Clawnsole privacy policy

Privacy without a hidden backend.

Clawnsole is a unified client for third-party video generation services across mobile and desktop. The installed desktop and mobile apps contain no analytics or advertising SDKs. The public splash page at clawnsole.app uses Google Analytics with region-aware consent controls, as described below. The developer does not operate an account system or cloud database for project data.

Effective August 27, 2026

You choose storage

Installed apps store data locally and can use a Drive folder you authorize.

Sent deliberately

Prompts and selected media leave the device only when you ask a connected provider to perform a task.

No developer cloud

Clawnsole’s developer does not receive or persist your keys, prompts, media, or project history.

On your device

Data stored locally

Clawnsole stores the information needed to provide its features in the app’s private local storage. Depending on how you use the app, this can include:

  • your selected provider and user-supplied provider API keys;
  • prompts, generation settings, provider job identifiers, status, errors, and estimated or provider-reported usage and cost;
  • reference images, source video, generated video, and local file references;
  • appearance, retention, and other app preferences; and
  • on the clawnsole.app splash page, your analytics consent choice.

Clawnsole has no developer-operated sync service. Local data is not uploaded to a Clawnsole account or developer-operated cloud. Provider API keys are kept in operating-system-backed secure storage rather than the local project-history JSON. Operating-system backups or device-management tools may handle app data according to your device settings and their own policies.

Optional cross-device sync

Data stored in Google Drive

Every installed Clawnsole app can use a Google Drive folder that you authorize to make selected Clawnsole data available across devices. If enabled, prompts, generation records, saved-reference metadata, retained inputs, generated media, folders, and tags are stored there. If you also enable encrypted settings sync, provider API keys and app preferences are uploaded only inside an authenticated encrypted vault. Google processes and retains the project files and encrypted vault under your Google account settings and its privacy policy.

Clawnsole requests the limited drive.file permission, which covers files the app creates or that you explicitly make available to it. Drive access tokens and desktop refresh tokens are not sent to the developer; desktop refresh tokens are stored using operating-system-backed encryption. The settings vault is encrypted on the device with a random key protected by your sync passphrase. The passphrase is not stored. A recovery code is shown once, and an unlocked vault key is cached in device-secure storage so you normally enter the passphrase only once per device. Keep the passphrase and recovery code private.

When you press generate

Data sent to a connected provider

When you ask Clawnsole to verify an account, check a credit balance, load a model catalog or price, or create, monitor, or download a generation, the app communicates directly with the provider you connected. It sends the provider API key and the information required for that request.

Depending on the provider, model, and task, a request can include prompts, settings, reference images, source video and its audio, provider job identifiers, and related request metadata.

Provider processing is separate from Clawnsole’s local storage.

The selected provider may process and retain inputs, outputs, account identifiers, and technical request information under its own terms and privacy policy. Review the applicable documents before sending private or sensitive material.

Black Forest Labs privacy policy Black Forest Labs usage policy LTX Platform privacy policy ArtCraft service Atlas Cloud privacy policy Runway privacy policy Krea privacy policy

Clawnsole currently supports Black Forest Labs (BFL / FLUX 3), LTX, which is operated by Lightricks, ArtCraft, Atlas Cloud, Runway, and Krea. Atlas Cloud and Krea are API aggregation platforms and may forward prompts and generation inputs to the underlying model provider selected for the request, and Runway may do the same for partner models served through its API; that provider’s data-handling and retention policies also apply. Clawnsole is not affiliated with or endorsed by any of these providers.

Apple testing

App Review provider access

An iOS build prepared for App Review may include temporary provider credentials so Apple can test generation without entering keys manually. These credentials are compiled into that build, are not written to Clawnsole’s local data file, and are never displayed in the interface.

Requests made with App Review access are still sent to and processed by the selected provider as described above. A user-supplied key for the same provider takes precedence after it is saved.

Splash-page measurement

Google Analytics on clawnsole.app

The splash page at https://clawnsole.app/ uses Google Analytics to understand visits and interactions, evaluate site performance, and decide what to improve. The Analytics tag is not present on this privacy policy, the terms of use, the hosted web app, or the native macOS, Windows, iOS, and Android apps.

The splash page uses the time zone reported by your browser through JavaScript’s Intl.DateTimeFormat API as a best-effort estimate of whether you are in the European Economic Area, United Kingdom, or Switzerland. This check happens in your browser and is not sent to Clawnsole or a separate IP geolocation service. Because a device time zone can be changed, unavailable, or different from your actual location, it is not a precise country determination. If the time zone is unavailable or ambiguous, Clawnsole shows the consent controls.

When the browser-reported time zone maps to one of those regions, Google Analytics is off by default. The Google tag is not loaded and no data is sent to Google Analytics unless you select Allow analytics. In other detected regions, Analytics loads automatically unless you previously selected Decline. Clawnsole stores an explicit choice in your browser’s localStorage so it can be honored on later visits. Visitors everywhere can open Analytics choices in the splash-page footer. Withdrawing consent disables Analytics, removes accessible Analytics cookies, and prevents it from loading on later visits in that browser.

When Analytics is enabled, Google Analytics may process the splash-page URL, referral information, interactions, session statistics, approximate location, browser and device information, IP addresses for processing and coarse location, and identifiers stored in first-party cookies. Google processes this information under its explanation for sites that use Google services and its privacy policy.

Clawnsole does not intentionally send provider API keys, prompts, reference media, generated media, Google Drive contents, or project history to Google Analytics. Analytics data is used for splash-page audience and product measurement, not advertising or cross-app tracking. Advertising storage, ads user data, ads personalization, Google signals, and ad personalization signals remain disabled. Google Analytics retention is controlled through the Analytics property settings. You can also limit Analytics through your browser’s cookie controls or Google’s Analytics opt-out browser add-on.

A short destination list

Other network requests

The macOS, Windows, iOS, and Android builds ask GitHub’s public releases API whether a newer Clawnsole version exists once per app launch, every 24 hours while running, and when you manually check where that action is available. The request contains no provider API key, prompt, reference media, generated media, or project history. GitHub receives an ordinary web request and its usual connection metadata. The iOS and Android stores still handle installation. Links that you choose to open, such as provider documentation or this policy, open in your web browser and are governed by the destination site’s policy.

What we receive

Data collected by the developer

The installed Clawnsole apps do not send the developer your API key, prompts, reference media, generated media, project history, contacts, precise location, advertising identifiers, or analytics events. The developer can access aggregate and event-level splash-page usage reports for visits where Google Analytics is enabled, as described above. Clawnsole does not use data for advertising or cross-app tracking.

Apple, Google, GitHub, the selected generation provider, any underlying model provider, and the platform through which you install or use Clawnsole may process account, download, purchase, diagnostic, crash, request, or connection information under their own policies and your settings with those services.

You stay in control

Your privacy choices

  • Do not add a provider key if you do not want Clawnsole to contact that provider.
  • Choose which prompts and media to submit for each generation.
  • Add, replace, or remove your provider keys from Providers at any time.
  • Clear generation history, reset preferences, or delete Clawnsole data from Settings.
  • Connect or disconnect optional Google Drive storage, or delete its Clawnsole files from Settings or Drive.
  • Revoke a provider key in the provider’s account dashboard to end its access.
  • Contact the provider directly about data it retains on its systems.

Retention and safeguards

Security and retention

User-supplied provider keys are stored in operating-system-backed secure storage. They are not sent to the developer and are uploaded to Google Drive only inside the optional passphrase- encrypted settings vault. App Review credentials, when present, are compiled into that iOS build and are not written to the local data file or shown in the interface. Keep provider keys private and revoke a key through the provider if you believe it has been exposed.

Clawnsole keeps local data until you remove individual records, use a clear-data control, or uninstall the app. Removing the app may remove data in its sandbox, subject to operating-system backup and device-management behavior. Optional Drive data remains in your Google account until you delete it through Clawnsole or Google Drive. Provider-side retention and deletion are controlled by the selected provider and, for an aggregated model, may also be controlled by the underlying model provider.

Policy maintenance

Changes and contact

This policy may be updated as Clawnsole adds providers or changes how data is handled. Material changes will be reflected on this page with a revised effective date.

For privacy questions, open an issue in the Clawnsole issue tracker. Do not include API keys, private prompts, or personal media in a public issue.