Privacy Policy

Last updated: May 2026

Short version: JARVOS is a local-first desktop application. Your emails, contacts, and documents are stored on your machine and never transmitted to JARVOS servers. We collect only what is necessary to operate your account and subscription.

1. What JARVOS Does Not Collect

The following data never leaves your machine and is never transmitted to JARVOS servers:

  • Email content (subjects, bodies, attachments)
  • WhatsApp messages or media
  • Contact names, phone numbers, or relationship data
  • Documents stored in your local Vault
  • AI prompts or AI responses
  • IMAP/SMTP credentials (stored in OS keychain only)

2. What We Collect

Account data: When you register, we store your email address, a bcrypt-hashed password, your organisation name, and the tier of your subscription. This is necessary to authenticate you and apply the correct feature set to your local application.

Billing data: Subscription and payment processing is handled by Stripe. We store your Stripe customer ID and subscription status. We do not store full card numbers — Stripe holds all payment instrument data on their PCI-DSS compliant infrastructure.

Anonymous usage analytics (opt-in only): If you opt in to analytics, we relay anonymised event counts (e.g. "email account connected", "upgrade clicked") to a self-hosted Plausible instance. No personal identifiers, no email content. You can opt out at any time in Settings → Privacy.

Crash reports (opt-in only): If you enable error reporting, Sentry captures crash stack traces to help us fix bugs. Stack traces do not contain email content or personal data. Opt out in Settings → Privacy.

3. Cloud AI Providers

If you configure an Anthropic or OpenAI API key, prompts you send through that path are transmitted to the respective provider and governed by their privacy policies. JARVOS does not proxy or log these requests — they go directly from your machine to the provider's API.

When using Ollama (local AI), nothing leaves your machine.

4. WhatsApp Bridge

Personal tier: The whatsapp-web.js bridge connects directly to WhatsApp's servers from your machine — no relay through JARVOS infrastructure. Messages are stored in your local database.

Business tier: The Meta Cloud API webhook is received by the JARVOS backend and forwarded to your local application over a secure connection. Message content is not stored or logged on JARVOS servers.

5. Data Retention

Your local application data is yours entirely — it lives in a SQLite file on your machine. You can delete it, back it up, or migrate it at any time.

Account data (email, subscription status) is retained as long as your account exists. You can request deletion by emailing support@jarvos.site. Deletion is processed within 30 days.

6. Third-Party Services

  • Stripe — payment processing
  • Crisp — support chat (only loaded on jarvos.site, not in the desktop app)
  • GitHub — application download hosting

7. Security

IMAP/SMTP passwords are encrypted with AES-256-GCM using a key stored in your OS keychain (Windows Credential Manager, macOS Keychain). They are never written to disk in plaintext and never transmitted over the network.

8. Contact

Privacy questions: privacy@jarvos.site

General support: support@jarvos.site