← Back to home

Privacy Policy

Last updated: August 2026

1. Who we are

Jarvis is a desktop AI assistant developed by Muhammad Danial Khilji, based in the United Kingdom. This policy explains how we collect, use, and protect your data when you use the Jarvis application and related services.

2. What data we collect

Account data: When you register, we collect your email address and a hashed version of your password. We never store your password in plain text.

Usage metadata: We log which model was used, token counts, and timestamps for each request. This is used for rate limiting and billing. We do not log the content of your prompts or responses.

Payment data: If you subscribe to Pro, payment is processed by Stripe. We store your Stripe customer ID and subscription ID. We never see or store your card details — Stripe handles that entirely.

3. What data we do NOT collect

  • We do not log, store, or read the content of your conversations.
  • We do not use telemetry, analytics, or tracking on the desktop app.
  • We do not sell, share, or transfer your data to third parties for marketing.

4. Secure Mode (fully offline)

When Secure Mode is enabled, all AI processing runs locally on your machine via Ollama. No data leaves your device — no network requests are made to our servers or any third party. Secure Mode is available on both Free and Pro tiers.

5. How your data is processed

In Cloud Mode (the default), your messages are sent to our backend proxy, which forwards them to the selected AI provider (e.g. DeepSeek, Google Gemini, Groq). The proxy does not store message content — it only logs metadata (model, tokens, timestamp) for rate limiting and billing.

The AI providers process your messages according to their own privacy policies. We select providers with strong data handling practices, but we encourage you to review their policies if you have concerns.

6. Sub-processors

We use the following third-party services to operate Jarvis:

  • Railway — backend hosting
  • Stripe — payment processing
  • Resend — transactional email (verification, password reset)
  • DeepSeek, Google (Gemini), Groq, Anthropic (Claude) — AI model providers

7. Data retention

Account data is retained while your account is active. Usage metadata is retained for billing and rate-limiting purposes. If you delete your account, all personal data (email, password hash, usage logs) is permanently purged. Stripe records are handled according to Stripe's retention policy.

8. Your rights (GDPR)

As a UK-based product, we comply with the UK GDPR. You have the right to:

  • Access your data — use the "Export data" button in Settings to download your profile and usage summary as JSON.
  • Delete your data — use the "Delete account" button in Settings to permanently delete your account, all personal data, and usage logs.
  • Correct your data — contact us to update your information.
  • Object to processing — you can stop using the service at any time, or switch to Secure Mode for fully offline use.

9. Security

  • Passwords are hashed with bcrypt.
  • All API communication uses HTTPS.
  • API keys are stored server-side only — never in the client app.
  • Local conversation history is encrypted at rest with Fernet (AES-128).
  • Desktop credentials are stored in the macOS Keychain.

10. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Continued use of Jarvis after changes constitutes acceptance.

11. Contact

For privacy-related questions or data subject requests, contact: khiljidanial@gmail.com

Home Privacy Policy Terms of Service