Privacy Policy
Local-first by design. We collect only what we must.
Our Privacy Commitment
Jarvis runs on your machine, with your providers, on your terms. We collect only what is needed to sell, support, and secure the product — never your local conversations, prompts, or generated outputs.
1.Scope of This Policy
This Privacy Policy explains how Jarvis handles information across the public website, account dashboard, source-access area, support workflows, and product communications.
- It does not cover third-party AI providers, payment processors, hosting platforms, or developer tools you choose to connect.
- Their own privacy policies apply to data you send directly to them.
- By using our website or dashboard, you acknowledge you have read and understood this policy.
2.Local-First Data Principle
Jarvis is built around local ownership. The boundaries are clear and intentional:
- Assistant conversations, memory files, screenshots, voice input, and prompts run on your own machine.
- Provider API keys you configure are stored locally and used only by your local Jarvis instance.
- Generated outputs (text, code, images, audio) stay on your device unless you choose to share them.
- We do not receive or store the content of your local sessions unless you deliberately send it to us for support.
3.Information We Collect
Account & Purchase Data
- Name, email address, avatar, and sign-in status.
- Purchase status, plan type, invoices, transaction IDs, and access eligibility.
- Download history of source packages and installers tied to your account.
Support Communications
- Messages, bug reports, screenshots, and files you choose to share with our support team.
- Diagnostic information you voluntarily attach to a support ticket.
- Records of past conversations to maintain a useful support history.
Website & Security Telemetry
- Basic analytics — pages visited, referral source, device type, and approximate region.
- Security logs to prevent abuse, protect downloads, and troubleshoot service issues.
- IP addresses are truncated where feasible before storage.
4.How We Use Your Data
Collected information is used only to operate the business side of the product:
- Provide login, source downloads, release notes, tutorials, and dashboard access.
- Confirm purchase status and prevent unauthorized distribution of paid materials.
- Respond to support requests and improve documentation around common issues.
- Send important account, access, security, and product update notices.
- Understand which public pages and docs are useful, without profiling private assistant usage.
- Detect and prevent fraud, abuse, and unauthorized access to paid resources.
6.Source Access & License Verification
When you download source packages or installers, we record minimal information necessary to enforce license terms.
- Account identifier and plan associated with each download event.
- Approximate timestamp and IP region for abuse detection.
- Version and platform of the artifact downloaded.
- We do not embed unique watermarks that identify individual customers in distributed source code.
7.Data Retention
We keep records only as long as they remain useful for legitimate business purposes.
- Account and purchase data — for the lifetime of your access plus 90 days after deletion.
- Billing and tax records — retained for 7 years to comply with financial regulations.
- Support conversations — retained for 24 months from last contact.
- Security logs — purged on a rolling 90-day schedule unless flagged for an active investigation.
- Backup copies — purged on a rolling 35-day schedule.
8.Data Security
Protecting your data is foundational, not an afterthought.
- TLS 1.3 encryption for all data in transit and AES-256 for data at rest.
- Role-based access controls with the principle of least privilege for internal systems.
- Mandatory two-factor authentication for all team members with production access.
- Continuous monitoring, intrusion detection, and routine security reviews.
- Documented incident response plan with notification within 72 hours of confirmed breach.
10.Analytics & Performance
We use privacy-respecting analytics to understand product usage and improve quality.
- Aggregated metrics on page views, feature usage, and conversion paths.
- Performance telemetry such as load times, error rates, and download success rates.
- All analytics IDs are hashed and IP addresses are truncated before storage where feasible.
11.International Data Transfers
We operate globally and may transfer your data across borders to deliver our services.
- Transfers to countries outside your region are protected by Standard Contractual Clauses.
- We assess each transfer to confirm an adequate level of data protection.
- EU/UK residents — your data is protected under GDPR and UK GDPR equivalents.
12.Your Privacy Rights
Depending on your jurisdiction, you have several rights over the personal data we hold.
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete information.
- Erasure — ask us to delete your data, subject to legal retention requirements.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — at any time, where processing is based on consent.
- You also control your local Jarvis data directly on your device — clearing local memory and provider keys does not require a request to us.
13.Children's Privacy
Jarvis is a developer product not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with information, please contact support and we will promptly delete it.
14.Breach Notification
In the unlikely event of a data breach affecting your personal information, we will notify you and the relevant authorities within 72 hours of confirming the breach. Notifications will detail the nature of the incident, the data involved, and the steps we are taking to mitigate harm.
15.Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via email or a prominent notice in your dashboard at least 30 days before they take effect.
16.Contact
For privacy questions, requests, or concerns, reach our support team:
- Privacy and data requests — through the support channel in your dashboard.
- General support — through the email address listed in your purchase receipt.
- Response time — within 48 hours for most requests.
- You also have the right to lodge a complaint with your local data protection authority.