Third-Party AI Services & Data Notice

HexClaw is local-first. A request is sent to a provider you configure only when you choose a cloud model or use an “Automatic” option that resolves to a cloud model.

In brief: Cloud models are supplied by the third-party provider you configure. HexClaw does not resell those services or create a provider account for you. Provider pricing, availability, and data practices are governed by that provider. You can switch to a local model or text-only search at any time.

1. Scope of this notice

This page explains what happens when HexClaw Desktop routes a request to a third-party AI provider, including chat, semantic indexing, and semantic retrieval. It supplements our Privacy Policy and Terms of Service.

HexClaw is a local-first, open-source client. Distribution of the client alone does not automatically make hexagon-codes the operator or reseller of the provider you choose. Equally, a party's legal role and responsibilities depend on the actual deployment and features provided, and on who determines the purposes and means of processing—not merely on labels such as “tool” or “wrapper.”

2. When HexClaw contacts a provider

Your choiceWhat happens
Local modelInference runs in the local runtime you configure. That model request is not sent to a cloud AI provider.
Cloud modelWhen you start the relevant action, the client sends the necessary content and credentials to your configured provider endpoint.
AutomaticThe client selects a model under the current availability and policy. If it selects a cloud model, the cloud data path applies and the interface shows the model actually used.
Text-only searchSearch uses locally extracted text and the local full-text index; no embedding provider is called for that search.

“Configured” or “available” does not mean data is being transmitted. A network call is normally made only when you submit a request, start or rebuild an index, or run a semantic query. Network conditions, provider queues, rate limits, and quotas can all affect cloud performance.

3. What semantic indexing sends

In the current knowledge-base embedding path, documents such as PDFs are extracted and split locally. A cloud embedding request contains the normalized text chunks; a semantic retrieval request contains the query text. The embedding request does not include the original PDF file, its original filename, its local filesystem path, or the local full-text index database.

A text chunk may still contain personal information, confidential material, or other sensitive content. Decide whether that content is suitable for the selected provider before choosing a cloud model. Other capabilities—such as chat, image understanding, or an attachment you actively add—may send prompts, context, images, or attachments as needed and are not covered by the “text chunks only” description above.

4. Information a provider may receive

A provider may also process request logs, account information, and device or network data under its own documentation. Its pricing, availability, data retention, use for model training, processing locations, security measures, and deletion options are governed by the latest terms, privacy notice, and account controls it provides to you.

5. Your choices and controls

6. Minors and children's personal information

In mainland China, personal information relating to a child under 14 is sensitive personal information. Where that law applies, processing it requires consent from a parent or other guardian and dedicated processing rules, together with a clear and reasonable purpose, data minimization, and appropriate safeguards.

If you are a parent, guardian, teacher, or school administrator, an adult should configure the model and provider. Remove unnecessary names, contact details, health information, identifiers, facial images, and learning records before transmission. A child should never submit an API key or sensitive material directly to an untrusted endpoint.

This page explains product data flows. It is not a substitute for any notice, consent, separate consent, guardian consent, security assessment, or dedicated policy required by law. A deployer or operator must assess its own purposes, users, context, and jurisdictions and adopt appropriate measures.

7. International transfers and processing locations

If your provider endpoint or its infrastructure is outside your country or region, a request may involve an international transfer of personal information. Before enabling it, review the provider's processing locations, subprocessors, data-residency options, and transfer mechanism, and determine whether notice, separate consent, a standard contract, certification, or security assessment is required. HexClaw does not choose a provider's processing location for you.

8. Security and incident response

9. Service boundaries and statutory rights

Third-party model output can be inaccurate, biased, or unsuitable for a particular purpose. Verify important conclusions and do not rely on unreviewed output for medical, legal, financial, safety, or other high-risk decisions.

Any “as-is” provision in an open-source license and any allocation of liability in a provider's terms apply only to the extent permitted by applicable law. Responsibilities that cannot lawfully be excluded or limited, and the statutory rights of consumers, data subjects, and minors, are not excluded or restricted by this notice.

10. Official references

These references are provided for convenience and are not legal advice for a particular deployment. Consider qualified professional advice for school, healthcare, large-scale personal-information, or international-transfer use cases.

11. Version and changes

Version: 1.0 Effective: 2026-07-19 Last updated: 2026-07-19

We will update this page when model integrations, material data paths, or applicable rules change. Significant product changes will also be noted in the changelog.