No training on your data
Your prompts stay private. tk_claw never trains on user inputs.
Privacy
Transparent privacy. No training on your prompts. Domestic hosting by default.
Principles
Six core commitments.
Your prompts stay private. tk_claw never trains on user inputs.
US-hosted inference by default. EU option available for GDPR.
Premium escalation goes directly to your API key. Toolklaw never sees it.
Zero-day deletion available. Logs don't roll longer than you allow.
Team workspaces get full routing audit trail. Know where every request went.
Toolklaw by Toolkit. OpenClaw-native architecture. Fully transparent routing.
Technical
From your agent to inference and back.
Toolklaw never stores, logs, or trains on your input. Goes straight to inference.
tk_claw runs on Cloudflare Workers. Your data doesn't touch Anthropic systems.
Result goes back to your OpenClaw gateway. No secondary storage or logging.
We log that a request happened, cost, and model. No prompt/response content.
Request immediate deletion. Logs purge within 24 hours. No backups kept.
Premium escalation sends to your GPT key directly. Toolklaw never sees it.
Compliance
Industry best practices and legal requirements.
GDPR-compliant. EU data hosted in EU-only infrastructure. Data subject rights honored.
HIPAA Business Associate agreement available. Encrypted at rest and in transit.
SOC 2 Type II certified. Annual audits. Security practices verified by third parties.
All data encrypted at rest. TLS 1.3 in transit. Keys rotated quarterly.
Cloudflare only (infrastructure). No data brokers or AI training providers.
Standard DPA available for enterprise customers. Custom terms on request.
Control
You control your data handling.
Default: 30 days. Change to 7, 14, 90, or 365 days. Zero-day available on request.
Default: US. Switch to EU, Canada, or Singapore. Affects all infrastructure.
Team workspaces get full audit trail. Access, modifications, deletions all logged.
Download your data as JSON. Configuration, API keys, usage history included.
Request account deletion. All data purged within 30 days. No recovery available.
Email privacy@toolklaw.com. Questions about your data? We respond within 2 days.
Questions
What you need to know.
No. Never. We don't use your data for model training, fine-tuning, or research.
Yes. Sign a BAA (Business Associate Agreement) in your dashboard. Covers all data.
US by default (Cloudflare edge). EU, Canada, Singapore options available.
Default 30 days. Configurable to 7, 14, 90, 365 days, or zero-day deletion.
We honor all data subject rights: access, correction, erasure, portability. Contact dpo@toolklaw.com.
Settings → Account → Danger Zone. Data deleted within 30 days. No recovery.
Legal
All the detail you need.
Last updated: March 14, 2025
Toolklaw by Toolkit ("we", "our", or "us") operates the Toolklaw website and service. This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our service.
We collect information you voluntarily provide (account creation, settings). We also collect usage data: which models you call, how many tokens, error rates. We do NOT collect or store your prompts or responses.
We use collected data to:
Configurable retention (default 30 days). Account data kept until deletion requested. Audit logs kept per compliance requirements.
Data encrypted at rest (AES-256) and in transit (TLS 1.3). Regular security audits. SOC 2 Type II certified.
You have the right to: access your data, correct inaccuracies, request deletion, export in portable format, restrict processing, and lodge complaints.
Questions? Contact dpo@toolklaw.com or write to:
Toolklaw Privacy
San Francisco, CA 94105
USA
Your data stays yours. No training. No selling. No surprises.