privacy and your data
your conversations live on your agent's own machine, no other customer's agent can reach them, and we do not train on them. this page says what we store, who can see it, and how to erase it.
the honest version of a privacy page is short, because most of what matters is structural rather than promised. your agent runs on its own machine. what it knows about you is on that machine. nobody else's agent shares it. we do not train on your conversations. and there are two things you should know that make us look less tidy, stated below rather than left out.
where does my data actually live?
on your agent's own computer. conversations, the files it keeps, and the memory it builds about you are stored on that machine, which is dedicated to your agent and shared with no other customer. your data never touches another customer's environment. your agent's computer is the page on what that machine is.
your account itself (your email, your plan, your billing) lives in our own systems, the way any subscription does.
do you train on my conversations?
no. we do not train on your conversations, and we do not share your information.
what your agent learns about you is for your agent. that is the whole point of it getting better at being yours: the learning stays with the one agent that is doing it.
who else can see my data?
the companies that process pieces of it. payment, sign-in, and the AI models your agent thinks with are provided by other companies, and each one sees what it needs for its job. they are listed by name, with what each one does, in our privacy policy. that list is the one to trust; this page points at it on purpose so it can never fall out of date on its own.
people who run InstaClaw. this is the sentence most services leave out. we can reach your agent's machine, because that is how we fix it when something breaks. we do not read your conversations for the sake of it, and there is no reason to, but a page that told you we could not reach the machine would be lying. if that matters for how you use your agent, tell us at help@instaclaw.io before you rely on it.
how are my keys protected?
the API keys you add on the dashboard, the keys of the wallet service your agent uses, and the credentials of accounts you connect are encrypted at rest (AES-256-GCM) before they are stored. two things are not encrypted at rest today, and we would rather you read that here than assume otherwise: the token your machine uses to talk to our servers, and any venue keys that live on the machine itself. both are on our list to close, and this sentence changes when they are. the keys your agent uses to work live on its own machine, not in a pool shared with other customers.
how do i erase my agent's memory?
from the dashboard: reset agent memory. it does exactly this, and it is worth knowing the edges before you press it.
| removed | kept | |---|---| | every conversation | your wallet | | everything it has learned about you | your connected channels | | the identity it built for itself | your plan and billing | | its memory folder | its skills |
it starts over as a new agent on the same machine, with the same wallet and the same channels. there is no undo, so if there is something in its memory you want to keep, ask it to write that down as a file first:
before i reset you, save everything important you know about me to a file called handoff.md
how do i delete everything?
email help@instaclaw.io from the address on your account and ask. there is no self-serve delete button yet, which is the second thing we said we would state plainly. when you cancel a subscription, your agent's machine is deactivated straight away, and what was on it may be permanently deleted 30 days after cancellation, per our privacy policy.
what next
- your agent's computer: the machine your data lives on
- privacy policy: the processor list, retention, and your rights in full
- channels: which channels we get delivery receipts from, and which we do not
- your agent's passport: the proof we receive, and the identity we never see
- verify your machine: check the machine your data lives on yourself
- your logins: what is vaulted where
Reading this as a machine? Get the raw markdown.