Privacy Policy

CamsClaw

Last updated: 2026-05-02

Who we are

CamsClaw is operated by Cams Biometrics (the same entity publishing camsbiometrics.com), registered in Chennai, Tamil Nadu — 600119, India. All data described here is processed by the same legal entity, in accordance with India's Digital Personal Data Protection Act 2023 (DPDPA) and where applicable the EU GDPR. Grievance officer: abuse@camsclaw.ai.

What data we collect

From everyone who runs a scan

We do not require accounts, do not run analytics, do not set tracking cookies, do not load third-party scripts, and do not share anything with ad networks. There is no "behavioral profile" of you.

From sites you scan

The scanner makes read-only HTTP requests to public endpoints. It does not submit forms, log in, upload files, or attempt to discover non-public URLs. Scan responses are stored as part of the public scan report (UUID-addressed permalink at /scan/{id}).

How long we keep it

DataRetention
Scan results (target, findings, score)Indefinite (public report)
HTTP access logs (IP, UA, path)90 days
Rate-limit counters (in-memory)1 hour / 1 day rolling
Verification tokens (challenge-pending)7 days
Verification records (verified_at set)Indefinite (proof of ownership)
Opt-out recordsIndefinite

Your rights (DPDPA + GDPR)

What we never do

Where the data lives

Scan database (SQLite) and operational logs are on a single server in Germany (Netcup). Cloudflare proxies the public site. No third-party SaaS has access to scan data.

Changes

If we materially change this policy we'll bump the date at the top and describe what changed. Significant changes will also be in the repo history at the public source.

Questions

Email abuse@camsclaw.ai — replies go to a real person, not a queue.