01 Who I am.
Night Owl IT is the trading name of Night Owl IT Ltd, a private limited company registered in England and Wales (company no. 17350821). I am Theunis Jacobs, the company's director. For the purposes of UK data protection law, the data controller is Night Owl IT Ltd, for any personal data described in this policy, including data collected through the JEEVES software, this website, and during consultancy engagements (except where we act as a processor on behalf of a client; see section 5).
Night Owl IT Ltd is not required to appoint a Data Protection Officer under UK GDPR, and has not done so. In practice all data protection matters are handled directly by me as its director.
02 Scope of this policy.
This policy applies to:
- The JEEVES household assistant software produced by Night Owl IT, and any of its connected services that interact with third-party APIs (including Google services).
- Visitors to
nightowlit.co.uk, including people who join the WorkRecap waitlist. - People who contact Night Owl IT about consultancy work.
- Clients who have entered into a written engagement with Night Owl IT.
It does not apply to third-party services that JEEVES is configured to connect to (such as Google Calendar, Home Assistant, or Spotify). Each of those services has its own privacy policy and you remain in control of the data held within them through your own account with that provider.
03 JEEVES & Google user data.
This section describes how the JEEVES software accesses, uses, stores, and shares data from your Google Account, and is the authoritative disclosure for Google API Services User Data Policy purposes.
3.1 What JEEVES is
JEEVES is a household voice assistant produced by Night Owl IT. It runs on hardware physically located in your home: a Windows PC that acts as the "brain", one or more Raspberry Pi devices that act as voice satellites, and a Home Assistant instance for smart home integration. JEEVES is not a cloud service. There is no Night Owl IT server that holds a copy of your data, and JEEVES does not function as a multi-tenant SaaS application.
3.2 Google API scopes used
When you choose to connect JEEVES to Google Calendar, the software requests the following OAuth scope from your Google Account:
https://www.googleapis.com/auth/calendar: used to read your calendar events so JEEVES can answer questions about your schedule, remind you of upcoming events, and (where you have asked it to) create or modify calendar entries on your behalf.
Granting access is optional. If you do not grant Calendar access, all other JEEVES features continue to work normally. You will simply not be able to ask calendar-related questions.
Authentication uses the OAuth 2.0 Device Authorization Grant ("Device Flow"). You are shown a short code and a URL on your phone or computer, you sign into your own Google account there, and you approve access. Your Google password is never seen, handled, or stored by JEEVES or by Night Owl IT.
3.3 How the data is accessed and used
When a Calendar scope grant is in place, JEEVES uses it exclusively to:
- Read upcoming events so the assistant can answer your spoken or typed questions ("what's on my calendar today?").
- Issue reminders for events you have asked JEEVES to remind you about.
- Create, update, or delete events when you specifically ask the assistant to do so.
Calendar data is not used for any other purpose. It is not used to train AI models, build user profiles, generate analytics, or influence anything outside the scope of your own household assistant.
3.4 Where the data is stored
Calendar data accessed through the Google API stays on the JEEVES brain (the Windows PC) in your own home. Short-lived caches may be kept locally to make the assistant feel responsive, but the authoritative copy of your calendar always remains in your Google account. The OAuth refresh token issued by Google is stored encrypted on the local JEEVES hardware.
Night Owl IT does not operate a central server that receives, copies, aggregates, or processes Google user data from JEEVES installations. There is no telemetry stream containing calendar contents, no remote backup of your calendar to Night Owl IT, and no scenario in normal operation in which your calendar data leaves your home network.
3.5 Who the data is shared with
Google user data accessed via JEEVES is not transferred or sold to any third party. Specifically, Night Owl IT does not:
- Sell, rent, or licence your Google user data to anyone, ever.
- Transfer it to advertising platforms, data brokers, or any information resellers.
- Use it to serve ads, including retargeting or personalised advertising.
- Use it to assess credit-worthiness or for any lending purpose.
- Use it to train, develop, or improve generalised or third-party AI / ML models.
During processing within your own JEEVES installation, calendar context may be sent as part of a prompt to a large language model (such as Anthropic's Claude) so that the assistant can give a useful answer. Those API calls are made by your own JEEVES installation, are governed by the AI provider's own data handling terms, and do not flow through any Night Owl IT-operated server. The choice of AI provider is configurable on your own install.
JEEVES's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
This commitment applies to all current and future versions of JEEVES. If the way JEEVES handles Google user data ever changes materially, this policy will be updated and existing users will be notified before the new processing begins.
3.6 How long the data is kept
Calendar data fetched from Google is held only as long as it's useful for the current assistant session, plus any local cache window (typically a few minutes to a few hours). When the OAuth grant is revoked, all locally cached calendar content is purged on the next JEEVES restart, and the encrypted refresh token is deleted.
3.7 How to revoke access
You can revoke JEEVES's access to your Google account at any time, in two ways:
- From your Google account directly: visit myaccount.google.com/permissions, find "JEEVES", and remove access.
- From within JEEVES itself: open the admin UI on the brain and disconnect the Google Calendar integration. This will also delete the locally stored refresh token.
Revoking access does not delete events from your Google Calendar. It only stops JEEVES from being able to read or modify them.
3.8 Security of the OAuth credentials
The OAuth refresh token issued by Google is stored on the JEEVES brain in an encrypted form. It is never transmitted off your home network in normal operation. Network traffic between JEEVES components is protected by mutual TLS, and the brain enforces an outbound allowlist limiting which external services it can contact at all.
04 Website data.
This website (nightowlit.co.uk) is a static page hosted
on a third-party hosting provider. It does not set tracking
cookies, run analytics scripts, or build a profile of you. There
is no cookie banner because there is nothing requiring consent
under the Privacy and Electronic Communications Regulations (PECR).
Your IP address and basic request details (browser type, page requested, referring URL) are processed transiently by the hosting provider for the purpose of serving the page and for routine abuse / security logging. These logs are not used to identify or profile you.
The site loads web fonts from Google Fonts. When your browser fetches these, your IP address is shared with Google's servers as part of the standard HTTP request. Google's Fonts service does not set cookies, but the IP transmission is worth being aware of. See policies.google.com/privacy for Google's own notice.
4.1 The WorkRecap waitlist
The form on the WorkRecap page asks for your email address and a few optional details (your first name, platform, role, how you keep track of your day today, and what the product would be worth to you). Submitting it does two things:
- An email notification is sent to me via Resend, the transactional email provider, so I can reply to you directly.
- The answers are stored as a lead record in a Supabase database operated by Night Owl IT, so signups can be counted and nobody's message gets lost in an inbox.
This data is used for exactly one purpose: contacting you about WorkRecap's launch and understanding what to build first. It is not added to any other mailing list, not shared with anyone, and not used for advertising. Ask to be removed (email with subject "Privacy request") and the lead record and notification email are both deleted.
The form includes an invisible anti-spam field rather than a CAPTCHA or tracking service, so joining the waitlist requires no third-party scripts at all.
4.2 The contact form
The guided enquiry form on the contact page asks for your email address and, optionally, your first name and answers about what you're trying to achieve, your timeline, and your budget. Submitting it sends the answers to me by email (via Resend) and stores them as an enquiry record in the same Supabase database, so that no message goes unanswered.
This data is used only to respond to your enquiry and, if we end up working together, as the start of the project record. It is handled under the same rules as enquiry emails: kept up to 12 months if no engagement follows, deleted sooner on request.
05 Consultancy client data.
If you contact Night Owl IT about possible work, or become a consultancy client, the following may be collected and used:
- Your name, business name, and contact details.
- The contents of your messages and project documents.
- Invoice records, payment references, and bank transfer details.
- Any personal data you share with me as part of the project.
Where a client engagement involves processing third-party personal data on your behalf (for example, records inside your Salesforce org, or messages on your home automation system), Night Owl IT acts as a data processor in respect of that data. The terms of that processing are set out in the engagement contract or a separate Data Processing Agreement, not in this policy.
06 Lawful basis.
UK GDPR requires a lawful basis for every kind of personal data processing. The bases relied on are:
08 Retention.
09 International transfers.
Personal data held by Night Owl IT is stored on systems located within the United Kingdom or the European Economic Area wherever possible. Some service providers (notably email and hosting) may transfer data to the United States or other countries outside the UK / EEA.
For JEEVES specifically: the Google API calls that JEEVES makes are sent to Google's servers, which may be located outside the UK. This data flow is between you (the user) and Google directly, in the same way as any other Google product you use. Night Owl IT does not intermediate or copy that traffic.
Where international transfers occur for Night Owl IT's own processing, they are protected by one or more of the following safeguards under UK GDPR:
- A current UK adequacy decision covering the destination country
- The UK International Data Transfer Agreement (IDTA)
- The UK Addendum to the EU Standard Contractual Clauses
10 Your rights.
Under UK GDPR you have a set of rights in relation to your personal data. Exercise any of them by emailing theunisj@nightowlit.co.uk. I'll respond within one calendar month and there's no charge for reasonable requests.
I may ask you to verify your identity before acting on a request, to make sure data isn't released to the wrong person.
11 Security.
Personal data is protected with appropriate technical and organisational measures, scaled to the sensitivity of the data and the risks involved. These include:
- Encrypted storage on all devices that hold client or user data.
- Full-disk encryption on the working laptop and backups.
- Multi-factor authentication on email, accounting, and hosting accounts.
- A password manager with strong, unique passwords for every service.
- Regular software updates and security patching.
- Network segmentation between client work and general-purpose devices.
- For JEEVES installations: encrypted OAuth tokens, mutual TLS between components, outbound network allowlisting on the brain, and signed software updates.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, you and the Information Commissioner's Office will be notified in line with UK GDPR timelines.
12 Children.
Night Owl IT's services are aimed at businesses and adult consumers. This website and the JEEVES software are not directed at children under the age of 16, and personal data relating to children is not knowingly collected. JEEVES is installed for an adult householder ("the Owner") who is responsible for any household members under 16 who may interact with the assistant.
If you believe a child has provided personal data to me directly, please get in touch and it will be deleted.
13 Changes to this policy.
This policy may be updated from time to time, for example to reflect changes in the services offered, the tools used, or changes in the law. The "last updated" date at the top of the page will always show when it was last revised.
If the change materially affects how Google user data is handled, existing JEEVES users will be notified and (where required) asked to consent to the updated terms before the new processing begins. Material changes affecting consultancy clients will be communicated by email.
14 Complaints.
If you are not satisfied with how I've handled your personal data or a data protection request, please contact me first so I can try to put things right. You also have the right to lodge a complaint with the UK's data protection regulator at any time:
15 Contact.
Questions about this policy, your data, JEEVES's handling of Google user data, or to exercise any of the rights listed in section 10: