Skip to content
Back to James

Privacy at James

Privacy Policy

Which data James processes, why it is needed and which rights you have.

Effective May 5, 2026
Clear words. No small print theatre.
C&P Apps · James Effective May 5, 2026

Effective: May 5, 2026

This Privacy Policy describes which personal data we process when you use the App „James — Your Assistant“ and the related services, for which purposes and on which legal basis. We fully comply with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Controller

The controller within the meaning of GDPR is:
C&P Apps Michael Knochen
Colliser Str. 11
07546 Gera, Germany
Email: support@james-butler.net

2. Data we process

2.1 Device UUID

On first launch, the device generates a random UUID (Universally Unique Identifier) which is stored locally and in our database. It is used solely to associate requests technically, to manage limits and Schnauzer credit balances per device, and to detect abuse. The UUID contains no personal-name information and is not linked to your Apple ID.

2.2 Inputs (prompts) and AI replies

Data flow: Your App sends a signed HTTPS request to our AWS Lambda function (region us-east-1). The Lambda forwards your input + the character prompt + memory/history (if any) to the appropriate third-party AI model (see §4) and returns the response to your App. We do not store the prompt text itself. In parallel the Lambda sends a technical logging entry to our MySQL server (hosted at netcup, Germany). This entry contains the model used, the active character, the number of tokens processed, the result URL (only for image generations), timestamp and technical metadata (app version, client type). Purpose: abuse detection and cost accounting.

2.3 Images and documents

Uploaded images are temporarily cached at imagenator.de until the AI model has processed them, then deleted automatically after 30 days. PDF documents are forwarded to OpenAI/Gemini when needed and discarded after processing.

2.4 Audio

When you use voice input, audio is streamed in real time to OpenAI Realtime. When you ask James to call a restaurant, the details required for that task are transmitted to the selected restaurant through Vonage telephony. James does not call you or other private individuals. We do not store recordings of your voice; transmissions are encrypted.

2.5 In-App Purchases and subscriptions

Purchases are handled exclusively via Apple In-App Purchase. Apple receives your payment information — we do not. We only learn from Apple that a purchase was successful and store the status (subscription active yes/no, Schnauzer balance) against your UUID. No payment data or credit card information is shared with us.

2.6 Usage analytics

Per request we record: timestamp, selected character, approximate token count, estimated USD cost, success/failure status, app version. Used for internal economic accounting and fair-use throttling (see Terms §7). There is no link to real names, email addresses or external tracking profiles.

2.7 Memories and profile

If you allow the AI in settings to remember things about you (name, preferences, etc.), these „memories“ are stored locally on your device and synchronised across your devices via Apple iCloud KeyValueStore. They are sent as context with each request but not persistently stored on our servers.

2.8 IP address

When your App calls our AWS Lambda function, your device’s IP address is technically transmitted to AWS. AWS stores it in CloudWatch logs for at most 7 days for security and abuse detection. Our MySQL database server (netcup) does not receive end-user IPs because the connection there is initiated by the Lambda, not by your device.

2.9 Google account integration (Gmail)

You may optionally connect your Google account in the App settings to use Gmail summaries in your morning Daily Briefings and as context for AI replies. This feature is opt-in and can be disconnected at any time in the App settings. Your Apple Calendar events are read separately and exclusively on-device via the iOS EventKit framework — we do not access Google Calendar.

Which Google data we access (OAuth scopes):

  • https://www.googleapis.com/auth/gmail.readonly — read-only access to your Gmail mailbox and related settings, used solely to integrate subjects, senders and short summaries of important unread messages into the Daily Briefing and into AI replies.
  • email — retrieval of the primary email address of your Google account, used solely to display the connected account in the App’s account list.
  • openid — standard OpenID Connect scope to uniquely associate the authenticated Google profile with your App account (no data exchange beyond the OpenID ID token).

How we use Google user data (Limited Use disclosure): James’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Google user data is used solely to provide the user-facing features the user requested (Daily Briefing, contextual AI replies).
  • We do not sell Google user data and we do not use it for advertising, profiling or any commercial purpose outside of the requested feature.
  • We do not transfer Google user data to third parties except as necessary to fulfil the requested feature (for example, an event title is included in a prompt to the chosen AI model when the user actively asks a question about their schedule).
  • We do not use Google user data to train AI models — neither our own nor those of our AI providers. AI providers (OpenAI, Google Gemini, Anthropic, xAI) process forwarded content under their respective API terms (no training on API content).
  • No human at C&P Apps reads your emails or calendar events. Processing is fully automated between your device and the Google/AI APIs.

Data segregation from DeepSeek (Limited-Use compliance): The AI characters „Zodiac“ and „Pirat“ run by default on a DeepSeek model. Because DeepSeek’s public terms do not contractually exclude training on API content, conversations that contain Google user data are subject to a server-side enforced data segregation: as soon as a request includes content received via Google APIs (Gmail messages or Google Calendar events), the request is automatically and without user action routed to Google Gemini instead — DeepSeek receives none of the request in this case. This routing rule is hard-coded in our backend (AWS Lambda) and is auditable. It guarantees that data obtained via Google APIs is at no point transmitted to DeepSeek, in accordance with the Limited Use requirement of the Google API Services User Data Policy.

Storage location and retention:

  • The OAuth refresh token is stored encrypted in the iOS Keychain on your device and never leaves the device.
  • Retrieved calendar/email content is held in device memory only while the feature is in use and is not persisted on our servers.
  • If you disconnect Google in the App, the refresh token is deleted locally immediately, and you can revoke the OAuth grant at any time via your Google account permissions.

Legal basis: Consent under Art. 6(1)(a) GDPR, given via the OAuth consent screen when connecting the account.

2.10 Microsoft account integration (Outlook / Microsoft 365)

You may optionally connect your Microsoft account (Outlook.com, Hotmail, live.com or Microsoft 365) in the App settings to use email summaries in your morning Daily Briefings and as context for AI replies. This feature is opt-in and can be disconnected at any time in the App settings.

Which Microsoft data we access:

  • Mail.Read (Microsoft Graph API) — read-only access to your mailbox, used solely to integrate subjects, senders and short text snippets of important unread messages into the Daily Briefing.
  • offline_access, email, openid — standard authentication scopes for the OAuth session.

How we use Microsoft user data: The same strict rules as for Google data apply (see §2.9): use solely for user-requested features, no sale, no advertising, no profiling, no transfer to third parties beyond what is required to fulfil the requested feature, no AI training, no human review.

Storage location and retention: The OAuth refresh token is stored encrypted in the iOS Keychain and never leaves the device. Retrieved email content is held in device memory only and is not persisted on our servers. When you disconnect, the refresh token is deleted locally immediately; you can additionally revoke OAuth access at account.live.com/consent/Manage.

Legal basis: Consent under Art. 6(1)(a) GDPR, given via the Microsoft OAuth consent screen.

2.11 IMAP accounts from other providers (e.g. web.de, GMX, T-Online, Posteo)

You may connect additional email accounts via IMAP/SMTP in the App settings (e.g. web.de, GMX, T-Online, Yahoo, Mailbox.org, Posteo, custom domain). Unlike with OAuth providers (Google, Microsoft), this uses username and password — the password is stored encrypted in the iOS Keychain only and leaves your device solely to authenticate to the relevant mail server.

Data flow: The App establishes a TLS-encrypted IMAP connection directly from your device to the respective mail server (port 993). Email content is processed locally and loaded into device memory only as Daily Briefing context. IMAP content is not transmitted to our servers; only the briefing to be answered by the AI model may forward selected content to OpenAI/Gemini (see §4).

Storage location: Server address, port and username are stored locally in App settings (UserDefaults); the password lives in the hardware-encrypted iOS Keychain.

  • Performance of the contract (AI replies, app features) — Art. 6(1)(b) GDPR
  • In-App Purchases / subscriptions — Art. 6(1)(b) GDPR
  • Abuse detection, fair-use throttling — Art. 6(1)(f) GDPR (legitimate interest: economic viability, IT security)
  • Statistical evaluation (anonymised/aggregated) — Art. 6(1)(f) GDPR
  • Legal obligations (accounting, criminal proceedings) — Art. 6(1)(c) GDPR
  • iCloud sync of profile/memories — Art. 6(1)(a) GDPR (consent via in-app settings)

4. Third-party providers

To answer your requests we forward your inputs to the following processors / third-party providers:

  • OpenAI Inc., USA — chat (GPT models), image generation (gpt-image-2), voice (gpt-realtime, TTS), moderation, embeddings
  • Google LLC, USA — Gemini models (chat, image, Deep Research), TTS
  • Anthropic PBC, USA — Claude models (chat)
  • xAI Corp., USA — Grok models
  • DeepSeek, China — DeepSeek models (chat)
  • Replicate Inc., USA — FLUX models (image generation), Hunyuan, Qwen
  • Black Forest Labs GmbH, Germany — FLUX models
  • Vonage Holdings Corp., USA — telephony (PSTN calls from James to selected restaurants)
  • Amazon Web Services (AWS), Inc., USA — Lambda hosting, CloudWatch logs
  • netcup GmbH, Germany — MySQL database, web hosting (james-butler.net)
  • Apple Inc., USA — In-App Purchases, iCloud sync, push notifications, Apple Watch / CarPlay
  • imagenator.de, Germany — temporary image caching

For US providers, transfers are based on the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework adequacy decision (where the provider is certified). You may object to such transfers by discontinuing use of the App.

5. Retention periods

  • UUID + subscription/credit status: while the account is active + 30 days
  • Technical request logs (model, character, tokens, timestamp): 90 days
  • Image cache (imagenator.de): 30 days
  • AWS CloudWatch logs: 7 days
  • Accounting-relevant in-app purchases: 10 years (German Commercial / Tax Code)

Upon request, all data not subject to mandatory retention is deleted within 30 days (see §7).

6. Cookies, tracking, advertising

The App itself sets no tracking cookies and does not use advertising IDs (IDFA). On the website james-butler.net we use only technically necessary cookies (e.g. language preference); no Google Analytics, no Facebook Pixel.

7. Your rights

At any time you have the right to:

  • Information (Art. 15 GDPR) about the data we store against your UUID
  • Rectification of incorrect data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR) — you can reset your UUID at any time by uninstalling the App or by contacting us at support@james-butler.net
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR) — particularly to processing for abuse detection on the basis of legitimate interest
  • Withdrawal of consent with effect for the future (Art. 7 GDPR)
  • Complaint to the competent supervisory authority (Art. 77 GDPR). For our seat that is the Thuringian State Commissioner for Data Protection and Freedom of Information, Häßlerstraße 8, 99096 Erfurt, www.tlfdi.de.

Please direct requests to support@james-butler.net, including your UUID as shown in the App.

8. Automated decisions

The AI replies and the automatic model throttling (see Terms §7) are algorithmic processing but not automated individual decisions with legal effect within the meaning of Art. 22 GDPR. You may contact us at any time to challenge or query a decision.

9. Security and protection of sensitive data

We employ layered technical and organisational measures (TOMs) that meet the current state of the art.

9.1 Encryption in transit
All transmissions between the App and our servers, and between our servers and third-party providers (OpenAI, Google, Anthropic etc.), use TLS 1.2 or higher. Certificates are renewed regularly. Voice transmissions to OpenAI Realtime use WSS (WebSocket over TLS).

9.2 Encryption at rest

  • Sensitive authentication data (in particular OAuth refresh tokens for Gmail / Outlook / Microsoft 365, plus IMAP passwords and Apple Calendar permissions) are stored on your device in the iOS Keychain. The Keychain is hardware-encrypted (Secure Enclave) and unlockable only via biometric authentication or device passcode.
  • Our MySQL database at netcup runs on a fully encrypted Linux volume (LUKS). Database backups are likewise stored encrypted.
  • Images in the temporary image cache (imagenator.de) sit on a TLS-protected server and are deleted after 30 days.

9.3 Access control

  • AWS Lambda functions are invoked exclusively via AWS-IAM-signed requests (SigV4). Unauthenticated calls are rejected.
  • Database connections are password-protected and reachable only from inside the AWS VPC — no direct access from end-user devices or the public internet.
  • Administrative access to servers and the database is restricted to the owner (C&P Apps Michael Knochen); access is via SSH key authentication with MFA only.

9.4 Handling of sensitive content (Google data, PDF content, voice recordings)

  • Content from Gmail, Outlook / Microsoft 365, IMAP mailboxes or the local Apple Calendar is not stored in our database. It is held in device memory only and forwarded to the chosen AI model on demand.
  • PDF content is forwarded to OpenAI or Google Gemini during processing and handled there per their API terms (no training on API content). PDFs are not persisted on our servers.
  • Voice recordings are streamed in real time to OpenAI Realtime and not recorded — neither by us nor by OpenAI (per OpenAI Realtime API policy).
  • There is no human review of your content by C&P Apps. Processing is fully automated.

9.5 Abuse protection

  • Per-UUID rate limits prevent automated mass abuse.
  • CloudWatch logs are retained for 7 days for anomaly detection and then deleted automatically.
  • In the event of a suspected security incident, we notify affected users and the competent supervisory authority within 72 hours per Art. 33/34 GDPR.

9.6 No use for AI training
We do not train AI models ourselves and do not permit our third-party providers to use content from our API calls to train their models. All AI providers we use (OpenAI, Google, Anthropic, xAI, Replicate) offer this contractually as the default for API customers.

10. Minors

James is not intended for children under 16. If we learn that a person under 16 is using the service without their guardian’s consent, we will delete the related data without undue delay.

11. Changes to this Policy

We update this Privacy Policy when our processing activities change. The current version is always available at james-butler.net/en/datenschutz.html. Material changes are announced in-app.

12. Contact

For privacy questions please reach us at support@james-butler.net. Postal address see above (§1).