// jarvis / privacy

JARVIS Privacy Policy

Effective 12 September 2026. This policy explains how the private JARVIS Personal Assistant accesses, uses, stores, and protects Google user data.

What JARVIS is

JARVIS Personal Assistant is a private, single-user project operated by Matt Roberts. It runs on a personally controlled Ubuntu server and is not offered as a service to the public.

Google data JARVIS accesses

JARVIS requests Google Drive permission so it can create, list, read, and update documents for its owner. The Google account connected to JARVIS is a separate account used for this project. Its intended working area is a dedicated folder named JARVIS Workspace.

How Google data is used

Google Drive data is used only to carry out an explicit personal-assistant request, such as:

  • creating a document requested by the owner;
  • finding or reading a document in JARVIS Workspace;
  • summarising, revising, or adding content when requested; and
  • returning a link or status confirmation to the owner.

Google user data is not sold, used for advertising, used to build advertising profiles, or made available to other people.

AI processing

When the owner explicitly asks JARVIS to write, revise, research, or summarise a document, relevant instructions and document content may be sent to the OpenAI API to fulfil that request. JARVIS does not use Google user data to train a general-purpose artificial intelligence model. Local automation requests that do not need document content do not send Drive documents for AI processing.

Storage and security

Documents remain in Google Drive. The OAuth credential and revocable access token are stored on the owner's HP Elite Slice with owner-only filesystem permissions. JARVIS also applies a software check before reading a document to confirm that it belongs to JARVIS Workspace. Document content is not intentionally written to application logs.

Sharing and disclosure

Data is shared with Google APIs as required to operate Google Drive. Relevant content may be processed by OpenAI only for an owner-requested task. Data may also be disclosed where required by law. No other third party receives Google user data from JARVIS.

Retention, deletion, and revocation

Documents remain in JARVIS Workspace until the owner deletes them. The local authorization token remains until it is revoked or removed. The owner can stop access at any time from the Google Account's third-party connections page, or by deleting the local token from the JARVIS server.

Once access is revoked, JARVIS can no longer read or change Drive content unless the owner completes authorization again.

Google API Services User Data Policy

JARVIS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Contact

Questions about this policy or requests concerning JARVIS data can be sent through the Views Are My Own contact page.

← Return to JARVIS