← Back to main

Privacy policy.

Last updated July 10, 2026

This Privacy Policy explains how Jaz (“Jaz,” “we,” “us,” or “our”) handles your information when you use the Jaz desktop application, the Jaz Browser Bridge extension, the jaz.chat website, and related services (together, the “Service”). Jaz is a personal AI built on coding agents and is designed to run on machines you own. We collect as little personal data as we can while still letting you sign in and use the Service.

1. Who we are

The Service is operated by Augustinas Malinauskas (“the operator”), the data controller for the limited personal data described below. You can reach us at any time at support@jaz.chat.

Jaz is local-first: most of what you create — your threads, loops, boards, memory, and files — lives on your own devices, not on our servers. This policy focuses on the small set of data we do receive when you create an account or interact with our hosted surfaces.

2. Information we collect

We collect the following categories of information:

  • Account information. When you sign in with Google, we receive your name, email address, language preference, profile picture, and your Google account identifier. We use this to create and secure your account.
  • Authentication data. Tokens and session identifiers needed to keep you signed in and to verify your identity. We do not receive or store your Google password.
  • Connected Google service data (Gmail and Calendar). Only if you choose to connect a Gmail account or Google Calendar, Jaz accesses the data needed for the features you use: Gmail messages, threads, drafts, and attachments, and Google Calendar events and calendar lists. Jaz reads this data to carry out your requests — for example, summarising a thread or checking your schedule — and, only when you ask, creates drafts, sends emails you have approved, or creates and updates calendar events. Connecting these services is optional and separate from signing in.
  • Browser Bridge data. If you install and enable the Jaz Browser Bridge Chrome extension, it may read browser data needed for the tasks you ask Jaz to perform, such as URLs, page titles, visible page text, semantic page elements, screenshots, tab metadata, and form fields. This data is sent to the Jaz backend you configure, normally the local Jaz backend running on your own computer.
  • Usage and diagnostic data. Basic, privacy-respecting product analytics and error logs (for example, which pages load, device and browser type, and crash diagnostics) so we can keep the Service working and improve it.
  • Communications. If you email us or otherwise contact us, we keep your messages and contact details so we can respond.

We do not sell your personal information, and we do not use it for advertising or for building advertising profiles.

3. Google sign-in, Gmail, and Google Calendar

Jaz offers sign-in through Google’s Identity Platform. When you sign in with Google, you authenticate directly with Google and grant Jaz access only to the basic profile and email information listed above, which we use to identify you and create your account.

Separately, and only if you choose to, you can connect one or more Google accounts so Jaz can work with your Gmail and Google Calendar on your behalf. These connections are optional, are additional to signing in, and can be revoked at any time. When you connect an account, Jaz requests only the scopes its features need:

  • Gmail (gmail.modify). Read your messages, threads, and attachments so Jaz can search, triage, and summarise your inbox; create and update drafts; and send drafts you have reviewed and approved. We request this single scope because the features need both reading mail and creating and sending drafts; narrower scopes cannot do both. Jaz never permanently deletes your mail, and every send requires your explicit, per-message approval.
  • Google Calendar (calendar.events and calendar.calendarlist.readonly). Read the calendars you are subscribed to and their events so Jaz can answer questions about your schedule and give time-aware help, and — only when you ask — create, update, or move events.

Access tokens for connected accounts are stored on the machine where you run Jaz, not on a central Jaz server. When you ask Jaz to act on your Gmail or Calendar — for example, to summarise a thread or draft a reply — the relevant content is sent to the AI provider you have connected (see Third-party AI providers below) solely to produce the result you requested.

Jaz’s use and transfer of information received from Google APIs — including Google Workspace APIs such as Gmail and Google Calendar — adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the user-facing features of the Service; we do not transfer it to others except to provide those features at your direction, comply with law, or as part of a merger or acquisition; we do not use it for advertising; we do not use it to develop, improve, or train generalised AI or machine-learning models; and we do not allow humans to read it unless you give explicit consent, it is necessary for security or to comply with law, or the data has been aggregated and anonymised.

You can review and revoke Jaz’s access to your Google account at any time from your Google Account permissions page.

4. How we use information

We use the information we collect to:

  • create your account, authenticate you, and keep your session secure;
  • provide, maintain, and improve the Service;
  • respond to your requests and provide support;
  • monitor performance, debug issues, and prevent fraud or abuse;
  • comply with legal obligations and enforce our terms.

Our legal bases for processing (where the UK GDPR or EU GDPR applies) are performance of our contract with you, your consent, our legitimate interests in operating and securing the Service, and compliance with legal obligations.

5. Data on your own devices

Jaz is designed so that your work stays with you. Your threads, loops, boards, memory, source code, and the API keys you connect to coding agents are stored locally on the machines you run Jaz on. The email and calendar data Jaz fetches from connected Google accounts is likewise stored on your own machine — both as the raw records Jaz retrieves and as the searchable notes Jaz builds from them — not on a central Jaz server. We do not receive this content unless you explicitly use a feature that sends it somewhere (for example, sharing an artifact or using an integration you configure).

6. Jaz Browser Bridge extension

Jaz Browser Bridge is an optional Chrome extension that connects browser automation features in Jaz to the signed-in Chrome profile on your own computer. The extension opens a WebSocket connection to the Jaz backend you configure and exposes browser actions such as navigating, reading page state, clicking, typing, scrolling, waiting, and taking screenshots.

By default, the bridge URL points to ws://127.0.0.1:5299/v1/browser/extension, which means browser data is sent to Jaz on your own machine. If you configure a remote Jaz backend, browser data is sent to that backend instead. If a browser task uses an AI provider you connected in Jaz, the relevant browser context may be sent to that provider to complete your request.

The extension stores its bridge URL, auto-connect setting, session-tab mappings, and recent local action history in Chrome storage. It does not sell browser data, use browser data for advertising, or run remotely hosted extension code.

7. Third-party AI providers and services

Jaz connects to coding agents and model providers — such as Anthropic (Claude), OpenAI (Codex), and xAI (Grok) — using the accounts, plans, or API keys you supply. When you run a thread or loop against one of these providers, your prompts and the relevant context are sent directly to that provider and are handled under that provider’s own terms and privacy policy. We encourage you to review them.

We also rely on a small number of service providers (subprocessors) to operate the Service, including:

  • Google — identity and sign-in (Google Identity Platform);
  • Cloudflare — hosting and content delivery for jaz.chat;
  • analytics and error-monitoring providers — to understand usage and diagnose problems.

These providers process data only on our instructions and to the extent needed to provide their service.

8. How we share information

We share personal information only in these limited circumstances:

  • with the service providers described above, acting on our behalf;
  • when you direct us to, or use a feature that shares data with a third party you choose;
  • to comply with applicable law, regulation, legal process, or an enforceable governmental request;
  • to protect the rights, property, or safety of Jaz, our users, or the public;
  • in connection with a merger, acquisition, or sale of assets, in which case we will require the recipient to honour this policy.

9. Data retention

We keep account information for as long as your account is active and as needed to provide the Service. When you delete your account, we delete or anonymise the personal data we hold about you within a reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, or enforce our agreements. Diagnostic logs are kept only for as long as they are useful for security and troubleshooting.

10. Security

We use technical and organisational measures appropriate to the sensitivity of the data — including encryption in transit and access controls — to protect personal information against loss, misuse, and unauthorised access. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security, but we work to protect your data and to address incidents promptly.

11. Your rights and choices

Depending on where you live, you may have rights over your personal data, including the right to access, correct, delete, or port it; to object to or restrict certain processing; and to withdraw consent. If you are in the UK, EEA, or a jurisdiction with similar laws (such as California), these rights apply to you.

To exercise any of these rights, email us at support@jaz.chat. We will respond within the time required by applicable law. You also have the right to lodge a complaint with your local data protection authority — in the UK, the Information Commissioner’s Office (ICO).

12. International data transfers

We and our service providers may process information in countries other than where you live, including the United Kingdom, the European Economic Area, and the United States. Where we transfer personal data across borders, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or the European Commission’s Standard Contractual Clauses.

13. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal data, contact us and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide a more prominent notice. Your continued use of the Service after an update means you accept the revised policy.

15. Contact us

If you have questions about this Privacy Policy or how we handle your data, contact us at support@jaz.chat.