Privacy Policy

Local-first by design. We collect only what we must.

Last updated: May 12, 2026Effective immediately

Our Privacy Commitment

Jarvis runs on your machine, with your providers, on your terms. We collect only what is needed to sell, support, and secure the product — never your local conversations, prompts, or generated outputs.

1.Scope of This Policy

This Privacy Policy explains how Jarvis handles information across the public website, account dashboard, source-access area, support workflows, and product communications.

  • It does not cover third-party AI providers, payment processors, hosting platforms, or developer tools you choose to connect.
  • Their own privacy policies apply to data you send directly to them.
  • By using our website or dashboard, you acknowledge you have read and understood this policy.

2.Local-First Data Principle

Jarvis is built around local ownership. The boundaries are clear and intentional:

  • Assistant conversations, memory files, screenshots, voice input, and prompts run on your own machine.
  • Provider API keys you configure are stored locally and used only by your local Jarvis instance.
  • Generated outputs (text, code, images, audio) stay on your device unless you choose to share them.
  • We do not receive or store the content of your local sessions unless you deliberately send it to us for support.

3.Information We Collect

Account & Purchase Data

  • Name, email address, avatar, and sign-in status.
  • Purchase status, plan type, invoices, transaction IDs, and access eligibility.
  • Download history of source packages and installers tied to your account.

Support Communications

  • Messages, bug reports, screenshots, and files you choose to share with our support team.
  • Diagnostic information you voluntarily attach to a support ticket.
  • Records of past conversations to maintain a useful support history.

Website & Security Telemetry

  • Basic analytics — pages visited, referral source, device type, and approximate region.
  • Security logs to prevent abuse, protect downloads, and troubleshoot service issues.
  • IP addresses are truncated where feasible before storage.

4.How We Use Your Data

Collected information is used only to operate the business side of the product:

  • Provide login, source downloads, release notes, tutorials, and dashboard access.
  • Confirm purchase status and prevent unauthorized distribution of paid materials.
  • Respond to support requests and improve documentation around common issues.
  • Send important account, access, security, and product update notices.
  • Understand which public pages and docs are useful, without profiling private assistant usage.
  • Detect and prevent fraud, abuse, and unauthorized access to paid resources.

5.Sharing & Processors

We do not sell personal information. We share limited data only with carefully chosen service providers and only when necessary.

  • Payment processors handle transactions under their own PCI-compliant infrastructure.
  • Email delivery providers send transactional and account messages on our behalf.
  • Hosting and CDN providers serve the website, dashboard, and download endpoints.
  • Customer support tools store ticket history and communication logs.
  • We may also disclose information if required by law, to enforce our terms, or to protect the product and customers from fraud or abuse.

6.Source Access & License Verification

When you download source packages or installers, we record minimal information necessary to enforce license terms.

  • Account identifier and plan associated with each download event.
  • Approximate timestamp and IP region for abuse detection.
  • Version and platform of the artifact downloaded.
  • We do not embed unique watermarks that identify individual customers in distributed source code.

7.Data Retention

We keep records only as long as they remain useful for legitimate business purposes.

  • Account and purchase data — for the lifetime of your access plus 90 days after deletion.
  • Billing and tax records — retained for 7 years to comply with financial regulations.
  • Support conversations — retained for 24 months from last contact.
  • Security logs — purged on a rolling 90-day schedule unless flagged for an active investigation.
  • Backup copies — purged on a rolling 35-day schedule.

8.Data Security

Protecting your data is foundational, not an afterthought.

  • TLS 1.3 encryption for all data in transit and AES-256 for data at rest.
  • Role-based access controls with the principle of least privilege for internal systems.
  • Mandatory two-factor authentication for all team members with production access.
  • Continuous monitoring, intrusion detection, and routine security reviews.
  • Documented incident response plan with notification within 72 hours of confirmed breach.

9.Cookies & Tracking

We use cookies and similar technologies to operate our site and improve your experience.

  • Essential cookies — required for authentication, security, and core dashboard functionality.
  • Functional cookies — remember your preferences such as theme and language.
  • Analytics cookies — help us understand how the public site is used so we can improve it.
  • You can manage cookie preferences through your browser settings or our cookie banner.

10.Analytics & Performance

We use privacy-respecting analytics to understand product usage and improve quality.

  • Aggregated metrics on page views, feature usage, and conversion paths.
  • Performance telemetry such as load times, error rates, and download success rates.
  • All analytics IDs are hashed and IP addresses are truncated before storage where feasible.

11.International Data Transfers

We operate globally and may transfer your data across borders to deliver our services.

  • Transfers to countries outside your region are protected by Standard Contractual Clauses.
  • We assess each transfer to confirm an adequate level of data protection.
  • EU/UK residents — your data is protected under GDPR and UK GDPR equivalents.

12.Your Privacy Rights

Depending on your jurisdiction, you have several rights over the personal data we hold.

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete information.
  • Erasure — ask us to delete your data, subject to legal retention requirements.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — at any time, where processing is based on consent.
  • You also control your local Jarvis data directly on your device — clearing local memory and provider keys does not require a request to us.

13.Children's Privacy

Jarvis is a developer product not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with information, please contact support and we will promptly delete it.

14.Breach Notification

In the unlikely event of a data breach affecting your personal information, we will notify you and the relevant authorities within 72 hours of confirming the breach. Notifications will detail the nature of the incident, the data involved, and the steps we are taking to mitigate harm.

15.Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via email or a prominent notice in your dashboard at least 30 days before they take effect.

16.Contact

For privacy questions, requests, or concerns, reach our support team:

  • Privacy and data requests — through the support channel in your dashboard.
  • General support — through the email address listed in your purchase receipt.
  • Response time — within 48 hours for most requests.
  • You also have the right to lodge a complaint with your local data protection authority.

This document forms part of the agreement between you and Jarvis. We may update it from time to time; the “Last updated” date above reflects the most recent revision. Continued use of our website, dashboard, and source materials after changes constitutes acceptance of the revised terms.