# Privacy

This page describes what JARVIS stores, why, and what you can do about it. It describes the
product as it behaves, and it does not claim protections beyond what the product actually does.

## What is stored

| Data | Why it exists | Where you manage it |
| --- | --- | --- |
| Account information | To identify and authenticate you | [Settings](/jarvis/account/settings/#account) |
| Conversations | To give you history and context | [Conversations](/jarvis/features/conversations/) |
| Memories | To personalise future conversations | [Memory](https://jarvis.spacekeep.dev/memory) |
| Tasks | To hold your list | [Tasks](https://jarvis.spacekeep.dev/tasks) |
| Search-related data | To record what was looked up and answered from it | [Web Intelligence](https://jarvis.spacekeep.dev/web) |
| Security data | Sessions, API keys, and sign-in activity | [Sessions & API Keys](/jarvis/account/sessions/) |

## Account information

Your JARVIS account holds:

- **Email address** — your sign-in identifier and the address that receives account and reset
  emails.
- **Display name** — optional, shown across JARVIS.
- **Reply language preference** — `auto`, English, German, or Italian.
- **Feature preferences** — whether memory and web search are on.
- **Sign-in provider links** — which of Google or GitHub is connected. Status only; no provider
  token or credential is kept.

See [Sign In](/jarvis/account/sign-in/) for how accounts are linked.

## Conversations

Conversations and their messages are stored so you can return to them. They belong to your account.

- Only you can read them.
- Other users cannot see them, and neither can anyone browsing the site.
- They are not used to build a public profile — JARVIS activity does not appear on your
  [SpaceKeep profile](/profiles/).
- Deleting a conversation removes it and its messages.

## Memory

Memory holds short facts you asked JARVIS to keep, filed as **User**, **Preference**, or
**Project**.

- It is stored per account and is private to you.
- **You can see every entry**, edit it, or delete it, at any time.
- **You can switch memory off**, which stops new memories being saved and stops stored ones being
  used in replies.
- Turning memory off does not delete what is already stored — delete entries yourself to remove
  them.
- Credential-shaped content is filtered before storage and is not saved as memory.

See [Memory](/jarvis/features/memory/) for exactly what gets saved.

## Search-related data

When JARVIS searches the web, it sends **the search query** — the subject of your request — to the
search service to retrieve results. That query is what a search engine needs in order to answer.

For your account, JARVIS records:

- The query, the time, and how many results came back.
- Whether the lookup succeeded or failed.
- Which conversation it came from.

You can review all of it on the [Web Intelligence page](/jarvis/features/web-search/#activity-history)
and clear the history at any time. Clearing the history does not change the preference or your
conversations.

With web search switched off, no queries are sent at all.

## Tasks

Task titles and their status are stored so your list persists. They belong to your account and are
covered by the same isolation as conversations.

## Security data

| Data | Purpose |
| --- | --- |
| Active sessions | To keep you signed in and to let you recognise a sign-in |
| API key metadata | Name, prefix, creation and last-used time, revocation state |
| Password reset requests | To send the reset email and invalidate old links |
| Sign-in provider links | To show connection status |

API keys are stored as a hash. The key itself is shown once at creation and cannot be retrieved
afterwards. Passwords are never readable back — not by you, not by support, not through any
endpoint.

## Who can see your data

| Audience | Access |
| --- | --- |
| You | Everything on your account, and you can delete items individually |
| Another JARVIS user | Nothing |
| Anonymous visitors | Nothing — account areas require a session |
| SpaceKeep Labs staff | Not through any interface available to users or JARVIS itself |

JARVIS will not disclose credentials, keys, session tokens, or internal system details in a reply,
however it is asked.

## Removing your data

| To remove | Do this |
| --- | --- |
| A conversation | **⋯** → **Delete** on the conversation |
| A memory | **Delete** on the Memory page |
| A task | **Delete** on the Tasks page |
| Web lookup history | **Clear history** on the Web Intelligence page |
| Active sessions | Change your password |
| An API key | **Revoke** on the Developer page |

> [!NOTE]
> Removing a conversation does not remove a memory that was saved from it. Memories are their own
> records — delete them on the Memory page.

## Related

- [Memory](/jarvis/features/memory/) — what is saved and what is not
- [Web Search](/jarvis/features/web-search/) — what a search sends
- [Account Security](/jarvis/security/account-security/) — credential and isolation guarantees
- [JARVIS Policies](https://jarvis.spacekeep.dev/policy) — the privacy summary in the app
