Jarvis Privacy Policy
Effective 6 October 2026 · updated 6 October 2026 (email content is now classified before Claude may see it)
Jarvis is a private personal assistant. It is software that its owner runs on their own Windows computer for their own personal use. It is not a public product: there are no other users, no sign-ups and no customers. The only Google account connected to Jarvis is the owner's own.
This policy explains what Google user data Jarvis accesses, why, where it is kept, who else can see it, and how access can be removed.
1. Google data Jarvis accesses
By default Jarvis asks Google only for read-only access:
| Permission | What it allows | Why Jarvis uses it |
|---|---|---|
Gmail, read-onlygmail.readonly | Read and search the owner's email | To find and read email when the owner asks, show which messages are waiting for a reply or have gone unanswered, and prepare a daily summary. |
Google Calendar, read-onlycalendar.readonly | Read the owner's calendars | To answer "what's on today?", spot clashes, find free time and remind the owner before events. |
The owner can later choose to grant extra permissions in Jarvis's settings. Each is requested separately through Google's own consent screen, and none is requested without the owner choosing it:
- Drafts and sending (
gmail.compose): create drafts; by default every email Jarvis sends needs the owner's approval of that exact message first. - Jarvis's own calendar (
calendar.app.created): a separate "Jarvis" calendar for time blocks. It cannot change the owner's other calendars. - Organising mail (
gmail.modify): labels, archiving and marking as read, which can be undone. Jarvis has no function that deletes email. - Editing the owner's calendar (
calendar.events): each change to the owner's own events needs the owner's approval.
2. How the data is used
Google user data is used only to provide the features the owner asks for in Jarvis. Specifically, Jarvis does not:
- sell Google user data, or give or transfer it to advertisers, data brokers or information resellers;
- use it for advertising of any kind, or to decide credit-worthiness or lending;
- use it to develop, improve or train artificial-intelligence or machine-learning models;
- let any person other than the owner read it.
Jarvis's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. Where the data is processed
On the owner's computer. Jarvis connects directly from the owner's computer to Google's APIs. Routine processing — for example sorting new mail by importance and writing the daily summary — is done by AI models that run locally on that computer.
Anthropic's Claude. For more complex requests Jarvis uses Anthropic's Claude through the owner's own Claude subscription. When the owner asks something Jarvis answers with Claude (for example "find the email from my dentist and tell me which time they offered"), the Google data Jarvis reads to answer — such as the text of the relevant email or the details of calendar events — is sent to Anthropic so Claude can produce the answer. Before anything leaves the computer, Jarvis checks it there first:
- each request is classified; requests that are highly sensitive (for example health, finance, legal or passwords) are handled only by the local models;
- each email is classified on the owner's computer before Claude may see any of it. Emails classified as private are not sent at all — not even their subject — and Jarvis's local model answers the owner about them instead;
- other emails are minimised first: passwords, security codes, card, bank and ID numbers, phone numbers, street addresses and full email addresses are removed, and only a limited part of the text is sent.
Anthropic processes this data under its own terms and privacy policy and the owner's account settings, which the owner keeps set so that their conversations are not used to train Anthropic's models.
The owner's phone. Jarvis can send short notifications to the owner's own phone through a notification server that runs on the owner's computer and is reachable only over the owner's private network. These can include, for example, the title of an upcoming calendar event, the name of someone waiting for a reply, or a one-line summary of an email the owner is asked to approve.
Google user data is not sent to any other company or service. Jarvis's web search does not include Google user data.
4. Storage, retention and deletion
- Access token: Google's sign-in token is stored on the owner's computer, encrypted with Windows Data Protection so that only the owner's Windows account can read it. It is never shown in Jarvis's interface.
- Email: Jarvis keeps a small local cache of message details — sender, recipients, subject, date, labels, Gmail's short preview text, and a one-line priority summary made by the local model. Full email bodies and attachments are not cached: they are fetched from Gmail when needed. An attachment is saved to disk only when the owner asks for it. Cached message details are deleted automatically after 30 days.
- Calendar: events are read from Google when needed and are not cached.
- Backups: Jarvis makes daily backups of its local database on the owner's computer and keeps the last seven, so deleted cache entries disappear from backups within about a week.
- Activity record: for the owner's own security, Jarvis keeps a tamper-evident log on the owner's computer of the actions it takes. Entries can include, for example, a search the owner asked for, or the recipient and subject of an email the owner approved. It never contains Google's tokens.
- Disconnecting Google in Jarvis's settings revokes Jarvis's access at Google, deletes the stored token and deletes the cached email details.
5. Removing access
Access can be removed at any time, either in Jarvis (Settings → Google → Disconnect) or from the Google Account at myaccount.google.com/permissions. After access is removed Jarvis can no longer read Gmail or Google Calendar.
6. Security
Jarvis's interface is available only on the owner's computer and, for the owner's paired phone, over the owner's private network; it is not exposed to the internet. This website is only an information page and has no connection to Jarvis or to any Google data.
7. Changes and questions
If Jarvis starts using Google data in a new way, this policy will be updated first and the date above changed. Questions can be sent to the owner using the contact address shown on Google's sign-in screen for Jarvis.