Privacy, in plain language

Savor Privacy Policy

Last updated:

The short version

Savor is built to help you capture and act on your intentions, not to monetize them. This notice covers the Savor mobile app and savorapp.ai.

  • Your cards are yours. Savor requires a free Apple or Google sign-in. We store your cards under your account for synchronization and recovery, while keeping an offline copy on your device.
  • AI is used when you ask for it. Savor sends only the text, image, audio, or relevant memory needed for that request—not your whole library. We do not use private Savor Content to train general-purpose AI models. Health-related information you choose to enter is treated as private Savor Content and processed only for features you request.
  • Product analytics do not include your content. We use a pseudonymous app-install identifier and content-free events to understand which features work. Crash reports can be turned off in Settings.
  • Savor is for ages 13 and older. On supported devices, the app consults Apple or Google Play for a privacy-preserving age range where the store says a check is required. Savor never asks for a birth date or its own age question. A store-reported under-13 range is blocked. If the store reports no requirement and shares no range, Savor opens without saving or inferring an age band.
  • Advertising measurement is optional and starts off. Website and mobile choices are separate. If you turn measurement on, Meta receives limited device or campaign information, never your cards, voice, or photos. Some privacy laws call this a “sale” or “share” even though no money changes hands.
  • Sharing is your choice. A card and its conversation are shown only to the people you choose. Photos do not travel with a shared card. A copy you shared can remain with its recipients after you delete your account; your name is then shown as “Someone.”
  • You can delete your account and Savor-held data. Use Settings → Account → Delete Account, or email us. Uninstalling the app by itself does not delete synced data. Website download-link signups store the email needed to send the link until you ask us to delete it.

What Savor is

Savor is a calm capture app for intentions — things you want to remember, organize, revisit, or act on later. On the surface it feels simple; underneath it is designed as a privacy-preserving layer for user-owned intent.

This policy covers savorapp.ai (our website and download-link signup) and the Savor mobile app for iOS and Android. Where website and app practices differ, we say so plainly.

Savor is operated by Cognitive Infrastructure, Inc., the controller of the personal data described in this policy. Our postal address is 396 Vineyard Point Road, Guilford, CT 06437, USA.

Representative

We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:

  • European Union (EU)
  • United Kingdom (UK)

Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/savorapp

What we collect and why

We collect only the categories needed for the uses below. “Savor Content” means the cards, notes, voice-derived text, photos, and related details you choose to give Savor.

Account

Your internal user ID, sign-in email (including an Apple private-relay address), display name, and provider tokens let us authenticate you, sync your account, recover it, and provide account features. If you use collaboration, we also store the version of the Terms and Community Rules you accepted and the server time of acceptance.

Your content

Cards and related metadata are stored locally and under your account so Savor can organize, resurface, sync, recover, notify, and share only when you choose. Photos are optional.

AI requests

Text, images, audio, and relevant on-device memory are processed only when you use the feature, to transcribe, extract, organize, research, or help you act on that request.

AI answer reports

If you report a Take action answer, Savor keeps the displayed answer, your selected reason, and limited account and request identifiers so Support can review the report and prevent duplicate or abusive submissions.

Product and device data

A pseudonymous app-install identifier, feature events, device and app version, crash details, and minimized server logs help us improve Savor, keep it reliable, and prevent abuse. They do not include Savor Content.

Optional ad measurement

Only after an affirmative choice, limited campaign events, browser details, a hashed signup email, or a resettable advertising ID help us measure our own ads. Savor Content is never included.

Website signup

If you request a download link, we use your email to confirm signup and send that link. We also process information required for security, legal obligations, and verified privacy requests.

Age assurance

On a fresh install, the app consults Apple's or Google Play's age-range service where the store says a check is required. Savor does not ask its own age question. When the store supplies a range, we may retain only the 13–17 or 18+ band, the time of the check, and the policy version—not exact age or store verification details. If no range is supplied and no check is required, we do not save or infer an age band.

Subscriptions

If you use Full SAVOR, the app stores and RevenueCat process an account-linked customer identifier, purchase history, product, subscription status, and renewal dates so Savor can validate, unlock, restore, and support the subscription. Savor does not receive your payment-card details.

When we use AI providers

When Savor uses an AI provider, it may receive the specific text, image, or audio you asked Savor to process — not your full Savor database. Where possible, ordinary parsing requests are not sent with your account profile and do not include your name, email, waitlist record, analytics ID, or unrelated captures. Content is transmitted over HTTPS/TLS.

Intention assistance. When you open Take action on an intention, OpenAI's moderation endpoint first checks the direction you type, separately from the model that writes the answer. Savor then sends Anthropic's Claude Sonnet 5.5 that direction, a digest of the intention's current facts and open questions (phone numbers, email addresses and links are reduced to their kind), facts you have confirmed in other intentions, and your first name — never your full Savor database, your email address, or your analytics ID. When a Take action step needs public research, Savor sends the research request and relevant context to OpenAI's GPT-5.6 Luna, which uses web search to look up world facts such as opening hours or school calendars.

Anthropic's published commercial-product policies and OpenAI's published API policies state that commercial or API customer inputs and outputs are not used to train models by default unless the customer opts in. We have not opted in. Provider-side retention may still apply under those policies.

For an account in the 13–17 age band, Savor holds Claude Sonnet 5.5's finished Take action answer and sends that text to OpenAI's moderation endpoint. The answer is shown only after it clears the check. Flagged output, or output that cannot be checked, is withheld. OpenAI receives the text being checked and a stable, pseudonymous safety identifier for this purpose, not the raw Savor account ID.

Reporting a generated answer. A signed-in person can choose Report this answer on a visible Take action answer and select one fixed reason. The report contains the displayed model-written answer (up to 4,000 characters), the selected reason, your Savor account ID, the intention and Take action surface identifiers, and report timestamps and status. It does not include your prompt or typed direction, card title or body, answers to follow-up questions, conversation history, surrounding context, another person's account ID, or a free-form allegation.

Savor Support reviews these reports, with a target of the next business day. The report evidence stays in Savor's private human-review queue; it is not sent to an AI provider, product analytics, crash reporting, or application logs. Accepted reports expire after 90 days unless account deletion removes them sooner or counsel approves a legal hold. A connection failure is not queued on your device; the app says the report was not sent and lets you retry. Reporting is not an emergency service.

Voice Input

When you use voice to create a reminder, audio is processed into text. Depending on your settings and network availability, transcription may occur on-device or via a secure API.

The resulting text is used to generate a reminder. We do not sell your audio or transcripts.

Advertising measurement

On this website, Meta Pixel and Conversions API remain off unless you affirmatively choose Allow measurement. If allowed, Meta may receive page and signup events, a hashed version of a signup email, advertising cookie identifiers, IP address, and browser information so we can measure campaign results. Website consent is separate from the mobile app setting and can be withdrawn here at any time.

Like most apps, Savor occasionally runs ads to reach new people. To see whether those ads actually work, we offer optional Meta advertising measurement in the mobile app. It is off on iOS and Android unless you affirmatively enable Meta ad measurement in Savor Settings. If enabled, the Meta (Facebook) SDK may receive your device's resettable advertising identifier and a few basic milestones like opening the app, finishing setup, creating your first reminder, or returning to or completing a reminder. This helps us learn which ads work.

We share only that advertising identifier and those content-free milestones. We never send Meta the content of your reminders, your voice recordings, your photos, or your name or email.

You're in control. On iPhone, Apple's App Tracking Transparency permission is also required after your in-app choice. You can withdraw consent anytime by turning Meta ad measurement off in Savor Settings. You can also reset, delete, or limit your advertising identifier in system settings. Savor's core features work the same either way.

Photos

When you choose to capture a photo, such as a bill or receipt, the image is sent securely to our backend and trusted processors solely to extract the relevant text for your reminder. The image stays on your device after processing; Savor's production service does not currently store photo bytes for account sync. We do not use your photos for advertising, and we do not sell them.

Where your information is stored

  • Your reminders database is stored on your device. This supports offline use and keeps your cards available during network interruptions.
  • Settings and lightweight state (e.g., whether you've seen a tutorial) are stored locally (AsyncStorage) on your device.

Savor also stores card content and metadata under your signed-in account using Google Cloud Run and Firestore. This supports synchronization across signed-in devices and recovery after a reinstall. Photos and other binary attachments remain on the device; the synced card may contain attachment metadata or a device-local reference.

Memory — what Savor remembers

Savor builds a small memory from the intentions you work through, so it can stop asking what you have already told it. This memory has three parts, and all of it lives in the database on your device:

  • Facts you established. Things you confirmed or typed while working on an intention — for example who a person is to you, a standing preference, or a birth year when you mention an age. Savor keeps the fact, not the sentence.
  • Things that happened. When you finish an intention, Savor keeps a short record of what it was, when, who was involved, where, and how it ended.
  • Patterns Savor noticed. Rhymes across finished intentions (“winter trips”) that Savor may offer as a suggestion. It never treats them as facts, and they are recomputed from the records above, so they go when those records do.

This memory is not uploaded to our servers. When you have turned on cloud AI for an intention, the relevant parts of it travel with that request as context (see “Cloud Services”), and the request is processed by our AI providers under the same terms as the rest of your intention. Health-related intentions are kept separate and are only ever used inside another health intention, never as a preference or a pattern.

Deleting your account, or the app, erases this memory from that device.

Cloud services

If you use features that call our backend (e.g., voice parsing), we process only the fields needed to complete the request. When server sync is enabled, the backend also processes card content and metadata to synchronize your account. Logs are minimized and used to maintain reliability and security.

We do not sell your data. We do not share the content of your reminders, voice, or photos with third parties for advertising. The one identifier we share for advertising — an optional resettable device advertising ID, only after your affirmative in-app choice — is described in “Advertising measurement.”

Sharing a card

Card sharing is available in Savor and is opt-in for each card. You choose a person in the app or hand them a private link; there is no public directory and Savor never addresses a share by email. A card can have at most 12 participants.

The people on a shared card can see its title, notes, location, dates, details, the sharer's display name, and every participant's display name. They can also see Chat messages and the activity trail, including joins, leaves, which fields were edited, and timestamps. This information is stored in private Firestore records so the shared card stays in sync. Photos do not travel with a shared card.

Blocking is silent and absolute: shares from a person you blocked are dropped, and they are not told. Deleting your account doesn't take back cards you shared: they stay with the people you shared them with.

Notifications

If enabled, Savor schedules local notifications on your device (e.g., daily summaries, time-based reminders, gentle nudges). You can turn these off anytime in Settings or your system settings.

Savor also includes Firebase Cloud Messaging. Its messaging software initializes in current app builds and Firebase may receive the app-instance or device token needed to prepare push delivery. Savor's production server does not currently send push notifications or register production-user tokens. In testing distributions where push is enabled, a notification may contain a participant's name and an event type, but never card content, Chat text, photos, or reminder details.

Product analytics and diagnostics

We use Mixpanel to understand content-free product usage, such as which features are used and whether onboarding completed. Events are associated with a pseudonymous app-install identifier, not your name or email, and never include the content of your cards, voice, or photos.

When Savor crashes or hits an unexpected error, we send a diagnostic report to Sentry so we can find and fix it. The report contains the technical stack trace, your device model, OS version and app version, and the same pseudonymous identifier we use for analytics. It never contains the content of your reminders, your voice recordings, or text from anything you scan. These reports are processed under a data processing agreement. You can turn crash reporting off in Settings.

Service providers

We use the following services. This table lists what each one does and what data they may receive. Links point to their own privacy policies. We require providers acting for Savor to protect personal data consistently with our instructions, this policy, and applicable law.

ServiceRoleData shared
VercelHosts savorapp.ai and serverless API routesRequest logs, IP, user agent; deployment metadata. No app intent content.
Firebase / FirestoreDownload-link signups; account identity, card sync, card sharing, and the private safety-review queue (app backend)Website: email, hashes, attribution cookies, IP, user agent. App: account identity, signed-in card content and metadata, and the shared-card content, display names, Chat, and activity described above. If you submit a safety report, the report record described in the AI section.
Firebase Cloud MessagingInitializes messaging support and delivers testing-enabled push notificationsApp-instance or device push token. Testing-enabled notifications carry a participant name and event type only — never card content, Chat text, photos, or reminder details.
ResendTransactional welcome email after download-link signupRecipient email address, email content
Meta Pixel / Meta Conversions APIWebsite conversion measurement when available and affirmatively allowedHashed email on signup events; page events; advertising cookie identifiers; IP address; browser information. See “Advertising measurement.” No private Savor Content.
Google Cloud RunHosts the Savor API (voice, photo, auth, sync, inbox, invites)Request payloads needed to fulfill each feature; truncated operational logs
OpenAISpeech-to-text and AI parsing when you use capture features; GPT-5.6 Luna research for the Take action pane; moderation checks on Take action input; and output-safety checks for accounts in the 13–17 age band.The audio, image, or text you submit for that request; for Take action, the direction you type for input moderation and, when research is needed, the research request and relevant intention context; for teen safety, the finished Sonnet text and a pseudonymous safety identifier. Handled under OpenAI's API terms; not used to train its models by default.
AnthropicClaude Sonnet 5.5 for parts of the Take action pane.The direction you type, a redacted digest of the intention, relevant confirmed memory context, and your first name — not your full library, email address, account ID, or analytics ID. Handled under Anthropic's commercial API terms; not used to train its models by default.
MixpanelContent-free product analytics (app)Pseudonymous app-install identifier and limited event details — no card content
SentryCrash and error diagnostics (app and backend)Stack traces, device model, OS and app version, and a pseudonymous identifier — never reminder content, voice transcripts, or scanned text
Apple App Store / Google PlayApp distribution, subscription billing, and store links on websiteStandard store install analytics and, if you subscribe, purchase and subscription records controlled by Apple/Google. No capture content.
RevenueCatValidates purchases and maintains Full SAVOR entitlement statusSavor account customer ID, store purchase history, product and subscription status, and renewal dates. No Savor Content or payment-card details.
Sign in with Apple / Google Sign-InAccount sign-in (required to use the app)Email, name, provider tokens during sign-in
Meta SDK (app, iOS and Android)App-install attribution and measurementStandard app activation / registration / retention events; a resettable advertising ID — only after affirmative in-app consent; iOS also requires ATT; withdrawal in Savor Settings disables measurement on either platform
Firebase App DistributionInternal/beta build distribution (CI pipeline)Tester email addresses provided for beta access

How long we keep information

Data typeTypical retention
App intents / tasks (local)Until you delete them or uninstall the app
App intents / tasks (server-synced)Until you delete the card or your account. A content-free deletion record is kept for up to 90 days so deletion can reach signed-in devices and retries can finish.
Voice audio sent for transcriptionDeleted on device and our API after transcription; provider-side handling governed by OpenAI policies
Photo / text sent for AI parsingHandled as request-time input on our API; provider-side retention governed by OpenAI's policies
Take action input, relevant context, research requests, and model outputHandled as request-time input on our API; provider-side retention is governed by Anthropic's and OpenAI's commercial API policies
AI answer safety reports you submitUp to 90 days, or deleted sooner with your Savor account. A counsel-approved legal hold may require longer retention.
Memory facts and finished-intention records (on your device only)Until you delete your account or uninstall the app
Patterns Savor noticed (on your device only)Recomputed from the records above; gone when they are
Email-to-inbox (server)Raw email: about 7–30 days; parsed metadata: up to about 90 days
Download-link signups (website)Stored in Firestore until deleted upon request
Invite signup (name + email)Stored with invite redemption in Firestore until deleted upon request
Sign-in session tokensUp to 90 days
Account identity (email, name, user ID)Until you delete your account or ask us to; we then delete them
Terms and Community Rules acceptanceThe accepted version and server timestamp stay with the account until you delete it.
RevenueCat purchase and subscription recordKept while needed to provide, restore, and account for the subscription. Account deletion asks RevenueCat to delete its customer record; Apple or Google may retain transaction records under their own policies and legal requirements.
Store-supplied eligible age band and assurance metadata, when availableUntil you delete your account. People in the 13–17 band are asked to complete the age check again after one year. Exact age, birth date, store install ID, and verification method are never kept by Savor. If the store provides no range and reports no requirement, Savor keeps no age band.
Mixpanel analyticsPer Mixpanel project retention settings unless you delete your account or ask us to; we then submit deletion of the random app install ID and your Savor account ID to Mixpanel
User-sent error reportsUp to 50 recent errors on device; server copies per operational logging practices

What we do not do

  • We do not sell your personal information for money. We do not broker, rent, or otherwise monetize your information to data brokers.
  • We do not sell or share private Savor Content for advertising. Your captures are for your productivity, not ad targeting or behavioral profiling. App capture content is not sent to Meta, Mixpanel, or other advertising partners for marketing purposes.
  • We do not use your private Savor Content to train general-purpose AI models. We do not build training datasets from your captures, voice audio, transcripts, photos, or task text.
  • We do not include capture content in product analytics. Our analytics use pseudonymous, content-free metadata — not task titles, notes, transcripts, or photos.
  • We do not use server-synced card content for advertising, product analytics, or training general-purpose AI models.

Your Choices

  • You can edit or delete reminders at any time in the app.
  • You can choose not to use voice capture, manage microphone permission in your system settings, and disable notifications in Savor Settings.
  • Website Meta measurement starts off. You can allow or withdraw it in the “Advertising measurement” section above; this choice is separate from the mobile app setting.
  • Mobile Meta advertising measurement starts off. You can choose to enable or withdraw it from the in-app Privacy setting, reset or limit your advertising ID in device settings, and decline app tracking on iPhone when prompted.
  • You can uninstall the app to remove local data from that device. Uninstalling alone does not delete server-synced cards.

Delete your account and data

The fastest option is in the app: Settings → Account → Delete Account. You can also request deletion without using the app by emailing support@savorapp.ai with “Account deletion request” in the subject and the email used for your account.

Deletion removes your account, cards, photos, backups, linked analytics identifiers, and other account data from Savor's servers and that device. Other current-version devices signed in to the account are signed out and erase their local copy. We keep a content-free deletion record for up to 90 days so deletion can propagate and failed retries can finish.

A card you shared stays with its recipients and shows you as “Someone.” Deleting your account does not cancel an App Store or Google Play subscription; cancel the subscription in the store first. Uninstalling Savor alone does not delete your account.

Your privacy rights

Privacy rights differ by location. We will not discriminate against you for exercising a right that applies to you. Email support@savorapp.ai with “Privacy request” in the subject. We may verify your identity and, where permitted, an authorized agent's authority before acting.

Consumer health data privacy

This section applies when a law such as the Washington My Health My Data Act covers health-related information you choose to put in Savor. Savor is not a healthcare provider and is not designed to diagnose or treat a condition.

What health data we may process and why

  • Categories: health conditions, symptoms, medications, appointments, care plans, health-related locations, or similar information you place in a card, note, photo, voice capture, or AI request.
  • Sources: you provide the information directly, or another person provides it in a card they choose to share with you. Savor does not infer health status from unrelated activity.
  • Purposes: capture, organize, store, sync, recover, remind, share at your direction, process a voice, photo, or AI feature you request, and review an AI-answer safety report you choose to submit. Health-related on-device memory stays separate from non-health preferences and patterns.

Who may receive it

Google Cloud and Firebase process card content for account storage and sync and store a safety report you choose to submit. Savor Support may read the reported answer for human review. Anthropic receives only the health-related content needed for parts of a Take action request. OpenAI receives only the health-related content needed when you request voice, photo, parsing, Take action input moderation or research, or, for a known teen account, output moderation. People you choose can receive a health-related card you share. We do not send consumer health data to Meta, Mixpanel, or Sentry, and we do not sell it. We do not use geofencing around healthcare facilities to identify or target anyone.

Your choices and rights

You choose whether to enter health information or use a feature that processes it. Where consent is required, Savor asks before collection or sharing beyond what is necessary to provide the feature you requested. You may ask to confirm, access, correct, delete, or receive a copy of consumer health data; withdraw consent for future processing; or appeal a denied request. Email support@savorapp.ai with “Consumer health data request” or “Privacy appeal” in the subject. We will not collect or use an additional category of consumer health data for a new purpose without first updating this disclosure and obtaining consent when the law requires it.

European privacy information

If you are in the European Economic Area, European Union, or United Kingdom, this section explains our legal bases and your rights. The controller is Cognitive Infrastructure, Inc. at 396 Vineyard Point Road, Guilford, CT 06437, USA; contact support@savorapp.ai.

Legal bases

  • Contract: sign-in, card storage and sync, sharing you initiate, notifications, support, and AI processing you request.
  • Legitimate interests: security, abuse prevention, reliability, human review of safety reports, content-free product analytics, and improving Savor, balanced against your rights. You may object to this processing.
  • Consent: optional website and mobile Meta measurement and permissions where consent is required. You may withdraw consent at any time; this does not affect earlier lawful processing.
  • Legal obligation: records and disclosures the law requires.

Teen eligibility and consent

The age at which a teenager can provide their own consent for an online service or optional data processing varies by European country. A 13+ age check does not, by itself, establish valid consent in every location. Savor may limit teen availability or a consent-based optional feature where local law requires additional authorization.

International transfers

We and several providers are in the United States. Where European transfer rules apply, we use an adequacy decision or safeguards such as the European Commission's Standard Contractual Clauses with appropriate technical and organizational measures. Contact us for details about a particular transfer.

Your European rights

Subject to legal limits, you may access, correct, erase, restrict, or receive a portable copy of personal data; object to legitimate-interest processing; and withdraw consent. Savor does not make solely automated decisions that produce legal or similarly significant effects. You may complain to the data-protection authority where you live, work, or believe a violation occurred.

EU and UK representative

We appointed Prighter Group with its local partners as our privacy representative and point of contact for:

  • European Union (EU)
  • United Kingdom (UK)

To contact Prighter or exercise your data-subject rights through it, visit https://app.prighter.com/portal/savorapp.

California privacy rights

This section applies to California residents under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Our plain-English position: we do not sell your information for money, and we do not sell or share your private Savor Content (reminders, voice, or photos) for advertising.

Personal information we collect and disclose

Over the past 12 months we have collected the following categories of personal information. We disclose the categories marked below to Meta for our own advertising measurement — this can be classified as a “sale” or “share” under the CCPA/CPRA even though we receive no money for it. We collect information directly from you, automatically from your device and use of Savor, and from Apple or Google when you sign in.

  • Identifiers — email address, hashed email (signup events), advertising cookie identifiers, device advertising identifier. Disclosed to Meta for advertising measurement.
  • Internet or network activity — page views, signup conversions, in-app feature events (content-free). Website conversion events disclosed to Meta.
  • Device / technical data — IP address, user agent, OS and app version. Disclosed to Meta as part of measurement.
  • Age range — a store-supplied 13–17 or 18+ band and assurance metadata, when available. Exact age, birth date, and store verification details are not collected by Savor. Not sold or shared for advertising.
  • Private Savor Content — reminders, voice-derived text, photos, notes, and an AI answer you report. Never sold or shared for advertising.
  • Inferences — inferences drawn from your intentions (preferences, patterns). Collected on your device only; not sold or shared; erased from that device when you delete your account or the app.

For an account with a current 13–17 band, optional mobile advertising measurement is unavailable and any earlier consent is cleared. If no age band is available, Savor does not infer that the person is an adult; measurement still requires affirmative in-app consent and, on iPhone, ATT. People under 13 are not eligible to use Savor.

Your rights

  • Know / access: request the categories and specific pieces of personal information we have collected about you
  • Delete: request deletion of personal information we hold
  • Correct: request correction of inaccurate personal information
  • Opt out of sale/sharing: opt out of the sale or sharing of personal information for cross-context behavioral advertising
  • Non-discrimination: we will not deny service, charge a different price, or provide a different quality of service for exercising these rights

How to exercise your rights

To make a request — including Do Not Sell or Share My Personal Information — email support@savorapp.ai with the subject line California Privacy Request. Include the email address connected to your Savor account or website signup, if any, so we can verify the request. You may also use an authorized agent, and we will verify their authority before acting. We honor verified requests within the timeframes required by law.

If your browser or device sends a Global Privacy Control (GPC) signal, we treat it as a valid request to opt out of sale/sharing where we can technically honor it on savorapp.ai. You can also limit cookies through your browser settings, decline App Tracking Transparency on iOS, and reset or limit your advertising ID in your device settings.

Other U.S. state privacy rights

Depending on where you live and the law that applies, you may have rights to access, correct, delete, or obtain a portable copy of personal data; opt out of sale, targeted advertising, or certain profiling; and appeal a request we deny. Savor does not use personal data to make decisions that produce legal or similarly significant effects.

Email support@savorapp.ai with “Privacy Request” or “Privacy Appeal” in the subject. You may also use the controls on this page to opt out of sale or sharing for advertising.

Children and teens

Savor is for people age 13 and older. On a fresh install, the app consults Apple or Google Play for a privacy-preserving age range where the store says an age check is required. Savor never asks for a birth date or its own age question. A required store verification or parental step cannot be bypassed inside Savor.

A store-reported under-13 range is stopped before sign-in or access to Savor's online features. Savor does not offer parent-managed accounts for children under 13. When the store supplies an eligible range, the app and private account record keep only the 13–17 or 18+ band, when the check happened, and the policy version—not exact age, store install ID, declaration method, or parental-control details. People in the 13–17 band are asked to complete the store check again after one year.

If the store reports that no age check is required and shares no range, Savor opens without saving or inferring an age band. In that situation, universal privacy, sharing, blocking, reporting, advertising-choice, and deletion protections still apply, but Savor cannot activate controls that depend on knowing a person is in the 13–17 band.

We use store age signals, verification and parental controls first for regional requirements. Country availability or the smallest necessary feature restriction may be used for a mandatory local exception the stores cannot enforce. These store controls support—but do not transfer—Savor's legal responsibilities.

Accounts with a current 13–17 band receive additional output-safety handling for model-written Take action answers. The privacy, sharing, blocking, advertising, and deletion protections described in this policy also apply. Our Teen Safety page explains each technical guardrail and its failure behavior.

If you believe someone under 13 has provided personal information to Savor, contact us so we can investigate and delete it.

Security

We use industry-standard safeguards to protect data in transit and at rest. No system is 100% secure; we continuously work to protect your information.

Changes to This Policy

We may update this policy as the app evolves. Material changes will be reflected on this page with an updated effective date and, where required, an additional notice or consent request.

We update this policy and the corresponding App Store and Google Play privacy labels before a new data practice takes effect for users.

Recent policy changes
  • September 18, 2026: Take-action processing moved from Anthropic to OpenAI.
  • September 22, 2026: Clarified account sync, Android advertising measurement, privacy controls, and account deletion steps.
  • September 23, 2026: Added card-sharing and Firebase Cloud Messaging details.
  • September 29, 2026: Clarified that website and mobile Meta measurement remain off until separate affirmative choices.
  • September 30, 2026: Added a layered summary, direct deletion guidance, and consumer-health and broader regional-rights information; clarified that account deletion submits linked Mixpanel identifiers for deletion; documented the 13+ age-assurance and teen AI-output safeguards; clarified that age checks are store-led where required and that Savor asks no age question of its own; and disclosed the content-free Terms and Community Rules acceptance record, subscriptions, and RevenueCat.
  • October 1, 2026: Added the appointed EU and UK representative language and Prighter rights-request portal.
  • October 1, 2026: Disclosed that Claude Sonnet 5.5 handles parts of Take action while GPT-5.6 Luna handles its public-information research, with OpenAI moderation on input and on finished output for known teen accounts.
  • October 1, 2026: Documented the in-app AI-answer reporting path, minimized report contents, human-review target, and 90-day retention limit.

Contact

For privacy questions, requests, or accessibility help with this notice, contact Cognitive Infrastructure, Inc. at:

support@savorapp.ai
396 Vineyard Point Road, Guilford, CT 06437, USA