Legal

Privacy

Last updated: September 11, 2026

What we collect

When you create an account we store your email address and a salted, hashed password. We never see or store your raw password.

Your conversations, tasks and built sites are stored so the workspace can resume where you left off.

Shipped sites count page views and unique visitors. The beacon sends only a per-visitor id and the page path — no names, no email, no browsing history.

Cookies and local storage: an httpOnly session cookie keeps you signed in, and local storage remembers interface choices such as whether onboarding was completed. Ads load in a separate A-ADS frame and may be subject to the provider’s own storage and privacy practices.

What we do with it

Your prompts and attachments are sent to the model or media provider needed to complete your request. Research queries go to the configured search provider; connected app actions go through Composio; advertisements load from A-ADS. We do not sell or rent your account data.

Your wallet private key is generated locally by the server, encrypted at rest (AES-GCM) and never leaves the backend or appears in the app.

What you can do

Your data is yours. You can delete conversations and sites, and you can request access, correction, export or deletion of your account data by emailing clanker.arena@gmail.com.

Credits are per-day and non-refundable — the daily allowance resets at midnight UTC by design. Referral bonus credits never expire.

Where it lives

Production data is stored in the encrypted, access-controlled storage attached to our Azure virtual machine. Model, integration and advertising providers may process limited request data in other countries under their own safeguards.

We keep this policy accurate; when it changes we update this page and note the date below.

Contact

Questions about your data? clanker.arena@gmail.com — answered by a human.