Privacy Report

Savor Privacy Policy

Last updated:

This policy explains what we collect, how we use it, and your choices.

  • Your cards stay available on your device in a local database for offline use.
  • Savor now requires a free account (Sign in with Apple or Google) to use the app. We store your account identity to sign you in. When server sync is enabled in your app version, we also store your cards under your account for synchronization and recovery.
  • When you use AI-assisted capture (voice, photos, typed parsing), we send feature-specific content to our backend (and OpenAI when needed) — not your full database or account profile.
  • We use aggregated, content-free analytics to improve the product — not task text, and not for advertising.
  • On this website, joining early access stores your email so we can send a welcome message and manage the waitlist.
  • We do not sell your personal information for money, and we do not broker or rent it. Limited advertising measurement is described in “Advertising measurement.”

What Savor is

Savor is a calm capture app for intentions — things you want to remember, organize, revisit, or act on later. On the surface it feels simple; underneath it is designed as a privacy-preserving layer for user-owned intent.

This policy covers savorapp.ai (our website and early-access signup) and the Savor mobile app for iOS and Android. Where website and app practices differ, we say so plainly.

What We Collect

  • Account identity when you sign in — an internal user ID, the email address from your sign-in provider (which may be an Apple “Hide My Email” private-relay address), and your display name. Stored on our backend only to authenticate you.
  • Device data necessary for app functionality (e.g., OS version, anonymous crash logs when enabled).
  • Reminders and related metadata you create in the app. They are stored locally on your device; when server sync is enabled in your app version, they are also stored under your account on our backend.
  • Optional voice input you initiate to create reminders.
  • A mobile advertising identifier, collected by the Meta (Facebook) SDK and shared with Meta to measure our advertising (see “Advertising measurement”).
  • Anonymous analytics identifiers and in-app activity (e.g., which features are used), collected via our analytics provider (Mixpanel). This never includes the content of your reminders, voice, or photos.
  • Photos you choose to capture, such as a bill or receipt, processed to extract text (see “Photos”).

How we use information

  • Provide the service: capture, organize, resurface, notify, share (when you opt in), and parse your inputs
  • Early access & website marketing: confirm waitlist signup, send welcome email, and measure campaign effectiveness through Meta Pixel / Conversions API when configured (see “Advertising measurement”)
  • Improve reliability: anonymous analytics, optional user-sent error reports (redacted), server logs
  • Security & abuse prevention: invite-code validation, rate limits, operational monitoring
  • Legal & compliance: respond to lawful requests where required

Voice Input

When you use voice to create a reminder, audio is processed into text. Depending on your settings and network availability, transcription may occur on-device or via a secure API.

The resulting text is used to generate a reminder. We do not sell your audio or transcripts.

Advertising measurement

Like most apps, Savor occasionally runs ads to reach new people. To see whether those ads actually work, we use Meta's advertising tools. When you install Savor, the Meta (Facebook) SDK reads your device's advertising identifier — a resettable ID your phone provides specifically for advertising — and shares it with Meta, along with a few basic milestones like “app installed” and “finished setup.” This lets us connect an install back to an ad and reach more people who'd find Savor useful.

We share only that advertising identifier and those anonymous milestones. We never send Meta the content of your reminders, your voice recordings, your photos, or your name or email.

You're in control: on iPhone you can decline when prompted, and on any device you can reset or limit your advertising ID in your system settings — Savor works exactly the same either way.

Photos

When you choose to capture a photo, such as a bill or receipt, the image is sent securely to our backend and trusted processors solely to extract the relevant text for your reminder. We do not use your photos for advertising, and we do not sell them.

Local Storage (Offline-first)

  • Your reminders database is stored on your device. This supports offline use and keeps your cards available during network interruptions.
  • Settings and lightweight state (e.g., whether you've seen a tutorial) are stored locally (AsyncStorage) on your device.

When server sync is enabled in your app version, Savor also stores card content and metadata under your signed-in account using Google Cloud Run and Firestore. This supports synchronization across signed-in devices and recovery after a reinstall. Photos and other binary attachments remain on the device; the synced card may contain attachment metadata or a device-local reference.

Cloud Services

If you use features that call our backend (e.g., voice parsing), we process only the fields needed to complete the request. When server sync is enabled, the backend also processes card content and metadata to synchronize your account. Logs are minimized and used to maintain reliability and security.

We do not sell your data. We do not share the content of your reminders, voice, or photos with third parties for advertising. The one identifier we share for advertising — a resettable device advertising ID — is described in “Advertising measurement.”

Notifications

If enabled, Savor schedules local notifications on your device (e.g., daily summaries, time-based reminders, gentle nudges). You can turn these off anytime in Settings or your system settings.

Analytics, Diagnostics & Advertising

We use Mixpanel to understand anonymous, aggregate usage (e.g., which features are used and whether onboarding completed). These events never include the content of your reminders, voice, or photos, and are not linked to your name or email.

When Savor crashes or hits an unexpected error, we send a diagnostic report to Sentry so we can find and fix it. The report contains the technical stack trace, your device model, OS version and app version, and the same anonymous identifier we use for analytics. It never contains the content of your reminders, your voice recordings, or text from anything you scan. These reports are processed under a data processing agreement. You can turn crash reporting off in Settings.

For advertising measurement, we share a resettable advertising identifier with Meta as described in “Advertising measurement.”

Third-party services / subprocessors

We use the following services. This table lists what each one does and what data they may receive. Links point to their own privacy policies.

ServiceRoleData shared
VercelHosts savorapp.ai and serverless API routesRequest logs, IP, user agent; deployment metadata. No app intent content.
Firebase / FirestoreWaitlist leads; account identity and card sync (app backend)Website: email, hashes, attribution cookies, IP, user agent. App: account identity and, when server sync is enabled, signed-in card content and metadata. Workspace sharing remains disabled.
ResendTransactional welcome email after waitlist signupRecipient email address, email content
Meta Pixel / Meta Conversions APIWebsite conversion measurement (when VITE_META_PIXEL_ID is configured)Hashed email on Lead events; page events; fbp/fbc cookies; IP; user agent. See “Advertising measurement.” No private Savor Content.
Google Cloud RunHosts the Savor API (voice, photo, auth, sync, inbox, invites)Request payloads needed to fulfill each feature; truncated operational logs
OpenAISpeech-to-text and AI parsing when you use capture featuresThe audio, image, or text you submit for that request. See “Voice Input” and “Photos” above for how this is handled.
MixpanelPrivacy-safe product analytics (app)anon_id and whitelisted event metadata — no capture text
SentryCrash and error diagnostics (app and backend)Stack traces, device model, OS and app version, and anon_id — never reminder content, voice transcripts, or scanned text
Apple App Store / Google PlayApp distribution; store links on websiteStandard store install analytics (controlled by Apple/Google). No capture content.
Sign in with Apple / Google Sign-InAccount sign-in (required to use the app)Email, name, provider tokens during sign-in
Meta SDK (app, iOS)App-install attribution and measurementStandard app activation / registration / retention events; a resettable advertising ID — iOS only after ATT is granted, and on Android subject to the in-app opt-out
Firebase App DistributionInternal/beta build distribution (CI pipeline)Tester email addresses provided for beta access

Data retention

Data typeTypical retention
App intents / tasks (local)Until you delete them or uninstall the app
App intents / tasks (server-synced)Until you delete the card or your account; a content-free deletion record may remain to propagate deletion to signed-in devices
Voice audio sent for transcriptionDeleted on device and our API after transcription; provider-side handling governed by OpenAI policies
Photo / text sent for AI parsingHandled as request-time input on our API; provider-side retention governed by OpenAI's policies
Email-to-inbox (server)Raw email: ~7–30 days; parsed metadata: up to ~90 days (infrastructure lifecycle rules in EMAIL_INBOX_RETENTION.md)
Waitlist leads (website)Stored in Firestore until deleted upon request
Invite signup (name + email)Stored with invite redemption in Firestore until deleted upon request
Auth session tokens90 days (backend JWT TTL)
Account identity (email, name, user ID)Until you delete your account or request deletion
Mixpanel analyticsPer Mixpanel project retention settings (anonymous IDs only)
User-sent error reportsUp to 50 recent errors on device; server copies per operational logging practices

What we do not do

  • We do not sell your personal information for money. We do not broker, rent, or otherwise monetize your information to data brokers.
  • We do not sell or share private Savor Content for advertising. Your captures are for your productivity, not ad targeting or behavioral profiling. App capture content is not sent to Meta, Mixpanel, or other advertising partners for marketing purposes.
  • We do not use your private Savor Content to train general-purpose AI models. We do not build training datasets from your captures, voice audio, transcripts, photos, or task text.
  • We do not include capture content in product analytics. Our analytics use aggregated, content-free metadata — not task titles, notes, transcripts, or photos.
  • We do not use server-synced card content for advertising, product analytics, or training general-purpose AI models.

Your Choices

  • You can edit or delete reminders at any time in the app.
  • You can disable voice features and notifications in Settings.
  • You can reset or limit your advertising ID in your device settings, and decline app tracking on iPhone when prompted.
  • You can uninstall the app to remove local data from that device. Uninstalling alone does not delete server-synced cards.
  • You can delete your account from within the app, or by emailing support@savorapp.ai. Account deletion removes the account identity and server-synced cards we store. Cards held locally on a device remain until you delete them or uninstall the app.

California privacy rights

This section applies to California residents under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Our plain-English position: we do not sell your information for money, and we do not sell or share your private Savor Content (reminders, voice, or photos) for advertising.

Personal information we collect and disclose

Over the past 12 months we have collected the following categories of personal information. We disclose the categories marked below to Meta for our own advertising measurement — this can be classified as a “sale” or “share” under the CCPA/CPRA even though we receive no money for it.

  • Identifiers — email address, hashed email (lead events), cookie IDs (_fbp, _fbc), device advertising identifier. Disclosed to Meta for advertising measurement.
  • Internet or network activity — page views, signup conversions, in-app feature events (content-free). Website conversion events disclosed to Meta.
  • Device / technical data — IP address, user agent, OS and app version. Disclosed to Meta as part of measurement.
  • Private Savor Content — reminders, voice-derived text, photos, notes. Never sold or shared for advertising.

Your rights

  • Know / access: request the categories and specific pieces of personal information we have collected about you
  • Delete: request deletion of personal information we hold
  • Correct: request correction of inaccurate personal information
  • Opt out of sale/sharing: opt out of the sale or sharing of personal information for cross-context behavioral advertising
  • Non-discrimination: we will not deny service, charge a different price, or provide a different quality of service for exercising these rights

How to exercise your rights

To make a request — including Do Not Sell or Share My Personal Information — email support@savorapp.ai with the subject line California Privacy — Do Not Sell or Share. Include the email address you used on the waitlist, if any, so we can verify the request. You may also use an authorized agent, and we will verify their authority before acting. We honor verified requests within the timeframes required by law.

If your browser or device sends a Global Privacy Control (GPC) signal, we treat it as a valid request to opt out of sale/sharing where we can technically honor it on savorapp.ai. You can also limit cookies through your browser settings, decline App Tracking Transparency on iOS, and reset or limit your advertising ID in your device settings.

Children's Privacy

Savor is not directed to children under 13. If you believe we've inadvertently collected data from a child, contact us to request deletion.

Security

We use industry-standard safeguards to protect data in transit and at rest. No system is 100% secure; we continuously work to protect your information.

Changes to This Policy

We may update this policy as the app evolves. Material changes will be reflected on this page with an updated effective date.

We update this policy and the corresponding App Store and Google Play privacy labels before a new data practice takes effect for users.

Contact

If you have questions or requests regarding this policy, contact:

support@savorapp.ai