operating system.

You can delete task conversations, manage memory entries, clear saved model API keys, remove trusted contacts, delete local Social conversation history, and manage skill drafts where the app provides controls.

Data sent to a model provider, website, relay, Termux/OpenClaw backend, endpoint, app store, or other third-party service is handled according to that service's own policies and controls.

Controls

Your choices

You can:

  • choose whether to configure a model provider;
  • choose which provider, model, base URL, and API key to use;
  • clear saved model API keys;
  • choose which tasks to run;
  • choose whether to use Android app-local runtime features, optional ADB, or optional Termux/OpenClaw backend features;
  • grant, deny, or revoke Android notification and Accessibility permissions;
  • grant, deny, or revoke iOS permissions in iOS Settings;
  • disable app-local screen-content tools, control tools, or local memory tools where the app provides controls;
  • manage task history, memory, artifacts, reusable task drafts, skill drafts, trusted contacts, and local Social history where controls are available;
  • avoid sending content to a model provider by not running model-backed tasks.
Children

Children

ClawMobile is not intended for children and should not be used by children.

Security

Security

ClawMobile uses platform storage features such as iOS Keychain, Android app-private storage, and Android Keystore-backed encryption for supported sensitive secret material. No storage or network system can be guaranteed perfectly secure.

Avoid storing or sending sensitive information to model providers, relays, backends, websites, app stores, or other apps unless you understand the risks. Review generated skills, demo recordings, logs, shared packages, screenshots, and artifacts before sharing them publicly or with trusted contacts.

Future services

Future services

If ClawMobile adds hosted accounts, payments, subscriptions, cloud sync, analytics, crash reporting, or a ClawMobile-hosted model router, this policy will be updated before those services are made available to users.

Updates

Changes to this policy

We may update this Privacy Policy as ClawMobile changes. The updated policy will show a new "Last updated" date. Material changes will be communicated in the app or on the ClawMobile website where appropriate.

Contact

Contact

For privacy or support questions, visit https://clawmobile.ae/contact or use the public ClawMobile GitHub repository.