Jarvis AI Assistant privacy modes: STRICT local-only, GUARDED with redaction, RELAXED for development.
Security & Privacy

A Private, Local-First
AI Assistant for Windows

Jarvis AI Assistant keeps your data on your machine. Three explicit privacy modes — STRICT, GUARDED and RELAXED — decide what, if anything, ever reaches a cloud model, and every external call is logged to your own disk.

Three modes, one rule

You decide where the thinking happens.

Searching for a private AI assistant usually ends in a trade-off. Either you get a capable cloud model and accept that your prompts, files and secrets travel to someone else’s servers, or you get a local model and accept that it cannot do much. Jarvis AI Assistant is built to refuse that trade-off. It is a Windows desktop app that runs on your own PC, stores its memory on your own disk, and makes every cloud call an explicit, visible decision that you control.

That control lives in three privacy modes. They are not buried settings — the mode is a first-class part of how the assistant behaves, shown in the app and switchable at any time.

STRICT — fully local

Every request is answered by a model running on your hardware through Ollama. No prompt, file contents or tool output leaves the machine. If you work on proprietary code, client data or anything under a regulatory regime, this is on-premise AI in the literal sense: the premises are your desk. The trade-off is honest — local models are smaller than frontier cloud models — but for a large share of everyday tasks they are more than enough, and the assistant’s tools, memory and voice work identically.

GUARDED — cloud with redaction (recommended)

Cloud providers are allowed, but before anything is sent, a redaction layer scans the outgoing text for API keys, passwords, tokens and personal identifiers and strips them. Every external call is written to a local audit log, so you can open it later and see exactly which provider received what, and when. You get the quality of frontier models without handing over the secrets that tend to live in a developer’s terminal and files.

RELAXED — no interception

The interception layer is removed altogether. It exists for development work on non-sensitive data where you want every provider at full throughput and no redaction in the way. It is clearly labelled as such in the app, and switching back is a single setting.

Beyond the modes, the architecture itself is local-first. Conversation history, long-term memory and your integration credentials are stored on your machine and encrypted at rest; a server-side database is optional, not required. You bring your own keys for whatever providers you enable, so there is no intermediary account that sees your traffic, and no usage-based markup that gives anyone an incentive to log it.

“Private” does not mean isolated, and it is worth being precise. If you choose a cloud provider in GUARDED mode, that provider receives the redacted prompt and processes it under its own terms; Jarvis cannot change those. What it can do is make sure the choice is yours, per request, and that a record of it exists on your disk rather than only on someone else’s.

Security & Privacy

Your data. Your machine. Your rules.

Jarvis is private by architecture, not by promise. Run fully local, redact before cloud, and audit every byte that ever leaves your device.

Three privacy modes

STRICT (fully local), GUARDED (redact-before-cloud), RELAXED. You choose per session — Jarvis never decides for you.

STRICT · GUARDED · RELAXED

Encryption at rest

Fernet-encrypted credential vault and memory store. Keys never committed, injected at build or runtime.

Fernet · AES-128

Full audit trail

Every external API call, tool execution, and secret access is logged to a replayable ledger you can inspect.

security_audit.db · traces.db

Automatic redaction

API keys, passwords, tokens, and PII are detected and masked before any data leaves your machine.

17-pattern redaction

Local model support

Run entirely offline with Ollama. No cloud, no data sharing, no account required.

Ollama · zero cloud

Auditable & inspectable

Every tool call, model request, and secret access is logged to a replayable trail. Read exactly what runs, when, and why — no black boxes.

Full audit trail

Privacy and control

You decide where Jarvis thinks.

Jarvis makes the local and cloud boundary visible. Choose a privacy mode for the work in front of you, inspect external activity, and disconnect services whenever you want.

  • Credentials are encrypted on your device.
  • Sensitive actions can require your approval.
  • External model and integration calls remain auditable.
Explore security and permissions

Strict

Local only

Use a local Ollama model so prompts, memory, and tool results stay on your machine.

Guarded

Cloud with protection

Use cloud models after secrets and sensitive patterns are redacted, with each external call recorded.

Relaxed

Direct cloud access

Use enabled providers without the redaction layer for trusted, non-sensitive work.

Why it matters

Local-first matters more when the assistant can run tools.

An assistant that only chats can leak what you type. An assistant that runs tools — reads files, queries git, opens your inbox — can leak far more, because the tool output flows back into the model’s context. That is exactly why Jarvis was designed around privacy modes from the start rather than adding a toggle later. The more an assistant can do on your machine, the more it matters where its reasoning happens. Our features page covers everything those tools can do.

Jarvis is a paid product with quarterly, annual and one-time lifetime plans — see the pricing page. Every plan includes every privacy mode; privacy is not an upsell. Download it from the Microsoft Store, pick STRICT or GUARDED on first launch, and read the privacy section of the usage guide for the exact setup. For a broader view of how private the alternatives really are, our comparison of AI assistants for the Windows desktop looks at what each one sends off-machine.