Legal

Privacy Policy

Last updated August 17, 2026

This page explains what Concept Bytes LLC collects when you use Jarvis, why, on what legal basis, and how long we keep it. The short version: we collect what we need to run your account and the assistant; we do not keep a server-side archive of your conversations; and we do not sell your data or use it for third-party advertising. Use of Jarvis is also governed by the Terms of Service.

01Who we are

This policy is for Jarvis, the Jarvis desktop application, and the website at jarvisdesktop.com (together, the “Service”). The controller of personal information processed through the Service is:

Concept Bytes LLC
Email: info@concept-bytes.com
Website: www.jarvisdesktop.com

In this policy, “we”, “us”, and “Concept Bytes” mean Concept Bytes LLC. If you need a postal address, email us and we will provide it.

Questions about this policy or about your data should go to info@concept-bytes.com. Use of Jarvis is also governed by the Terms of Service, which cover acceptable use, billing, and liability. Those subjects are not repeated here.

02We collect user data

We collect information so we can create your account, run the product, and keep it working. That includes:

  • Account details — email address, password (stored as a hash, never in plain text), and an optional display name.
  • Billing details — plan, subscription status, and identifiers needed to manage a payment. Card numbers are handled by Stripe, not stored on our servers.
  • Product use — sign-in time, downloads, registered devices, and usage events the desktop app or our servers record (for example that a voice minute or an AI request was spent). These tell us the product is being used and let us enforce plan limits. They do not include the text or audio of a conversation.
  • What you say to Jarvis — text you type and voice you speak, so the assistant can reply. How that is handled, and the fact that we do not keep a conversation archive, is explained in the next two sections.
  • Website traffic — page views, referring site, device type, and country. Country is inferred from your IP address at the network edge. We do not ask your browser for a precise location, and we do not store raw IP addresses for analytics.
  • Technical logs — the usual request metadata a hosted site sees (time, path, status code, and similar), used to run, secure, and debug the Service.
  • Rate-limit fingerprints— a salted hash of the visitor's IP address, used only to throttle the public website chat. The address itself is not stored.

03What happens to conversations

This is the part people usually want first. Jarvis is an assistant: to answer you, the content of that turn has to reach a language model. What we do not do is keep a copy afterwards.

We do not store prompts, replies, or transcripts in our database. There is no account chat history on our servers that you can reopen later, and our staff cannot read your conversations from our systems. What we keep is that a request happened — for example that a credit was spent — not what was said.

On the website, the widget remembers the current thread in your browser's session storage so the window does not go blank if you close it and open it again in the same tab. That copy lives on your device. It is sent back to us only as context for the next message, and we do not write it to a database. Closing the tab clears it.

On the desktop app, each request is forwarded to the model and the reply is streamed back. We do not save that exchange on our servers. If the app keeps a local history on your computer, that copy stays on your computer and is under your control.

After a reply has been generated, our servers discard the prompt and the output. Providers that generated the reply may retain data for a limited time under their own policies, which we do not control. See “We use AI” below.

04Voice and audio

Microphone access is used only when you start a voice session. Audio is streamed to ElevenLabs so it can be turned into text and spoken back. We do not retain the original recording after the session, and we do not store a transcript of that session in our database.

ElevenLabs processes the audio to provide the feature. How long they keep it, and whether they use it for anything beyond providing the service, is governed by their terms and the account we hold with them. We do not use voice audio to train our own models.

05We use AI

When you talk to Jarvis — on the website or in the desktop app — the content of that turn is sent to the language or speech model that generates the reply. That is how the product works. We do not use those conversations to train our own models, and we do not sell them.

Text replies go through OpenAI's API. OpenAI states that, on the API, it does not use inputs or outputs to train its models by default. It may still retain data for a limited time for abuse monitoring, under its own policy. We do not control that retention. See OpenAI's API data controls.

Speech goes through ElevenLabs, as described above. See ElevenLabs' privacy policy. We do not make claims about their training or retention beyond what those terms say.

06We do not sell your data or use it for third-party advertising

We disclose information to service providers that help us operate Jarvis, but we do not sell personal information or disclose it to advertisers or data brokers for their own advertising or profiling purposes. We do not rent our user list. In California terms, we do not “sell” personal information and we do not “share” it for cross-context behavioural advertising.

The companies that receive data do so only as needed to run the Service:

  • Supabase — accounts, sessions, and the product database.
  • Vercel — hosts the website and provides privacy-focused traffic analytics. It is not an advertising network.
  • OpenAI — the language model behind text replies.
  • ElevenLabs — speech recognition and spoken replies.
  • Stripe — checkout and subscription billing.
  • Have I Been Pwned — a check, at signup and password reset, that a new password has not already appeared in a public breach. The password itself is never sent; only a short hash prefix leaves your device.

Those providers process data on our behalf to operate Jarvis. They are not given it to advertise to you on other sites.

07How we use data, and the legal basis

If you are in the European Economic Area, the United Kingdom, or another place that requires a legal basis, we rely on the following. Even if those laws do not apply to a particular visitor, this is still why we use the data.

  • Performance of a contract. Creating and keeping your account, signing you in, processing a subscription, answering assistant requests, metering credits, and enforcing device limits are necessary to provide the Service you asked for.
  • Legitimate interests. Keeping the Service secure, preventing abuse, debugging outages, and understanding how the site and app are used (aggregated traffic and usage events, not conversation content). We balance those interests against your rights; you can object, as described below.
  • Legal obligation. Keeping billing and tax records, and responding to a lawful request from a court or regulator.
  • Consent. We do not currently send marketing email or use advertising cookies. If we add either, we will ask where the law requires it, and you will be able to withdraw consent without affecting other processing.

08Cookies and similar technology

We use cookies and similar storage for two jobs: keeping you signed in, and measuring site traffic with Vercel Web Analytics. Session cookies are required for the account pages to work. Analytics tell us which pages are visited; they are not used to advertise to you on other sites, and we do not run advertising, retargeting, or social-media pixels.

The website chat also uses session storage on your device, as described above. That is not a tracking cookie.

You can block cookies in your browser. If you block the session cookie, you will not be able to stay signed in. If we later add non-essential tracking, we will update this section and, where required, ask for consent.

09How long we keep it

We keep personal information only as long as we need it for the purposes above, then delete or anonymise it. In practice:

  • Account profile (email, display name, account status) — for as long as the account exists. When the account is deleted, we delete this row.
  • Chat history, prompts, and transcripts— not stored on our servers. The website widget's copy lasts until you close the tab. We do not keep a server-side archive.
  • Voice recordings — not retained by us after the session. Audio is streamed to ElevenLabs for processing only.
  • Usage events and credit ledger — for as long as the account exists, so we can enforce plan limits and handle billing disputes. Deleted with the account.
  • Download and device records — for as long as the account exists, or until a device is removed. Deleted with the account.
  • Website chat rate-limit hashes — about one day. Older windows are purged automatically.
  • Application and server logs — kept by our hosting provider for a short operational period, typically days to a few weeks, to run and debug the Service. They are not a conversation archive.
  • Website analytics — aggregated traffic figures held by Vercel for the reporting window of our plan.
  • Billing and tax records — we and Stripe keep payment and subscription records for as long as tax and accounting rules require, typically up to seven years, even after an account is closed.
  • Deleted-account backups — after we delete an account, residual copies may remain in encrypted backups until those backups rotate. We do not use backup copies for any other purpose.

10Your rights

You can, from your account or by emailing us:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate account details.
  • Ask us to delete your account and the personal data we control.
  • Ask us to restrict certain processing, or object to processing we base on legitimate interests.
  • Ask for a portable copy of account data you have given us, where that right applies.
  • Withdraw consent, if we ever rely on it, without affecting processing that does not need consent.
  • Cancel a subscription from the billing portal.
  • Complain to a data-protection regulator, including in your country of residence.

Depending on where you live, some of those rights may apply as a matter of law (for example under the UK or EU GDPR). We will honour a valid request even where a particular statute may not formally apply to us.

California residents may have additional rights under the CCPA/CPRA if that law applies to our business — including to know, access, correct, and delete personal information, and to opt out of sale or sharing. We do not sell personal information or share it for cross-context advertising. We will not discriminate against you for exercising a privacy right: you will not be charged a different price or given a lesser service for making a request. Whether every CCPA right applies depends on statutory thresholds we may or may not meet; the wording above is how we handle requests, not a claim that every California provision necessarily applies.

To make a request, email info@concept-bytes.com. We may need to verify that the request comes from the account holder.

11Children

Jarvis is not directed at children under 13. You must be at least 13 years old to create a Jarvis account. If we learn that we have collected personal information from a child under 13 without appropriate parental consent, we will delete it.

12Automated decisions

Jarvis uses AI to generate assistant responses. We do not use Jarvis to make automated decisions about you that produce legal or similarly significant effects — for example, we do not use it to decide whether you may open an account, what you will be charged, or whether a payment is accepted. Those decisions are made by our account, billing, and security systems, or by you.

13Business transfers

If Concept Bytes LLC is involved in a merger, acquisition, financing, reorganisation, bankruptcy, or sale of all or part of its business, information may be transferred as part of that transaction, subject to applicable law. We will continue to treat it under this policy, or we will notify you of a new controller.

14Security

We use HTTPS, hashed passwords, signed-in access controls, and server-side checks so one user cannot read another user's data. No internet service is perfectly secure. If we become aware of a breach that affects you, we will notify you as the law requires.

15International processing

Concept Bytes LLC is established in the United States. We and our providers process data in the United States and may process it in other countries. If you use Jarvis from the EEA, the UK, or elsewhere, your information will be transferred to the United States so the Service can run. Where a provider offers a transfer mechanism (for example standard contractual clauses), we rely on that mechanism. By using the Service you understand that US law will apply to that processing.

16Changes

If we change this policy in a material way, we will update the date at the top of this page. Continued use of the Service after a change means you accept the updated policy.

Questions: info@concept-bytes.com.