Privacy

Your data stays
under your control.

Self-hosted Clavus runs on hardware you own. The invite-only Hosted alpha and beta run on a private managed instance and use the limited operational data described below. Last updated 13 August 2026.

The short answer

  • Self-hosted stays with you. Your threads, files, notes and memories live in a folder on your own machine.

  • No self-hosted product telemetry. Hosted testing is the exception: it uses an account and the aggregate operational counters listed in section 3.

  • You control AI providers when self-hosting. Hosted testing currently includes operator-managed OpenRouter and ElevenLabs access, described in section 4.

  • Website and Hosted testing are explicit exceptions. Both are described below, including the exact fields and retention.

1. Who is responsible

Clavus is an independent project by Janis Berneker, Switzerland. Questions about this policy go to janis@berneker.ch. This policy covers this website and the Clavus apps: Clavus Server, the Mac app and the iOS app.

2. How Clavus is built

In a self-hosted installation, Clavus Server runs on your own Mac. It holds your conversations, documents, memories and API keys, and it is the only thing your phone and your Mac app talk to. We do not operate it, cannot reach it and receive no copy of what is in it. Hosted test instances are managed separately under the exception in section 3.

By default that data sits in ~/.openclaw in your home folder. Deleting that folder deletes everything Clavus knows. Backups, disk encryption and who else can reach that machine are yours to decide.

3. What the apps send us

In self-hosted Clavus, nothing is sent automatically. There is no analytics SDK, automatic crash reporter or licence check in the apps. You do not create a Clavus account, so there is no profile, email address or device identifier on our side. If you deliberately choose Report a bug, Clavus sends the description and diagnostic package shown by that action to the private support history; it can include recent conversation excerpts needed to reproduce the issue and is removed within 90 days.

The Hosted Clavus alpha and beta are the exception. Each tester has a private instance at Hetzner Online GmbH in Germany, operated by Clavus for the test. The operator can access that instance for support, security and maintenance. It records the last account login and sends daily aggregate product counters to the private operator console: active days, message and dictation counts, and the split between desktop and mobile. Product activity is transmitted only at day-level precision. These counters contain no prompts, replies, conversation titles, files or provider credentials.

Hosted instances upload a daily encrypted backup containing Clavus app data, workspace files and agent sessions, but not provider authentication stores or instance configuration files. The operator holds the decryption key. The control plane keeps the seven most recent backups and removes backups older than 13 days. The same voluntary bug-report process applies to Hosted testers; central and instance copies are removed within 90 days and support reports are excluded from new backups.

Two connections do leave your machine on their own: downloading the apps, and the automatic update check. Both go to GitHub, where the release files are hosted, so GitHub sees your IP address and browser or app version. Nothing about your usage or your content is attached; see GitHub's privacy statement.

4. AI providers

Clavus is the interface; the intelligence comes from model providers. In a self-hosted installation, your machine calls the provider you configured directly, using the API key or subscription in your name. What travels is what a request needs: your prompt, the parts of the conversation being continued, and anything you attach such as a file, a screenshot or dictated audio. We are not part of that self-hosted exchange. Each provider's own terms and retention rules apply:

In self-hosted Clavus, you choose which providers to enable and a provider without a configured key is never contacted. During the Hosted alpha and beta, Clavus assigns operator-managed OpenRouter credentials for model requests and ElevenLabs credentials for dictation and speech; Janis Berneker bears those test costs and administers the keys. Those providers process the request content required for the feature under their own terms. Any personal subscription you connect remains under your own account. The same holds for other services you connect yourself, such as web search or a calendar.

5. This website

This site is hosted by Vercel, which processes standard server request data such as IP address, user agent and requested page to deliver and secure the site.

We also use Vercel Web Analytics to see whether anyone is finding the page. It sets no cookies and builds no cross-site profile. It records aggregated page views with country, device type, referring site, and which call to action was clicked. We cannot identify you from it, and there are no ad networks or social trackers on this site.

Your dark-mode preference is kept in your browser's local storage. It stays on your device and is never transmitted.

If you apply to test Clavus, we store your name, email address, preferred testing stage, selected operating systems, whether you previously used Typewise Keyboard, optional note, consent time, application and update dates, pipeline status, and invitation date when applicable in a private Vercel Blob store. We use these details only to review your application and contact you about Clavus testing. We do not share them or add you to a general newsletter. Applications have no automatic expiry today; we keep them until you withdraw, the waitlist ends, or we finally decide not to proceed with the application. Email janis@berneker.ch at any time to have them removed.

6. Beta testing

The iOS app is distributed through Apple TestFlight. If you ask for an invitation, we receive the Apple ID email address you send us and use it only to add you to the tester group. Apple then handles the distribution and shows us installation and crash statistics for the beta; see Apple's privacy policy. Ask us to remove you and the address goes with you.

7. Your rights

Under the Swiss FADP and the GDPR you can ask what personal data we hold, and have it corrected or deleted. For self-hosted Clavus, your content is on your own hardware, where you can inspect or erase it without asking anyone. Hosted testers can ask us to delete their application, account, support reports, instance and backups, subject to the short technical rotation periods described above. For data a model provider has processed, its own privacy process also applies. Write to janis@berneker.ch for any request.

8. Changes

If Clavus ever starts collecting something, this page changes first and says so plainly, with a new date at the top. There is no mailing list to notify. That is rather the point.