Policy · Effective August 28, 2026
Privacy is an architectural boundary.
This policy explains how the Jarvis Home Project handles data, including data obtained through Google Nest and Home Assistant.
Project scope
Jarvis Home Project is a private, self-hosted household intelligence project operated for personal use. This public website is informational. It does not provide access to the private Jarvis system, household devices, live status, cameras, or personal records.
Google user data accessed
After the Google account owner gives explicit OAuth authorization, the private system may access Google Nest device and structure information made available through Google Device Access and Home Assistant. Approved data is limited to:
- Nest thermostat operating state, set point, ambient temperature, humidity, fan status, and device metadata.
- Nest Hub Max camera availability state and motion-event metadata.
- Identifiers required to associate approved devices and events with the correct Home Assistant entities.
Jarvis never asks for or receives the Google account password. OAuth access can be revoked by the account owner through Google Account settings.
How the data is used
Google user data is used only to provide household awareness to the account owner—for example, reporting thermostat conditions or whether an approved device is available. It is not used for advertising, profiling, eligibility decisions, surveillance, or training public machine-learning models.
Storage and protection
Operational data and credentials remain in the owner-controlled, self-hosted environment. Access tokens are stored outside the public website and source repository with restricted filesystem permissions. The public site contains no live household data.
The system publishes only a fixed allowlist of approved fields. Camera access tokens, entity-picture URLs, images, snapshots, streams, and media identifiers are excluded from the Jarvis observer interface. Restricted operational state is separated from the public-safe observer snapshot.
Sharing, sale, and transfer
Google user data is not sold, rented, shared with advertisers, or disclosed to data brokers. It is processed only by the owner-controlled services necessary to operate the private project, including Google Device Access and Home Assistant as authorized by the owner.
Retention and deletion
Current-state observations are refreshed and may replace earlier state. Limited operational records may be retained to diagnose reliability and security issues. The owner can stop collection by revoking Google authorization or disabling the Nest integration, and can remove retained local data from the self-hosted environment.
Children’s privacy
The project is not offered to children and does not knowingly collect Google account data from children. Household device-health monitoring uses explicit privacy boundaries: child-associated devices do not expose logged-in, screen-lock, camera, screenshot, or remote-control information through Jarvis.
Public website data
This website does not require an account and does not intentionally set advertising or behavioral-tracking cookies. Standard hosting and security infrastructure may process basic request information—such as IP address, browser type, requested page, and timestamp—to deliver and protect the site.
Contact and updates
Privacy questions can be sent to the project contact address displayed on the Google OAuth consent screen. Material changes to this policy will be published here with an updated effective date.