Privacy Notice

Effective date: 2026-02-09.

Summary

This Privacy Notice is provided by Remodeled AI, LLC. It describes data handled by Command Claw shared services (the control plane and model gateway).

  • We provide one isolated tenant (VM + volume) per subscriber.
  • By default, we do not log or store AI prompts or AI responses in our control plane or model gateway.
  • We store limited metadata needed for billing, reliability, and support.

This notice does not describe what you store inside your tenant. Your tenant is your environment and may contain user content depending on your configuration.

What We Collect

Account and authentication
  • Email address
  • Password hash and session/auth metadata
Billing
  • Stripe customer/subscription identifiers
  • Payment metadata for subscriptions, credit purchases, and auto top-ups

We do not store full payment card numbers. Stripe handles payment details.

Tenant and infrastructure metadata
  • Tenant slug/subdomain
  • Droplet/volume identifiers, region/size, and IP address
  • Health timestamps/status and storage usage numbers (bytes/percent)
AI usage metering (metadata only)
  • Provider/model identifier
  • Token counts and computed cost
  • Request ID and timestamp
Onboarding secrets

Telegram bot token: stored on your tenant volume after provisioning. If we temporarily store it during onboarding, it is encrypted at rest and deleted after it is applied.

Basic logs

Like most services, we may process basic operational logs (for example: timestamps, request IDs, status codes, and high-level error information) to keep the Service reliable and secure. We avoid logging request bodies that may contain sensitive content.

What We Do Not Collect

How We Use Data

We use the information above to provide and operate the Service (provisioning your tenant, maintaining billing state, enforcing credits, and monitoring reliability).

We may also use limited information for security (for example: abuse prevention and incident response) and to provide support when you request it.

Legal Bases (Where Applicable)

Depending on your location, we process personal information under one or more of these bases:

  • To perform our contract with you (provide the Service).
  • To comply with legal obligations (for example: tax, accounting, or lawful requests).
  • For legitimate interests (for example: security, abuse prevention, and reliability).
  • With your consent, where required (you may withdraw consent where applicable).

Where Data Lives

Shared services (control plane/model gateway) store billing, metering metadata, and infrastructure metadata.

Your tenant VM + volume stores OpenClaw state, workspace data, and tenant secrets such as your Telegram bot token. If you run skills or integrations, those may store additional data in your tenant.

Cookies and Similar Technologies

We use essential cookies and similar technologies to run the Service (for example: to keep you signed in and protect against abuse). We do not use advertising cookies.

Subprocessors

We use vendors to provide the Service, such as Stripe (billing), Resend (transactional email), Railway (hosting shared services), Neon or Railway Postgres (database), DigitalOcean (tenant droplets/volumes), Porkbun (DNS), and AI providers (for example: OpenAI, Anthropic, and Google Gemini) via our model gateway.

We may update subprocessors over time. We share only what is reasonably necessary for each vendor to perform their role.

How We Share Information

We may share information:

  • With vendors/subprocessors that help us provide the Service.
  • To comply with law or respond to lawful requests.
  • To protect the Service and our users (for example: fraud and abuse prevention).
  • In connection with a merger, acquisition, financing, or sale of assets (in which case information may be transferred as part of the transaction).

Retention and Deletion

If you cancel, we delete your tenant droplet and volume when your subscription period ends. This removes data stored on that tenant volume.

We may retain limited billing and accounting records as required for legitimate business and legal reasons.

International Transfers

We may process and store information in the United States and other countries where we or our vendors operate. Where required, we take steps designed to provide appropriate safeguards for such transfers.

Security

Tenants are isolated from each other (one tenant per VM + volume). We avoid storing sensitive content in shared services by default and design systems so secrets are not unnecessarily exposed.

No system is perfectly secure. You are responsible for securing and backing up data inside your tenant, including any skills you install.

Your Choices and Requests

You can access and update certain account information from your dashboard. You can also request deletion by cancelling your subscription, which triggers tenant deletion at the end of the billing period.

Depending on where you live, you may have rights to access, correct, delete, or object to certain processing of your personal information. To make a request, email contact@remodeled.ai.

We may need to verify your identity before fulfilling a request, and we may deny requests where legally permitted (for example: to comply with law or protect security).

Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Changes

We may update this notice as the product evolves. Material changes will be communicated in-product or by email.

Contact

If you have questions about this notice or want to make a privacy request, email contact@remodeled.ai.