Privacy Policy
The short version. Jarvis stores your trips, your preferences and the travel documents you give it, so it can plan and keep track of your travel. It is not sold, not used for advertising, and not used to train AI models. If you connect a mailbox, Jarvis looks only for travel confirmations. You can delete everything from inside the app at any time.
1. Who is responsible for your data
Jarvis is operated by Aviv Salton, a sole trader (עוסק פטור) established in Israel, who is the data controller for the purposes of this policy.
For anything to do with your data, write to support@gowithjarvis.com. That address is monitored and is the fastest route to a human.
2. What Jarvis collects
Information you give directly
- Account details: your email address, and a display name and photo if you choose to add one. If you sign in with Apple or Google, we receive your email address and name from them. If you use Apple's Hide My Email, we only ever see the relay address.
- Traveller profile: the answers you give during onboarding and in Settings: travel style, budget range, pace, dietary requirements, accessibility needs, and the nationality of the passport you travel on. Dietary and accessibility answers may reveal information about your health or beliefs. They are optional, you can remove them at any time, and they are used for one purpose only: filtering what Jarvis suggests.
- Trips and itineraries: destinations, dates, the places in your plan, your tasks and notes.
- Messages: what you write in the chat, and Jarvis's replies.
- Documents: files you upload or forward, such as boarding passes, hotel confirmations, insurance policies and visa approvals. These frequently contain passport numbers and booking references.
Information from a connected mailbox
Connecting a mailbox is entirely optional and Jarvis works without it. If you do connect one, Jarvis searches for travel confirmations (flights, hotels, trains, car hire) and extracts the booking details into your trip. It does not read, index or store the rest of your mail.
You can also skip the connection entirely and forward individual confirmations to a private
address on in.gowithjarvis.com. In that case Jarvis only ever sees what you choose
to send it.
Information collected automatically
- Technical data: device type, operating system version, app version, and error diagnostics, used to keep the app working.
- Location: only if you grant permission, and only to show what is near you. Jarvis does not track your location in the background.
3. Why Jarvis uses it
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and running your account | Account details | Performance of a contract |
| Planning trips and suggesting places | Trips, traveller profile, messages | Performance of a contract |
| Checking entry and visa requirements | Passport nationality, destinations, dates | Performance of a contract |
| Filing your bookings and documents | Documents, mailbox confirmations | Performance of a contract |
| Sending verification codes and service notices | Email address | Performance of a contract |
| Keeping the service secure and debugging faults | Technical data | Legitimate interests |
Jarvis does not use your data for advertising, does not sell or rent it, and does not use it to train AI models. See section 6.
4. Where your data is stored
Your account, trips, messages and documents are stored with Supabase, on
infrastructure located in Singapore (AWS ap-southeast-1). Data is
encrypted in transit and at rest, and access is restricted per user by row-level security so one
account cannot read another's records.
Because Jarvis is operated from Israel and hosted in Singapore, using the service involves an international transfer of your personal data. Where required, transfers are made under appropriate safeguards including standard contractual clauses with the providers listed below.
5. Services Jarvis shares data with
Jarvis relies on the following providers. Each receives only what it needs to do its job, and none of them are permitted to use your data for their own purposes.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Supabase | Database, authentication, file storage, server functions | All account and trip data | Singapore |
| OpenAI | Understands your messages, writes itineraries, extracts booking details from confirmations | Chat messages, trip context, and the content of travel confirmations being parsed | United States |
| Google Places | Place details, opening hours, ratings | Search terms and destinations, not your identity | United States |
| SerpApi | Flight search results | Routes and dates, not your identity | United States |
| Serper | Web search for current travel information | Search terms, not your identity | United States |
| LiteAPI (Nuitée) | Hotel availability and rates | Destination, dates, guest count, not your identity | European Union |
| Resend | Sends verification codes and service email | Your email address and the message | European Union (eu-west-1) |
| Apple · Google | Sign-in, and mailbox access if you connect one | Authentication tokens; mailbox scope only if granted | United States |
| Cloudflare | Hosts gowithjarvis.com and its DNS | Website requests only, no app data | Global edge network |
OpenAI processes data through its API, under terms that prohibit using it to train models. If this list changes materially, this page is updated and the date at the top changes with it.
6. Google user data and Limited Use
If you connect a Google mailbox, Jarvis requests read access in order to find your travel confirmations and file them against the right trip. That is the only purpose.
Jarvis's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained from Google APIs is not used for advertising, not sold or transferred except as needed to provide the features described here or as required by law, and not used to develop, improve or train generalised artificial intelligence models. No human reads your mail, except where you specifically ask for support, where it is necessary for security purposes, or where the law requires it.
You can disconnect a mailbox at any time from Settings → Connected Email, or revoke access directly at myaccount.google.com/permissions. On disconnection, the stored access tokens are destroyed immediately and the booking data extracted from your mail is deleted within 30 days unless you have separately saved it to a trip.
7. How long data is kept
- Account and trip data: kept while your account exists.
- Mailbox tokens: destroyed immediately when you disconnect.
- Data extracted from mail: deleted within 30 days of disconnection.
- Deleted accounts: when you delete your account, your profile, trips, itineraries, chats, tasks, documents and expenses are removed immediately from the live database. Encrypted backups roll off within 30 days.
- Diagnostic logs: retained up to 30 days.
8. Your rights
Under Israel's Protection of Privacy Law, 5741–1981, you may request access to the personal data held about you and ask for it to be corrected or deleted. If you are in the European Economic Area or the United Kingdom, you additionally have rights to restrict or object to processing, to data portability, and to lodge a complaint with your supervisory authority.
Most of these you can exercise yourself, immediately, inside the app: edit your profile in Settings, and delete everything from Settings → About & Legal → Delete account. For anything else, write to support@gowithjarvis.com and you will have a reply within 30 days.
9. Security
Data is encrypted in transit (TLS) and at rest. Access to your records is enforced at the database level by row-level security. Mailbox tokens are held in an encrypted secrets vault and never stored in the app. Sign-in is by one-time code or by Apple or Google, so there is no password to leak.
No system is perfectly secure. If a breach affects your personal data, you will be notified without undue delay, along with the relevant authority where the law requires it.
10. Children
Jarvis is not intended for anyone under 16, and accounts are not knowingly created for them. If you believe a child has provided personal data, write to support@gowithjarvis.com and it will be deleted.
11. Changes to this policy
This page is updated when the service changes. The date at the top always reflects the current version. If a change materially affects how your data is used, you will be told in the app or by email before it takes effect.
12. Contact
Aviv Salton (עוסק פטור), Israel
support@gowithjarvis.com