Legal
Privacy Policy
Last updated 16 July 2026.
The short version. Digital Jeeves is a free AI assistant for Windows — and, in beta, Android — run by a small UK business. We built it so that, if you want, very little has to leave your device — bring your own local AI model (via LM Studio) or your own API key, and your prompts and anything Jeeves reads from your screen stay on your device. We never see them. The one thing that does sync, if you sign in to a Digital Jeeves account, is the short list of facts Jeeves remembers about you, so it can greet you across your devices (see Cross-device memory). We also run an optional Facebook Page that mirrors public posts and comments into our community forum (see section (e)).
If you choose an optional paid cloud subscription instead, your requests (and, only if you switch it on, screen content) are sent through our gateway to an AI provider (Anthropic, OpenAI, DeepSeek or Google Gemini) so we can answer for you. If you're a Premium subscriber and use the optional AI image generation feature, what you describe (and, for edits, the image itself) is sent to Google Gemini or, as a fallback, OpenAI. On our website, we collect what you'd expect: your account, forum posts, beta sign-ups and bug reports.
We use only essential cookies today — no analytics or ads. You can download all your data and delete your account yourself from your account page. A reminder throughout: AI can make mistakes — please check anything important before you rely on it, and in Act mode Jeeves always asks before it does anything on your PC. Questions any time: [email protected].
This Privacy Policy explains what personal data Digital Jeeves collects, why, what we do with it, and the rights you have over it. We've written it in plain English because we want you to actually understand it — not just agree to it.
Digital Jeeves is a free AI assistant, available for Windows 10 and 11 and, in beta, for Android phones. It has three modes: Guide (it points at the on-screen controls you need), Act (it carries out tasks for you, asking you to confirm before it does anything significant), and Chat. The app and this website are operated by Digital Jeeves, a UK sole trader/small agency based in England. (The Android app is in beta and evolving; we'll keep this policy updated as it develops.)
A core part of why Digital Jeeves exists: the app is free, so it's available to everyone regardless of skill or financial situation. An optional subscription is a way to support the research, development, the developer, and the running costs behind it — but you never have to pay to use Jeeves.
This document covers privacy only. The terms on which you may use the app and website — including your consumer cancellation rights and the limits of our liability — are set out separately in our Terms of Use / End User Licence Agreement, which you should read alongside this policy.
Last updated: 16 July 2026.
Who we are (the data controller)
The controller responsible for your personal data is Digital Jeeves, a sole trader/small agency based in England, United Kingdom.
You can contact us about anything in this policy, including exercising your privacy rights, by email at [email protected].
We are based in the UK and this policy is governed by the laws of England & Wales. We handle personal data in line with the UK GDPR and the Privacy and Electronic Communications Regulations (PECR).
The most important thing to understand: where your data goes depends on how you use Jeeves
Digital Jeeves is deliberately designed so you can use it without sending us anything at all. How your data is handled depends entirely on which setup you choose:
- Free, with a local model or your own API key — your prompts and screen content stay on your PC. We don't receive them and there's no account required.
- Optional cloud subscription — your requests are sent through our gateway to an AI provider so we can answer them for you.
- The website — forum, beta sign-up, bug reports and your account are handled on our servers.
The sections below explain each of these in detail.
Do you have to give us any data?
You are not legally required to give us any personal data. What you need to provide simply depends on how you want to use Jeeves:
- Using Jeeves with a local model or your own API key requires no data to be provided to us at all — there is no account, and nothing reaches us.
- To use the website account or forum, or to take out a cloud subscription, you do need to provide account details and, for billing, payment-related information. This is a contractual requirement in the sense that without it we simply can't create your account, run the forum for you, or provide the paid service — there's no penalty, you just wouldn't be able to use those parts.
- For bug reports and beta sign-ups, giving us your details is entirely optional; if you don't, we just can't follow up with you.
A note on getting things right: AI can be wrong, and Jeeves can act on your PC
Two things are important to understand before you rely on Jeeves:
- AI can make mistakes. Jeeves's answers and suggestions are generated by AI models and can be incomplete or simply wrong. Please check anything important yourself before you act on it — don't treat its output as guaranteed correct.
- In Act mode, Jeeves performs tasks on your PC. This is powerful, so there's a safeguard built in: Jeeves always asks you to confirm before it carries out any action. Read each confirmation prompt before you approve it, so you stay in control of what happens on your computer.
The full terms covering your use of the app, including cancellation rights and the limits of our liability, are in our separate Terms of Use / End User Licence Agreement.
(a) The desktop app used for free — with a local model or your own API key
This is the most private way to use Jeeves. When you bring your own local AI model (through LM Studio) or plug in your own API key, nothing leaves your PC to us:
- Your prompts and any screen content Jeeves reads are used only locally, on your device, to power the assistant. We do not receive them.
- To read your screen (in Guide and Act modes), Jeeves uses Windows' built-in accessibility/UIA APIs and on-device OCR. This happens locally.
- In Act mode, Jeeves always asks you to confirm before it performs any action on your PC.
- Any API keys you enter are stored encrypted on your device using Windows DPAPI.
- Jeeves keeps a small "memory" of useful facts about you (for example your name, or a preference you mention) in an on-device SQLite database, protected behind your Windows credentials. If you are signed in to a Digital Jeeves account, these facts are also synced to our cloud so they follow you across your devices — see Cross-device memory below. If you are not signed in, they never leave your machine, and you can turn memory off or delete individual facts in the app.
Because we don't receive your prompts or screen content in this mode, there is very little personal data for us to hold — the main exceptions are your website account, if you created one, and (if you're signed in) the memory facts that sync to our cloud, described next.
Note: if you use your own API key, your prompts go directly from your PC to that provider under your own arrangement with them — that relationship is between you and them.
(b) The desktop app with a cloud subscription
If you choose an optional cloud subscription (Basic or Premium), Jeeves routes your requests to a third-party AI model for you, so you don't need your own model or key. In this mode:
- Your requests are sent to the Digital Jeeves gateway and on to the AI provider you're using (see "Who we share data with" below).
- These requests include your prompts and, only if you choose to enable it, screen content. Sending screen content is your choice — it is off by default.
- Our cloud service records usage information for each request — the provider and model used, token counts and cost — so we can meter usage and protect you (and us) against unexpected overspend.
- Jeeves still asks you to confirm before taking actions on your PC, exactly as in the free version.
A word of caution about screen content. Because screen content can contain anything that happens to be on your screen — potentially including sensitive information such as health, religious or political details — please avoid enabling screen content while sensitive information is on screen. If you do choose to turn it on, you are giving your explicit consent for that content (including any such sensitive information it may contain) to be sent to the AI provider to answer your request; you can turn it off again at any time. If you would rather not share this kind of information at all, keep screen content switched off and use prompts only.
Lawful basis: Contract — we process these requests to deliver the subscription service you've signed up for. Where screen content you enable happens to include special-category information, we rely on your explicit consent for that content. Recording usage/metering is also supported by our legitimate interest in preventing abuse and overspend.
The Android app (in beta)
Our Android app brings the same assistant to your phone, and shares the same model choices — a fully on-device model (nothing leaves the phone), your own model server, or an optional Digital Jeeves cloud subscription. A few things are specific to Android:
- Contacts (optional). If you grant the Contacts permission, Jeeves can look a contact up by name to find their number so it can help you text or call them. The lookup is read-only and runs on your phone. If you're using a cloud subscription or your own model server, the matched name and number are included in the request sent to your chosen AI provider so it can complete the task; in fully offline on-device mode, nothing leaves the phone. Contacts access is off until you grant it, and can be revoked any time in Android settings.
- Screen control via the accessibility service (optional). To operate the phone for you, Jeeves uses Android's accessibility service to read the current screen and tap, type and scroll. As on Windows, it only reads the screen when you ask it to act; it's off until you both switch the service on and tick the consent box; and password fields are never sent. When enabled, the on-screen text it reads is sent to your chosen model (your own server or our cloud), exactly like the screen content described in (b).
- Confirmations. On Android, Jeeves asks you to confirm before it taps anything that looks irreversible — sending, paying, buying, deleting and the like — rather than before every single tap, so please still glance at each confirmation. Quick actions like drafting a text or email, or dialling a number, open a pre-filled screen for you to send or place yourself.
- Where secrets and settings live. Your API keys and sign-in tokens are encrypted at rest with an AES-256 key held in the Android Keystore. App settings and any cached memory facts are kept in the app's private storage. Android's standard system backup is enabled, so app data (including cached settings and memory facts) may be copied to your own Google account backup; encrypted keys and tokens are backed up only as unreadable data, and you can turn system backup off in Android settings.
- On-device model download. If you choose to run an offline on-device model, the model file is downloaded once from Hugging Face (huggingface.co). Only the download is made — your prompts and data are never sent to them.
Cross-device memory (synced facts)
If you sign in to a Digital Jeeves account, the facts Jeeves remembers about you are synced to our cloud so they're available on all your devices — for example, something you teach Jeeves on Windows can greet you on your phone. This applies to any signed-in user, not only paid subscribers.
- What we store: each remembered fact's text, an optional category, and a timestamp, linked to your account identifier. We never sync anything that looks like a password or API key — those are blocked before they can be saved.
- Your control: you can turn memory off, or review and delete individual facts, in the app at any time. Deleting a fact removes it from your devices and from our cloud; deleting your account removes them too.
- Not signed in? If you use Jeeves without signing in, your memory stays entirely on your device and none of it reaches us.
Lawful basis: contract / legitimate interests in providing the cross-device memory feature you've signed in to use.
(c) The website — account, forum, beta sign-up and bug reports
When you use our website, we collect and store the following (most records are linked to your login identity; the exception is our "From our Facebook" forum area — see section (e) — which mirrors public content from our Facebook Page):
- Your account/profile — display name, email, avatar and bio, plus basic activity details we keep for the forum: when you joined, when you were last seen, your post count, and your forum role.
- Forum activity — the posts and threads you write, your reactions, and in-app notifications.
- Beta sign-ups — your name, your email, anything you choose to write in the optional "anything you'd like us to know" box, and your browser's user-agent string (recorded automatically to help us understand which setups testers use), if you sign up for the beta.
- Bug reports — the description you submit, an optional contact email, diagnostic context about the app, your operating system and the situation, and — unless you switch diagnostics off before sending — a snapshot of recent app log lines and a tail of Jeeves's action audit trail, to help us reproduce and fix the problem. Because those logs can reflect what you were doing at the time, please avoid putting anything you'd rather not share into a report.
- Synced memory facts — if you're signed in, the facts Jeeves remembers about you are stored in our cloud (see Cross-device memory above).
Lawful bases: Contract for providing your account and the forum you signed up to use; legitimate interests for handling bug reports and improving the service (to keep the app working well and fix problems); consent where you actively choose to sign up for the beta.
Your login account itself — username, email, password (stored as a hash), security information and sign-in tokens — is held on our identity server at login.digital-jeeves.co.uk. This is your "account of record".
Where we get your data
Most of the data we hold comes directly from you — what you type, the profile you set up, the posts you write, and the details you enter when you sign up for the beta or submit a bug report.
A couple of things reach us slightly less directly, so we want to be clear about them:
- Your login identity comes from our identity server (login.digital-jeeves.co.uk), which you set up when you create your account. Your website and cloud records are linked to that login.
- Diagnostic context in bug reports (app version, operating system and the situation) is generated by the app on your device at the moment you choose to submit a report, and sent to us with it.
- From Facebook — if you post or comment publicly on our Facebook Page, we receive your public Facebook name and the text you wrote via Meta's Graph API, and mirror it into our public forum (see section (e)).
- From your phone's contacts (Android) — if you grant the optional Contacts permission, a contact's name and number can be included in a request when you ask Jeeves to text or call them (see "The Android app").
(d) Billing (subscriptions)
If you take out a paid subscription, we hold the information needed to manage it: your email, your Stripe customer and subscription IDs, your plan, status, budget and billing period.
Card payments are handled entirely by Stripe on their own secure, Stripe-hosted checkout. Your card number is never entered on our site and we never see or store it — we only keep the Stripe IDs and your billing status.
Lawful bases: Contract for taking payment and providing the subscription; legal obligation for keeping billing and tax records for the period the law requires.
(e) Our Facebook Page and community forum
We keep our public Facebook Page and our community forum in sync, so both communities see the same conversation. This feature is optional and is off unless we have switched it on. When it is on:
- Comments and posts from our Facebook Page are mirrored into the forum. When someone posts or comments publicly on our Page, we copy their public Facebook display name and the text of their message into a clearly-labelled "From our Facebook" area of our public forum. Only public content is involved — we never read private messages.
- Forum threads in that area are published to the Page. Threads in the "From our Facebook" category are published out to our Facebook Page; ordinary forum posts elsewhere on the site are not sent to Facebook.
- Replies may be AI-drafted. Where a Page comment needs a reply, Jeeves may draft one using our AI provider (DeepSeek), and a person reviews and approves it before it is posted back to Facebook. AI can be wrong, so we keep a human in the loop for public replies by default.
If you commented on our Page and would like your name or comment removed from our forum, email [email protected] and we will take it down — you do not need a Digital Jeeves account to ask.
Lawful basis: our legitimate interest in running a joined-up community across our forum and our Page. Because a public comment could mention anything, please avoid posting sensitive personal details in one.
Operational logs
To keep the service running, secure and debuggable, our website, cloud gateway and back-office automatically record technical operational logs. These can include your IP address, your login identifier, the web addresses (paths) you request, timestamps, and the details of any error. We hold these in a first-party, self-hosted log store that only our administrators can view; we do not use them to build a profile of you, and they are not shared with a third party. We keep them for around 30 days and then delete them automatically. (We may also add a richer self-hosted error-monitoring tool — Sentry, self-hosted — in future; it is not live yet.)
Lawful basis: legitimate interests in running, securing and fixing the service. You can object — see "Your rights".
Purposes and lawful bases at a glance
- Providing the app and your account/subscription — lawful basis: contract.
- Routing cloud-subscription requests to AI providers — lawful basis: contract (plus your explicit consent for any special-category information within screen content you choose to enable).
- Security, operational logging, anti-abuse and protecting against overspend — lawful basis: legitimate interests.
- Syncing your remembered memory facts across your devices — lawful basis: contract / legitimate interests.
- Running our Facebook Page ↔ community forum sync — lawful basis: legitimate interests.
- Fixing bugs and improving the service — lawful basis: legitimate interests.
- Beta sign-up and any future optional analytics — lawful basis: consent (you can withdraw it at any time).
- Keeping billing and tax records — lawful basis: legal obligation.
Where we rely on legitimate interests (for example, fixing bugs, improving the service and protecting against abuse and overspend), you have the right to object — see "Your rights" below.
Who we share data with (our processors and third parties)
We keep the number of third parties deliberately small. We share data only with the following, and only as needed:
- Stripe — our payment processor for subscriptions. You enter card details on Stripe's own hosted checkout; we store Stripe IDs and billing status, not card numbers.
- Cloudflare — provides our CDN, TLS/encryption in transit, and security/bot-protection in front of the website. It processes site traffic and may set essential security cookies. This includes Cloudflare Turnstile, a privacy-friendly anti-abuse check for the "Ask Jeeves" chatbot; because the chatbot is available across the site, its script may load on any page, but it only acts when you use the chatbot.
- AI model providers — Anthropic, OpenAI, DeepSeek and Google (Gemini) — receive your prompt content when you use a cloud subscription (and, if you enabled it, screen content), and DeepSeek receives messages you send to the public "Ask Jeeves" website chatbot. If our Facebook integration is enabled, DeepSeek also receives the text of public comments left on our Facebook Page (and the commenter's name) so it can draft a suggested reply for us — a person reviews and approves each draft before anything is posted. Under our accounts, these providers do not use this content to train their models, per their API terms.
- Google (Gemini API) and OpenAI — AI image generation. If you're a Premium subscriber and use the AI image generation feature, the text you describe (and, for edits, the image itself) is sent to Google's Gemini API and, as a fallback if Gemini is unavailable, to OpenAI. Under our accounts, these providers do not use this content to train their models.
- Meta Platforms (Facebook) — if we run our optional Facebook Page integration, we use Meta's Graph API to read our Page's posts and the public comments people leave on them, and to publish posts and replies back to the Page. Through this we receive a commenter's public Facebook display name and their comment text. We only access public content on our own Page; we never read private messages. See section (e).
- Hugging Face — if you choose to run an on-device model on Android, the model file is downloaded once from Hugging Face (huggingface.co). Only the file download is made; your prompts and data are not sent to them.
- Email (SMTP) — used to send transactional email such as bug-report acknowledgements and invites, and, if we enable it, short internal digests of high-severity errors to our own operations inbox (these can include the same technical detail as our operational logs).
- Our own in-house operational logging — our website, cloud gateway and back-office write structured operational logs (errors, warnings and request diagnostics) to a self-hosted, first-party log store that only we can access via an admin-only viewer (see "Operational logs" above). This is kept in-house and is not shared with any third party. We also plan to add a richer self-hosted error-monitoring tool (Sentry, self-hosted), which is not yet live.
We do not sell your personal data, and we do not share it with advertisers.
International transfers
Some of the providers above are based outside the UK and EEA, so using those parts of the service involves an international transfer of your data. Specifically:
- US-based AI and infrastructure providers — Anthropic, OpenAI and Google (AI models), Cloudflare (CDN, TLS and security), Meta Platforms (Facebook, where the Page integration is enabled) and Hugging Face (on-device model downloads on Android) operate globally, including in the United States.
- DeepSeek — the AI provider behind some cloud-subscription requests, the public "Ask Jeeves" website chatbot, and (where enabled) the drafting of Facebook replies — is based outside the UK/EEA, in China, so using it involves an international transfer that relies on Standard Contractual Clauses with the UK Addendum rather than a UK adequacy decision.
Where your data is transferred internationally, we rely on appropriate safeguards recognised under UK data protection law — such as UK adequacy regulations where they apply, or the UK International Data Transfer Agreement (IDTA), or Standard Contractual Clauses with the UK Addendum — so that your data continues to be protected to a comparable standard. You can contact us at [email protected] for more detail on, or a copy of, the safeguards in place for a particular provider.
Cookies and similar technologies
Today, we use only essential/security cookies. We do not use any analytics or advertising cookies.
The essential cookies we use are:
- dj.auth — keeps you signed in (set only for signed-in users).
- Antiforgery (CSRF) cookie — protects our forms against cross-site request forgery.
- Transient OIDC sign-in cookies — used briefly during the login process.
- Cloudflare security cookies — part of Cloudflare's security and bot-protection.
- Cloudflare Turnstile — anti-abuse protection for the "Ask Jeeves" chatbot; because the chatbot is available across the site, its script may be present on any page, but it only acts when you use the chatbot.
These are strictly necessary for the site to work and to keep it secure, so under PECR they don't require your consent. Our website's own assets (CSS, JavaScript and fonts) are self-hosted; the only external script we load is Cloudflare Turnstile, for the "Ask Jeeves" chatbot — and because the chatbot is offered across the site, that script may load on any page.
Optional analytics (off unless you opt in). We have built an optional, privacy-friendly analytics option (Google Analytics) that is switched off by default. If we ever switch it on, any such cookie would be non-essential, would load only after you opt in via a cookie banner, and you could change your choice at any time through that banner — until you consent, no analytics or advertising cookie is set. If we do turn it on, we also set one small essential preference cookie, dj.consent, which simply remembers your choice (analytics accepted, or essential only) for about six months so we don't keep asking; it is a preference cookie, not an analytics or advertising cookie.
How long we keep your data (retention)
- Account and profile data — kept for as long as your account exists. When you delete your account, it is removed or anonymised (see your rights below).
- Billing and tax records — kept for around 6 years to meet our legal accounting/tax obligations, even after you cancel.
- Bug reports and diagnostics — kept for a limited period, long enough to investigate and fix the issue, then removed.
- Beta sign-ups — kept until you unsubscribe or ask us to delete them.
- Forum posts — retained as part of the discussion history, but anonymised if you delete your account.
- Cloud usage records — because these underpin billing and must support our accounting and tax records, they are kept for around 6 years in line with the billing records above, after which they are deleted or aggregated into anonymous totals.
- Synced memory facts — kept in our cloud until you delete them in the app or delete your account, at which point they are removed.
- Mirrored Facebook content — public posts and comments we mirror from our Facebook Page into the forum, and any AI-drafted replies we hold for approval, are kept as part of the forum's discussion history. If you are a commenter and want your name or comment removed, email us and we will delete it.
- Operational and diagnostic logs — our structured server logs (see "Operational logs") are kept for around 30 days and then automatically deleted.
Data you use with a local model or your own key stays on your device under your control and is not subject to our retention because we never receive it — except for your memory facts, which, if you are signed in, are synced to and retained in our cloud until you delete them.
Your rights, and how to exercise them here
Under UK GDPR you have the right to: access your data, have it corrected (rectification), have it erased, restrict processing, object to certain processing, port your data (get a machine-readable copy), and withdraw consent at any time where we rely on it.
Your right to object. Where we rely on legitimate interests — for example, handling bug reports, improving the service, and protecting against abuse and overspend — you have the right to object to that processing at any time. Just email us at [email protected] and we'll consider your objection.
We've built practical, self-service tools so you can act on most of these yourself:
- Access & portability — sign in and download your data as JSON from your account hub at /account (this covers your website and cloud data, including your synced memory facts). Your identity/login data can be downloaded separately from the identity server's own /Manage/PersonalData page.
- Rectification — you can edit your profile directly, and manage your login details on the identity server.
- Erasure — use /account/delete to delete or anonymise your website and cloud data — including your synced memory facts — and cancel your Stripe subscription; this then hands off to the identity server to remove your login. Forum posts are retained but anonymised.
- Billing — you can manage or cancel your subscription any time via the Stripe billing portal.
- Withdraw consent — unsubscribe from beta communications, turn off screen content in the app, or (once available) change your analytics choice in the cookie banner.
You can also exercise any of these rights, or ask for help, by emailing [email protected]. If you don't have a Digital Jeeves account — for example, you commented on our Facebook Page and it was mirrored into our forum — you can still ask us to access or remove your data by email.
If you're unhappy with how we've handled your data, you have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO) at ico.org.uk. We'd appreciate the chance to put things right first, so please do contact us too.
Children
Digital Jeeves is a general-purpose tool and is not directed at children. As a deliberate policy choice, we set our threshold at 16 — higher than the UK's minimum age of 13 for consenting to online services under the Data Protection Act 2018 — and we don't knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us at [email protected] and we'll remove it.
How we keep your data secure
We take sensible steps to protect your data, including:
- Encryption of secrets on your device — on Windows, API keys are encrypted with Windows DPAPI and your on-device memory is protected behind your Windows credentials; on Android, your API keys and sign-in tokens are encrypted at rest with an AES-256 key held in the Android Keystore, and app settings and any cached memory facts are kept in the app's private storage.
- Synced memory in our cloud — where memory facts are synced, they are sent over TLS and held in our access-controlled DJ_CLOUD database, linked to your account identifier.
- Encryption in transit — traffic to our website and gateway is protected with TLS.
- Access controls — access to systems and data is limited to what's necessary to run the service.
No system can be guaranteed perfectly secure, but we work to protect your data appropriately for its sensitivity.
Automated decision-making
We do not use your personal data for automated decision-making that produces legal effects or similarly significant effects about you. The AI features respond to your requests and always ask before Jeeves takes an action on your PC — they don't make binding decisions about you.
Changes to this policy
We may update this Privacy Policy from time to time — for example, if we switch on optional analytics, evolve the Android app or the Facebook Page integration, or change how the service works. When we do, we'll update the "Last updated" date at the top, and we'll let you know about significant changes where appropriate. Please check back occasionally so you're aware of any updates.
Last updated: 16 July 2026.