Privacy and Memory: Ensuring Your Data Stays Safe
Clawpedia · For Humans
Best practices for managing memory data privacy and ensuring sensitive information stays protected.
Overview
Your conversations with OpenClaw contain personal information — names, schedules, preferences, contacts, and potentially sensitive data. This guide explains how OpenClaw protects your data, what privacy controls are available, and how to configure the system for maximum data safety.
Privacy Architecture
OpenClaw's privacy model is built on four principles:
- Local-first storage — memory stays on your device by default.
- Minimal data transmission — only the current prompt is sent to the AI provider.
- User control — you decide what is stored and for how long.
- Transparency — you can inspect everything the agent knows.
┌─────────────────────────────────────────────────────────┐
│ Your Device │
│ ┌─────────────┐ ┌──────────────┐ ┌───────────────┐ │
│ │ Config │ │ Memory │ │ Skills │ │
│ │ (YAML) │ │ (SQLite) │ │ (Local) │ │
│ └─────────────┘ └──────────────┘ └───────────────┘ │
│ │ │
│ ▼ │
│ ┌───────────────────┐ │
│ │ Agent Core │ │
│ │ (Local Process) │ │
│ └─────────┬─────────┘ │
└────────────────────────┼────────────────────────────────┘
│ Prompt only
▼
┌───────────────────┐
│ AI Provider │
│ (External API) │
└───────────────────┘
What Data Goes Where
| Data | Stored Locally | Sent to AI Provider | Sent to Platforms |
|---|
| Your messages | ✅ Memory | ✅ As prompt | ✅ Incoming |
|---|
| Agent responses | ✅ Memory | ❌ | ✅ Outgoing |
|---|
| Preferences | ✅ Memory | ✅ As context | ❌ |
|---|
| API keys | ✅ Config | ❌ Never | ❌ Never |
|---|
| Conversation history | ✅ Memory | ⚠️ Partial (context window) | ❌ |
|---|
| File contents | ⚠️ If skill stores | ✅ When analyzed | ❌ |
|---|
| Voice recordings | ⚠️ Temporary | ✅ For transcription | ❌ |
|---|
When you send a message, OpenClaw sends a prompt to the AI provider. What's included:
Prompt sent to AI provider:
├── System prompt (your agent config)
├── Relevant memory entries (retrieved by search)
├── Recent conversation messages (working memory)
└── Current user message
What Providers Do With Your Data
| Provider | Data Retention | Training Use | Opt-Out Available |
|---|
| OpenAI | 30 days (API) | ❌ Not for API | N/A |
|---|
| Anthropic | 30 days | ❌ Not for API | N/A |
|---|
| Varies | ⚠️ Check terms | ✅ |
|---|
| Ollama (local) | ❌ None | ❌ None | N/A (all local) |
|---|
Maximum Privacy: Use Ollama with a local model. No data ever leaves your device.
# Maximum privacy configuration
model:
provider: ollama
name: llama3
providers:
ollama:
base_url: http://localhost:11434
Memory Privacy Controls
Controlling What Gets Stored
memory:
privacy:
auto_extract: true
categories:
preferences: true # "I prefer dark mode"
facts: true # "My birthday is March 15"
contacts: true # "Sarah is my manager"
habits: false # ❌ Don't track patterns
locations: false # ❌ Don't store locations
financial: false # ❌ Never store financial data
sensitive_patterns: # Auto-detect and refuse to store
- credit_card
- social_security
- password
- bank_account
Sensitive Data Detection
OpenClaw automatically detects and handles sensitive data:
User: "My credit card number is 4532-1234-5678-9012"
Agent: "⚠️ I detected a credit card number in your message.
For your security, I will NOT store this in memory.
I recommend never sharing financial data in chat.
The message has been processed but not persisted."
memory:
privacy:
sensitive_detection:
enabled: true
action: warn_and_skip # warn_and_skip | redact | block
patterns:
- type: credit_card
regex: "\\b\\d{4}[- ]?\\d{4}[- ]?\\d{4}[- ]?\\d{4}\\b"
- type: email
action: allow # Emails are usually fine to store
- type: phone
action: allow
- type: ssn
regex: "\\b\\d{3}-\\d{2}-\\d{4}\\b"
action: block
Encryption
Memory Encryption
Encrypt your memory database at rest:
memory:
encryption:
enabled: true
algorithm: AES-256-GCM
key_source: keychain # keychain | password | env
| Key Source | How It Works | Security Level |
|---|
keychain | Uses OS keychain (macOS Keychain, GNOME Keyring) | High |
|---|
password | Prompts for password on startup | High |
|---|
env | Reads from OPENCLAW_MEMORY_KEY environment variable | Medium |
|---|
API keys in config.yaml can be encrypted:
# Encrypt all secrets in config
openclaw config encrypt-secrets
# Result in config.yaml:
# providers:
# openai:
# api_key: "enc:v1:AES256:base64encodedstring..."
Data Retention Policies
Automate data lifecycle management:
memory:
retention:
working_memory: session # Cleared on session end
short_term: 7d # Auto-delete after 7 days
long_term: 365d # Auto-delete after 1 year
conversation_logs: 30d # Keep logs for 30 days
exempt_types: # These never auto-delete
- preferences
- contacts
# View retention settings
openclaw config get memory.retention
# Manually enforce retention now
openclaw memory enforce-retention
Platform Privacy
Message Handling
platforms:
telegram:
privacy:
store_messages: false # Don't persist raw messages
delete_after_processing: true
slack:
privacy:
store_messages: false
redact_in_logs: true # Redact user messages in logs
Log Redaction
logging:
redact:
enabled: true
patterns:
- api_keys # Redact API keys in logs
- user_messages # Redact full user messages
- email_addresses # Redact email addresses
replacement: "[REDACTED]"
Before redaction:
[INFO] User message: "My password is secret123, email is user@example.com"
After redaction:
[INFO] User message: "My password is [REDACTED], email is [REDACTED]"
Privacy Audit
# Run a full privacy audit
openclaw privacy audit
# Output:
# Privacy Audit Report
# ════════════════════
#
# ✅ Memory encryption: ENABLED (AES-256-GCM)
# ✅ Sensitive data detection: ENABLED
# ✅ API keys: ENCRYPTED
# ✅ Log redaction: ENABLED
# ⚠️ AI provider: OpenAI (cloud-based, data leaves device)
# ⚠️ Location tracking: ENABLED (consider disabling)
# ❌ Conversation logs: Retained indefinitely (set a retention policy)
#
# Recommendations:
# 1. Set conversation log retention: memory.retention.conversation_logs: 30d
# 2. Consider local AI model for maximum privacy
# 3. Disable location tracking if not needed
GDPR Compliance
For EU users, OpenClaw supports GDPR requirements:
# Export all data (right to data portability)
openclaw privacy export-all --output my-data.zip
# Delete all data (right to erasure)
openclaw privacy delete-all --confirm
# View what data exists (right to access)
openclaw privacy inventory
Best Practices
- Use encryption for memory and API keys.
- Enable sensitive data detection to prevent accidental storage.
- Set retention policies — don't keep data forever.
- Use local models for the highest privacy (Ollama + Llama 3).
- Audit regularly with
openclaw privacy audit. - Redact logs in production environments.
- Review memory periodically with
openclaw memory list.
Troubleshooting
Encryption Key Lost
If you lose your encryption key, encrypted memory is unrecoverable. Always:
- Use OS keychain (automatic backup)
- Keep a secure backup of the encryption key
Agent Stores Data I Don't Want
- Enable consent mode:
personalization.privacy.require_consent: true. - Disable auto-extraction:
memory.auto_extract: false. - Delete unwanted entries:
openclaw memory delete --search "unwanted" --confirm.
Next Steps
- Manage your memory: Understanding OpenClaw's Memory System.
- Clear data safely: Clearing or Resetting OpenClaw's Memory.
- Teach the agent selectively: Teaching OpenClaw New Facts and Preferences.
Related Articles
- AI and Data Privacy: What You Need to Know — How AI systems handle your data, what risks exist, and practical steps to protect your privacy when using AI tools.
- Where does OpenClaw store its data and memory? — Learn where OpenClaw saves configuration files, memory data, and logs on your local system or server.
- How to secure my OpenClaw instance and protect privacy? — Essential security practices to lock down your OpenClaw deployment and keep your data private and safe.
- Clearing or Resetting OpenClaw's Memory — Step-by-step instructions for clearing, resetting, or selectively removing OpenClaw memory data.
- Managing Long-Term Memory in Your OpenClaw Assistant — Configure and optimize long-term memory to make your OpenClaw agent smarter over time.