1. Scope and summary
This policy applies to the Plawie Android application and this website. Plawie is maintained by the Plawie project team. It does not create a central Plawie cloud account in the current public build and does not include advertising or a cross-site analytics SDK.
Important: “native-first” does not mean every request is offline. The app tells you which model/provider path you selected; you should review that choice before sending sensitive content.
2. Data stored or processed by the app
Working data on your device
Depending on the features you use, Plawie can store setup state, preferences, model/provider selections, conversation and memory data, downloaded models and skill packs, dependency receipts, generated media, logs, and scheduled-task state in app-controlled or user-selected storage.
Credentials and wallet material
Provider API keys, imported wallet material, and cryptographic state are designed to use Android secure storage and device authentication where the feature requires it. They are not uploaded to plawie.app. Clearing app data, deleting the wallet, or uninstalling can make locally held data unavailable; back up only through the app's reviewed export flow.
Data you ask tools to access
When you grant permission and invoke a capability, the app can process camera images, microphone audio, location, files, device sensors, notifications, or screen content needed for that action. A result may become part of the current agent conversation and may be sent to the model provider you selected.
3. Optional product analytics
Plawie can send a small, explicit set of product and reliability events to PostHog only when the app or website build has a valid analytics destination and you choose to turn analytics on. Analytics is not required to download the app, use local or BYOK features, connect a wallet, or participate in the Product Hunt launch.
The analytics event can include a random Plawie installation identifier, a random app or browser-session identifier, event name, timestamp, app or website release channel, platform, a bounded feature or error category, and allowlisted campaign labels such as producthunt. With analytics enabled, the Android app can also record a visible foreground or picture-in-picture session marker and a heartbeat every five minutes while that visible use continues. Passive wake-word listening and background Gateway or foreground-service uptime do not count as active use. The website does not send the page URL, referrer, search terms, or arbitrary UTM values. PostHog and network infrastructure can still receive ordinary connection metadata such as an IP address and browser/user-agent while delivering the request.
Product analytics excludes prompts, assistant responses, transcripts, audio, media, filenames, wallet addresses, balances, transaction hashes, signatures, API keys, provider credentials, raw URLs, raw exceptions, and arbitrary payloads. Person-profile processing, advertising identifiers, autocapture, and session replay are disabled.
Turning analytics off stops new analytics events and removes Plawie’s analytics identifier and pending analytics state from local app or browser storage. Previously delivered pseudonymous events may remain under the analytics service’s configured retention. Because Plawie does not attach an account, email, wallet, or hardware identity to these events, do not treat an analytics installation as a verified person.
4. Connected services
Plawie connects to third parties only as needed for features you select. Their own policies and account terms apply.
- Model providers: prompts, attachments, tool results, model identifiers, and request metadata needed to generate a response.
- OpenClaw, GitHub, package registries, and ClawHub: version checks, release downloads, skill metadata, and optional dependency packs during setup or repair.
- Blockchain networks and explorers: public addresses, balances, network identifiers, transaction data, and RPC requests when you use wallet features.
- Reown and external wallets: session and routing metadata required to connect a wallet that you select.
- LI.FI or another displayed bridge provider: token, chain, address, amount, quote, route, and transaction-status data needed for a bridge request.
- PostHog: only the consented, pseudonymous product-analytics events described above when analytics is configured and enabled.
Blockchain transactions and addresses are public by design and can remain visible permanently. Do not treat a public wallet address as private information.
5. Android permissions
Plawie can request Android permissions for internet access, notifications, foreground operation, microphone, camera, location, storage/files, overlays, device sensors, vibration, alarms, wake locks, media projection, and biometric/device authentication. Availability varies by Android version.
Grant only the permissions needed for features you intend to use. Android Settings lets you revoke most permissions later. Revoking a permission can disable the related skill or tool. The app should request runtime-gated sensitive access near the feature that needs it; a manifest declaration alone does not mean Plawie continuously collects that data.
6. Website data
This static site is delivered by Netlify. Like most hosting and security services, Netlify may process request information such as IP address, browser/user-agent, requested URL, timestamp, and security events in infrastructure logs. The site itself does not set a marketing cookie, load an advertising pixel, or include a visitor-account form.
Following a link to a model provider, wallet, or another third-party site moves you under that site's privacy policy.
7. Retention, deletion, and your choices
- Use Android's app settings to review permissions, clear local app data, or uninstall Plawie.
- Use Plawie's own controls to delete supported conversations, downloaded assets, credentials, and wallet state before uninstalling where you need a selective deletion.
- Manage or delete provider data and accounts through the provider that received it.
- Do not post keys, wallet recovery material, private logs, personal conversations, or sensitive images in a public GitHub issue.
Local data generally remains until you delete it, clear app data, or uninstall. Public blockchain records cannot be deleted by Plawie. Third-party retention is controlled by the relevant provider.
Children
Plawie is not directed to children under 13. Wallet, model-provider, and exchange-related services may set higher age requirements in their own terms.
Security
We use platform protections and design controls appropriate to the feature, but no device, network, wallet, or software system is risk-free. Keep Android updated, protect your device lock, verify every transaction, and never share a recovery secret.
8. Changes and contact
Material changes will update the effective date and the public site history. For a privacy question or deletion-path problem, use the support page or contact @plawie_app on X / Twitter. Never include sensitive data, credentials, private wallet material, or personal conversations in a public message.