Skip to content
JervisJervis DESKTOP MCP
HomePrivacyTermsSupportالعربيةDownload

Privacy

Privacy Policy

Effective 14 September 2026

This policy explains what data Jervis Desktop MCP (“Jervis”, “we”, “us”) handles when you use the website at desktop.jervis.cloud, the Jervis Desktop app for Windows, the hosted Remote MCP service at mcp.jervis.cloud and the sign-in service at auth-mcp.jervis.cloud. Jervis is operated by Kerolos Zakaria (Jervis Tech).

On this page

  1. Data we collect
  2. What we do not do
  3. How we use data
  4. Who receives data
  5. How long we keep data
  6. Your choices and rights
  7. Security
  8. International processing
  9. Children
  10. Changes to this policy
  11. Contact

The short version

  • You choose which project folders are shared, and whether each one is read-only or editable.
  • When your AI assistant uses a Jervis tool, the request and its result, which can include the contents of your files, pass through and are stored by the Jervis service, then go to the AI provider you use.
  • We do not sell personal data, show ads, or use analytics or tracking cookies.
  • You can ask us to access or delete your data at any time by emailing keroloszakaria2@gmail.com.

Data we collect

Account data. Jervis accounts are created by invitation. The sign-in service (a Keycloak server we host ourselves) stores your username, email address, an internal account identifier and your password in hashed form. The Remote MCP service receives only your account identifier and granted permissions from the sign-in token; it does not store your email or name.

Device data. When you pair the desktop app, we store the device name (by default your Windows computer name), operating system, processor architecture, number of processor cores, total memory, app and runtime version, enabled features, the device’s public key and fingerprint, and pairing, last-seen and revocation times. We do not collect IP addresses, MAC addresses or your Windows username through the app.

Tool requests and results. When your assistant calls a tool, we store the tool name, its arguments (for example file paths, search text or content to be written), the result returned by your device (which can include file contents from the projects you share) and any error. The service needs this to relay work between your device and your assistant.

Approval records. For actions that need your approval, we store your account identifier, the device, the tool, a risk level and a short preview describing the action, such as paths and byte counts. Previews do not include file contents.

Security audit records. We log security events such as pairing, approvals, authorised calls and revocations. Each record contains the event type, account or device identifier, tool name, outcome and time. Audit records do not contain arguments, file contents or IP addresses.

Server logs. Like most websites, our web servers may record your IP address, the time, the requested address and your browser’s user agent when you visit the website or reach the service.

Data on your computer. The desktop app keeps your project list (names, folder paths and permissions), an encrypted device credential, a log of request identifiers without their contents, and your language preference on your PC. These stay on your device except as described in this policy.

What we do not do

  • We do not use analytics, advertising, tracking pixels or crash-reporting services.
  • The website sets no cookies. The sign-in service uses only the cookies needed to keep you signed in.
  • We do not sell or rent personal data, and we do not use your files to train AI models.
  • Project sharing in the desktop app does not read your screen or clipboard and does not run shell commands.

How we use data

  • To provide the service: signing you in, pairing devices, routing tool requests and returning results.
  • To keep the service secure: verifying devices, enforcing permissions and approvals, and investigating misuse.
  • To answer your support, privacy and security requests.
  • To meet legal obligations.

Who receives data

Your AI provider. Tool results, including file contents your assistant requests, are sent to the AI assistant you connected, such as ChatGPT (OpenAI) or Claude (Anthropic). Their handling of that data is governed by their own terms and privacy policies.

Hosting provider. Our servers run on a virtual private server rented from Hostinger, which provides the underlying infrastructure.

Legal requirements. We may disclose data if required by law, or where necessary to protect the rights, safety or security of users, the public or the service.

We do not share personal data with anyone else.

How long we keep data

  • Account data is kept while your account exists and deleted when you ask us to delete your account.
  • Device records are kept after a device is revoked, so revoked devices stay blocked, until your account is deleted.
  • Tool requests and results are currently kept in service storage and are not deleted automatically. You can ask us to delete them at any time.
  • Approval records expire for use after a few minutes but remain stored until your account is deleted.
  • Security audit records are kept for as long as needed for security and accountability. They are append-only and contain identifiers, not file contents.
  • Server logs are kept for a limited period for security and troubleshooting.
  • Data on your computer stays until you remove it. Uninstalling the app does not delete the .jervis-desktop-mcp folder in your user profile.

Your choices and rights

  • Choose which projects to share, keep them read-only, pause sharing for a project, or close the app to stop sharing entirely.
  • Revoke a paired device by asking your assistant to use the jervis_remote_revoke_device tool, and remove the Jervis connector in ChatGPT or Claude.
  • Ask us for a copy of your data, a correction, or deletion of your account, device records and stored tool requests and results by emailing keroloszakaria2@gmail.com.

We respond to privacy requests within 30 days. We may need to confirm that the request comes from the account owner. Some audit records may be kept where needed for security or legal reasons.

Security

Connections to the website and service use HTTPS (TLS 1.2 or later). Each desktop device signs its requests with its own key, and the private key is protected on your PC with Windows data protection. Pairing codes are stored only as hashes and expire after 15 minutes. Service data is kept on access-restricted servers, and security events are recorded in a tamper-evident log. No system is completely secure, so please share only the projects you need.

International processing

Our hosting provider and the AI provider you use may process data in countries other than your own. By using Jervis with an AI assistant, your requested content is processed by that provider under its own safeguards.

Children

Jervis is not intended for anyone under 18, and we do not knowingly collect data from children. Contact us if you believe a child has provided us with personal data.

Changes to this policy

We will update the effective date above when this policy changes, and give notice on this website before material changes take effect.

Contact

Kerolos Zakaria (Jervis Tech) · keroloszakaria2@gmail.com

Back to top

Jervis.Built by Jervis Tech. Your workspace, connected.
PrivacyTermsSupport
© 2026 Jervis Tech