PRIVACY POLICY
Last Updated: March 2026
1. General Information
We take the protection of your personal data very seriously. This Privacy Policy informs you about how
AsIfThatWorks & ThatsBuiltByPham by Ký Anh Pham ("we", "us", or "asifthatworks") collects, uses, and protects
your data when you use our SaaS platform and our AI agents (Jarvi, Grim, Murphy, Forge, and
Chronicles).
Controller: AsIfThatWorks & ThatsBuiltByPham by Ký Anh Pham
Brückenstraße 12, 12439 Berlin, Germany
Email: support@asifthatworks.com
2. Data Collection and Purposes
We process personal data only as far as necessary to provide a functional website and our services (Art.
6 para. 1 lit. b GDPR).
• Account Data: Name, email address, phone number, and authentication data.
• User Content: Preferences, goals, personal notes, milestones, and voice memos.
• Contextual Data: Location data and time zones.
• Integration Data: Data from Google Calendar and Google Tasks (if connected).
2b. Messaging Platform Data
Jarvi operates across multiple messaging platforms. When you interact with Jarvi through any of the
following platforms, we collect and process:
Telegram:
• Your Telegram user ID, username, and display name.
• Message content you send to the Jarvi bot.
Facebook Messenger:
• Your Page-Scoped ID (PSID) as provided by Meta.
• Your display name and profile picture URL (as provided by Meta's API).
• Message content you send to Jarvi via Messenger.
Instagram Direct Messages:
• Your Instagram-Scoped ID (IGSID) as provided by Meta.
• Your Instagram username.
• Message content and comments you send to Jarvi via Instagram.
WhatsApp:
• Your phone number as provided by Meta's WhatsApp Business API.
• Your WhatsApp display name.
• Message content you send to Jarvi via WhatsApp.
Purpose: This data is used solely to provide the Jarvi service — processing your
requests, managing your calendar, tasks, goals, and memory. We do not sell, share, or use this data
for advertising purposes.
3. Google API Services User Data Policy & Compliance
AsIfThatWorks integrates with Google APIs to provide intelligent calendar scheduling, task management, and inbox organization through our AI agents (Grim, Murphy, and Jarvi's Gmail Inbox Intelligence). We strictly adhere to the Google API Services User Data Policy across all Google integrations.
3.1 Data Accessed (Google OAuth Scopes)
When you choose to connect your Google account, AsIfThatWorks requests explicit access only to the scopes necessary to perform the requested scheduling and task management actions:
• Google Calendar API (https://www.googleapis.com/auth/calendar / calendar.events): Allows reading your upcoming events, detecting schedule conflicts, and creating or updating events on your monitored calendars.
• Google Tasks API (https://www.googleapis.com/auth/tasks): Allows reading your task lists, creating new action items, and marking tasks completed.
• Gmail API (https://www.googleapis.com/auth/gmail.readonly, gmail.labels, gmail.modify): Allows reading your inbox message metadata and content so Jarvi can classify and organize it, creating and applying labels, archiving messages, and creating draft replies. Jarvi never sends email on your behalf — every draft it creates requires you to press Send yourself inside Gmail.
• User Identification (openid, email, profile): Used solely to authenticate your Google connection and display your connected account address in your settings dashboard.
3.2 Data Usage (How Google Data is Processed)
We process Google user data exclusively to deliver functionality requested by you:
• Grim (Scheduling Agent): Reads your Google Calendar events strictly when you query your schedule or when proactive conflict monitoring checks for overlapping events. When requested, Grim inserts or modifies calendar events on your behalf.
• Murphy (Execution Agent): Reads and updates your Google Tasks lists to synchronize action items created during your productivity workflows.
• Jarvi's Gmail Inbox Intelligence: Reads message metadata and content strictly when you request an inbox scan, PARA-style restructuring, unsubscribe cleanup, or reply drafting. It applies the labels and archive actions you approve, and creates unsent draft replies for your review. Jarvi never sends a message autonomously.
• We do not use Google Calendar, Google Tasks, or Gmail data for user profiling, advertising, behavioral targeting, or surveillance.
3.3 Data Sharing & Disclosure
• No Third-Party Sharing: AsIfThatWorks does not share, sell, transfer, or disclose Google user data (including Calendar events, Tasks, Gmail message content/metadata, or OAuth tokens) to any third-party advertisers, data brokers, or external analytics platforms.
• No Base Model Pre-Training: Information obtained via Google APIs is never used to pre-train, fine-tune, or train foundational AI base models.
3.4 Data Storage & Protection
• Encryption at Rest: All Google OAuth access tokens, refresh tokens, and synchronization metadata are encrypted at rest inside our secure EU-based database cluster.
• Encryption in Transit: All communication between your device, our backend servers, and Google APIs uses HTTPS with TLS 1.3 encryption.
• Account Isolation: Your Google OAuth tokens and synced data are strictly bound to your individual user account and inaccessible to any other user.
3.5 Data Retention & Deletion
• Retention Policy: We retain your Google OAuth credentials and synced data only for as long as your Google account remains actively connected to AsIfThatWorks.
• Instant Access Revocation: You can disconnect your Google Account at any time via your Dashboard settings or directly revoke access at Google Account Security Permissions.
• Data Deletion Process: You may request deletion of your account and all associated Google user data at any time via Profile > Security > Delete Account or by visiting our Data Deletion Page or emailing support@asifthatworks.com. Requesting deletion immediately cancels any active subscription and schedules erasure; your account remains accessible (so you can cancel the request if it was a mistake) until the 30-day grace period ends, at which point your Google OAuth tokens are revoked with Google and all associated calendar/task/Gmail records are permanently wiped from our systems.
3.6 Mandatory Google API Services Limited Use Compliance Statement
AsIfThatWorks' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Artificial Intelligence and Data Privacy
To provide our intelligent services, your inputs are processed by advanced Large Language Models (LLMs).
We prioritize your privacy through a Hybrid Neural Architecture:
• Cloud Orchestration: We utilize enterprise-grade instances of OpenAI and Google Gemini
to perform multi-agent reasoning. Data processed through these providers is handled under Data Processing
Addendums (DPAs) that prohibit the use of your data for training their base models.
• Local Shield (Ollama):local shield Local models are maintained as an emergency fallback
and for highly sensitive, low-latency processing on our secure EU-based servers.
5. Third-Party Services and Subprocessors
• Hosting: Hostinger (EU-based servers).
• Payments: Stripe (Subscription processing).
• Email: Hostinger email services.
• Meta Platforms, Inc.: Messenger API, Instagram Graph API, and WhatsApp Business API
for receiving and sending messages on Meta platforms.
• Telegram: Telegram Bot API for receiving and sending messages on Telegram.
• Google Analytics (Google LLC): Website usage analytics on our public marketing
pages only — see §5a. Never used on the authenticated Dashboard.
5a. Cookies & Analytics
Our public website (this page and other marketing/legal pages) uses Google Analytics
4 (GA4), provided by Google LLC, to understand aggregate visitor behavior — pages
viewed, approximate location (country/city level), device and browser type, and referral
source. GA4 does not log or store full IP addresses.
• Consent-based, not automatic: The Google Analytics script does not load,
and no analytics cookies are set, until you actively click "Accept" on the cookie banner
shown on your first visit. Declining means Google Analytics never runs for you at all. This
is required under Art. 6(1)(a) GDPR and § 25 TTDSG (German Telecommunications-Telemedia Data
Protection Act), since we are established in Germany.
• Changing your choice: A small 🍪 button (bottom-left of the screen) reopens
the cookie banner at any time so you can switch between Accept and Decline.
• International transfer: Google LLC may process this data in the United
States under the EU-U.S. Data Privacy Framework (see §6).
• Google's own policy: See Google's Privacy Policy
and Google's Analytics opt-out browser add-on.
• Not used on the app: The authenticated Dashboard uses only first-party,
GDPR-strictly-necessary presence pinging — no third-party analytics of any kind runs there.
6. International Data Transfers
Data transfer to the USA is based on the EU-U.S. Data Privacy Framework or Standard Contractual Clauses (SCCs) approved by the European Commission.
7. Data Retention
We store your data as long as your account is active. Chat history and memory data are retained to
provide continuity of service across sessions.
You may request deletion of your data at any time. Your account enters a 30-day grace period
(billing is canceled immediately; you can cancel the deletion request at any point during this
window), after which all account data, chat history, integration tokens, goal data, and memory
entries are permanently removed and your Google OAuth tokens are revoked with Google.
8. Your Rights
Under the GDPR, you have the right to access, rectification, erasure, data portability, and objection. You can download a complete copy of your data yourself at any time via Profile > Security > Download My Data — no need to email us for this. For rectification, objection, or any other request, contact support@asifthatworks.com.
9. Data Security
We implement state-of-the-art technical measures (e.g., SSL/TLS encryption) to protect your data.
10. Data Deletion
You have the right to absolute erasure. You can trigger this at any time through your Dashboard > Profile > Delete Account. This action is irreversible and immediately wipes all tasks, memories, messages, and integration tokens from our live systems. Alternatively, email support@asifthatworks.com.