SAVI Privacy Policy
Effective date: July 28, 2026
SAVI helps you save useful things from your digital life and find them later. SAVI is local-first: your saved library stays on your iPhone unless you deliberately export it or choose an optional feature that clearly says it uses cloud processing.
SAVI is provided by Andreus Bello-Lif. For privacy purposes, Andreus Bello-Lif is the controller of information processed by SAVI's optional cloud service and support channels.
SAVI does not sell personal information, show ads, or track you across apps or websites owned by other companies.
Why SAVI Processes Information
SAVI processes information only for the purposes described in this policy. Depending on the feature and where you live, the legal basis is:
- your request to provide the app or support service;
- your consent for optional SAVI Sense cloud processing, which you can revoke;
- SAVI's legitimate interests in securing, preventing abuse, troubleshooting,
- compliance with a legal obligation or protection of legal rights.
and maintaining the service, balanced against your rights; or
Declining or revoking optional cloud consent does not prevent local SAVI organization from working. SAVI Sense suggestions do not make decisions that produce legal or similarly significant effects about you.
What SAVI Stores On Your Device
Depending on what you choose to save, SAVI may store links, titles, summaries, source names, folders, tags, notes, thumbnails, screenshots, images, PDFs, files, audio, places, and related timestamps. SAVI also stores app preferences and folder organization on your device.
Private Vault items are protected by the device-authentication controls available on your iPhone. They remain local and are not eligible for SAVI Sense cloud processing.
Apple may include SAVI data in an iCloud device backup if you enable that Apple feature. SAVI does not operate or access your iCloud device backups.
Link Metadata And Previews
When you save or open a web link, SAVI may contact the linked website or its normal web resources to obtain a page title, description, source name, icon, or thumbnail. As with ordinary browsing, the website may receive the requested URL, your IP address, and standard network information.
Optional SAVI Sense Cloud Processing
SAVI Sense can suggest a clearer title, summary, folder, or tags. Local organization can work without cloud processing.
Cloud SAVI Sense is optional. Before SAVI creates a cloud session or sends a SAVI Sense request, the app explains the feature and asks for versioned permission. You can decline, stop current processing, or revoke permission in Settings.
When you permit cloud SAVI Sense, SAVI may send a minimized text-only request to SAVI's protected backend and an AI processing provider. The request may include text you chose to save, a web address, page or source text, and the folders or tags needed to return an organization suggestion. SAVI does not send image pixels, screenshots, PDF pages, audio, file bytes, Private Vault items, locked-folder content, or content detected as credentials, financial, identity, medical, legal, or similarly protected information.
Cloud results may be inaccurate. Review important titles, summaries, and organization choices before relying on them. SAVI does not use saved content for advertising, and SAVI does not permit its AI processing provider to use SAVI requests to train public models.
Cloud Session, Security, And Reliability Data
After cloud permission, SAVI may create a private anonymous backend session. SAVI may process:
- an anonymous user identifier;
- a hashed installation or device-abuse identifier;
- Apple device-integrity evidence;
- CAPTCHA or abuse-prevention evidence;
- request identifiers, request state, timestamps, quota state, and deletion
- app version, build, coarse device or operating-system details, and technical
state;
diagnostics needed to secure and operate the service.
Cloudflare may process CAPTCHA and ordinary security/network data but does not receive the saved text sent to SAVI Sense. Apple may process device-integrity evidence. SAVI's backend and AI processing provider process only the minimized request needed to deliver the optional feature.
SAVI's production backend is hosted in the European Union. Some service providers may process information in other countries under their applicable privacy and transfer safeguards.
When information must be transferred from the EEA, UK, or Switzerland to a country without an applicable adequacy decision, SAVI requires an available lawful transfer mechanism, such as approved standard contractual clauses or an equivalent safeguard, together with any supplementary measures required for the processing. You may ask [email protected] for information about the applicable transfer safeguard.
Security And Incident Response
SAVI uses technical and organizational safeguards designed for the nature and limited amount of information processed, including data minimization, bounded retention, access controls, transport protection, integrity checks, and separation of local Private Vault content from eligible cloud processing. No app, device, network, or cloud service can be guaranteed completely secure.
SAVI maintains a process to investigate suspected incidents, reduce harm, preserve necessary evidence, and provide notices to affected people or authorities when applicable law requires them. Report a suspected SAVI security issue to [email protected] without including passwords, identity documents, financial records, Private Vault items, or other sensitive content.
Retention And Deletion
SAVI Sense request content and results expire 24 hours after creation. An hourly cleanup normally removes expired records during the next scheduled run; cleanup failures are monitored and escalated.
Content-free operational, security, quota, and completed deletion-proof records expire 30 days after creation and are normally removed during the next hourly cleanup. Unresolved deletion safety tombstones may be retained beyond 30 days only until the backend can verify that deletion is complete. These tombstones contain no saved content or raw deletion proof, and an unresolved record older than 24 hours triggers an operational alert.
Inactive anonymous cloud identities are scheduled for deletion after 30 days of inactivity once activity and session checks pass.
The contracted AI processing provider may retain request data for security and abuse monitoring for up to 30 days. SAVI does not permit the provider to use SAVI requests to train public models.
You can delete SAVI Sense cloud data in the app:
Settings → SAVI Sense → Delete SAVI Sense Cloud Data → Delete Cloud Data
The app provides a deletion request identifier and retries safely if a network interruption prevents immediate confirmation. Revoking cloud permission stops new cloud processing. See /data-deletion for full instructions.
You can delete local saves inside SAVI. Removing SAVI from your iPhone deletes its local app container, subject to copies or backups you control.
Accounts, Social Features, Sync, And Notifications
The App Store 1.0 release does not include personal accounts, Friends or public social profiles, SAVI cloud-library sync, remote push notifications, or cross-app advertising analytics. Core saving does not require you to provide a name, email address, phone number, or contacts.
Support
If you email support, SAVI receives your email address and whatever information you choose to include. Support messages are used to answer you, investigate problems, and protect the service. Do not send passwords, identification documents, financial records, Private Vault items, or other sensitive saved content.
Children
SAVI is not directed to children under the minimum age required by applicable law to consent to data processing. SAVI does not knowingly collect personal information from children in a way that requires parental consent.
Your Choices And Rights
You can keep cloud SAVI Sense off, revoke its permission, delete its cloud data, delete local items, export your library, or remove the app. Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to processing of personal information.
If EEA or UK data-protection law applies, you may also have the right to data portability, to withdraw consent without affecting earlier lawful processing, and to lodge a complaint with the supervisory authority where you live, work, or believe an infringement occurred. Because SAVI 1.0 uses an anonymous cloud session and does not require a personal account, SAVI may need a deletion request identifier or other reasonable proof to locate a request without collecting unnecessary identity data.
For privacy questions or rights requests, email [email protected]. For general help, email [email protected].
Changes
If SAVI's data practices materially change, this policy and the App Store privacy details will be updated before the new practice is used.
Contact
Privacy: [email protected]
Support: [email protected]