Jarvis Privacy Policy
1. Who this policy covers
This policy describes how Jarvis (“Jarvis”, “the app”) accesses, uses, stores, protects and shares data obtained from Google APIs (“Google user data”).
Jarvis is a private, self-hosted AI assistant operated by a single individual (“the owner”) for his own use. Jarvis is used only with Google accounts that belong to the owner. It is not offered to the public, has no other users, and does not collect data from anyone else.
2. Google data Jarvis accesses
Jarvis accesses Google user data only after the owner grants permission on Google's standard consent screen. Depending on the permissions granted, Jarvis can access:
| Google service | Data accessed | Permissions (OAuth scopes) |
|---|---|---|
| Gmail | Email messages and threads (headers, body, attachments), drafts, labels and basic mail settings | gmail.readonly, gmail.compose, gmail.send, gmail.modify, gmail.labels, gmail.settings.basic |
| Google Calendar | Calendars, events, attendees and availability | calendar, calendar.events |
| Google Drive | File and folder names, metadata, contents and sharing settings | drive, drive.file |
| Google Docs | Document contents | documents |
| Google Sheets | Spreadsheet contents | spreadsheets |
| Google Slides | Presentation contents | presentations |
| Google Account | Email address and basic profile (name) | userinfo.email, userinfo.profile |
Jarvis does not access Google data that is not needed to fulfil a request from the owner, and requests no permissions beyond those listed above.
3. How Jarvis uses Google data
Jarvis uses Google user data only to provide the features the owner asks for, on demand:
- Gmail: to search, read and summarize the owner's email, draft replies, and send, label or archive messages after the owner approves.
- Google Calendar: to read the owner's schedule and availability, and to create, update or delete events after the owner approves.
- Google Drive: to find, read, upload, organize and share the owner's files after the owner approves any change.
- Google Docs, Sheets and Slides: to read, summarize, create and edit the owner's documents, spreadsheets and presentations after the owner approves any change.
- Google Account profile: to identify which of the owner's Google accounts is connected, so that each request goes to the correct account.
Jarvis does not use Google user data for advertising, marketing, profiling, credit or lending decisions, or any purpose unrelated to the owner's own requests. Jarvis does not sell Google user data.
4. Storage and retention
Jarvis runs entirely on a private server owned and operated by the owner. No part of Jarvis is cloud hosted.
- Google content is not stored by Jarvis. Email, calendar entries, files and document contents are fetched from Google when a request needs them and are processed to produce a response. Jarvis does not copy them into its own database or file storage.
- Conversation history. Excerpts of Google data that appear in the owner's conversation with the assistant (for example, a summary of an email) remain only on the owner's self-hosted server and can be deleted by the owner at any time.
- Authorization tokens. The only Google credentials Jarvis stores are the OAuth tokens that let it stay connected. They are kept on the owner's server until access is revoked or the tokens are deleted.
- Google. Changes the owner approves (such as sending an email or editing a document) are made in the owner's Google account and are stored by Google under Google's own terms.
6. Limited Use disclosure
Jarvis's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Jarvis:
- uses Google user data only to provide and improve user-facing features that are prominent in Jarvis;
- transfers Google user data only as needed to provide those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to the user;
- does not use or transfer Google user data for serving advertisements, including retargeting, personalized or interest-based advertising;
- does not use Google user data to develop, improve or train generalized or non-personalized artificial-intelligence or machine-learning models;
- does not allow humans to read Google user data, except the owner himself, with the owner's affirmative agreement for specific messages, for security purposes, or to comply with applicable law.
7. How Google data is protected
- Jarvis runs on a private, self-hosted server under the owner's physical and administrative control; it is not cloud hosted.
- OAuth tokens are stored only on that server, protected by operating-system access controls.
- Access to the running assistant requires authentication, and remote access is limited to the owner's private network and VPN.
- Communication with Google APIs uses encrypted HTTPS connections.
- Jarvis requests only the permissions listed in section 2, and every action that sends, deletes, shares, creates or edits data requires the owner's confirmation.
8. Revoking access and deleting data
- Revoke access: remove “Jarvis” at myaccount.google.com/permissions. Jarvis immediately loses access to that Google account.
- Delete stored tokens: the owner can delete Jarvis's stored authorization tokens from the server at any time.
- Delete conversation history: the owner can delete any conversation containing excerpts of Google data from the server at any time.
Because Jarvis does not keep its own copy of Google content, revoking access and deleting the tokens and conversation history removes all Google user data held by Jarvis.
9. Other information
Jarvis does not use cookies, analytics or tracking on this website, and does not collect personal information from visitors to this website. Jarvis is not directed to children and is used only by its adult owner.
10. Changes to this policy
If this policy changes, the updated version will be posted on this page with a new “Last updated” date.
11. Contact
Questions about this policy or about how Jarvis handles Google user data: CONTACT_EMAIL