Privacy Policy

Jarvis AI ("we", "our", "us") respects your privacy. This Privacy Policy explains what data the Jarvis software — the macOS app and the Jarvis mobile app for iOS and Android (together, the "App") — and this website ("Site") collect, where that data goes, and what choices you have. Last updated 2026-07-14.

Last updated: 2026-07-14

Plain English Summary

Jarvis is built privacy-first, on both Mac and mobile. On Mac, everything happens on your device by default and your voice never leaves it. On mobile, you bring your own Google Gemini API key and your voice audio goes directly from your phone to Google, never through our servers. Neither app runs accounts or servers that store your conversations. The only data we receive about you, by default, is: (1) the email you submit to the Jarvis 2.0 waitlist on this website, and (2) optional, anonymous app-usage telemetry that contains no transcript content and no personal identifiers. Cloud transcription or LLM APIs are entirely optional. You bring your own API key, and your data goes directly from your device to that provider, never through us.

Data Jarvis Processes On Your Mac (Local, Never Sent To Us)

Microphone audio: captured while you hold the hotkey, transcribed locally using Whisper.cpp or Parakeet models that run on your device, then discarded. Transcripts: stay on your Mac unless you choose to send them to an LLM (see below). Settings, hotkey configuration, custom dictionary, and any memory items you create: stored locally in your macOS user data folder (~/Library/Application Support/Jarvis/). Whisper models: downloaded from HuggingFace on first use, then cached locally.

Optional Cloud Services You Can Enable

You may choose to enable cloud-based transcription (OpenAI Whisper, Deepgram Nova-3) or cloud-based LLMs (OpenAI, Anthropic Claude, Google Gemini, or a local Ollama instance) by entering your own API key in Settings. You may also choose to connect a Google account (Calendar, Drive, Tasks, Sheets — see the next section for detail). Email is separate: it uses your own IMAP/SMTP mailbox credentials, not a Google OAuth scope. When enabled, the App sends data directly from your Mac to that provider over HTTPS. We never see this data, never proxy it, and never store your API keys or OAuth tokens on our servers — they are kept locally in your settings file or macOS Keychain. You are responsible for understanding the privacy policies of the providers you enable: OpenAI, Anthropic, Deepgram, Google. All cloud features are off by default and require explicit consent before first use.

Google Account Data (Calendar, Drive, Tasks, Sheets)

When you choose to connect a Google account in Jarvis, the App requests OAuth permission to access specific Calendar, Drive, Tasks, and Sheets data via the official Google APIs. Jarvis does NOT request any Gmail scope and makes no calls to the Gmail API. Email in Jarvis runs over standard IMAP/SMTP with an app password you create yourself, which does not involve Google OAuth or the Gmail API at all. Data flows directly from Google to your Mac — Jarvis AI operates no backend server that handles, stores, indexes, or otherwise processes your Google account content. OAuth tokens are stored encrypted in your local macOS Keychain via Electron safeStorage.

Scopes Jarvis requests and what each is used for:

• https://www.googleapis.com/auth/calendar.readonly — Read your calendar events so Jarvis can display today's schedule on the Today widget, answer voice queries like "what is on this week", and find free slots when you ask. We do not create or modify events with this scope.

• https://www.googleapis.com/auth/calendar.events — Requested only if you ask Jarvis to create, move, or cancel an event. It is never part of the initial connection: the App runs a separate incremental-authorization flow at the moment you first ask for a write, and until you grant it Jarvis cannot modify your calendar.

• https://www.googleapis.com/auth/tasks — Requested only if you connect Google Tasks, so Jarvis can show your task lists and add or complete the tasks you ask it to. Requested at the moment you connect that service, never as part of a general sign-in.

• https://www.googleapis.com/auth/spreadsheets — Requested only if you connect Google Sheets, so Jarvis can read a sheet you point it at and write the rows you ask it to write. Requested at the moment you connect that service, never as part of a general sign-in.

• https://www.googleapis.com/auth/drive.file — Per-file scope. Jarvis can only access files it has itself created in your Drive on your behalf; Jarvis cannot see, read, or modify any other files in your Drive.

• openid, email, profile — Standard sign-in scopes used to identify the connected Google account.

Write actions: Creating or editing calendar events, tasks, and spreadsheet rows are never performed through the read-only scopes above. If you ask Jarvis to perform such an action, the App runs a separate, optional incremental-authorization flow where you must explicitly consent to the specific additional scope (for example calendar.events) at that moment. Until you grant the upgrade, Jarvis cannot and does not perform the write action. Sending email never uses a Google scope at all — it goes through your own IMAP/SMTP mailbox credentials.

Limited Use commitment: Jarvis AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Specifically: (a) Calendar, Drive, Tasks, and Sheets data is used only to provide and improve the user-facing Jarvis features described above; (b) we do not transfer this data to third parties for advertising or any unrelated purpose; (c) we do not sell this data; (d) we do not use this data to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models — when you invoke a Jarvis feature that summarizes or reasons over Calendar or Drive content using a cloud LLM you have configured (OpenAI, Anthropic, Google Gemini, etc.) the relevant content is sent directly from your Mac to that provider using your own API key under their published API terms, which for these providers generally prohibit training on submitted user content; (e) no human at Jarvis AI reads or otherwise accesses your Calendar, Drive, Tasks, or Sheets content at any time; the only parties that can read this content are you (on your device) and the cloud AI provider you have chosen if and only if you invoke a feature that requires it.

Session replays and Google data: interface replays mask all on-screen text precisely so that Calendar, Drive, Tasks, or Sheets content rendered in the Jarvis interface is not captured or transmitted (see "App Analytics & Session Replays" above).

Revocation: You can disconnect any Google account at any time from Jarvis Settings → Connections → Disconnect, which deletes the locally stored OAuth token. You can also revoke Jarvis's access at the Google account level at https://myaccount.google.com/permissions — once revoked there, Jarvis can make no further API calls regardless of local state. We recommend revoking at the Google level if you uninstall Jarvis without first disconnecting.

Jarvis Mobile App (iOS / Android)

The Jarvis mobile app is a separate, voice-first companion app. You supply your own Google Gemini API key in the app; your voice audio streams directly from your phone to Google's Gemini API over HTTPS using that key, and is never routed through, proxied by, or stored on our servers.

What is sent to Google Gemini, and when: the app asks for your explicit consent during setup, before anything is sent. Once you agree, the following is transmitted to Google (and only to Google) each time you use Jarvis: your voice audio while you talk; text messages you type and the replies generated; photos or files you explicitly attach to a conversation; and lightweight personal context the app adds so replies are useful (your first name, remembered facts you asked Jarvis to keep, and — only when you invoke a feature that needs it — calendar events, contact names, or your approximate city). Google processes this under the Gemini API terms (https://ai.google.dev/gemini-api/terms). We never see, store, proxy, or sell any of it. If you decline consent, nothing is ever sent.

Optional account: you can sign in with Google or Apple inside the app. This is optional — signing in unlocks nothing extra; it only stores your email address, display name, and avatar (via Supabase, our authentication provider) so we can occasionally reach you about the product. Conversations, memory, and your API key are never linked to this account or uploaded. You can delete the account at any time in the app: Settings → account card → Delete account. Deletion is immediate and permanent, removes every record tied to the account on our side, and does not touch the conversations or memory on your phone. You can also request deletion by emailing [email protected]. Skipping sign-in entirely leaves nothing linking your usage to your identity beyond an anonymous per-install ID.

Local storage: conversation history, remembered facts, preferences, and your Gemini key are stored only on your device, using iOS Keychain / Android Keystore (via secure on-device storage) and the app's local storage. None of this is uploaded to us.

Permissions requested, all on-device and only when needed: Microphone (to hear you — required); Calendar (only when you ask about your schedule or to add an event); Contacts (only when you ask Jarvis to call, text, or look up someone); Location, when-in-use only (only when you ask about weather, nearby places, or directions). None of these permissions are requested upfront at first launch — each is requested the first time, and only the first time, a feature that needs it is actually used. We never request "always" background location, and Jarvis mobile does not use Face ID, motion data, or the Reminders app.

Local notifications: the app may schedule on-device reminders you explicitly ask for, a "come back" nudge after a period of inactivity (its text may reference something light from your last conversation, generated on-device from your own conversation content — never anything sensitive — and never sent to us), and a morning brief notification when you have real agenda items. All of these are generated and scheduled locally; sending them does not involve our servers.

Analytics and crash reporting: the mobile app uses the same anonymous, opt-out PostHog analytics described below, tagged by platform so Mac and mobile usage can be told apart within the one PostHog project. It also uses Sentry for crash reporting (same Sentry project used by the Mac app, distinguished by a platform tag) — crash reports never include your Gemini API key (stripped before sending) or conversation content.

App Analytics & Session Replays (Jarvis 2.0 Beta)

During the Jarvis 2.0 beta, analytics are enabled by default in the closed-source distribution and can be turned off at any time in Settings → Privacy → Analytics. Two kinds of data are sent to PostHog (processed at us.i.posthog.com in the United States). (1) Usage events: which features are used (for example "dictation completed", "onboarding step viewed"), counts and durations, app version, OS version, Mac architecture, and configuration facts such as which AI provider type is connected. Events carry a random UUID generated at first launch on your Mac; it is not linked to your email, name, or any account. Usage events never include transcript text, message content, file paths, or document contents. (2) Interface session replays: a visual reconstruction of how the Jarvis interface is used (screens visited, buttons clicked), which we use to find usability problems in the beta. On-screen text in replays is masked: the content of your chats, emails, memory, and other text is replaced with placeholder characters before anything leaves your Mac, and no audio is ever recorded. Replays are retained for 30 days, usage events for up to 12 months. Turning the toggle off stops both immediately. Open-source builds compiled from source ship with analytics disabled and no PostHog key.

Data This Website Collects

When you submit an email to the Jarvis 2.0 waitlist, we store: your email address, the random A/B/C test variant assignment, the page you submitted from (modal or page), your browser user-agent string, the referring URL, and a server timestamp. This data is stored in a Firestore database hosted on Google Cloud (region: us-central1) and used solely to email you when Jarvis 2.0 opens up. We do not share or sell waitlist emails to anyone. You can request removal at any time by emailing [email protected]. The website also uses Firebase Analytics (a Google service) to record anonymous page views and clicks; this does not include your email or any other personally identifying information.

Investor page (jarvis.ceo/investor): this access-coded page, intended for investors we share it with, additionally uses PostHog to record page analytics, session replays, and, if you choose to use the voice feature, transcripts of your conversation with the Jarvis demo agent. That page states this before the conversation starts. This data is used solely for our fundraising process and is retained on the same schedule as other PostHog data (replays 30 days, events up to 12 months). Write [email protected] to have it removed.

Auto-Update

The App checks the GitHub Releases API (api.github.com) every six hours to see if a new version is available. This check sends your current Jarvis version and your IP address (a standard HTTP request) to GitHub. It does not send any of your audio, transcripts, settings, or identifiers. You can disable auto-update in Settings.

No Accounts, No Logins, No Cloud Sync

Jarvis does not have a signup or login system. There is no user account, no profile, no cloud-stored history. The App stores a placeholder local user record purely for code structure ("user@localhost") that exists only on your Mac and is sent nowhere.

Permissions Jarvis Requests From macOS

Microphone: required, to capture your voice when you press the hotkey. Accessibility: required, so Jarvis can detect the function key and type the transcript into other apps. Calendar, Reminders, and Screen Recording: optional, only requested the first time you invoke a feature that needs them (for example, asking Jarvis to read events from your local macOS Calendar app, or "look at my screen"). These are standard macOS Privacy permissions and live entirely on your Mac — distinct from the Google Account OAuth flow described in the previous section, which is the path Jarvis uses to read Google Calendar. macOS permissions can be reviewed and revoked at any time in System Settings → Privacy & Security.

Children

Jarvis is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has submitted their email to our waitlist, contact [email protected] and we will delete it.

Your Rights (GDPR / CCPA / Equivalent)

If you are in the EU, UK, California, or another jurisdiction with similar laws, you have the right to access, correct, delete, port, or restrict processing of personal data we hold about you. Since we hold very little. Typically just your waitlist email and an anonymous app UUID. Most requests are simple. Email [email protected] to exercise any of these rights. We respond within 30 days. We do not sell personal data, so the CCPA "right to opt out of sale" does not apply.

Data Retention

Waitlist emails: kept until Jarvis 2.0 launches and the waitlist closes, then deleted unless you have become a paid user. App usage events: kept up to 12 months by PostHog; interface session replays: 30 days. Local app data on your Mac: kept until you uninstall Jarvis or delete the user data folder yourself.

International Transfers

Our website infrastructure (Firebase Hosting, Firestore, Analytics) is operated by Google Cloud and may process data in the United States or other Google data centers. If you enable optional cloud APIs (OpenAI, Anthropic, Deepgram, Google Gemini), data is processed by those providers in regions defined by their own policies. PostHog telemetry is processed in the United States.

Security

Local data on your Mac is protected by macOS file permissions and disk encryption (FileVault, if you have it on). Data in transit (waitlist signups, optional cloud API calls, auto-update checks) is sent over TLS/HTTPS. No security system is perfect. If you spot a vulnerability, please email [email protected].

Changes To This Policy

If we materially change how we handle data, we will update this policy and bump the Last Updated date at the top. Significant changes will be announced on the Jarvis website. Continued use of Jarvis after changes constitutes acceptance.

Contact

For any privacy question, data request, or DPO inquiry, email [email protected] (or [email protected] for formal data-protection officer matters). We respond within 30 days, usually within 72 hours.

See also our Terms of Service.