Privacy Notice
Product: Jaade Last updated: 2026-09-26
This notice explains how the Jaade desktop application handles your data. Jaade is a local application that runs on your own device.
Summary
Most of your data stays on your device. Jaade does not operate a backend server that collects your workspace or connected-account content. When you use online features, your device communicates with the services you choose: connected accounts such as Google, configured AI providers, update hosts, and optional telemetry services. Agents can also use other network tools you authorize. Retrieved account content may be sent to your configured AI provider and retained in local conversations. Connecting an account is optional.
Data Stored Locally
The following is stored on your device and not transmitted to us:
- terminal sessions and output (via node-pty);
- project, task, and session data (in a local SQLite database);
- your settings, including any API keys you enter.
API keys you provide are stored locally and used only to authenticate with the corresponding third-party service.
Data Sent to Third Parties
- AI providers (for example, Anthropic or OpenAI): When you use agent or chat features, your prompts, relevant file contents, and related context are sent to the AI provider you have configured, using your own credentials. That data is handled under the provider's terms and privacy policy. We do not receive or store this content.
- Connected services: When you connect Google, Jaade communicates directly with Google's sign-in and API services to authenticate you and retrieve data for the features you authorize. Google receives the corresponding API requests and ordinary connection information, such as your IP address.
- Software updates: The app may contact an update server to check for and download new versions. This may expose standard technical information such as your IP address and app version to the update host.
- Telemetry processors (PostHog, Sentry): when you enable telemetry, anonymous usage events and crash reports are sent to these processors. See "Telemetry" below for exactly what is and isn't collected and how to turn it off or opt out.
Google Account Connections
What Jaade accesses and why
Jaade uses Google OAuth in your system browser; it does not ask for or receive
your Google password. It requests your account identifier and email address
(openid and email) to identify and label the connected account. Each service
requests its own read-only permission:
- Gmail (
gmail.readonly): search results, message and thread identifiers, subjects, senders, recipients, dates, labels, snippets, and message text. This supports searching mail, summarizing messages, and answering questions about your mailbox. The built-in connector does not download attachment files or send, edit, delete, or mark messages as read. - Google Calendar (
calendar.readonly): calendar lists and event details, including titles, descriptions, times, locations, recurrence, and attendees. This supports agenda summaries, event searches, and scheduling questions. The built-in connector does not create, change, or delete events.
These read permissions can cover more data than an individual request needs. Jaade retrieves data through bounded searches and reads rather than maintaining an automatic copy or index of your entire mailbox or calendar.
When account data is used or shared
You control which connected accounts a chat or supported assistant task may use. When an authorized agent retrieves data, relevant results become part of its context and may be transmitted to the AI provider configured for that agent. For example, summarizing an email can send its text to that provider. Summaries and other derived information may also enter conversation history or assistant memory. Jaade does not route this content through a Jaade-operated server.
Buddy missions may use connected accounts by default when Connectors are enabled; you can change their account access. If you enable a recurring Buddy heartbeat and grant it an account, it can run read-only checks in the background without a new prompt for each check. Review its instructions and account selections before enabling it. Removing account access stops subsequent connector reads.
Google content is used to provide the account-related features you authorize. Jaade does not sell Google user data, use it for advertising, or use it to train general-purpose AI models. Jaade's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
AI providers are separate services. Their retention, human-review, and training practices depend on the provider, product, account terms, and settings you choose; Jaade does not override those settings. Use Google connectors only with provider terms and settings compatible with Google's Limited Use requirements, including restrictions on general-purpose model training. This notice does not claim that every independently configured provider has been verified for that purpose.
Storage, retention, and your controls
Google access and refresh tokens are stored on your device, encrypted using Electron's operating-system-backed secure storage. Jaade refuses to save them when secure credential storage is unavailable. Tokens are not exposed as connector tool results to agents. Account labels and connection settings are also stored locally. API communication with Google uses HTTPS.
Retrieved content and generated summaries can remain in local chats, agent session files, Buddy history or memory, and files that you ask an agent to create. These records are separate from encrypted token storage; this notice does not promise that all local content is encrypted. Their retention depends on the relevant history, memory, and file controls, and copies may exist in your backups or with your AI provider.
- Stop access in Jaade: Remove a chat or task's account access, disable a recurring heartbeat, or disconnect the account in Connectors. Disconnecting removes that connection's saved local credentials and account grants.
- Revoke Google's authorization: Remove Jaade from your Google Account connections. Disconnecting inside Jaade does not revoke the shared Google authorization, because another connected Google service may still use it.
- Remove retained content: Separately delete relevant conversations, assistant memories, agent session records, exported files, and backups as needed. Disconnecting or revoking access does not erase prior content or data already sent to an AI provider. Use that provider's controls for its copies.
Jaade's account controls govern its built-in connectors. An agent's separately authorized browser, filesystem, shell, or third-party tools have their own access and data-handling behavior.
Telemetry
To help us fix bugs and prioritize improvements, Jaade can collect anonymous telemetry. This is on by default for new installations and missing preferences; saved opt-outs are preserved. Telemetry can be turned on or off at any time in Settings → Privacy (the change takes effect immediately).
We use two third-party processors for this:
- PostHog (product analytics): a small, fixed set of anonymous events (for
example, that the app launched or that a feature was used), each tagged with
the app version and your operating system (e.g. "macOS"). PostHog assigns a
random, anonymous identifier; we do not link it to your name, email, or
account, and we never call any "identify" function. Data is processed on
PostHog's US cloud. Autocapture, page views, and session recording are
disabled, as are Web Vitals and automatic error capture. Before transmission,
we allow only
app_launched,screen_view,feature_used, andagent_run. Their properties are limited to the app version, coarse operating system, fixed screen/feature names (such as workspace, settings, and buddy), and built-in agent provider names. The app sends only the anonymous identifier and required delivery metadata; URLs, referrers, person properties, and unexpected SDK metadata are removed before sending, and IP-based location lookup is disabled. As with any network request, PostHog receives your IP address when an event is delivered. Development builds send no analytics unless explicitly enabled by the developer, and still respect the Privacy setting. - Sentry (crash & error reporting): diagnostic reports when the app crashes or hits an unexpected error, including a stack trace, the app version, and operating-system information.
We never collect your prompts, file or terminal contents, file paths, project names, API keys, or any other content you work with. Standard technical metadata inherent to any network request (such as your IP address) may be visible to these processors; PostHog and Sentry handle it under their own terms and privacy policies.
Unless telemetry is turned on, no analytics events and no crash reports are sent.
Your Responsibility
Because agents can read and transmit file contents to AI providers, avoid using the Software with sensitive data (such as health, financial, or government-ID information) that you do not want sent to those providers.
Children
The Software is not directed to children under 13 (or the minimum age in your jurisdiction).
Changes
We may update this notice. Material changes will be reflected by the "Last updated" date above.
Contact
Privacy questions: [email protected].