Last updated: June 29, 2026
This policy describes the Jarvis Google Chat app. It is written for Google Workspace Marketplace and OAuth publication and focuses on Google user data, Chat events and project communication data.
1. Controller
Alexander Paulus
Estrada De Santa Clara 39A
9300-146 Câmara de Lobos, Portugal
Phone: +351960164051
Email: alex@paulus-development.com
2. What Jarvis Does
Jarvis is a Google Chat app for project, task and support communication. Google Chat sends app events to a small relay service. The relay verifies Google requests, normalizes the event and forwards it to the local Jarvis system or stores it briefly for polling. Jarvis then checks whether the Chat space, user and organization are allowed to access the requested project context.
Jarvis is deny-by-default. If a space is not mapped to an approved organization, customer, project, thread or asset scope, Jarvis does not reveal project context and only provides setup or safety guidance.
3. Categories of Data Processed
Depending on how you use the app, Jarvis may process the following data:
- Google Chat event data, such as event type, space ID, space name, thread ID, message ID, timestamps and command or interaction metadata.
- Message content that mentions Jarvis, is sent in a direct message to Jarvis, or is otherwise submitted through a supported Jarvis command.
- User and organization identifiers available in the Google Chat event, such as display name, Google user ID, email address or domain information where Google provides it.
- Project and access-control metadata, such as organization, customer, allowed projects, allowed resources, trust level, permitted answer types and approval settings.
- Audit information, including channel, principal, organization, allowed resources, user query, decision, blocked reason, source IDs used for an answer and action IDs where approval is required.
- Support data you send voluntarily, such as links, screenshots, attachments, bug descriptions or project details.
- Technical security data, such as request metadata, token verification results, error logs and abuse-prevention records.
4. Google User Data Access, Use, Storage and Sharing
Jarvis accesses Google user data only to provide the Google Chat app features you use: receiving Chat events, identifying the requesting user or space, deciding whether access is allowed, generating a response from approved context, and recording an audit trail for security and accountability.
Jarvis does not sell Google user data, does not use Google user data for advertising, retargeting, personalized ads, credit-worthiness, lending, surveillance, or unrelated analytics. Jarvis does not use Google user data to train general AI models.
Google user data is shared only with service providers needed to operate Jarvis, such as hosting, security, logging or AI-processing providers where explicitly configured for a workspace or project. These providers may process data only for the disclosed operational purposes. Jarvis may also disclose data if required by law or to protect security and rights.
5. Purposes and Legal Bases
- Providing project and support communication features: Art. 6(1)(b) GDPR where processing is necessary for a contract or pre-contractual communication.
- Security, access control, abuse prevention and audit trails: Art. 6(1)(f) GDPR based on legitimate interests in secure and accountable operation.
- Compliance with legal obligations: Art. 6(1)(c) GDPR.
- Optional features or expanded access where consent is requested: Art. 6(1)(a) GDPR.
6. Human Access to Data
Human access is limited to Alexander Paulus and authorized service providers where necessary for support, debugging, abuse prevention, security, legal compliance, or when you explicitly ask for review. Customer and project information is separated by access scope.
7. Retention
Jarvis stores personal data only as long as needed for the purposes described above. Relay queue entries are intended to be short-lived and are removed after processing or when no longer needed. Project communication, access mappings and audit logs may be retained for the duration of the customer relationship and for a reasonable period afterwards to document support decisions, security events and legal claims. Backups and technical logs are deleted or overwritten according to operational backup cycles unless longer retention is legally required.
You can request deletion of personal data as described below. Some records may need to be retained where required by law, contract documentation, security investigation or legitimate legal defense.
8. Security
Jarvis uses technical and organizational safeguards including Google request verification, access-context checks before retrieval, deny-by-default space mapping, scoped resource access, audit logging, transport encryption where available, limited administrative access and separation of customer/project contexts.
9. International Transfers
Jarvis may involve providers located outside Portugal or the European Economic Area, including Google services. Where required, transfers are based on adequacy decisions, Standard Contractual Clauses, data processing agreements or other safeguards under applicable data protection law.
10. Your Rights
Under the GDPR, you may have rights to access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent. To exercise your rights, contact alex@paulus-development.com. You also have the right to lodge a complaint with a competent data protection authority, including the Portuguese Comissão Nacional de Proteção de Dados (CNPD).
11. Children
Jarvis is intended for business and project communication and is not directed to children.
12. Changes
This policy may be updated when Jarvis features, data processing, legal requirements or Google publication requirements change. Material changes to Google user data use will be reflected in this policy before the data is used for a new purpose.
13. Contact and Related Documents
For support or privacy questions, email alex@paulus-development.com or use the contact page. The Jarvis Terms of Service are available at /jarvis/terms.
Deutsche Kurzfassung
Jarvis verarbeitet Google-Chat-Ereignisse, Nachrichten an Jarvis, Nutzer- und Space-Kennungen, Projektfreigaben und Auditdaten, um die Google-Chat-App bereitzustellen, Zugriffe zu prüfen, Antworten aus freigegebenem Kontext zu erzeugen und Missbrauch zu verhindern. Google-Nutzerdaten werden nicht verkauft, nicht für Werbung verwendet und nicht zum Training allgemeiner KI-Modelle genutzt. Projektkontext wird nur für explizit freigegebene Spaces und Nutzer verarbeitet. Datenschutzanfragen können an alex@paulus-development.com gerichtet werden.