What we monitor
OneClickClaw monitors server activity for security and compliance purposes. The categories we observe are:
- SSH session metadata, including login times, source IP addresses, session durations, and the commands executed during the session.
- Network connection metadata, including destination IP addresses, ports, and byte counts (no packet contents).
- Filesystem metadata, including file names, sizes, and last-modified timestamps (no file contents).
- Listening ports, including the port number and the name of the process listening on it.
What we do not monitor
We do not read the contents of your business data, your customer conversations, your AI provider responses, or any files on your server, unless we are actively investigating an alert from monitoring or responding to a valid legal request.
We never have access to your AI provider API key. It is encrypted on your VPS and used only by OpenClaw at runtime. See API Key Security for details.
Why we monitor
Monitoring lets us:
- Detect outbound abuse such as DDoS-shaped traffic or port scans.
- Detect compromised servers (malware, cryptominers, botnet activity).
- Respond to legal notices (DMCA, abuse complaints) with evidence and a clear timeline.
- Honour our partnership obligations to Webdock, who provides the underlying infrastructure.
The legal basis under GDPR Article 6(1)(f) is "legitimate interest": keeping the platform safe for all customers and meeting our contractual obligations to our infrastructure partner.
How long monitoring data is kept
Monitoring data is retained for up to 90 days, then deleted automatically. The only exception is when a record is part of an active investigation or legal proceeding, in which case it is kept for as long as legally required.
Your rights over monitoring data
Under GDPR you have the right to access, correct, and request deletion of personal data we hold about you, including monitoring data. To exercise these rights, email info@oneclickclaw.io. See GDPR Compliance for the full process.
