Effective Date: January 1, 2024
Last Updated: February 21, 2026
At Savida, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application. Please read this privacy policy carefully.
We collect the following data types to operate Savida:
Contact Info (name, email)
Purpose: Account, Support
Provider: Supabase Auth
Linked to you: Yes • Tracking: No
Identifiers (device ID)
Purpose: App functionality, Security, Diagnostics
Provider: Sentry, Amplitude, Firebase
Linked to you: Yes • Tracking: No
Financial Info (last 4 digits, balances, transactions)
Purpose: Core finance features
Provider: Plaid
Linked to you: Yes • Tracking: No
AI Coach Data (pseudonymized spending summaries and prompts)
Purpose: AI coaching personalization
Provider: OpenAI API
Linked to you: Yes • Tracking: No
Usage Data (app interactions)
Purpose: Analytics, Product improvement
Provider: Amplitude, Firebase
Linked to you: Yes • Tracking: No
Session Analytics
Purpose: UX improvement (opt-in EEA/UK/CH)
Provider: Microsoft Clarity (iOS SDK)
Linked to you: No • Tracking: No
Diagnostics (crashes, performance)
Purpose: App stability
Provider: Sentry, Firebase
Linked to you: No • Tracking: No
We do not sell data. We do not use collected data for cross-app tracking unless you grant permission (see Section 5 below).
When you create an account, we collect:
When you connect financial accounts, we collect:
We use your information to:
Our app integrates with third-party services. Below are comprehensive disclosures for each service:
We use Plaid Inc. ('Plaid') to link your financial accounts to Savida. Plaid's services are governed by their Privacy Policy at https://plaid.com/legal/.
When you link accounts through Plaid:
Before first use of AI Financial Coach, we ask your permission in-app for AI data sharing. When enabled, we send pseudonymized text to our AI provider (OpenAI API). We remove direct identifiers (name, email, account IDs) and do not include full account numbers or bank credentials.
We use Supabase for secure user authentication and account management. Supabase processes your email address, password (encrypted), and authentication tokens to provide secure login. Your authentication data is encrypted in transit and at rest. You can delete your account and associated data in Settings → Account → Delete Account. Privacy policy: https://supabase.com/privacy
We use Google Firebase services for app functionality, analytics, and crash reporting. Firebase collects:
Firebase uses cookies and mobile identifiers. Data is used for app improvement, personalization, and bug fixing. For more information, see Google's Privacy Policy at https://policies.google.com/privacy.
We use Amplitude to analyze app usage and user behavior to improve Savida. Amplitude processes:
We do not share personally identifiable information beyond what's necessary for analytics. Amplitude does not sell user data to third parties. Your data is encrypted in transit and at rest. You can request deletion of your data by contacting [email protected]. Learn more at https://amplitude.com/privacy.
We partner with Microsoft Clarity to capture how you use and interact with Savida through behavioral metrics, heatmaps, and session analysis using the native iOS SDK. This helps us improve our product and user experience.
Clarity collects:
We mask fields that may contain personal or financial data (including account numbers, amounts, names, and passwords). Session recordings are never stored on your device. App usage data is captured using first-party technologies. Microsoft may use this data for product improvement and advertising purposes. For more information, visit https://privacy.microsoft.com/privacystatement.
For EEA, UK, and Switzerland users: We obtain your consent before collecting this data as required by GDPR. Session recording is OFF by default unless you consent.
We use Sentry for error tracking and application monitoring. Sentry collects crash reports, error logs, device information (device model, OS version), and performance metrics. This data is used solely to identify and fix bugs and improve app stability. Sentry does not collect advertising identifiers or track users across apps. Data is encrypted in transit (TLS/HTTPS) and at rest (AES-256). For more information, visit https://sentry.io/privacy/.
We do not sell, trade, or rent your personal information. We share your information only in these situations:
Our service providers (Plaid, Supabase, OpenAI, Firebase, Sentry, Microsoft Clarity, Amplitude) must provide the same or stronger protections as this policy (per Apple Guideline 5.1.1). Each provider operates under their respective privacy policies, linked in Section 3 above.
AI Financial Coach is optional. Before your data is sent to OpenAI, we show an in-app permission prompt that explains exactly what data is sent and who receives it. You can allow or decline. You can change this anytime in Settings → Data & Privacy → AI Data & Consent.
We request only the permissions we need, and we explain why before iOS shows a system prompt. You can change permissions in iOS Settings → Savida and manage analytics/session recording in Savida → Settings → Security → Privacy. Opting out of analytics or session recording does not limit core budgeting/expense features.
For users in the EEA, UK, and Switzerland: Analytics and session recording are disabled by default. You will be asked to opt in when first using the app.
If any data we or our partners collect is used to track you across apps or websites, iOS will present the App Tracking Transparency prompt and we'll only proceed if you tap Allow. Currently, tracking features are feature-flagged and not active. When enabled in the future, you will have full control over tracking permissions.
You can control data collection in Settings → Security → Privacy:
We implement industry-standard security measures:
We retain your information for as long as your account is active or as needed to provide services. Specifically:
You have the right to:
You can delete your account at any time in Savida → Settings → Account → Delete Account. Deleting your account removes your profile and financial data from our active systems within 30 days and from backups within 90 days, except where we must retain information to comply with law, prevent fraud, or resolve disputes.
California residents have additional rights under the California Consumer Privacy Act (CCPA):
Categories of Personal Information We Collect:
Business Purposes for Collection:
Categories of Third Parties We Share With:
Your CCPA Rights:
We do not sell your personal information to third parties. To exercise your CCPA rights, contact us at [email protected].
If you are in the European Economic Area (EEA), UK, or Switzerland, you have rights under GDPR:
Legal Basis for Processing:
Your Rights:
Data Protection Officer: For privacy inquiries related to GDPR, contact our Privacy Officer at [email protected].
Residents of certain U.S. states (including Virginia, Colorado, Connecticut, and Utah) have similar rights to access, delete, and correct their data, which we will honor. Please contact us to exercise any applicable rights under state law.
Canadian residents have rights under PIPEDA including the right to access, correct, and delete personal information. For privacy inquiries, contact our Privacy Officer.
Savida is not intended for children. We do not knowingly collect personal information from anyone under the age of 13 (or under 16 in regions where a higher age threshold applies, such as the European Union). If we discover that a child under the applicable age has provided us with personal information, we will delete such information from our systems.
Your information may be transferred to and processed in the United States or other countries where our service providers operate. These countries may have different data protection laws than your country of residence. We ensure appropriate safeguards are in place for such transfers.
If you are located in Canada, the EEA, UK, or other regions with data transfer restrictions, we rely on appropriate legal mechanisms (such as Standard Contractual Clauses) to ensure your data is protected when transferred to the US.
Our mobile app uses local storage for:
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. For material changes, we will provide additional notice through the app or email.
We provide this Privacy Policy in English. If you require it in another language, please contact us.
If you have questions about this Privacy Policy or your data, please contact us:
Email: [email protected]
Address: 2224 Augusta Place, Santa Clara, CA 95051
This contact serves as our privacy officer for all jurisdictions including Canada, EU, and UK.
For data deletion requests: [email protected]