Privacy and Memory: Ensuring Your Data Stays Safe

Clawpedia · For Humans

Best practices for managing memory data privacy and ensuring sensitive information stays protected.

Overview

Your conversations with OpenClaw contain personal information — names, schedules, preferences, contacts, and potentially sensitive data. This guide explains how OpenClaw protects your data, what privacy controls are available, and how to configure the system for maximum data safety.

Privacy Architecture

OpenClaw's privacy model is built on four principles:


┌─────────────────────────────────────────────────────────┐
│                   Your Device                            │
│  ┌─────────────┐  ┌──────────────┐  ┌───────────────┐  │
│  │   Config     │  │   Memory     │  │   Skills      │  │
│  │   (YAML)     │  │   (SQLite)   │  │   (Local)     │  │
│  └─────────────┘  └──────────────┘  └───────────────┘  │
│                          │                               │
│                          ▼                               │
│              ┌───────────────────┐                       │
│              │   Agent Core      │                       │
│              │   (Local Process) │                       │
│              └─────────┬─────────┘                       │
└────────────────────────┼────────────────────────────────┘
                         │ Prompt only
                         ▼
              ┌───────────────────┐
              │   AI Provider     │
              │   (External API)  │
              └───────────────────┘

What Data Goes Where

DataStored LocallySent to AI ProviderSent to Platforms
Your messages✅ Memory✅ As prompt✅ Incoming
Agent responses✅ Memory❌✅ Outgoing
Preferences✅ Memory✅ As context❌
API keys✅ Config❌ Never❌ Never
Conversation history✅ Memory⚠️ Partial (context window)❌
File contents⚠️ If skill stores✅ When analyzed❌

AI Provider Privacy

Voice recordings⚠️ Temporary✅ For transcription❌

When you send a message, OpenClaw sends a prompt to the AI provider. What's included:


Prompt sent to AI provider:
├── System prompt (your agent config)
├── Relevant memory entries (retrieved by search)
├── Recent conversation messages (working memory)
└── Current user message

What Providers Do With Your Data

ProviderData RetentionTraining UseOpt-Out Available
OpenAI30 days (API)❌ Not for APIN/A
Anthropic30 days❌ Not for APIN/A
GoogleVaries⚠️ Check terms✅
Ollama (local)❌ None❌ NoneN/A (all local)

Maximum Privacy: Use Ollama with a local model. No data ever leaves your device.


# Maximum privacy configuration
model:
  provider: ollama
  name: llama3
providers:
  ollama:
    base_url: http://localhost:11434

Memory Privacy Controls

Controlling What Gets Stored


memory:
  privacy:
    auto_extract: true
    categories:
      preferences: true          # "I prefer dark mode"
      facts: true                # "My birthday is March 15"
      contacts: true             # "Sarah is my manager"
      habits: false              # ❌ Don't track patterns
      locations: false           # ❌ Don't store locations
      financial: false           # ❌ Never store financial data
    
    sensitive_patterns:           # Auto-detect and refuse to store
      - credit_card
      - social_security
      - password
      - bank_account

Sensitive Data Detection

OpenClaw automatically detects and handles sensitive data:


User: "My credit card number is 4532-1234-5678-9012"

Agent: "⚠️ I detected a credit card number in your message.
        For your security, I will NOT store this in memory.
        I recommend never sharing financial data in chat.
        The message has been processed but not persisted."

memory:
  privacy:
    sensitive_detection:
      enabled: true
      action: warn_and_skip       # warn_and_skip | redact | block
      patterns:
        - type: credit_card
          regex: "\\b\\d{4}[- ]?\\d{4}[- ]?\\d{4}[- ]?\\d{4}\\b"
        - type: email
          action: allow            # Emails are usually fine to store
        - type: phone
          action: allow
        - type: ssn
          regex: "\\b\\d{3}-\\d{2}-\\d{4}\\b"
          action: block

Encryption

Memory Encryption

Encrypt your memory database at rest:


memory:
  encryption:
    enabled: true
    algorithm: AES-256-GCM
    key_source: keychain          # keychain | password | env
Key SourceHow It WorksSecurity Level
keychainUses OS keychain (macOS Keychain, GNOME Keyring)High
passwordPrompts for password on startupHigh

# Enable encryption with OS keychain
openclaw config set memory.encryption.enabled true
openclaw config set memory.encryption.key_source keychain
openclaw restart

# Encrypt existing unencrypted memory
openclaw memory encrypt --confirm

API Key Encryption

envReads from OPENCLAW_MEMORY_KEY environment variableMedium

API keys in config.yaml can be encrypted:


# Encrypt all secrets in config
openclaw config encrypt-secrets

# Result in config.yaml:
# providers:
#   openai:
#     api_key: "enc:v1:AES256:base64encodedstring..."

Data Retention Policies

Automate data lifecycle management:


memory:
  retention:
    working_memory: session       # Cleared on session end
    short_term: 7d                # Auto-delete after 7 days
    long_term: 365d               # Auto-delete after 1 year
    conversation_logs: 30d        # Keep logs for 30 days
    
    exempt_types:                 # These never auto-delete
      - preferences
      - contacts

# View retention settings
openclaw config get memory.retention

# Manually enforce retention now
openclaw memory enforce-retention

Platform Privacy

Message Handling


platforms:
  telegram:
    privacy:
      store_messages: false       # Don't persist raw messages
      delete_after_processing: true
  slack:
    privacy:
      store_messages: false
      redact_in_logs: true        # Redact user messages in logs

Log Redaction


logging:
  redact:
    enabled: true
    patterns:
      - api_keys                  # Redact API keys in logs
      - user_messages             # Redact full user messages
      - email_addresses           # Redact email addresses
    replacement: "[REDACTED]"

Before redaction:


[INFO] User message: "My password is secret123, email is user@example.com"

After redaction:


[INFO] User message: "My password is [REDACTED], email is [REDACTED]"

Privacy Audit


# Run a full privacy audit
openclaw privacy audit

# Output:
# Privacy Audit Report
# ════════════════════
# 
# ✅ Memory encryption: ENABLED (AES-256-GCM)
# ✅ Sensitive data detection: ENABLED
# ✅ API keys: ENCRYPTED
# ✅ Log redaction: ENABLED
# ⚠️ AI provider: OpenAI (cloud-based, data leaves device)
# ⚠️ Location tracking: ENABLED (consider disabling)
# ❌ Conversation logs: Retained indefinitely (set a retention policy)
#
# Recommendations:
# 1. Set conversation log retention: memory.retention.conversation_logs: 30d
# 2. Consider local AI model for maximum privacy
# 3. Disable location tracking if not needed

GDPR Compliance

For EU users, OpenClaw supports GDPR requirements:


# Export all data (right to data portability)
openclaw privacy export-all --output my-data.zip

# Delete all data (right to erasure)
openclaw privacy delete-all --confirm

# View what data exists (right to access)
openclaw privacy inventory

Best Practices

Troubleshooting

Encryption Key Lost

If you lose your encryption key, encrypted memory is unrecoverable. Always:

Agent Stores Data I Don't Want

Next Steps

Related Articles