Legal
Privacy Policy
Effective date: 13 March 2026 · Last updated: 13 March 2026
The short version: Your agent runs in a dedicated environment. Account services use shared infrastructure with logical tenant separation. AI requests reach external providers. Account deletion has retention exceptions, described below.
1. Who we are
This Privacy Policy describes how Pyratz Labs SAS, a French simplified joint-stock company ("we", "us", "our"), collects, uses, and protects personal data when you use the Mr.Chief platform ("Service").
Data Controller: Pyratz Labs SAS
Privacy contact: privacy@misterchief.ai
Where we act as a data processor on your behalf — for example, when your AI Agents process personal data about third parties (your clients, contacts, etc.) under your instructions — you remain the data controller. Contact us to obtain a Data Processing Agreement (DPA).
2. What data we collect
2.1 Account data
When you register, we collect:
- Email address
- Password (stored as a salted password hash using Django’s password hashing)
- Name (optional, used to personalise your Agent)
- Industry and role (optional, provided during onboarding)
2.2 Agent configuration data
- Agent name, persona, and autonomy settings you configure
- Provider credentials (stored encrypted using Fernet: AES-128-CBC + HMAC-SHA256)
- BYOK API keys (encrypted at rest, never logged in plaintext)
- Communication style and preference settings
2.3 Usage and interaction data
- Messages sent to and received from your AI Agents
- Tasks created, delegated, and completed
- Selected account, billing and infrastructure audit events
- Token consumption metrics
- Optional public-page analytics require a fresh browser choice
2.4 Billing data
- Subscription plan and billing history
- Payment method details — processed and stored by Stripe, Inc. We never see or store your raw card number; we only receive a Stripe payment token
- VAT number (if provided for EU business invoicing)
2.5 Technical data
- IP address (used for fraud prevention and rate limiting; not stored long-term)
- Browser type and operating system (for compatibility purposes)
- Session tokens (stored as HttpOnly cookies; expire on logout or after 24 hours)
- Error logs (anonymised where possible)
2.6 What we do NOT collect
- We do not collect special category data (health, biometric, political opinions, etc.) unless you explicitly provide it through your Agent interactions
- We do not collect data from third parties about you without your knowledge
- Optional advertising measurement requires your separate browser choice; we do not sell your data
3. Legal bases for processing (GDPR Article 6)
| Processing activity | Legal basis |
|---|---|
| Providing and operating the Service | Contract (Art. 6(1)(b)) |
| Processing payments and billing | Contract (Art. 6(1)(b)) |
| Fraud prevention and security | Legitimate interests (Art. 6(1)(f)) |
| Optional public-page analytics and advertising | Separate browser consent; off by default |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Audit logs and dispute resolution | Legitimate interests (Art. 6(1)(f)) |
Where we rely on consent, you can withdraw it at any time from Settings > Privacy without affecting the lawfulness of processing before withdrawal.
4. How we use your data
- To provide the Service: Running your AI Agents, storing your preferences, processing tasks on your behalf.
- To operate your dedicated infrastructure: Provisioning and managing your dedicated OpenClaw runtime on AWS EC2 / Fly.io.
- To communicate with you: Transactional emails (account confirmation, billing receipts, security alerts). Marketing emails only with your explicit consent.
- To ensure security: Fraud detection, abuse prevention, rate limiting, audit logging.
- To improve the Service: Optional public-page analytics require a fresh browser choice; we retain essential operational and error monitoring. External model providers process requests according to their applicable terms and settings.
- To comply with law: Responding to lawful requests from authorities, maintaining required records.
External AI processing: Requests go to your chosen provider or through OpenRouter. Review the provider’s data-use and retention settings before sending sensitive content; the platform does not technically enforce a universal no-training policy across providers.
5. Data sharing and sub-processors
We do not sell your data. Services used to operate the platform include the providers below. Your connected tools and selected AI models may involve additional providers. Contact us for the applicable processing agreements and deployment details.
| Sub-processor | Purpose | Location |
|---|---|---|
| AWS | Coordinator, database and EC2 agent runtimes where configured | Deployment-dependent |
| Fly.io | Agent runtimes where configured, including legacy runtimes during migration | Deployment-dependent |
| Vercel | Frontend hosting | Service-dependent |
| Stripe | Payments and billing | Service-dependent |
| Resend | Email delivery | Service-dependent |
| OpenRouter | Managed model access and routing to model providers | Selected model/provider-dependent |
| Anthropic, OpenAI, xAI, Google Gemini | Optional direct provider keys (BYOK) | Provider-dependent |
| Sentry | Error monitoring when configured | Service-dependent |
BYOK requests use your configured provider credentials. Managed model access uses OpenRouter and the selected model provider. Processing locations and terms depend on the service and configuration; this list is not a guarantee of EU-only processing.
We may also disclose data to law enforcement or courts where required by applicable law, and to our legal or financial advisors under confidentiality obligations.
6. Data retention
| Data category | Retention period |
|---|---|
| Account and profile | Account disabled; email replaced and name cleared. The user row and other profile or linked identity data may remain. Contact us about erasure of retained personal data. |
| Passwords and stored BYOK keys | Cleared during the initial deletion step |
| VM, chats, tasks and related records | Removed asynchronously after external resource cleanup succeeds; failed cleanup is retried |
| Billing, consent and audit records | Retained after deletion; no automatic expiry purge is implemented |
| Operational logs and backups | Separate infrastructure retention; contact us for applicable schedules |
| Optional analytics | Browser choice expires after six months; provider retention and historical records follow applicable requirements |
Closing your account starts a staged cleanup; it does not immediately erase every record. Billing, consent and audit history survives account deletion. The current system does not enforce a scheduled purge of those retained records. Contact privacy@misterchief.ai about retention or erasure requests.
7. International data transfers
Hosting, AI providers and connected services may process data outside the EU/EEA. We do not guarantee EU-only processing. Contact privacy@misterchief.ai for current processing locations, applicable transfer safeguards and agreements for your use case.
8. Your rights under GDPR
As a data subject under the GDPR, you have the following rights. All requests are handled within 30 days (extendable by a further 60 days for complex requests, with notification).
Right of access (Art. 15)
Request a copy of all personal data we hold about you, along with information about how we process it.
Right to rectification (Art. 16)
Request correction of inaccurate or incomplete data. Most data can be updated directly in your account settings.
Right to erasure (Art. 17)
Request deletion of your personal data ('right to be forgotten'), subject to our legal retention obligations. Closing your account triggers automatic erasure.
Right to data portability (Art. 20)
Receive your data in a structured, machine-readable format (JSON). Available from Settings > Account > Export data.
Right to restriction (Art. 18)
Request that we restrict processing of your data while a dispute is being resolved.
Right to object (Art. 21)
Object to processing based on legitimate interests, including direct marketing. Marketing opt-outs take effect immediately.
Right to withdraw consent (Art. 7(3))
Withdraw marketing consent at any time from Settings > Privacy, without affecting prior lawful processing. Use Cookie preferences in the footer to separately withdraw analytics or advertising on this browser.
Right to lodge a complaint (Art. 77)
You have the right to file a complaint with the CNIL (France's supervisory authority) at cnil.fr, or with the supervisory authority in your country of residence.
To exercise any of these rights, contact us at privacy@misterchief.ai with subject line "GDPR Request — [Right]". We may ask you to verify your identity before processing the request.
9. Cookies and tracking
We use a minimal set of cookies, classified as follows:
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| her_auth_token | Authenticated session management | Strictly necessary | 24 hours; server-side session validity is refreshed with authenticated activity |
| csrftoken | Cross-site request forgery protection | Strictly necessary | Session |
| her.locale | Language preference | Functional | 1 year |
| __Host-her.tracking-consent / __Host-her.tracking-pending | Remember and synchronize your optional cookie choice | Preference | Up to 6 months |
| _ga* / _gid | Google Analytics, only after analytics consent | Optional analytics | Provider-configured duration |
| _gcl* / _fbp / _fbc | Advertising measurement, only after advertising consent | Optional advertising | Provider-configured duration |
Analytics (Google Analytics) and advertising measurement (Google Ads, Meta and LinkedIn) are separate optional choices, off by default. Configured vendors load only after a fresh choice on eligible public pages; they remain absent from the private workspace and pages with URL parameters. Providers may process data outside your country. Closing the prompt does not grant consent. Change your choice through Cookie preferences in the footer or Privacy settings. Withdrawal reloads the document to unload vendor code. Essential cookies remain necessary to operate the service. Browser refusal takes priority over account history.
10. Security measures
We implement the following technical and organisational measures to protect your data:
- Encryption in transit: Public service connections use HTTPS.
- Credential encryption: Stored provider credentials use Fernet (AES-128-CBC + HMAC-SHA256). The service manages the encryption keys and decrypts credentials when needed to operate your agent.
- Dedicated runtime: Each user has an OpenClaw runtime on AWS EC2 / Fly.io. Shared coordinator services use logical tenant separation.
- Operational access: Authorized operators may access infrastructure and data for support and maintenance.
- Operational records: Selected account, billing and VM events are recorded; this is not a complete user-facing agent audit log.
For our full security architecture, see our Security page.
11. Children's privacy
The Service is not directed to children under 16 years of age (or the applicable digital age of consent in your country). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will delete it promptly. Contact us at privacy@misterchief.ai if you believe this has occurred.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email (to your registered address) and by posting a banner in the Service at least 30 days before the changes take effect. Your continued use after the effective date constitutes acceptance. Where changes require fresh consent (e.g., new processing purposes), we will collect that consent explicitly before processing begins.
13. Contact and supervisory authority
For any privacy-related question, request, or complaint:
Pyratz Labs SAS
Privacy: privacy@misterchief.ai
You also have the right to lodge a complaint with the French data protection authority:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07