ClawSwap — Privacy Policy

Effective Date: February 16, 2026


1. Introduction

This Privacy Policy describes how ClawSwap and its contributors ("ClawSwap," "we," "us," or "our") collect, use, and share information in connection with the ClawSwap protocol, API, SDK, MCP server, and related services (the "Service"). This policy applies to all Users, including autonomous software agents ("Agents") and their human operators.

ClawSwap is designed as minimal-data infrastructure. We collect only the data necessary to operate the Service, and the majority of information we process is publicly available on-chain data. We do not require user accounts, personal identification, or email registration to use the Service.

2. Information We Collect

2.1 On-Chain Transaction Data

When you use the Service, the following data is recorded on public blockchain networks (Solana and/or Base) and is inherently accessible to anyone:

  • Wallet addresses (source and destination) involved in swap transactions.
  • Transaction hashes, token amounts, and transfer details.
  • x402 payment transaction records (USDC transfers to our treasury wallet).
  • Gas sponsorship transaction records.

This data is part of the public blockchain record. ClawSwap does not create or control this data; it is a consequence of blockchain-based transactions. We may index and aggregate on-chain data related to the Service for operational and analytics purposes.

2.2 API Request Data

When you interact with the ClawSwap API, MCP server, or SDK, we may automatically collect:

  • IP addresses of API callers (for rate limiting and abuse prevention).
  • API endpoint called, request timestamps, and response codes.
  • User-Agent strings and HTTP headers.
  • Request parameters (token types, amounts, chain identifiers, wallet addresses).
  • x402 payment headers and verification status.

2.3 Website Analytics Data

If you visit the ClawSwap website (clawswap.xyz), we may collect standard web analytics data including:

  • Page views, referral sources, and session duration.
  • Browser type, operating system, and device information.
  • Approximate geographic location derived from IP address.

We may use third-party analytics services (such as Vercel Analytics or similar privacy-respecting tools) to process this data.

2.4 Information We Do NOT Collect

ClawSwap does not collect:

  • Names, email addresses, or other personal identifiers (no account registration required).
  • Government-issued identification documents.
  • Private keys, seed phrases, or wallet credentials.
  • Social media profiles or linked accounts.
  • Biometric data.
  • Financial account information beyond on-chain wallet addresses.

3. How We Use Information

We use collected information for the following purposes:

Data Type Purpose Legal Basis
On-chain transaction data Service operation, swap execution and monitoring, analytics dashboards Legitimate interest in operating the Service; data is publicly available
IP addresses Rate limiting, abuse prevention, OFAC compliance screening Legitimate interest in security and legal compliance
API request metadata Performance monitoring, debugging, service improvement Legitimate interest in maintaining and improving the Service
Website analytics Understanding usage patterns, improving user experience Legitimate interest; consent where required by law

4. Data Sharing and Disclosure

ClawSwap does not sell your data. We may share information in the following limited circumstances:

4.1 Blockchain Networks

Transaction data is broadcast to and recorded on public blockchain networks (Solana, Base) as an inherent part of using the Service. This data is permanently and publicly accessible. We have no ability to delete, modify, or restrict access to on-chain data.

4.2 Third-Party Service Providers

We use third-party services to operate the Service. These providers may process data on our behalf:

  • Relay: Bridge provider that processes cross-chain swap transactions. Receives transaction parameters, wallet addresses, and token amounts.
  • Dexter: x402 payment facilitator that verifies USDC payments. Receives payment transaction data.
  • Coinbase CDP: Paymaster service for gas sponsorship on Base (Phase 2). Receives transaction calldata and wallet addresses.
  • Vercel: Hosting provider for API and website. May process IP addresses and request metadata through their infrastructure.

Each of these providers operates under their own privacy policies. We encourage you to review them.

4.3 Legal Requirements

We may disclose information if we believe in good faith that disclosure is necessary to: (a) comply with applicable law, regulation, or legal process; (b) enforce our Terms of Service; (c) protect the rights, property, or safety of ClawSwap, our users, or the public; or (d) respond to lawful requests by public authorities.

4.4 Aggregated and De-identified Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you. This includes aggregate swap volume statistics, protocol performance metrics, and ecosystem usage data that may be published publicly or shared with partners.

5. Data Retention

  • On-chain data: Retained permanently on public blockchain networks. ClawSwap has no ability to delete on-chain data.
  • API server logs (including IP addresses): Retained for up to 90 days, then automatically purged or anonymized.
  • API request metadata: Retained in aggregated/anonymized form for up to 12 months for analytics purposes.
  • Website analytics: Retained according to the policies of our analytics provider, typically up to 24 months.

We retain data only as long as necessary for the purposes described in this policy or as required by law.

6. Data Security

We implement reasonable technical and organizational measures to protect data processed by the Service, including encryption of data in transit (TLS), access controls on infrastructure, and regular security reviews. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

You are responsible for maintaining the security of your wallet private keys and any credentials used to interact with the Service. ClawSwap will never request your private keys or seed phrases.

7. Your Rights

Depending on your jurisdiction, you may have certain rights regarding your personal data:

  • Access: You may request information about the data we hold about you.
  • Correction: You may request correction of inaccurate data.
  • Deletion: You may request deletion of data we hold about you, subject to legal retention requirements. Note that on-chain data cannot be deleted.
  • Objection: You may object to processing of your data for certain purposes.
  • Data Portability: You may request a copy of your data in a structured, machine-readable format.

To exercise any of these rights, please contact us at legal@clawswap.xyz. We will respond to requests within 30 days or as required by applicable law.

Because ClawSwap does not require user accounts or collect personal identifiers, we may be unable to associate API request data with a specific individual. In such cases, we may ask you to provide additional information to verify your identity before processing your request.

8. Autonomous Agent Considerations

The Service is designed for use by both humans and autonomous software agents. The following additional considerations apply to Agents:

  • Data submitted by Agents to the Service is treated identically to data submitted by human users under this policy.
  • The human operator or principal who deploys an Agent is responsible for ensuring the Agent's interactions with the Service comply with this policy and applicable data protection laws.
  • Agents should not submit personal data of third parties to the Service without appropriate authorization.
  • x402 payment data generated by Agents is subject to the same retention and processing terms as human-initiated payments.

9. International Data Transfers

The Service is operated globally and data may be processed in jurisdictions outside your country of residence. By using the Service, you consent to the transfer and processing of data in such jurisdictions. We will take reasonable steps to ensure that data transfers comply with applicable data protection laws.

10. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete that information promptly.

11. Cookies and Tracking Technologies

The ClawSwap website may use essential cookies required for basic site functionality. We do not use advertising cookies or cross-site tracking technologies. If third-party analytics tools are deployed, they may set their own cookies subject to their respective privacy policies. You can control cookie settings through your browser preferences.

The ClawSwap API does not use cookies. API interactions are stateless and authenticated solely through x402 payment headers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be communicated through our website, API documentation, or response headers. The "Effective Date" at the top of this policy indicates when it was last revised. Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at legal@clawswap.xyz.


Last updated: February 16, 2026