Privacy Policy

Last updated: March 2026

1. Introduction

Suprenv ("we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our ZeroClaw AI agent hosting service.

2. Information We Collect

Account Information: When you create an account, we collect your name, email address, and payment information. Payment data is processed securely by Clerk/Stripe and we do not store complete card numbers.

ZeroClaw Configuration:

  • AI provider API keys (encrypted at rest)
  • Telegram bot tokens (encrypted at rest)
  • Agent names, system prompts, and settings
  • Team member invitations and permissions

Usage Data: We automatically collect:

  • Number of agents created and their resource usage
  • Message counts and API call frequency
  • Feature usage patterns
  • Device, browser, and IP address (for security)

Agent Memory & Conversations: Your ZeroClaw agents store conversation history and persistent memory in your allocated storage. We do not access this data unless necessary for security investigations, legal compliance, or troubleshooting with your explicit consent.

3. How We Use Your Information

We use your information to:

  • Provision and maintain your ZeroClaw containers
  • Process payments and manage subscriptions
  • Provide technical support and troubleshooting
  • Send service notifications and updates
  • Detect and prevent fraud, abuse, and security threats
  • Improve our service (aggregated, anonymized data)
  • Comply with legal obligations

4. AI Provider Interactions

When you configure a ZeroClaw agent with an AI provider (OpenAI, Anthropic, etc.):

  • Your API key is encrypted and stored securely
  • Messages sent to/from your agent pass through our infrastructure
  • AI providers process your messages according to their own privacy policies
  • We log metadata (timestamps, message counts) for debugging and billing

Important: AI provider terms and data handling are separate from ours. Review each provider's privacy policy for details on how they process your data.

5. Telegram Bot Data

ZeroClaw agents communicate via Telegram. When you chat with your agent:

  • Messages are transmitted through Telegram's infrastructure
  • Conversation history is stored in your ZeroClaw container
  • Telegram's privacy policy applies to their data handling
  • We do not share your Telegram data with third parties

6. Data Storage & Security

Your data is stored in secure data centers within the European Union. Security measures include:

  • Encryption: Data encrypted at rest (AES-256) and in transit (TLS 1.3)
  • Container Isolation: Each ZeroClaw runs in an isolated Docker container
  • Access Controls: Role-based access, audit logging, MFA for staff
  • Infrastructure: Regular security audits, automated vulnerability scanning

No method of transmission over the Internet is 100% secure. While we implement industry best practices, we cannot guarantee absolute security.

7. Data Sharing

We may share your information with:

  • Service Providers: Clerk (authentication), Stripe (payments), infrastructure providers (container hosting)
  • AI Providers: When you configure an agent with OpenAI, Anthropic, etc., they process your messages
  • Legal Authorities: When required by law, regulation, or valid legal process
  • Security: To protect our rights, privacy, safety, or property

We do not sell your personal data or agent conversations to third parties.

8. Team ZeroClaw & Shared Memory

Team ZeroClaw agents include shared memory accessible to all team members. Be aware:

  • Team members can view shared conversation history and memories
  • Individual workspaces are isolated per member
  • Team owners control member access and can remove members
  • Removed members lose access immediately but data remains for remaining members

9. Your Rights (GDPR & Data Protection)

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data (account deletion)
  • Portability: Export your agent configurations and memories
  • Object: Object to certain processing activities
  • Withdraw Consent: Withdraw consent for optional data processing

To exercise these rights, contact us at privacy@suprenv.xyz

10. Data Retention

We retain your data while your account is active. After account deletion:

  • Agent data: Deleted within 30 days (may be retained in backups for up to 90 days)
  • Account data: Deleted within 30 days
  • Billing records: Retained for 10 years (legal/accounting compliance)
  • Security logs: Retained for 1 year

11. Cookies & Tracking

We use cookies and similar technologies for:

  • Essential: Authentication, session management (required)
  • Functional: Remembering preferences
  • Analytics: Understanding usage patterns (anonymized)

You can manage cookie preferences through your browser settings. Disabling essential cookies may affect functionality.

12. Children's Privacy

Suprenv is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we discover we have collected data from a minor, we will delete it immediately.

13. International Data Transfers

Your data is stored in the European Union. Some service providers may be located outside the EU. We ensure appropriate safeguards are in place (Standard Contractual Clauses, adequacy decisions) for any international transfers.

14. Changes to This Policy

We may update this policy periodically. Significant changes will be notified via email or in-app notification at least 30 days before taking effect. Continued use after changes constitutes acceptance.

15. Contact

For privacy-related questions or to exercise your rights, contact our Data Protection Officer at: privacy@suprenv.xyz