Last updated: July 31, 2026
Privacy Policy
1. Overview
Clawvisor, Inc., a Delaware corporation ("we," "us," "our"), operates Spirehawk. Spirehawk is a productivity tool for teams working with AI coding agents. It keeps a searchable record of what your agents did, what it cost, and how that work connects to the tickets it belongs to. It has two parts: software that runs on your own Mac, and a cloud service at app.spirehawk.ai. This policy covers both.
It does not cover our public marketing pages at spirehawk.ai, which collect different data through different services and are covered by a separate Marketing Site Privacy Notice. Nothing described in that notice receives data from the product.
Spirehawk is a workplace product. An organization deploys it for its own team, and its administrators choose how its data is handled. Where we process data on that organization's instructions, the organization is the controller and we act as its processor. For account and sign-in information, session records, and product analytics, we are the controller.
A data processing agreement is available on request.
2. What stays on your Mac
Your AI agent — Claude Code, Codex, or Claude Desktop — sends its requests through a small proxy running on your own machine, which passes them to your model provider and streams the reply back. In the standard setup that traffic never touches our servers.
The proxy records what passed through it into a database on your Mac. Because it records complete requests and replies, this includes your prompts, the conversation history your agent resends, system instructions, and the inputs and outputs of tool calls — which for a coding agent routinely means source code, file contents, and shell output. It also records ordinary details such as which model was used, timings, token counts and estimated cost, plus enough information to tell whether an agent is still running.
Captured conversation content is encrypted before it is written. The key sits in a protected file on the same machine. That protects a copied database, a stolen backup, or a detached disk. It does not protect the content from you, from software running as you, or from whoever administers that Mac.
We strip some credentials before writing, but the check is deliberately narrow: it recognizes a few standard token formats and field names, and nothing else. A differently named key or an unusual credential format is not detected. Treat captured content as potentially containing secrets.
Whose provider credential is used. Normally your agent's own credential passes straight through and we never see it. There are two exceptions. Claude Desktop cannot supply its own, so it is served with an Anthropic key we hold. And an administrator can register a provider credential for the organization — held encrypted by us, or in a secret manager they control — in which case requests use theirs rather than yours. Neither is ever returned by our API.
3. What we collect in the cloud service
- Account: your Google account identifier, email address and display name. There are no passwords; sign-in is through Google only, and we ask Google for nothing beyond your email address and basic profile.
- Sessions: for each sign-in, the IP address and browser, when it started, when it was last seen, and whether it was revoked.
- Organization: name, members' email addresses and roles, any department or team, and invitations, which carry the invitee's email address.
- Machines: each enrolled Mac's name, platform, software versions, a device identifier and key, and its applied policy version. No device IP address.
- Usage: for each model request, who and which machine made it, when, the provider and model, token counts, estimated cost, status, duration, and any ticket it was attributed to.
- Conversation state: conversation identifiers, a status chosen from a fixed list, timings, and a one-line summary. Section 5 explains when that summary contains content from your conversation.
- Administration: audit records of administrative actions, including the acting member's email address, and any spend cap set on a member together with the reason given for it.
- Work trackers: if you connect Linear or Jira, the ticket details we read back, plus your access tokens, stored encrypted. Linear is sent your email address in order to find work assigned to you.
Conversation and event identifiers hold no conversation content, but they are persistent and tied to your account, so treat them as personal data.
4. Where conversation content lives
Spirehawk retains conversation content as a core function of the product. Where it is kept depends on your organization's setting:
- On your Mac (the default). Captured content stays encrypted on your own machine and is not uploaded. Only usage details, which carry no conversation content, are centralized. Section 5 covers the one route by which limited conversation text leaves the machine.
- In our cloud as well. If an administrator turns this on, captured content is also uploaded and stored encrypted in our database; the local copy is still written. The keys are held in our own Google Cloud project, so the service can decrypt that content. There is no customer-managed key option.
Either way, tool inputs are stripped out of the usage records that reach us.
We do not sell your data, do not use it for advertising, and do not train models on your conversations.
What we can see. Centralized usage details, conversation-state labels and one-line summaries are ordinary readable data in our database, keyed to your account. Spirehawk staff with production access can read them. A customer-visible approval and audit trail for staff access is not yet built.
5. Conversation state and summaries
Spirehawk uses a language model to label what a conversation is doing — working, waiting on you, finished — and to write a one-line summary of it. Where your organization has cloud processing enabled, limited text from your conversation is sent to our cloud service for this.
Each request carries a capped amount of recent conversation text — on the order of a few messages, not the whole conversation — together with a list of tool names and the previous summary. System instructions, thinking blocks, raw tool arguments and housekeeping calls are left out. Under the default local setting your own machine assembles that request and sends only the trimmed result.
This is on for a workspace created while setting up a Mac — the route someone takes when enrolling their own machine — even though that workspace stores conversations locally. A workspace created from the web console with local storage has it off. It is an organization-level setting with no per-member opt-out, and an administrator can change it at any time.
When it is on, the summary is text derived from your conversation and is stored in our database, subject to the retention in section 12. An administrator can instead require these to stay on members' machines, which deletes the centrally held ones. When it is off, the summary is a fixed placeholder containing no conversation content.
These requests are processed by Google's Gemini models inside our own Google Cloud project, in Google's United States location. We require the provider to retain nothing, and we keep neither the text sent nor the raw reply — only identifiers, model, token counts, cost and status. None of it is used to train a model. You may instead configure your own provider credential on your Mac, in which case the same limited text goes to the provider you choose, under your own relationship with them.
6. Optional integrations
An administrator can switch on integrations that store extra data or send data outside Spirehawk: work trackers such as Linear and Jira; source-code and document connectors used to confirm that work Spirehawk inferred actually exists; organization-wide provider credentials; and additional language-model tasks that propose links between conversations and work. Where these are enabled we store the connection's tokens encrypted, along with the identifiers and titles needed to show the link. Document contents and email bodies are not stored.
Where Spirehawk is configured to write a comment back to a ticket, that comment is visible to anyone who can read the ticket, including people without a Spirehawk account. Turning writeback off stops further updates but does not remove a comment already posted.
7. How we use your data
To run the service; to show AI agent activity, usage and estimated cost to you and to your administrators; to label conversation state and write summaries; to attribute work to tickets where your organization enables it; to apply organization policy and keep organizations separate from one another; to secure the service and investigate abuse; and to provide support.
8. What your administrators can see
An owner or administrator of your organization can see:
- your request, token and estimated-cost totals, against your email address;
- an organization-wide feed of individual model requests, including which machine made each one;
- the IP address and browser of each of your active sessions, and can revoke them;
- every member's email address, name, role, department and team;
- your conversation identifiers and their attribution status, and organization-wide conversation-state counts;
- the audit log, the machine inventory, and any spend cap set on you.
They cannot see, anywhere in the service: your prompts, your agent's replies, your transcripts, your summaries, your searches, or any tool input or output. This is a limit on what the service makes available to administrators. It is not a statement about where that content is stored, which section 4 describes.
Spirehawk reports usage and estimated cost per member, and an administrator can group usage by member and sort it by spend. It does not produce a productivity score, treat idle time as a performance signal, rank people on their output, or generate comparative language about individuals.
Telling employees is the organization's responsibility. The organization deploying Spirehawk is responsible for informing its people that their AI agent activity is observed, and for any notice, consent or works-council obligation that follows. We document what is visible; we do not send notices on an organization's behalf.
9. Cookies and browser storage
In the product there are no advertising cookies and no cross-site tracking. The web console sets two strictly necessary cookies, both short-lived, limited to a single page, and not readable by scripts running in the page: one to download the desktop application, one to authenticate the live activity feed. Your session token and sign-in state are held in browser storage that your browser clears when the tab closes.
Our public marketing pages at spirehawk.ai set an optional analytics cookie, which visitors can decline or switch off. Nothing collected there is connected to your Spirehawk account, and the Marketing Site Privacy Notice covers it.
10. Product analytics
We use PostHog for product analytics in the web console and the desktop application. It is off unless an analytics key is configured for the deployment.
Sent: which screen was used, which API route was called with identifiers replaced by placeholders, a status, a duration, and a short fixed list of properties including the provider and model your agent used. The permitted properties are a fixed list.
Not sent: prompts, replies, transcripts, summaries, tool data, file paths, search text, or credentials. Your user identifier, organization, email address and role are explicitly excluded, and email-shaped values are redacted. The model name is passed through as your agent supplies it, so a custom model name you configure appears as you set it.
No account identity is sent. We create no person profile, and the analytics identifier is generated by PostHog's own library rather than derived from your account. We do not record your screen, capture your clicks automatically, or track the pages you visit.
IP address. PostHog receives the request IP address, retains it, and derives an approximate location from it. Standard details such as browser and screen size are also sent.
Signing out rotates the analytics identifier. Do Not Track is respected and is the only opt-out.
11. Sub-processors
- Google Cloud Platform — hosting, database, key management, file storage, sign-in, and the Gemini models used for conversation state and summaries described in section 5.
- PostHog — product analytics when enabled, ingesting to its United States region.
The service runs in the United States on Google Cloud Platform. Google processes data as a sub-processor under its Cloud Data Processing Addendum.
Your model provider is normally your own relationship, not our sub-processor. By default your agent's requests go to the provider it is already configured for, under your own credential, and we are not a party to that relationship. The exceptions are the two in section 2. Anything you or your administrator connects under section 6 receives data at your organization's direction and is governed by that provider's own terms.
12. How long we keep things
There is no single retention period.
Conversation content and anything derived from it. Your organization sets a retention window, which defaults to 30 days and can be set by an administrator to any value from 1 to 3650 days. On your Mac, expired content is deleted when Spirehawk starts and every 24 hours after that. Centrally held summaries and state records — and, where cloud storage is on, the stored content — are deleted on the same window, measured from when we received the record rather than from your machine's clock. Anything derived from a conversation inherits its retention, so a summary cannot outlive its source. Usage records still waiting to reach us sit in a queue that this cleanup deliberately leaves alone, so a temporary outage cannot lose them.
Fixed dashboard clocks. Per-member usage figures are retained for 30 days and session counts for 48 hours, regardless of the organization's window and not settable by an administrator.
For as long as the organization exists. Usage and cost records, work-attribution records, audit records, notification records and spend caps. No implemented process deletes these, and the conversation retention window does not govern them.
Indefinitely, tied to your account rather than to an organization. Your account record and your session records — including the IP address and browser of every sign-in — are keyed to you, not to any organization. They persist even if you never join one, and they outlive your leaving one. A session token is valid for 30 days and is never extended, but its expiry or revocation does not delete the session record. Nothing in the service deletes these.
Backup retention and expiry are not yet defined, and there is no legal-hold capability.
13. Deletion and data requests
You can ask for access to, correction of, or deletion of your personal data by emailing support@spirehawk.ai. The limits below apply today.
- There is no self-serve deletion of an account or of an organization, and no route in the service deletes either. Requests are handled manually, and we do not offer a completion timeline.
- Leaving an organization is not erasure. It ends the membership, clears the organization from your sessions, revokes your machines, and removes your per-member usage rollups, notifications and spend caps. Usage records, audit records, session records including IP address and browser, your account record itself, conversation-state records, invitations and machine records all remain.
- Ending a session does not delete its record. Signing out or revoking a session marks it revoked and invalidates the token; the record, with its IP address and browser, is kept.
- There is no data export. Nothing today produces a portable copy of your data.
For data we handle on your employer's behalf, direct your request to your employer, which is the controller for it; we will support them in responding.
14. Security
Conversation content is encrypted as described in sections 2 and 4. Every endpoint the desktop software ships with uses HTTPS, though it will honour a non-HTTPS endpoint if one is deliberately configured. Traffic between your agent and Spirehawk never leaves your Mac, and Spirehawk refuses to accept a connection from anywhere else unless a development setting is turned on, which no shipped installation turns on.
Requests for an organization's data are confined to that organization, and we test that separation; account and sign-in lookups are keyed to your account or your session instead. Your organization's policy is signed before it reaches an enrolled Mac, and that Mac cannot weaken it. Session tokens are stored in a form that cannot be turned back into the token. The credential a Mac uses when it enrols is stored both that way and encrypted, so a Mac that re-enrols can be issued it again; that one we can recover. Connected work-tracker tokens are likewise stored encrypted. Desktop releases are signed and notarized. Credentials, conversation content, raw tool data and search text are kept out of logs, diagnostics and analytics.
We hold no compliance attestation or audit report, and there is no published availability commitment.
15. Your rights
If you are located in the European Economic Area or the United Kingdom, you have rights under the General Data Protection Regulation including access, rectification, erasure, restriction of processing, portability and objection. Our legal bases for processing are performance of our contract with you in providing the service, and our legitimate interests in security, fraud prevention and improving the service. The service runs in the United States on Google Cloud Platform; transfers of personal data from the EEA or the UK to the United States are governed by Google's Data Processing Addendum, which incorporates Standard Contractual Clauses approved by the European Commission. To exercise any right, contact support@spirehawk.ai. Section 13 sets out the limits that apply today.
16. Children's privacy
Spirehawk is a workplace product. It is not directed at individuals under the age of 18 and we do not knowingly collect personal information from children.
17. Changes to this policy
We may update this policy from time to time. For material changes we will give at least thirty (30) days' notice by email or through a prominent notice within the service. Changes are posted on this page with an updated date.
18. Contact
For questions about this policy, or to exercise any right described in section 13, contact support@spirehawk.ai.