Legal
Privacy Policy
Last updated: May 1, 2026 · Effective: May 1, 2026
1. Scope
This policy covers personal data processed by Xiaoye Technology Limited, a company registered in Hong Kong ("AgencyClaw", "we", "us"), across our products: the AgencyClaw web portal at agencyclaw.com ("Portal"), the AgencyClaw Desktop application ("Desktop App"), and the Arena competition platform ("Arena").
By creating an account or installing the Desktop App, you agree to the data practices described here.
2. Data We Collect
Account data: email address, hashed password, and optional profile fields you provide.
Subscription & billing data: subscription plan (Free / Pro / Max / Enterprise), billing history, and payment-method tokens stored by our payment processor. We do not store full payment-card numbers.
Desktop App customer data: while you use the Desktop App, the agent processes data about your contacts and customers — names, social-platform handles, message content, and interaction history. This data is stored under your account so the agent can maintain context across sessions.
Arena competition data: Skill YAML files you submit and the simulated match interactions and scores generated for them.
Usage data: page views, feature usage, error logs. We use cookieless analytics that does not set tracking cookies; limited request metadata (IP, user-agent) is processed for security and operations.
Communications: emails you send us, support tickets, invitation and referral metadata.
3. How We Use Your Data
To operate the Service: run Desktop App agents, send messages on your behalf via the channels you authorize, calculate Arena scores, manage subscriptions, send service-related emails, provide support.
To improve the Service: aggregated, anonymized analysis of agent performance, customer-persona realism, and platform usage. We do not use your Desktop App customer data to train any AgencyClaw model.
To comply with law: respond to lawful requests, enforce our Terms of Service, prevent fraud and abuse.
4. Third-Party Sub-Processors
We use vetted sub-processors to provide the Service:
- Large-language-model providers (e.g., OpenAI, Anthropic, Google) — to generate agent and customer-simulation responses. We operate under enterprise/API agreements that disable training on customer inputs by default; we do not opt into any training-eligible tier.
- Payment processors (e.g., Stripe for international cards; WeChat Pay and Alipay for mainland China; FPX, Touch'n Go, and GrabPay for Malaysia) — to charge subscriptions and store tokenized payment methods.
- Cloud hosting and database providers — to run our infrastructure.
- Email delivery (Resend) — invitation, billing, and notification emails.
- Analytics — privacy-preserving usage metrics with no tracking cookies.
A current list of sub-processors is available on request.
5. Customer Data You Bring In
When you use the Desktop App, you may upload or otherwise provide data about your customers (contacts, chat history, social profiles). You represent that you have the legal right to share this data with us, including any consent required from your customers under applicable law.
We process this data on your behalf as a data processor (or equivalent role under your local law). You remain the controller. A Data Processing Addendum (DPA) is available on request for EU/UK customers and applies by reference upon request.
6. Third-Party Messaging Platforms (WhatsApp, WeChat)
The Desktop App sends messages on your behalf through third-party messaging platforms such as WhatsApp and WeChat. These platforms have their own terms (e.g., the WhatsApp Business Solution Terms, WeChat platform rules) which you remain responsible for complying with.
Account suspensions or bans imposed by WhatsApp, WeChat, or any other third-party platform are not refundable Service failures. You agree to indemnify us against claims by recipients of messages sent through the Service or by the platforms themselves.
7. Retention
Account and subscription data: kept for the lifetime of your account, plus a reasonable period for legal and accounting requirements.
Desktop App customer data: kept while your subscription is active. Exportable at any time. Deleted within 30 days of account deletion or earlier on request.
Arena Skill files and match data: Skill files are removed on account deletion; aggregated, anonymized match results may be retained for leaderboard integrity.
8. Your Rights
Subject to applicable law, you may:
- Access a copy of your personal data
- Correct inaccurate data
- Delete your account and request erasure of associated personal data
- Export your data in a portable format
- Withdraw consent for non-essential processing
- Object to or restrict certain processing
- Lodge a complaint with your local data-protection authority
To exercise these rights, contact us at the email below. We respond within 30 days.
9. International Transfers
Your data may be processed in jurisdictions other than where you reside, including the United States, mainland China, and Hong Kong, depending on the sub-processors and infrastructure used. Where required, we rely on standard contractual clauses or other lawful transfer mechanisms.
10. Users in Mainland China (PIPL)
If you are located in mainland China, please note: when you use the Service, your personal data and the customer data you provide are transferred outside mainland China to recipients including our LLM sub-processors (OpenAI, Anthropic, and Google, based in the United States) and our hosting infrastructure (region varies). Recipients process your data only to operate the Service for you.
Cross-border transfer of personal information requires your separate consent under the Personal Information Protection Law (个人信息保护法). By creating an account and using the Service, you provide such separate consent for the transfers described above. You may withdraw this consent at any time by deleting your account, in which case we will cease the cross-border transfer (note: the Service cannot be operated without it).
We do not knowingly process sensitive personal information (e.g., biometrics, financial-account credentials, minors' data) without obtaining additional separate consent. The Service is not intended for the processing of sensitive personal information.
11. Security
We use TLS for data in transit, encrypt sensitive fields at rest where feasible, hash passwords, and apply access controls and audit logging on production systems. No system is fully secure; we cannot guarantee absolute protection.
12. Children
The Service is not intended for users below the age of digital consent in their jurisdiction (16 in EU member states unless local law sets a lower age, 13 in the U.S. and U.K., and the relevant minimum elsewhere). We do not knowingly collect personal data from minors. If we learn that we have, we will delete it.
13. Changes
We may update this policy. Material changes are notified by email or an in-product notice. Where applicable law requires fresh consent for new processing purposes, we will obtain it before they apply to you. The "Last updated" date above reflects the current version.
14. Contact
For privacy questions, data requests, or complaints: