This policy explains what HiJavis ("we", "the app"), operated by DeepShare AI, collects, why, how long we keep it, and how you can delete it. HiJavis is available as an iOS app and at javis.is.
Your email address and authentication identifiers, handled by our identity provider Clerk, so you can sign in and so your data stays yours.
Voice recordings, their transcripts, text you type into the app, and the notes, events and wiki pages derived from them.
Only if you choose to connect Google: your OAuth tokens, Gmail message headers and thread text, and the events on your primary Google Calendar. See section 2.
Only if you use the Javis Wiki Sync plugin for Obsidian and select folders for upload: the text, path and title of the notes in those folders. See section 3.
Only if you connect an AI assistant such as Claude, or the Javis Wiki Sync plugin for Obsidian, to Javis: the name the assistant or plugin registers under, the addresses it asks us to send you back to, the network address its registration request came from, and a record of each refresh token we issue it, holding a fingerprint of the token rather than the token itself. See sections 3 and 4.
Server logs containing request timestamps, the network (IP) address and client software each request came from, the address requested, error traces and account identifiers, used to operate and debug the service.
Connecting your Google account is optional and can be undone at any time. When you connect, HiJavis requests exactly two OAuth scopes:
| Scope | Why HiJavis needs it |
|---|---|
https://www.googleapis.com/auth/calendar.events |
To read the events on your primary calendar inside the window the app is displaying, so the Javis calendar shows your real schedule alongside what HiJavis drafted; and to create, update and delete the events you act on in the app — including deleting an event from Google when you discard it in Javis, even if HiJavis did not create it. This scope does not grant access to your calendar list or sharing settings. |
https://www.googleapis.com/auth/gmail.readonly |
To read message headers and previews so the app can shortlist which threads are worth keeping; to read the text of a shortlisted thread so the app can judge whether to propose it to you; and, when you ask the assistant about your email, to search your mailbox and read the messages needed to answer. This scope is read-only: HiJavis cannot send, delete or modify your mail. |
When you open the Javis calendar, HiJavis reads the events on your primary Google Calendar for the window being displayed and merges them with the events Javis holds, so you see one schedule rather than two. Those Google-native events are shown to you and nothing more: they are not stored on our servers and they are not sent to an AI model. Events you confirm in Javis are written to Google, and discarding an event in Javis deletes it from Google — which includes events created elsewhere, since they are shown in the same list.
HiJavis periodically lists recent threads and scores them from their headers and the short preview Gmail returns alongside them. Headers are often not enough to tell a useful thread from a routine one, so HiJavis also retrieves the text of a bounded batch of the threads it cannot settle that way. That read happens before you see anything, it is capped in both the number of threads and the amount of text per thread, and the text is used only to decide whether the thread is worth proposing. It is not written to our database.
What happens next depends on the score:
You can also ask the assistant about your mail directly. When you do, it searches your mailbox and reads the messages it needs to answer you.
What HiJavis keeps: the wiki pages produced from approved and auto-added threads, a record of which threads have already been processed, and the suggestion cards themselves — each holding the sender address, the subject and Gmail's preview line. Unreviewed cards are kept until you act on them, disconnect Google, or delete your account. We do not store message bodies in our database; transient copies of anything the assistant read may remain in your assistant's private session history, on our servers, until you delete your account.
AI assistants you connect. If you connect an AI assistant such as Claude to Javis (see section 4), it can list the suggestion cards waiting for your review, read your wiki pages (including those produced from your email), and confirm or discard cards for you. It is never given access to your mailbox: Javis answers its read requests from what it has already stored. Confirming a card through an assistant has the same effect as confirming it in the app, so Javis then reads that thread from Gmail and summarises it into your wiki.
Summarisation and transcription use third-party AI model providers. Content sent to them is limited to what is needed to produce the result, is not used by us to train models, and is governed by those providers' terms. We do not sell your data, and we do not use Gmail or Calendar data for advertising.
HiJavis's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we do not transfer Google user data to third parties except as necessary to provide or improve the user-facing features that are prominent in the app's interface and described above, to comply with applicable law, or as part of a merger, acquisition or sale of assets after obtaining your explicit prior consent; we do not use it for advertising; and no human reads it except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
Connecting an AI assistant (section 4) is one of those user-facing features. Google user data reaches an assistant only after you connect it and choose Allow on the Javis consent screen, and only in reply to the requests it makes with the access you granted.
The Javis Wiki Sync plugin for Obsidian copies your Javis wiki into your vault. Uploading your own notes is optional and off until you choose folders for it.
What is sent. If you select one or more folders for upload, the plugin sends the full text of every Markdown note in those folders to the Javis server, together with its path and title. Notes outside the folders you select are never read or sent.
How it is used. Javis stores that text so it can add what the note says to your wiki, and process it again when you edit the note. An AI model provider (see "Automated processing and AI providers" above) summarises the note into your wiki pages, and those pages sync back into your vault.
When you delete a note, or move it out of every selected folder, the plugin tells the server:
Some things are kept after a deletion:
stale_sources property naming the note.javis_sync: false)
are never rewritten by Javis, so they keep what they say, including
anything from the deleted note, until you edit them.Connection records. The plugin signs in to Javis through the same connector an AI assistant uses, so Javis keeps the same registration and token records for it as for an assistant: the name it registers under, the address it asks us to send you back to, the network address its registration request came from, and SHA-256 fingerprints of the refresh tokens we issue it. They are kept and deleted on the same schedule, described under "Tokens and how they are stored" and "Disconnecting" in section 4.
Deleting your Javis account deletes all of it.
You can connect an AI assistant that supports the Model Context Protocol
(MCP), such as Claude, to your Javis account through our connector at
https://mcp.javis.is/mcp. Connecting is optional and nothing is
shared until you set it up.
When you connect, you sign in to Javis and see a consent screen showing the name the assistant registered under and what it will be able to do. Nothing is shared unless you choose Allow. From then on, what Javis sends the assistant about you is what the tools it calls return, plus your account identifier and email address inside its access token (see "Tokens and how they are stored" below). The assistant decides when to call the tools while it works on your requests.
The connector does not provide your Google Calendar events or your Google credentials, and it gives the assistant no access to your mailbox.
wiki_export_tool when it
asks for the changes since an earlier date, and the Obsidian plugin
receives it the same way. Deleting your Javis account deletes it.Adding sessions and confirming threads use an AI model provider, as
described in "Automated processing and AI providers" in section 2. Javis
marks both tools as actions that change your data (MCP's
destructiveHint) so that your assistant asks you before each
call. Whether and how it asks is decided by the assistant and its settings,
not by Javis.
What a tool returns becomes part of your conversation with the assistant, and the assistant's provider (Anthropic, for Claude) handles it under its own terms and privacy policy, not this one. Javis does not use data shared with an assistant to train any model.
Javis does not receive your conversations with the assistant. It receives the requests the assistant makes to the connector (which tool to run and the parameters it passes, such as a search query or a session id), along with the standard request metadata recorded in our server logs, such as the network address and client software each request came from (see "Diagnostics" in section 1).
The Gmail-derived data above is available to an assistant only as a feature you turn on by connecting it, under the Limited Use terms in section 2. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Remove the Javis connector in your assistant's settings. An assistant can
also revoke its refresh token at our revocation endpoint
(https://mcp.javis.is/oauth/revoke); after that the token no
longer works, although an access token already issued keeps working until it
expires, at most an hour later. A refresh token that is not used expires 30
days after it was issued.
Token records that expire without being revoked are deleted about a week after they expire. Deleting your Javis account deletes all of your token records, and refresh tokens stop working. An assistant's registration is deleted by a daily cleanup once it is more than a week old and no token records remain for it. Records of refresh tokens that were replaced (each time the assistant refreshes its access) or revoked are kept until you delete your Javis account, so the registration of an assistant that refreshed at least once is kept at least until then.
Disconnecting Google (Settings → Google → Disconnect) asks Google to revoke our token and marks the stored credentials revoked, so nothing in HiJavis can use them again. The revoked rows themselves stay in our database in encrypted form until you delete your account — they are unusable, but they are not erased at disconnect. It also purges the email data HiJavis derived from your inbox: the record of which threads were processed, every suggestion card you had not yet reviewed, every card HiJavis added automatically, and the sender addresses and mailbox links inside your wiki pages. Calendar events are never stored, so disconnecting simply stops HiJavis reading them.
Two things deliberately survive a disconnect, because they record decisions you made: the wiki pages you approved, and the suggestion cards you confirmed — which still carry the sender address, subject and Gmail preview line they were shown with. You can delete either individually.
Disconnecting an AI assistant, or the Obsidian plugin, does not erase its connection records. Records of refresh tokens that were replaced or revoked are kept until you delete your account, and an assistant's registration is kept while any of its token records remain (see section 4).
Deleting your account removes your account data, your recordings and transcripts, your wiki, the Obsidian notes you uploaded (including the paths and fingerprints kept after a note is deleted), your assistant's session history, all stored Google credentials, revoked ones included, and the token records of your AI-assistant and Obsidian plugin connections. Request deletion in the app, or by emailing support@deepshare.ai. Backups containing deleted data expire within 30 days.
You may also revoke HiJavis's access directly at myaccount.google.com/permissions.
You can request access to, correction of, export of, or deletion of your data by emailing support@deepshare.ai. We respond within 30 days.
HiJavis is not directed to children under 13, and we do not knowingly collect their data.
We will update the date at the top of this page when this policy changes, and will notify you in the app of material changes before they take effect.
DeepShare AI — support@deepshare.ai