1. Google data Jarvis may access
The exact permissions depend on the features a user enables. They may include:
- Google Tasks data needed to list, create, update, organize, or complete tasks requested by the user.
- Google Calendar data needed to list availability and create, update, or organize events requested by the user.
- Gmail data needed for enabled email features, such as preparing, sending, reading, or organizing messages requested by the user.
- Google Drive file metadata and content needed to search, preview, summarize, or download files in a workflow explicitly started by the user. Jarvis does not edit, share, move, or delete Drive files through this read-only permission.
- Basic account information, such as name and email address, used to connect the correct Google account.
Jarvis requests the narrowest permissions reasonably required for enabled features.
2. How Google user data is used
We use Google user data only to perform actions the user requests, display relevant information, maintain the authorized connection, prevent duplicate actions, diagnose failures, protect the service, and provide requested support.
We do not sell Google user data. We do not use Google user data for advertising. We do not use private Google Workspace content to train general-purpose advertising models or sell user profiles.
3. Storage and security
The current desktop release stores each user's OAuth refresh token in encrypted local credential storage. Access tokens are short-lived and refreshed automatically when needed. Tokens are not stored in plaintext project files.
Any hosted deployment that processes Google user data must apply encryption in transit, access controls, least-privilege permissions, logging minimization, and documented retention controls. We will update this policy before materially changing how Google user data is handled.
4. Sharing and disclosure
We do not share Google user data except with service providers acting on our instructions and bound by security obligations, when the user directs Jarvis to share information with a specified recipient, or when required by law or security needs.
When an enabled AI feature needs message, event, task, or file content to answer the user's explicit request, Jarvis may send only the necessary content to contracted AI-processing infrastructure. Those providers process the content on our behalf for the requested feature; we do not permit Google user data to be used to train generalized AI or advertising models.
Any transfer or use of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements.
5. Retention and deletion
OAuth tokens are retained while the user keeps the Google connection active. Operational logs are limited to information needed for reliability and security and should not contain complete message or file bodies unless required for a user-requested workflow.
Users may disconnect Google Workspace at any time. After a verified deletion request, we will delete or render inaccessible stored OAuth tokens and associated service data, except information that must be retained for legal, security, or fraud-prevention purposes.
6. User controls
- Review and revoke Jarvis access from Google Account security settings.
- Disable individual Google Workspace features where supported.
- Request access, correction, export, or deletion of data associated with Jarvis.
- Contact us at minhtq@aisutralab.com.
7. Children's privacy
Jarvis is not directed to children under the minimum age required to consent to online services in their jurisdiction. We do not knowingly collect Google Workspace data from children without appropriate authorization.
8. Changes and contact
We may update this policy when features, laws, or data practices change. We will update the effective date and provide additional notice when a change materially affects Google user data.
SutraLabminhtq@aisutralab.com
https://www.aisutralab.com/
