Privacy
What we collect,
which is very little
This page describes the software in this repository rather than a template. Where it says nothing is collected, that is because nothing collects it — there is no analytics script, no cookie, and no third-party request on this website.
Who is responsible
registered company name, street address, postcode and city, Croatia. Questions about this notice, or any request under the sections below, go to privacy@clawharbor.io.
This website
- No cookies. The site sets none. It ships no JavaScript at all, so it has nothing to set them with. There is no consent banner because there is nothing to consent to.
- No analytics. No page-view tracking, no session recording, no fingerprinting.
- No third-party requests. Fonts are served from this domain. They were previously loaded from Google's CDN, which sends a visitor's IP address to Google before they have agreed to anything; they are now vendored into the site precisely so that transfer does not happen.
- Server logs. Our hosting providers record the usual request metadata — IP address, time, path, user agent — to serve the page and to spot abuse. That is a legitimate interest under Art. 6(1)(f) GDPR, and those logs are kept only as long as the provider's own retention allows.
The service
If you submit a URL to the console, we fetch that website and produce a manifest describing its shape. What that involves:
- What is stored: the URL you submitted, a job record with its progress log, the generated manifest, and a short-lived cache of pages fetched from the site. The manifest holds the site's shape — colours, type scale, tool descriptions, CSS selectors — not its content.
- What is not stored: no copy of the site's text, images, fonts or logo files, and no history. The cache expires in minutes to hours and sits in front of a live pass-through rather than accumulating a database.
- Personal data in a crawl: a public business website may contain personal data — a named contact, a staff photograph. We fetch only pages that are publicly reachable and permitted by that site's robots.txt, never anything behind a login. If a manifest describes your site and you want it gone, see removal requests; it is removed on request, without argument.
- Language models: when capability synthesis is enabled, the crawler's observations — page structure, headings, form field names — are sent to Anthropic's API to propose tool names and descriptions. It is disabled on the public endpoint at the time of writing. No submitted URL is used to train a model.
Who processes data for us
- Vercel — serves this website.
- Cloudflare — DNS and CDN in front of it.
- Our own server, a virtual machine in the EU, runs the console, the crawler and the hosted MCP endpoints.
- Anthropic — only when capability synthesis is enabled, as described above.
Your rights
Under the GDPR you may ask for access to your data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interest. Write to privacy@clawharbor.io. You may also complain to the Croatian supervisory authority, AZOP (azop.hr), or to the authority where you live.