Przejdź do zawartości

OpenClaw Drive Privacy Policy

Effective date: 4 October 2026

1. Operator and contact

OpenClaw Drive is operated by A.STUDIO SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Gdańsk, Poland, KRS 0001144640, NIP 5842861805, REGON 540429280 ("A.Studio", "we", "us").

Privacy and data-access questions may be sent to [email protected].

2. Purpose of OpenClaw Drive

OpenClaw Drive is a private business integration used by authorized A.Studio personnel for accounting, payroll, HR, and reporting workflows. It connects to Google Drive only after an authorized Google account owner grants OAuth consent.

3. Google user data accessed

The application may access the following Google Drive data:

  • file and folder names, identifiers, MIME types, sizes, dates, and other metadata;
  • folder structure and capabilities needed to locate an approved destination;
  • the content of a document specifically requested for an authorized business workflow;
  • files submitted by an authorized user for upload to an approved destination; and
  • OAuth credentials and refresh tokens needed to maintain the authorized connection.

The application requests the https://www.googleapis.com/auth/drive scope because a headless business integration must work with an existing A.Studio Drive folder tree. Application-level controls restrict supported operations to configured and approved locations below the A.Studio root folder.

4. How Google user data is used

Google user data is used only to:

  • locate and read a file or folder requested by an authorized user;
  • extract information needed for the requested accounting, payroll, HR, or reporting task;
  • upload an approved document to a predefined destination;
  • create a predefined reporting folder when expressly requested;
  • verify the result of an authorized operation and prevent duplicate uploads; and
  • maintain, secure, troubleshoot, and audit the integration.

OpenClaw Drive does not expose commands to delete, move, overwrite, or change permissions on Google Drive items. It does not use Google user data for advertising, profiling, creditworthiness, or sale to data brokers.

5. Automated and service-provider processing

When an authorized user requests a workflow, relevant Drive metadata or document content may be processed within A.Studio's private OpenClaw environment and by infrastructure or AI model service providers acting on A.Studio's instructions. Such processing is limited to providing the user-requested feature, security, troubleshooting, and legally required operations. Google user data is not made public or transferred for advertising purposes.

Authorized A.Studio personnel may view specific files or derived information when this is required for the requested business workflow, security investigation, or legal compliance.

6. Storage and retention

<ul><li>OAuth credentials are stored in a private server directory protected by operating-system access controls.</li><li>Documents uploaded by the application remain in the user's Google Drive until an authorized Drive user removes them.</li><li>Retrieved file metadata, extracted content, and operation results may be retained in private OpenClaw session or audit records for the requested business workflow, security, troubleshooting, and applicable legal retention requirements.</li><li>Data is retained only for as long as reasonably necessary for those purposes and is then deleted or anonymized when no longer required.</li></ul>

7. Sharing and disclosure

We do not sell Google user data. We disclose it only to authorized A.Studio personnel, service providers acting on our instructions to operate the requested feature, or when required for security or by applicable law. Service providers may not use the data for their own advertising or unrelated purposes.

8. Google API Limited Use

OpenClaw Drive's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. 

See the<ahref="https://developers.google.com/terms/api-services-user-data-policy">Google API Services User Data Policy</a>.

9. Security

We apply access controls, private credential storage, least-functionality application commands, duplicate protection, and encrypted network transport. OAuth URLs, authorization codes, client credentials, access tokens, and refresh tokens are not intentionally exposed in public interfaces or ordinary business messages.

10. User choices, revocation, and deletion requests

A Google account owner may revoke the application's access at any time from the Google Account security settings. After revocation, OpenClaw Drive can no longer access that account unless consent is granted again.

To request information about retained data or request deletion where no legal retention obligation applies, contact<ahref="mailto:[email protected]">[email protected]</a>.

11. Changes to this policy

We may update this policy when the application's data practices or legal requirements change. The effective date above will be updated. If a change materially expands how Google user data is used, users will be informed and new consent will be obtained where required before the new use begins.

<ahref="https://www.astudio.club/openclaw-drive">Return to the OpenClaw Drive homepage</a>