Jarvis privacy notice
Last updated: 8 October 2026.
Application and responsible operator
This policy applies to Jarvis, the privately hosted personal voice and text assistant operated by Gurshan Singh. It specifically describes the optional Google Calendar integration and the public application-information website. Privacy and deletion requests can be sent to singhgurshan83@gmail.com. Jarvis is not a public calendar-sharing service.
Google authorization and data accessed
Google Calendar authorization is optional. The integration uses Google's supported OAuth authorization flow; Jarvis does not request or store the user's Google password. Google supplies access and refresh tokens so the private application can make authorized Calendar API requests. The present scope is https://www.googleapis.com/auth/calendar.events.owned.readonly. The permission covers owned-calendar events, while the application restricts its queries to the primary calendar explicitly selected for the Jarvis profile.
Calendar access is bound to a Jarvis profile and limited by the application to the explicitly selected primary calendar. To answer a question, Jarvis requests bounded date ranges and relevant event fields, including event identity, title, start/end times, location and source link where available. Calendar information is used to answer the request and maintain relevant follow-up context.
Purpose and use of calendar information
Jarvis uses those fields to present the requested agenda, find the next appointment within a bounded horizon, and answer contextual questions about an event's time or location. Relevant results are supplied to the private, locally hosted answering model and speech pipeline to produce the requested answer. Calendar text is treated as information, not instructions to operate devices or other tools. Jarvis does not automatically create reminders or permanent personal-memory facts from calendar entries.
Google Workspace API data is not used to develop, improve or train non-personalized AI or machine-learning models. Calendar data is not used for advertising, profiling for advertising, credit decisions, or a public event database.
Storage and protection
Authorization tokens are kept in protected local application storage with operating-system access restrictions. Calendar API communication uses HTTPS. The private application and its local model are separate from this public information site. Tokens, event data and private conversation records are not included in the public website deployment. The integration binds access and retrieved context to the selected Jarvis profile. These controls reduce exposure but are not a claim that any system is immune to security incidents.
Retention and deletion
Tokens are retained while the connection is configured so Jarvis can answer later requests without repeating authorization. Relevant calendar results, generated answers and conversation/tool records may be retained in private application history for continuity and troubleshooting. There is currently no automatic fixed-duration purge of this history; records remain until the operator removes them. Disconnecting Google access does not automatically erase separately retained history, audit records or backups.
To request removal of locally retained calendar information or the saved connection, contact singhgurshan83@gmail.com and identify the Jarvis profile and records concerned without sending a password or token. The operator can remove the saved connection and relevant local records and explain any separately retained backup copies. Removal from Jarvis does not delete the original events from Google Calendar. This notice does not claim that revocation or forgetting a preference erases all transcripts or backups.
Sharing and disclosure
The calendar integration does not send calendar content to web search or delegated Codex workers. Public information pages contain no calendar information. Calendar data is not sold or used for advertising.
Google receives the authorized API requests needed to retrieve the selected events. Returned event data is processed by the owner's private Jarvis service, its local answering model and the selected user-facing console/audio endpoint. It is not published or broadcast to other profiles. The operator may access locally retained records to support the personal application or fulfill a deletion request. Jarvis does not transfer Google Calendar data to third parties for unrelated purposes.
Current permissions and future changes
The current integration is read-only. If the user authorizes the event-creation increment, Google supplies an owned-calendar event-writing permission that also technically permits changes and deletion. The Jarvis controller will restrict that increment to explicitly confirmed event creation in the selected primary calendar. The new permission has not yet been requested or granted.
Any new Google permission requires a separate authorization. This policy and the application's public description will be updated when calendar data handling changes. A planned capability described here is not currently enabled.
Your choices and revoking access
The user can revoke Jarvis's Google access in their Google Account third-party connections settings. For questions about locally retained information or its removal, contact the operator at singhgurshan83@gmail.com. Revocation prevents future authorized access but does not claim deletion of existing local records or Google Calendar events.
Public website hosting
Cloudflare hosts these public information pages and may process ordinary website request information such as IP addresses and security metadata to serve and protect the site. This website does not request Google authorization, display calendar entries or collect private Jarvis conversation content. No application analytics have been added to these pages. Website hosting is separate from storage of Google Calendar data in the private application.
Google API Limited Use
Jarvis's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.