Privacy
The relay sees request and response content in transit. This connection is not end-to-end encrypted: the MCP client sends plaintext JSON-RPC within HTTPS to the relay, which forwards it over an encrypted WebSocket. We never store or log message content.
We store OAuth client registrations, hashed tokens and codes, Gateway and grant IDs, and creation and last-used timestamps. Short-lived hashed rate-limit keys and attempt timestamps prevent pairing-code guessing. CIMD metadata is cached for one hour. Expired records are pruned hourly.
Revocation deletes grant data, tokens and authorization codes immediately. Unused client registrations are deleted after 30 days. Used authorization codes and rotated refresh token hashes are kept until expiry to detect replay; they are also deleted on revocation.
No analytics, advertising, or sale of data. Your Gateway retains its own conversations and controls what your agent may do. Contact security@openclaw.ai with privacy or security questions.