Last updated: 2026-10-06
This document is available in English only.
At Jarvel, we take your privacy seriously. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have regarding your data. This policy applies to the entire Jarvel suite: Jarvel Home (jarvel.com), Jarvel ID, Jarvel Mail and Jarvel Calendar, Jarvel Notes, Jarvel Chat, Jarvel Cloud, Jarvel Docs, Jarvel Social, Jarvel Wallet, Jarvel Maps, Jarvel Photos, Jarvel Video, Jarvel Travel, Jarvel Translate, and the supporting services shared across the suite, such as file storage, notifications, and contacts (together, the "Services"). It applies to all users of the Services, regardless of how you access them. Jarvel, based in the Netherlands, acts as the data controller for the personal data processed through the Services. The exception is company accounts: when an organization uses Jarvel for its employees, that organization is the controller for the company accounts it manages, and Jarvel processes their data on its behalf, as described in section 7. We are committed to processing your data in compliance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
The details are below, but these principles hold across the whole suite: • One account, separate apps: each Jarvel app keeps its own data, and data moves between apps only when you link them, you can unlink at any time • Your content is yours: we do not sell your personal data, and we do not scan the content of your emails, notes, files, messages, or documents to build advertising profiles or show you ads • No third-party trackers: our apps and websites do not use third-party advertising or analytics trackers • EU hosting: your data is stored on servers located in the European Union; the two service providers outside the EU, which send our emails and check the address you sign in from, are listed in sections 8 and 10 • Full control: you can export your data or delete your account at any time from your Jarvel ID account settings; a company account is deleted by the organization that manages it
We collect the following categories of personal data: Account Information (Jarvel ID, provided by you): • Email address (required for account creation and authentication) • Username (chosen during onboarding, unique identifier) • Display name and profile picture / avatar (optional, visible to connected apps) • Password hash (your password is never stored in readable form) • Date of birth, where you choose to provide it Organization Data (Jarvel ID, if you belong to an organization): • The organizations you belong to, your role in each, and whether your account is a company account • Invitations you send or receive, including the invitee's email address • Whether you share your calendar with coworkers, and the actions administrators take on your account Content You Create in the Apps (only in the app concerned): • Jarvel Mail & Calendar: email messages you send and receive, including headers and attachments, calendar events and invitations • Jarvel Notes: notes and lists • Jarvel Chat: messages and conversations • Jarvel Cloud & Docs: files, folders, documents, and collaboration activity • Jarvel Social: profile details, posts, comments, reactions, and connections • Jarvel Wallet: financial records and transactions you enter or import • Jarvel Maps: searches, routes, and saved places • Jarvel Photos: photos and videos with their metadata (such as when and where they were taken and the camera used), albums and who they are shared with, and the faces and people recognized in your library • Jarvel Video: videos you upload, your channel, comments, likes, playlists, subscriptions, and watch history • Jarvel Travel: trips with their destinations and steps (places, times, and notes), who you share them with, and the countries you have visited • Jarvel Translate: your translation history (the text you translate and the result) and favorites, and the glossaries of your organization • Contacts: contact entries you create or sync Technical Data (collected automatically): • IP addresses (logged during authentication and session activity) • Browser user agent strings (used to identify devices in session management) • Session metadata (creation time, last activity time, expiration) • Approximate location derived from the IP address you sign in from (city and country), the network the address belongs to, and whether it is a hosting or VPN address, kept in the security sign-in log • Server logs and diagnostic data needed to operate and secure the Services Traffic Samples (Jarvel Maps app, unless you turn them off): • While you navigate by car, the app sends the positions and times from your phone's GPS once a minute, so we can tell how fast traffic moves on the roads you drive • Samples are not stored with your account; they carry a random code that only links the samples of one trip • Positions within 500 meters of where the trip starts and of its destination are never sent • You can turn this off at any time with "Help improve traffic" in the app's settings Preference Data: • Theme, language, country, timezone, date format, and currency preferences • Notification preferences Security Data: • Two-factor authentication secrets (encrypted, if enabled) • Audit logs (authentication events, profile changes, consent actions, and actions of organization administrators) • Consent version accepted during onboarding Support Data: • Correspondence when you contact us for support
Your data is used for the following purposes: • Providing each Service you use: storing and syncing your content, delivering messages you send, showing you your own data across your devices • Authenticating your identity when you sign in, and managing your active sessions across devices • Delivering one-time email codes and service notifications (new device sign-ins, password changes, and actions an organization takes on your account) • Powering cross-app features you have enabled by linking apps, such as the app launcher, the shared notification feed, and shared contacts • Running organizations: showing members of an organization to each other, sharing calendars between coworkers as described in section 7, and letting owners and administrators manage the organization and its company accounts • Detecting and preventing spam, fraud, abuse, and unauthorized access • Responding to your support requests • Estimating live traffic and the usual speed of each road in Jarvel Maps from traffic samples, which also improves the routes and arrival times we give other drivers • Improving the reliability and performance of the Services, using aggregated or de-identified information wherever possible • Complying with legal obligations We do not sell your personal data to third parties. We do not use the content of your emails, notes, files, messages, or documents for advertising, profiling, or marketing purposes, and we do not show ads in the Services.
Under GDPR Article 6, we process your personal data on the following legal bases: Contract Performance (Art. 6(1)(b)): • Account creation and management • Providing the Services you use, including storing and transmitting your content • Authentication and session management Consent (Art. 6(1)(a)): • Linking Jarvel apps to your account and sharing data with third-party applications (via OAuth consent screens) • Optional email notifications • Optional profile data such as your avatar Legitimate Interest (Art. 6(1)(f)): • Security monitoring and fraud prevention (audit logs, IP logging, rate limiting) • Spam and abuse filtering in communications services • Service improvement and debugging • Estimating traffic in Jarvel Maps from traffic samples; you can object at any time by turning off "Help improve traffic" in the app • Enforcing our Terms of Service Legal Obligation (Art. 6(1)(c)): • Responding to valid legal requests from authorities • Maintaining records as required by applicable law Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
The suite is deliberately built so that each app keeps its own data store. Your notes live in Jarvel Notes, your mail in Jarvel Mail, and so on. Apps do not read each other's content. When you sign in to a Jarvel app with your Jarvel ID, you link that app to your account through the same OAuth consent flow used for third-party apps. Linking shares only the account information shown on the consent screen (typically your user ID, email, display name, and avatar), not the content you keep in other apps. Jarvel ID also notifies linked apps of account-level events via webhooks, for example when you update your profile, request a data export, or delete your account, so that every linked app can honor your rights. Some features you enable may pass specific data between apps (for example, the shared notification feed or shared contacts); these only operate across apps you have linked. You can unlink an app at any time from your Jarvel ID account settings, which stops all sharing with that app from that moment on.
A company or team can use Jarvel as an organization. People belong to an organization either with their own personal Jarvel account, after accepting an invitation, or with a company account that the organization creates for them on its own verified email domain. Who Is Responsible: For company accounts, the organization that manages the account is the data controller, and Jarvel processes the account's data on the organization's behalf as its processor. Questions about how your organization uses your company account, and requests to exercise your rights over it, should be addressed to your organization. For personal accounts that belong to an organization, Jarvel remains the controller as described in the rest of this policy. What Owners and Administrators Can Do: • Create company accounts on the organization's verified domains, and reset their passwords • Suspend a company account, which signs it out everywhere while its content stays in place, and lift the suspension • Delete a company account and choose the coworker who receives the work it shared (see section 11) • See the organization's members and pending invitations, invite people, change roles, and remove members • Turn individual Jarvel apps off for company accounts, and set how much of their calendars coworkers can see • Owners only: delete the organization, choosing whether its company accounts are deleted or turned into personal Jarvel accounts A company account belongs only to its organization: you cannot delete it yourself or leave the organization with it. Administrators cannot reset, suspend, or delete a personal account; they can only remove it from the organization, and you can leave an organization at any time. What Coworkers See: • Every member sees the other members' names, profile pictures, and roles, and the email addresses of company accounts • The email address of a personal account is shown only to the organization's owners and administrators • Company accounts share their calendar with coworkers at the level the organization chooses: nothing, only when they are busy, or also event titles and places • Personal accounts share no calendar with coworkers unless they turn on calendar sharing for that organization, and they can turn it off again at any time • Events you mark as private never show their title or place to coworkers; at most they show as busy Notices: When an administrator suspends, reinstates, or deletes your company account, we email the account's address; the deletion email names the coworker who receives your shared work. When Jarvel suspends an organization, or an organization is deleted, its other members are emailed as well.
We share your personal data only in the following circumstances: At Your Direction: Some Services inherently transmit content to others when you use them, for example sending an email to a recipient outside Jarvel, inviting someone to a document, or publishing a post on Jarvel Social. What you share, and with whom, is your choice. Within Your Organization: If you belong to an organization, its members and administrators see the information described in section 7. Service Providers: We use a limited number of service providers to operate the Services, such as hosting infrastructure and email delivery. These providers process data only on our behalf, under data processing agreements, and are contractually bound to protect your data. Hosting of the Services and storage of your data stay in the European Union. The service providers outside the EU are: • Google Workspace (United States): sends the service emails of the Services through its SMTP service, such as sign-in codes, notifications, invitations, and notices. It processes the recipient's email address and the content of those emails. • ipinfo.io (United States): receives the IP address of each sign-in and tells us which network it belongs to and whether it is a hosting or VPN address, which we use to detect suspicious sign-ins. Legal Requirements: We may disclose your data when required to do so by law, such as in response to a valid court order, subpoena, or government request. We will notify you of such requests unless prohibited by law. Business Transfers: If Jarvel is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy. We never sell your personal data, and we do not share it with advertisers or data brokers.
When you authorize a third-party application via the Jarvel ID consent screen, we share the specific data categories you consented to (typically: user ID, email, display name, and avatar). You can review and revoke app permissions at any time from your account settings. Third-party Connected Apps are governed by their own privacy policies. Revoking access stops future sharing but does not delete data the app already received; contact the app's operator to exercise your rights over that data.
The Services are hosted within the European Union. Your personal data is stored on servers located in the EU. Two of our service providers are based in the United States (see section 8): Google Workspace, which sends our service emails, and ipinfo.io, which checks the IP address you sign in from. Transfers to them are covered by the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework. We will only make any other transfer outside the EU/EEA where adequate safeguards are in place, such as: • European Commission adequacy decisions • Standard Contractual Clauses (SCCs) • Binding Corporate Rules Note that content you address to recipients outside the EU/EEA (for example, an email you send to a non-EU recipient) is transmitted to that recipient's provider as an inherent part of the Service.
We retain your data according to the following schedule: Active Account Data: Retained for as long as your account is active and you use the Services. Content you delete inside an app (for example a note, file, or message) is removed from your account and purged from our systems within a reasonable period, subject to trash/undo features the app may offer. Deleted Accounts: After an account is deleted, it enters a 30-day grace period during which it can be recovered. After this period, its personal data, including its content in every Jarvel app, is permanently and irreversibly deleted from our systems. • Company accounts: when an organization deletes a company account, the work the account shared (with the organization, with other people, or by link) goes to the coworker the organization names, and everything it did not share, including its mailbox, is deleted. • Personal accounts in an organization: items you made in an organization go to that organization (to one of its owners) when your account is deleted. If you are the only owner of an organization that has other members, you need to hand over ownership or delete the organization first; an organization you own with nobody else in it is deleted together with your account. Deleted Organizations: A deleted organization is kept for 30 days, after which it is permanently erased. Session Data: Expired sessions are automatically cleaned up. Active session data is retained for the duration of the session (typically 30 days of inactivity). Security Sign-in Logs: The record of each sign-in, with its IP address and approximate location (city and country), is kept for 730 days so that we can recognize sign-ins that don't match your usual pattern and verify account recovery requests, after which it is permanently deleted. Traffic Samples: Each batch of positions is matched to roads and then deleted, at the latest 15 minutes after it arrives. The resulting speed per road section, with the random trip code, is kept for one hour. After that it only survives in the average speed of that road section for each hour of the week, which no longer contains any trip or code. Audit Logs: Each Jarvel app keeps a log of account, security, and administrative actions (such as password changes, consent actions, and changes made by organization administrators) for 365 days, after which entries are permanently deleted. Organization Invitations: Invitations expire after 7 days and are deleted 30 days after they expire or are accepted. Data Exports: A data export download is available for 24 hours, after which it is deleted. Email OTP Codes: One-time codes expire after 10 minutes and are permanently deleted after use or expiration. Backups: Encrypted backups are retained for up to 30 days, after which deleted data also disappears from backups. Messages you have sent to others (for example an email delivered to its recipient) remain with the recipient even after you delete your copy or your account.
Under the GDPR, you have the following rights regarding your personal data: Right of Access (Art. 15): You can request a copy of all personal data we hold about you. Use the "Download data" feature in your Jarvel ID account settings for instant access. Right to Rectification (Art. 16): You can correct inaccurate personal data directly through your account settings and inside each app. Right to Erasure (Art. 17): You can delete individual content inside each app, and you can delete your account at any time. After a 30-day grace period, your data is permanently deleted, as described in section 11. A company account is deleted by the organization that manages it. Right to Restrict Processing (Art. 18): You can request that we limit how we process your data in certain circumstances. Right to Data Portability (Art. 20): You can export your data in a machine-readable format via the "Download data" feature. Right to Object (Art. 21): You can object to processing based on legitimate interest. Right to Withdraw Consent (Art. 7(3)): You can withdraw consent at any time, for example by unlinking apps, revoking Connected App permissions, or deleting your account. To exercise any of these rights, use the built-in tools in your account settings or contact us at info@jarvel.com. We will respond to your request within 30 days.
You have the right to object to processing of your personal data based on our legitimate interests. Upon receiving your objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests. You may request restriction of processing in the following cases: • You contest the accuracy of your personal data (processing restricted during verification) • The processing is unlawful but you prefer restriction over erasure • We no longer need the data, but you need it for legal claims • You have objected to processing and are awaiting verification of our grounds When processing is restricted, we will only store your data and not process it further without your consent, except for legal claims or the protection of another person's rights.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format. Jarvel ID provides a built-in data export feature in your account settings that covers: • Your profile information (username, email, display name) and account status • Your preference settings • Active session data • Connected application consents • Your organizations and roles, and invitations you sent or received • Notifications, the history of your email address and username, and account recovery requests • Audit log of account activity, including actions others took on your account • The data you keep in every Jarvel app Exports that include data from the apps are processed asynchronously and delivered to your email as a download link, which stays valid for 24 hours. For a very large mailbox, the export contains your most recent messages and points you to the .mbox download in Jarvel Mail (Settings, "Export your mail"), which contains every message with its attachments. You can request one data export per hour, free of charge.
We implement appropriate technical and organizational measures to protect your personal data, including: Encryption & Hashing: • Passwords are hashed using bcrypt with a cost factor of 12 (industry standard) • JWT tokens are signed using RS256 (RSA with SHA-256) • All data in transit is encrypted via TLS/HTTPS • TOTP secrets for two-factor authentication are encrypted at rest Access Controls: • Role-based access control for administrative functions • Session tokens are hashed before storage (we never store raw tokens) • Sensitive fields (password hash, TOTP secret) are excluded from standard database queries • Each app's data store is separate, limiting the impact of any single compromise Infrastructure: • The Services are hosted on infrastructure with industry-standard security certifications • Rate limiting is applied to authentication and abuse-prone endpoints • All administrative actions are logged in the audit trail While we take every reasonable precaution to protect your data, no system is completely secure. We encourage you to use a strong, unique password and to enable two-factor authentication when available. If you believe you have found a security vulnerability in a Jarvel service, please report it to us at info@jarvel.com.
The Services use a minimal set of cookies and local storage, strictly for essential functionality. We do not use tracking cookies, third-party analytics, or advertising cookies anywhere in the suite. Cookies: • jarvel_refresh, Secure, HTTP-only cookie containing your refresh token for session management. Essential for keeping you signed in. Expires with your session. Local Storage: • jarvel_language, stores your preferred interface language. Persists until changed. • jarvel_theme, stores your theme preference (light/dark/system). Persists until changed. • Per-app preferences of the same kind (for example view options), stored locally on your device. These storage mechanisms are strictly necessary for the Services to function and do not require consent under GDPR Recital 30 and the ePrivacy Directive.
The Services are not intended for use by individuals under 16 years of age, in compliance with the GDPR's age of consent requirements for information society services. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take immediate steps to delete the account and all associated data. If you are a parent or guardian and believe your child has created a Jarvel account, please contact us at info@jarvel.com so we can take appropriate action.
We do not engage in automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, as defined in GDPR Article 22. We use automated measures such as rate limiting, suspicious-login detection, and spam and malware filtering in communications services to protect you and the Services. These are security measures, not profiling for marketing. If an automated measure affects your ability to access the Services or delivers a wrong outcome (for example, a legitimate message marked as spam), you can contact us for manual review.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will: • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33 • Notify affected users without undue delay if the breach is likely to result in a high risk to your rights and freedoms (GDPR Article 34) • Provide clear information about the nature of the breach, the likely consequences, and the measures taken to address it We maintain incident response procedures and conduct regular security reviews to minimize the risk and impact of potential data breaches.
The Services may contain links to third-party websites or services that are not operated by us, including links inside content other users share with you. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services. When you authorize a Connected App and are redirected to that application, you leave the Jarvel services. We strongly advise you to review the privacy policy of every site you visit and every application you authorize.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements, for example when we add new apps to the suite. When we make changes, we will: • Update the "Last updated" date at the top of this page • Notify you via email or through the Services for material changes • Give you the opportunity to review changes before they take effect We encourage you to review this Privacy Policy periodically. Your continued use of the Services after changes take effect indicates your acceptance of the updated policy.
For any questions about this Privacy Policy or how we handle your personal data, you can reach us at: Email: info@jarvel.com You also have the right to lodge a complaint with a data protection supervisory authority if you believe your data protection rights have been violated. In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority). We are committed to resolving any concerns about your privacy and our collection or use of your personal data.