James Back to site

Privacy Policy

Last updated 14 September 2026. This is the full version. Nothing important is hidden in small print.

The short version. Your conversations are stored on our own server in Helsinki, Finland, inside the European Union. Audio is never saved to a file, only the text of what was said, because that is how James remembers you. We do not sell data, we do not advertise, and we do not use your conversations to train models. One email to privacy@hellojames.io gets you a copy of everything or deletes all of it.

1. Who is responsible

The service at hellojames.io is operated by Protremix Technology Limited ("we"), the data controller for the purposes of the EU General Data Protection Regulation (GDPR).

To be completed before launch: company registration number and registered office address. Our operating entity is currently being registered in a Dubai free zone. We will not publish a registration number we do not yet hold. Until then, all requests reach us at the email addresses below and are answered within the statutory time limits.

Contact for anything on this page: privacy@hellojames.io. For legal notices: legal@hellojames.io.

2. Who the data is about

Two different people are usually involved, and they have different rights.

If you are setting James up for someone else, you are telling us that you have the standing to do so and that you will tell them. James also tells them himself: in the first conversation he says that he is an artificial intelligence, who set him up, and asks whether it is alright to talk. If they say no, he stops. Their refusal overrides the account holder's wishes.

3. What we collect

DataWhy we have it
Name, age, how to address the person, language, chosen voice, chosen roleSo James can speak to them correctly instead of interviewing them
What you tell us about the person: their history, interests, what not to raiseSo the first conversation is a conversation and not a form
Names and relationships of people in their life, and important datesSo James does not ask "who is Lena?" and does not open cheerfully on the anniversary of a death
The text of conversationsMemory. Without it James cannot continue where you stopped, which is the entire product
Notes about health, mood, and moments of crisisSo he adjusts how he speaks, and so he can decide to reach a family member. See section 5
Contact details of the person to reach in an emergencySo the message can actually be delivered
Technical records: session times, duration, error logsBilling, and finding faults

What we do not collect

4. Cookies

We use no tracking cookies and no analytics. The site stores one thing in your browser's local storage: the language you picked, so you do not have to pick it again. That never leaves your device. This is why there is no cookie banner: we have nothing to ask you about.

5. Health and crisis data, Article 9

Conversations like these unavoidably touch on health, mental state, and sometimes thoughts of dying. Under GDPR Article 9 this is special category data and needs stronger grounds than ordinary personal data.

We process it only on the basis of separate explicit consent, which you give during setup on a screen that says what it is for. It is not buried in a general acceptance of terms. You can withdraw it at any time, and withdrawing it means we delete those notes.

What we do with it: adjust how James speaks, and let him decide whether to contact the family member you named. What we never do with it: sell it, share it with insurers or employers, or use it to build profiles for anything other than this conversation.

6. Legal grounds

PurposeGround
Running the service you asked forPerformance of a contract, Article 6(1)(b)
Memory of conversations, so James recognises and remembers the personContract, Article 6(1)(b). It is the service, not an extra
Health, mood and crisis notesExplicit consent, Article 9(2)(a)
Messaging a family member in an emergencyConsent given at setup. Where there is an immediate risk to life, also vital interests, Article 6(1)(d)
Keeping the service secure and finding faultsLegitimate interests, Article 6(1)(f)
Billing and accounting recordsLegal obligation, Article 6(1)(c)

7. Where your data is, and who else touches it

Conversation text, memory, profiles and notes are stored on our own server in Helsinki, Finland, inside the European Union. It is a dedicated machine, not shared hosting, provided by Hetzner Online GmbH as our infrastructure processor. For storage, this data does not leave the EU.

Processors we use

These are the only third parties that receive any of your data, each for one narrow purpose, each under a data processing agreement.

ProcessorWhat it receivesWhere
Hetzner Online GmbHHosts the server. Encrypted storage of everything aboveFinland, EU
OpenAI, Ireland and USALive speech and text of the conversation, for speech recognition and reply generation. Under OpenAI's API terms this data is not used to train their models. This is the only part of a conversation that leaves our serverEU and USA, Standard Contractual Clauses
TelegramOnly the emergency or check-in message itself, and the recipient's chat identifier. Never the conversationPer Telegram's own terms
Let's EncryptNothing personal. Issues the certificate that encrypts the connectionUSA

Public sources James reads from

When James looks something up in the real world, he queries open public services. These receive only the query, never who is asking, and never anything from the conversation beyond the search term itself.

We use these deliberately instead of letting a language model invent an answer. An invented clinic address given to someone who needs a doctor is not a minor error.

8. How long we keep it

9. Your rights

Under GDPR you can ask us to:

Write to privacy@hellojames.io. We answer within 30 days and usually much faster. There is no charge.

If you think we have handled your data badly, you can complain to the data protection authority in your country. Because our server is in Finland, that can also be the Finnish Data Protection Ombudsman.

10. Automated decisions

James decides by himself whether a situation is serious enough to message the family member you named. We are telling you plainly because it is an automated decision that affects a real person.

What it can do: send the message you authorised, to the contact you gave, and say the emergency number out loud. What it cannot do: call emergency services on your behalf, contact anyone you did not name, or make any decision about money, medicine or care. If a message fails to send, James says so out loud rather than letting anyone believe help is coming.

11. Children

The service can be set up for a child, and the account must then be held by a parent or legal guardian, who gives consent under Article 8. We do not knowingly create accounts for children on their own. If you believe a child has an account without a guardian, write to privacy@hellojames.io and we will remove it.

12. Security

Summarised here, described in full on the security page: encrypted connections only, each person reachable by their own private link, no audio at rest, access to the server limited to key-based administration, and an automated test on every code change that confirms one person's memory cannot be reached from another's link.

13. If something goes wrong

If there is a personal data breach that puts people at risk, we notify the relevant supervisory authority within 72 hours and tell affected people directly, in plain words, including what was taken and what to do about it.

14. Changes

If we change this policy in a way that matters, we will email account holders before it takes effect, not after. The date at the top always reflects the current version.