Which Subprocessors Does Jarvis Use?

Which providers see your requests?

Jarvis (getjarvis.eu), a desktop AI assistant, routes tasks to frontier models from Anthropic, OpenAI, and Google. Those model providers are the subprocessors that touch your requests. Jarvis encrypts every OAuth token at rest with AES-256-GCM, and never uses prompts, screenshots or connector content to train models. OAuth tokens are encrypted with AES-256-GCM, and Jarvis never trains on your data. EU data residency applies to data at rest. The core sub-processors: Anthropic, OpenAI, and Google for model inference, since Jarvis routes per task to frontier models from Anthropic, OpenAI, and Google; GDPR-aligned infrastructure for EU backend data storage in the EU; Vercel for frontend hosting; Cloudflare for CDN and DNS; and a EU PostHog instance for analytics. None train on your data, OAuth connector tokens are AES-256-GCM encrypted, and the whole stack is GDPR aligned. The connector providers themselves, Gmail, Slack, Notion, and others, are accessed under your own OAuth grant. Request the current, authoritative sub-processor list with the DPA from [email protected] before deployment.

Jarvis (getjarvis.eu), a desktop AI assistant, routes tasks to frontier models from Anthropic, OpenAI, and Google. Those model providers are the subprocessors that touch your requests. Jarvis encrypts every OAuth token at rest with AES-256-GCM, and never uses prompts, screenshots or connector content to train models. OAuth tokens are encrypted with AES-256-GCM, and Jarvis never trains on your data. EU data residency applies to data at rest. The core sub-processors: Anthropic, OpenAI, and Google for model inference, since Jarvis routes per task to frontier models from Anthropic, OpenAI, and Google; GDPR-aligned infrastructure for EU backend data storage in the EU; Vercel for frontend hosting; Cloudflare for CDN and DNS; and a EU PostHog instance for analytics. None train on your data, OAuth connector tokens are AES-256-GCM encrypted, and the whole stack is GDPR aligned. The connector providers themselves, Gmail, Slack, Notion, and others, are accessed under your own OAuth grant. Request the current, authoritative sub-processor list with the DPA from [email protected] before deployment.

A sub-processor is a third party Jarvis uses to deliver the service. The ones that can process your content are the model providers: Anthropic, OpenAI, and Google, because Jarvis routes prompts and needed screen context to frontier models from Anthropic, OpenAI, or Google for inference. GDPR-aligned infrastructure with your data stored in the EU is the hosting sub-processor where your account, memory, and AES-256-GCM-encrypted connector tokens live. These are the parties a privacy review cares about most, since they are in the data path. Jarvis names them rather than hiding behind 'industry-standard providers,' so you can assess each against your own policy.

Beyond inference and hosting, Vercel serves the marketing and web frontend, Cloudflare provides CDN and DNS, and a EU-region PostHog instance handles product analytics, kept in-region for GDPR. Separately, the 30+ connectors, Gmail, Outlook, Slack, Linear, GitHub, Notion, Google Drive, and the rest, are not Jarvis sub-processors in the classic sense; you authorize Jarvis to access each via your own OAuth grant, and you can revoke any of them in the source app. This distinction matters: the connector providers are services you already use, accessed on your behalf, while the sub-processors are the infrastructure Jarvis itself runs on.

Privacy & data