Jarvis Workspace Assistant

Privacy Policy

Last updated:

1. Overview

Jarvis Workspace Assistant (“Jarvis”) is a private, personal-use automation assistant operated exclusively for its account owner. This Privacy Policy explains how Jarvis accesses, uses, stores, and shares Google user data when the account owner authorizes access through Google OAuth.

Jarvis is not offered as a public service and does not accept registrations from third parties.

2. Google user data accessed

Depending on the permissions explicitly granted by the account owner, Jarvis may access:

  • Gmail messages, message metadata, labels, drafts, and sending capabilities;
  • Google Calendar calendars and events;
  • Google Drive files and file metadata;
  • Google Docs documents;
  • Google Sheets spreadsheets;
  • Google Contacts contact information.

Jarvis only accesses data needed to perform functions requested or authorized by the account owner.

3. How Google user data is used

Google user data is used solely to provide personal-assistant functionality to the authorized account owner, including:

  • searching, reading, summarizing, organizing, drafting, and managing email;
  • creating, reading, updating, and organizing calendar information;
  • locating, reading, creating, updating, organizing, and sharing files or documents when requested;
  • reading contact information when needed to perform an authorized task;
  • maintaining operational context necessary to complete requested workflows.

Jarvis does not use Google user data for advertising, profiling for advertising, creditworthiness decisions, or sale to third parties.

4. AI and service-provider processing

To perform requested assistant functions, relevant portions of Google user data may be processed by infrastructure services and AI inference providers configured by the account owner. Such processing is limited to providing the requested functionality and is performed under the account owner’s direction.

The operator of Jarvis does not use Google user data to train or develop generalized artificial intelligence or machine-learning models.

5. Data storage and retention

OAuth credentials are stored on a private server with access controls and restrictive filesystem permissions.

Operational logs, assistant session history, generated artifacts, or task records may retain limited Google user data or excerpts when necessary to complete a task, preserve requested context, diagnose failures, or provide an audit trail.

Stored data is retained only while needed for those purposes or until the account owner deletes it. The account owner controls the server and may request or perform deletion at any time.

6. Data sharing

Jarvis does not sell Google user data.

Google user data may be transmitted only:

  • to Google APIs to perform authorized operations;
  • to infrastructure or AI processing providers necessary to provide requested functionality;
  • when explicitly directed by the account owner, such as sending an email or sharing a file;
  • when required for security, fraud prevention, or compliance with applicable law.

Jarvis does not allow unrelated third parties to access Google user data.

7. Security

Jarvis uses OAuth authorization rather than storing the account’s primary Google password. Access tokens and refresh tokens are restricted to the private runtime environment. Reasonable technical and organizational safeguards are used to reduce unauthorized access, disclosure, alteration, or destruction.

No method of electronic storage or transmission is completely secure; therefore, absolute security cannot be guaranteed.

8. User control and revocation

The account owner may revoke Jarvis’s Google access at any time from the Google Account permissions page. The account owner may also delete locally stored OAuth credentials, operational history, or generated artifacts from the private server.

Revoking access prevents Jarvis from obtaining new Google API access tokens but does not automatically remove information already stored in operational records; that information must be deleted separately when required.

9. Changes to this policy

This Privacy Policy may be updated when Jarvis’s functionality, requested Google scopes, processing providers, or data-handling practices change. The published “Last updated” date will identify the most recent revision.

10. Contact

Questions about authorization, privacy, or data handling may be sent to the user-support address displayed on Jarvis’s Google OAuth consent screen.